express
express copied to clipboard
test: add test for ignoring comma-separated X-Forwarded-Host when trust proxy disabled
Verify that req.host ignores comma-separated X-Forwarded-Host values when trust proxy is disabled, ensuring security by using Host header instead of potentially malicious forwarded headers