4 ms·
Because it's inefficient unnecessary overhead for static requests. The place to block application specific hacky looking requests isn't in the general HTTP req
by points 16y ago
Because it's inefficient unnecessary overhead for static requests.
The place to block application specific hacky looking requests isn't in the general HTTP request parser. It's in the 'application specific' stuff.
- blasdel 16y agoThe headers and such for even the most static requests still get used all over — dispatch, caches, logging, etc. The overhead is minuscule, especially compared to a hand-rolled parser that's literate enough to be maintainable. And the purpose isn't to "block application specific hacky looking requests", it only does that as a side-effect — this isn't some inane IDS bullshit sold to PHBs. It's not looking for exploit signatures, it just sanitizes all input as a consequence of correctness.