Fetching contributors…
Cannot retrieve contributors at this time
26 lines (21 sloc) 873 Bytes

[add_header_multiline] Multiline response headers

You should avoid using multiline response headers, because:

  • they are deprecated (see RFC 7230);
  • some HTTP-clients and web browser never supported them (e.g. IE/Edge/Nginx).

How can I find it?

Misconfiguration example:

add_header Content-Security-Policy "
    default-src: 'none';
    script-src data:;
    style-src data:;
    img-src data:;
    font-src data:;";

more_set_headers -t 'text/html text/plain'
    'X-Foo: Bar

What can I do?

The only solution is to never use multiline response headers.