Re: [whatwg/fetch] Safelist Last-Event-ID (#568)

@johnwilander @horo-t I'm no longer convinced that safelisting this is correct as it would allow for the kind of values that might result in script execution on the server and they could potentially bypass the length checks we now have in place. Do you have thoughts on how to fix this?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/568#issuecomment-762849224

Received on Tuesday, 19 January 2021 13:48:13 UTC