4 ms·
Since we're sharing our own WTFs; You can include the same header multiple time in a HTTP message, and this is equivalent to having one such header with a comm
by Zash 6y ago
Since we're sharing our own WTFs;
You can include the same header multiple time in a HTTP message, and this is equivalent to having one such header with a comma-separated list of values.
Then there's WWW-Authenticate (the one telling you to re-try with credentials). It has a comma-separated list of parameters.
The combination of those two leads to brokenness, like how recently an API thing would not get Firefox to ask for username and password, because it happened to have put "Bearer" before "Basic" in the list.
https://tools.ietf.org/html/rfc7235#section-4.1 https://tools.ietf.org/html/rfc7235#section-4.1
- richdougherty 6y agoAnd some headers have their own exceptions to this. The Set-Cookie header (sent by the server) should always be sent as multiple headers, not comma separated as user agents may follow Netscape's original spec. https://stackoverflow.com/questions/2880047/is-it-possible-to-set-more-than-one-cookie-with-a-single-set-cookie https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie On the other hand in HTTP/1.1 the Cookie header should always be sent as a single header, not multiple. In HTTP/2, they may be sent as separate headers to improve compression. :) https://stackoverflow.com/questions/16305814/are-multiple-cookie-headers-allowed-in-an-http-request
- superhawk610 6y agoThis article [1] is a really great read on some of the pitfalls you encounter due to the way duplicate headers are parsed in different browsers (skip to "Let's talk about HTTP headers" if you want to jump right into the code). [1]: https://fasterthanli.me/articles/aiming-for-correctness-with-types https://fasterthanli.me/articles/aiming-for-correctness-with...