teleclimber / Dropserver

An application platform for your personal web services. https://dropserver.org
Apache License 2.0
48 stars 1 forks source link

Sandbox proxy: filter headers through list of acceptable headers #87

Open teleclimber opened 2 years ago

teleclimber commented 2 years ago

I think I should white-list acceptable headers (especially coming back from sandbox), ignore others if they don't start with "X-". Also need to notify app dev that this is happening, probably via appspace log.

Edit: List of Headers here: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers