Neil Katin writes: > > Ned said: > > There are plenty of ways to approach this that do not require putting a hard > > upper limit on URL size. For example, you could say that "all implementations > > are required to support URLs at least 255 characters long and implementations > > are encouraged to support URLs of as long a length as is feasible". > > You could also say that servers may not silently truncate or ignore > URLs that are beyond their implementation limit; instead they must > return a specific error (e.g. "URL too long"). This keeps > implementations from taking the lazy way out and still being able to > claim compliance with the spec. The problem is more that many implementations use static buffers of, let's say 1024 bytes for reading the HTTP request line. If the request line is longer than the buffer then the application dies or is open for security attacks. This was the case with a version of the NCSA server and also a version of the Netscape client, I believe. -- Henrik Frystyk Nielsen, <frystyk@w3.org> World-Wide Web Consortium, MIT/LCS NE43-356 545 Technology Square, Cambridge MA 02139, USAReceived on Friday, 9 February 1996 13:25:49 UTC
This archive was generated by hypermail 2.4.0 : Thursday, 2 February 2023 18:42:57 UTC