Cory Benfield added the comment:

While we're here and I'm recommending to drop as little data as possible: we 
need to be really careful about not exposing ourselves to any kind of data 
smuggling attack here.

It's really important that we don't let attackers construct bodies of requests 
or responses that will cause us to misinterpret header blocks. It's therefore 
going to be really tricky to balance those concerns.

----------

_______________________________________
Python tracker <rep...@bugs.python.org>
<http://bugs.python.org/issue24363>
_______________________________________
_______________________________________________
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com

Reply via email to