szepeviktor / waf4wordpress

WAF for WordPress 🔥 with 60+ security checks and weekly updates
https://github.com/szepeviktor/wordpress-website-lifecycle
MIT License
123 stars 25 forks source link

Handle transfer encoded requests #9

Open szepeviktor opened 1 year ago

szepeviktor commented 1 year ago
// FIXME Allow transfer encoded requests
if (! empty($_SERVER['TRANSFER_ENCODING'])) return false;

HTTP/2 disallows all uses of the Transfer-Encoding header other than the HTTP/2 specific: "trailers".

https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Transfer-Encoding

szepeviktor commented 1 year ago

in rest_40x()

// FIXME
if('/yoast/v1/ryte'===$route) break;