|
|
|
|
|
by garblegarble
161 days ago
|
|
> If both are present but different the unprefixed version should be favoured. That seems uncontroversial & not complex to implement. oops, you just enabled smuggling where there's a mismatch between what a proxy/firewall/etc supports and what an internal service supports. X-Do-Evil: true
Do-Evil: false
|
|
That's not a reason not to consider it a threat vector when implementing, but no more than when implementing any header (that interacts with another)