Skip to content

Conversation

@agalakhov
Copy link
Member

This adds header limits in order to reject suspicious requests.

It were much better to use single-pass header parsing instead. Unfortunately, httparse does not support it yet and none of its alternatives is mature enough.

Copy link
Member

@daniel-abramov daniel-abramov left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for tackling this issue! I've left a couple of minor comments, but overall it looks good for a quick fix!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants