-
-
Notifications
You must be signed in to change notification settings - Fork 133
Open
Description
https://www.ietf.org/archive/id/draft-ietf-httpbis-rfc6265bis-15.html#section-5.6-6 says:
If the set-cookie-string contains a %x00-08 / %x0A-1F / %x7F character (CTL characters excluding HTAB): Abort these steps and ignore the set-cookie-string entirely
But cookie-rs seems to happily accept such cookies in the latest version. (Tested with a null byte)
This is tested as part of the web platform testsuite - servo currently fails this test because of this issue (https://wpt.fyi/results/html/dom/documents/resource-metadata-management/document-cookie.html?label=master&label=experimental&product=servo)
Metadata
Metadata
Assignees
Labels
No labels