You are viewing a plain text version of this content. The canonical link for it is here.
Posted to github@trafficserver.apache.org by GitBox <gi...@apache.org> on 2021/06/02 14:20:28 UTC

[GitHub] [trafficserver] shinrich commented on pull request #7887: Fail parsing the request line version if there are too many characters

shinrich commented on pull request #7887:
URL: https://github.com/apache/trafficserver/pull/7887#issuecomment-853069532


   @maskit that is a very good point.  I have adjusted the PR to only change the default value of proxy.config.http.strict_uri_parsing from 0 to 1.  Probably having a default of 0 (disabled) made sense 15 years ago when many more clients played very loose with the spec, but these days good clients should be within spec and we should be in the more secure stance out of the box.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org