Merge pull request #170 from TeamPiped/harden-headers

fix: filter out some headers that could leak user information
This commit is contained in:
Bnyro 2024-04-05 20:20:57 +02:00 committed by GitHub
commit 8e93dde1b5
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -121,6 +121,9 @@ fn is_header_allowed(header: &str) -> bool {
| "user-agent"
| "range"
| "transfer-encoding"
| "x-real-ip"
| "origin"
| "referer"
)
}