Open jwodder opened 10 months ago
did we encounter any of such, e.g. as triggered by rclone or some other FUSE system?
@yarikoptic I don't believe so. The only clients that would ever send bodies with external entities would be malicious. At the moment, it seems that the xml-rs library that dandidav
uses for parsing XML simply ignores any external entities.
RFC 4918 requires that when a
PROPFIND
request contains any XML external entities and the server rejects it as a result, the rejection should be a 403 response of the form: