Re: 302 redirect bypasses security and allows validation of pages on localhost

On Mon, 2005-02-21 at 20:58 +0000, David Dorward wrote:
> Rick -Gilligan- Uschold's post raises an issue. Presumably to avoid
> exposing internal servers to the public, the validator rejects
> attempts to validate http://localhost/. By issuing a 302 redirect from
> a remote site, users can bypass this.

Known issue, assigned to me.  I'm trying to find time to fix that RSN.
http://lists.w3.org/Archives/Public/public-qa-dev/2005Feb/0000.html

Received on Monday, 21 February 2005 21:42:36 UTC