httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Ben Laurie <...@gonzo.ben.algroup.co.uk>
Subject Re: spaces in HTTP headers
Date Fri, 17 Nov 1995 22:54:35 GMT
> 
> 
> 
> >  http://aqui.stllab.ibm.com
> 
> They have a system which requests URLs from other servers, their
> system adds an extra header to the HTTP headers, e.g. when talking
> to xxx.lanl.gov it added
> 
>  FOO: xxx
> 
> note the leading space. Apache created env var "HTTP_ FOO" = "xxx",
> and the shell rejected it when trying to do a "exec cmd"
> 
> My boss says that Apache should be fixed to not send the " " in the
> env var (that'd mean checking incoming HTTP headers against the spec).
> I say, slap the wrists of the people at ibm and be done with it.
> 
> I've mailed the resource owners to tell them about their spec
> violation.

Surely the correct thing to do is to reject it as an invalid request.

> 
> rob

-- 
Ben Laurie                  Phone: +44 (181) 994 6435
Freelance Consultant        Fax:   +44 (181) 994 6472
and Technical Director      Email: ben@algroup.co.uk
A.L. Digital Ltd,           URL: http://www.algroup.co.uk
London, England.

Mime
View raw message