HomePhorge

Provide software protections for HTTP response splitting

Description

Provide software protections for HTTP response splitting

Summary:
This addresses a few things:

  • Provide a software HTTP response spliting guard as an extra layer of

security, see http://news.php.net/php.internals/57655 and who knows what HPHP/i
does.

  • Cleans up webroot/index.php a little bit, I want to get that file under

control eventually.

  • Eventually I want to collect bytes in/out metrics and this allows us to do

that easily.

  • We may eventually want to write to a socket or do something else like that,

ala Litespawn.

Test Plan:

  • Ran unit tests.
  • Browsed around, checked headers and HTTP status codes.

Reviewers: btrahan, vrana

Reviewed By: btrahan

CC: aran, epriestley

Differential Revision: https://secure.phabricator.com/D1564

Details

Provenance
epriestleyAuthored on Feb 6 2012, 9:59 AM
themackabuPushed on Tue, Mar 25, 8:07 PM
Parents
rPbe424bf381a5: Utilize hsprintf() in OAuth
Branches
Unknown
Tags
Unknown

Event Timeline