Re: Should allowHostHeaderMismatch be case sensitive

2023-12-15 Thread Mark Thomas
On 15/12/2023 14:48, Christopher Schultz wrote: Do we need to argue over encoding and/or rules of case-insensitive-matching? Could we? Probably. Do we need to? Unlikely. My expectation is that most clients aren't even including the host in the request line these days. Non-ASCII hostnames a

Re: Should allowHostHeaderMismatch be case sensitive

2023-12-15 Thread Christopher Schultz
Mark, On 12/15/23 04:12, Mark Thomas wrote: On 11/12/2023 17:20, Mark Thomas wrote: On 11/12/2023 17:08, David Cleary wrote: Just want to check if this is by design. The above property default was changed to better secure the default configuration. We started having some tests fail due to thi

Re: Should allowHostHeaderMismatch be case sensitive

2023-12-15 Thread Mark Thomas
On 11/12/2023 17:20, Mark Thomas wrote: On 11/12/2023 17:08, David Cleary wrote: Just want to check if this is by design. The above property default was changed to better secure the default configuration. We started having some tests fail due to this. In our scenario ( as shown below ), the H

Re: Should allowHostHeaderMismatch be case sensitive

2023-12-11 Thread Mark Thomas
On 11/12/2023 17:08, David Cleary wrote: Just want to check if this is by design. The above property default was changed to better secure the default configuration. We started having some tests fail due to this. In our scenario ( as shown below ), the Host header value in the HTTP request is