Skip to content
  • Rémi Denis-Courmont's avatar
    HTTP access: validate user agent string · 2656ae56
    Rémi Denis-Courmont authored
    First, we should not let user shoot themselves in the foot. But most
    importantly, we need to validate the string as it is marked as a safe
    option (especially CRLF there could be disastrous).
    2656ae56