diff options
author | Maxim Dounin <mdounin@mdounin.ru> | 2021-06-28 18:01:04 +0300 |
---|---|---|
committer | Maxim Dounin <mdounin@mdounin.ru> | 2021-06-28 18:01:04 +0300 |
commit | 5f85bb3714a81d158f4d849ad5c61aec2737a9f0 (patch) | |
tree | 432fbcb511cea5b4f1583e365883af738f8c92d4 /src/http/modules/ngx_http_proxy_module.c | |
parent | d9c1d1bae7ae2c83fb65ca00a47ad6c1199a691e (diff) | |
download | nginx-5f85bb3714a81d158f4d849ad5c61aec2737a9f0.tar.gz nginx-5f85bb3714a81d158f4d849ad5c61aec2737a9f0.zip |
Added CONNECT method rejection.
No valid CONNECT requests are expected to appear within nginx, since it
is not a forward proxy. Further, request line parsing will reject
proper CONNECT requests anyway, since we don't allow authority-form of
request-target. On the other hand, RFC 7230 specifies separate message
length rules for CONNECT which we don't support, so make sure to always
reject CONNECTs to avoid potential abuse.
Diffstat (limited to 'src/http/modules/ngx_http_proxy_module.c')
0 files changed, 0 insertions, 0 deletions