Re: [PATCH] 3.0/3.1 : send 307 status from deny_info

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Thu, 18 Nov 2010 21:53:18 +1300

On 18/11/10 08:27, Alex Rousskov wrote:
> On 11/16/2010 09:16 PM, Amos Jeffries wrote:
>> This makes Squid send an HTTP/1.1 307 status response to 1.1+ clients if
>> the deny_info directive is used to redirect non-GET/HEAD requests.
>>
>> Current behaviour is to use a 302, which browsers will prevent
>> displaying for security protection against injection attacks. Using 307
>> will give browsers a better chance to identify the redirects and handle
>> them safely.
>
> The change in the default status code should probably be reflected in
> squid.conf.
>

Oops. Yes thanks.

Will make squid.conf say:
  The browsers will get redirected (302 or 307) to the specified URL
after formatting tags have been replaced.

Amos

-- 
Please be using
   Current Stable Squid 2.7.STABLE9 or 3.1.9
   Beta testers wanted for 3.2.0.3
Received on Thu Nov 18 2010 - 08:53:23 MST

This archive was generated by hypermail 2.2.0 : Thu Nov 18 2010 - 12:00:05 MST