enforcing access is via urlbase

Christian Robottom Reis kiko at async.com.br
Fri Oct 1 07:02:49 UTC 2004


On Fri, Oct 01, 2004 at 09:15:15AM +0800, bugzilla at glob.com.au wrote:
> > Another point is that if the end-user is using HTTP/1.0 to access 
> > Bugzilla, then there is no way for Bugzilla to know which hostname they 
> > used. (although we can certainly tell if they're using SSL or not)
> 
> ah.  i'd forgotten about that.  that would be a show stopper.

Odd. Doesn't the 1.0 spec define a Host: header that is mandatory? AFAIK
only 0.9 allowed Host:less connects.

Take care,
--
Christian Robottom Reis | http://async.com.br/~kiko/ | [+55 16] 3361 2331



More information about the developers mailing list