Re: Handling multiple headers when only one is allowed

> Well, there is actually a fourth choice: Ask the user (Yes, I know, the  
> user will most likely know just as little as the client about what those  
> header were intended to mean, and the opportunities for social  
> engineering attacks will be legion).

There's also a fifth. Based on implementation experience we can probably  
figure out what the scenario for headers should be. You might end up with  
special cases, but at least you know it can be implemented and you can  
give advice for future clients so they will no longer have to reverse  
engineer the market leader.

