Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

rack-protection: Don't track the Accept-Language header by default #1504

Merged
merged 1 commit into from Dec 15, 2018

Commits on Dec 15, 2018

  1. Don't track the Accept-Language header by default.

    Some modern browsers (e.g., Safari 12, Chrome 71) don't set the
    Accept-Language header for websocket requests. A mixture of
    requests with and without this header results in unavailable
    sessions in websocket handlers due to the built-in Firesheep
    protection.
    
    The existing default is inappropriate for any applications
    employing Rack sessions for websocket connections.
    temochka committed Dec 15, 2018
    Copy the full SHA
    6cf49c8 View commit details
    Browse the repository at this point in the history