comparison src/http/ngx_http_script.h @ 9242:ddcedfa3a809

HTTP: just one empty line now accepted when parsing request line. This ensures that multiple CRLFs cannot be used as a DoS vector, and also in line with RFC 9112 ("SHOULD ignore at least one empty line"). Further, bare CRs are no longer accepted.
author Maxim Dounin <mdounin@mdounin.ru>
date Sat, 30 Mar 2024 05:10:40 +0300
parents 3ab8e1e2f0f7
children
comparison
equal deleted inserted replaced
9241:07ca679842de 9242:ddcedfa3a809