redbot icon indicating copy to clipboard operation
redbot copied to clipboard

Detect Content-Length and Transfer-Encoding Conflict

Open mnot opened this issue 14 years ago • 1 comments

mnot avatar Jul 30 '11 03:07 mnot

   If a message is received with both a Transfer-Encoding header
   field and a Content-Length header field, the Transfer-Encoding
   overrides the Content-Length.  Such a message might indicate an
   attempt to perform request or response smuggling (bypass of
   security-related checks on message routing or content) and thus
   ought to be handled as an error.  The provided Content-Length
   MUST be removed, prior to forwarding the message downstream, or
   replaced with the real message-body length after the transfer-
   coding is decoded.

mnot avatar Feb 03 '12 12:02 mnot