Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.Sign up
Missing Content-Type: create critical sibling of 920340 in PL2 #1118
This works as advertised.
Two minor things:
Could you capitalize "PL2: block" please?
The two rules have identical messages. This is a bit odd:
I'm not sure how to bring a clearer message across.
You got this right. Here is why:
920340 only brings 2 points. But it's a major evasion as you can work around URLENCODED bodyprocessor this way. Now @spartantri thinks mobile clients omit the header a lot, while @lifeforms says he hardly sees any FPs. As long as we do not know for sure we do not want to raise the severity of 920340, however, we want to make sure to block this evasion at PL2 by default. Hence the duplication via 920341.
I think it is odd, to bring a stricter twin of a rule, but here, I personally think it is appropriate.