Chaitya Shah
Chaitya Shah
@ioquatix what is the max timeout that Falcon uses to exit in this case?
@ioquatix that appears to be a better approach as opposed to a timeout set by us @nateberkopec thoughts?
@nateberkopec, has there been any consensus on this yet? Should we introduce an optional host validation that can be enabled as needed? Additionally, based on this comment (https://github.com/rack/rack/issues/1970#issuecomment-1269061994), @ioquatix, does...
@ioquatix In my opinion it should be an optional configuration/middleware. However after reading [RFC 7230, Section 5.4](https://datatracker.ietf.org/doc/html/rfc7230#section-5.4) > Since the Host header field acts as an application-level routing mechanism, it...
> It isn't always, but yes, it can be a security issue. Let me know if you'd like to chat about it over a video call some time. @ioquatix Have...