Open lielran opened 1 year ago
I have the same issue.
Same here. Digging deeper with my almost nonexistent Lambda skills, I noticed this code fragment in the Lambda@Edge function which seems to handle that request:
status: '302',
statusDescription: 'Found',
headers: {
location: [{
key: 'Location',
value: `/?${body}`,
}],
},
};
So as I read it, it takes the request body (which is multipart form encoded) and attaches it as-is to the redirect Location: header. This data contains multiple CRLF (\r\n).