Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RFC 6265bis: Reject cookies with CTL characters #1576

Merged
merged 2 commits into from
Jul 20, 2021

Conversation

chlily1
Copy link
Contributor

@chlily1 chlily1 commented Jul 19, 2021

Reject cookies with any CTL characters, instead of truncating them. Addresses #1531.

@chlily1 chlily1 marked this pull request as ready for review July 19, 2021 20:57
@chlily1
Copy link
Contributor Author

chlily1 commented Jul 19, 2021

@sbingler @miketaylr PTAL, thanks!

@sbingler
Copy link
Collaborator

LGTM

@@ -2409,7 +2405,11 @@ The "Cookie Attribute Registry" should be created with the registrations below:

## draft-ietf-httpbis-rfc6265bis-09

* No changes yet.
* Update cookie size requirements:
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(Thanks for adding this one)

Copy link
Collaborator

@miketaylr miketaylr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm, thanks!

@chlily1 chlily1 merged commit ab8c088 into main Jul 20, 2021
@chlily1 chlily1 deleted the chlily1-remove-ctl-truncation branch July 20, 2021 19:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants