Skip to content

Conversation

@ioquatix
Copy link
Member

@ioquatix ioquatix commented Jul 1, 2025

There are known security issues where content-length header is set more than once.

In addition, there are other headers which really shouldn't be set multiple times. Let's formalize this so that we fail with a bad request.

Types of Changes

  • Bug fix.
  • Breaking change.
  • Security.

Contribution

@ioquatix ioquatix force-pushed the singleton-header-enforcement branch from debde00 to 3733af5 Compare July 1, 2025 00:48
@ioquatix ioquatix force-pushed the singleton-header-enforcement branch from 3733af5 to b59646e Compare July 1, 2025 00:59
@ioquatix ioquatix merged commit 2c346ea into main Jul 1, 2025
36 of 40 checks passed
@ioquatix ioquatix deleted the singleton-header-enforcement branch July 1, 2025 01:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants