Skip to content

Diagnostics for EnableInsecureAbsoluteFormHostOverride #39756

@Tratcher

Description

@Tratcher

Is there an existing issue for this?

  • I have searched the existing issues

Is your feature request related to a problem? Please describe the problem.

#39334 added a 6.0 servicing workaround for clients that sent a certain kind of invalid requests. The affected client is being updated (slowly) so we were not planning to port the fix to 7.

The customer has asked for some additional diagnostics so they can know if anybody else is hitting this issue (without disabling the mitigation), and that would help inform if we need to port the fix to 7.0.

Describe the solution you'd like

Add some diagnostics (logs or events) for when this mitigation is hit so we can track how many & who would be affected if it were disabled. We need to work with the customer to find the most consumable output.

Additional context

No response

Metadata

Metadata

Assignees

Labels

area-networkingIncludes servers, yarp, json patch, bedrock, websockets, http client factory, and http abstractionsfeature-kestrel

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions