enforcing access is via urlbase

David Miller justdave at bugzilla.org
Fri Oct 1 07:08:09 UTC 2004


Christian Robottom Reis wrote:
> On Fri, Oct 01, 2004 at 09:15:15AM +0800, bugzilla at glob.com.au wrote:
> 
>>>Another point is that if the end-user is using HTTP/1.0 to access 
>>>Bugzilla, then there is no way for Bugzilla to know which hostname they 
>>>used. (although we can certainly tell if they're using SSL or not)
>>
>>ah.  i'd forgotten about that.  that would be a show stopper.
> 
> Odd. Doesn't the 1.0 spec define a Host: header that is mandatory? AFAIK
> only 0.9 allowed Host:less connects.

Nope.  That's why name-based virtual hosts don't work in HTTP/1.0

-- 
Dave Miller      Project Leader, Bugzilla Bug Tracking System
http://www.justdave.net/             http://www.bugzilla.org/



More information about the developers mailing list