Message132393
If the spec forbids control characters in headers, the module should
enforce that.
The most frequent example of header injection is the redirect-case: an
application is forwarding using the Location header to a user-supplied
URL.
http://google.com/codesearch?as_q=self.redirect%5C%28self.request.get
Other examples are proxies, setting user-agent, or, as you mention,
custom set-cookies headers. |
|
| Date |
User |
Action |
Args |
| 2011-03-28 11:23:32 | Felix.Gröbert | set | recipients:
+ Felix.Gröbert, pje |
| 2011-03-28 11:23:32 | Felix.Gröbert | link | issue11671 messages |
| 2011-03-28 11:23:32 | Felix.Gröbert | create | |
|