-
Notifications
You must be signed in to change notification settings - Fork 2.1k
Sanitize length headers when validating quota #26366
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
@DeepDiver1975, thanks for your PR! By analyzing the history of the files in this pull request, we identified @PVince81, @MorrisJobke and @nickvergessen to be potential reviewers. |
|
Not sure why (you deleted the "Motivation" section 😉), but ok as a safeguard 👍 |
added again |
|
Thanks, makes sense! merging |
|
@DeepDiver1975 do we want a backport for this ? |
|
I guess so ... @Peter-Prochaska critical enough to backport this to earlier versions? THX |
|
@DeepDiver1975 @PVince81 its a good idea to backport this. It is not the big change... |
|
I will take care... |
|
This thread has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs. |
Description
In case an invalid value for one of the length headers is sent we ignore them when checking the quota
Motivation
By submitting a non numeric value as length header the quote checks could be bypassed.
Types of changes
Checklist: