diff options
author | Daniel Stenberg <daniel@haxx.se> | 2015-05-31 00:39:19 +0200 |
---|---|---|
committer | Daniel Stenberg <daniel@haxx.se> | 2015-05-31 00:39:19 +0200 |
commit | 4e7c3c12d32ad3e8d939dfd2fcd7fca84d42cd9c (patch) | |
tree | 502f34bd72f5729e493ca436c41fe00aeca6a70f /docs/TODO | |
parent | 9a0a16a61c3adf56bdf80a774677b311ef27d376 (diff) |
5.6 Refuse "downgrade" redirects
Diffstat (limited to 'docs/TODO')
-rw-r--r-- | docs/TODO | 9 |
1 files changed, 9 insertions, 0 deletions
@@ -49,6 +49,7 @@ 5.3 Rearrange request header order 5.4 SPDY 5.5 auth= in URLs + 5.6 Refuse "downgrade" redirects 6. TELNET 6.1 ditch stdin @@ -348,6 +349,14 @@ This is not detailed in any FTP specification. Additionally this should be implemented for proxy base URLs as well. +5.6 Refuse "downgrade" redirects + + See https://github.com/bagder/curl/issues/226 + + Consider a way to tell curl to refuse to "downgrade" protocol with a redirect + and/or possibly a bit that refuses redirect to change protocol completely. + + 6. TELNET 6.1 ditch stdin |