Hacker News new | ask | show | jobs
by thayne 1256 days ago
Or it is defense in depth. Although blocking it even if the / is percent encoded seems a bit excessive, especially as a default.