mirror of
https://github.com/lightpanda-io/browser.git
synced 2026-10-09 04:42:30 -04:00
webapi: enhance header to block forbidden response headers
This commit is contained in:
7 files changed
+149
-6
No files matched your search
@@ -1140,6 +1140,15 @@ fn testHTTPHandler(req: *std.http.Server.Request) !void {
|
||||
});
|
||||
}
|
||||
|
||||
if (std.mem.eql(u8, path, "/set_cookie")) {
|
||||
return req.respond("", .{
|
||||
.extra_headers = &.{
|
||||
.{ .name = "Set-Cookie", .value = "lp_hidden=1; Path=/set_cookie_scope" },
|
||||
.{ .name = "X-Visible", .value = "yes" },
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
if (std.mem.eql(u8, path, "/redirect_same_echo_headers")) {
|
||||
// Same-origin 302 to /echo_headers: Authorization must survive the hop.
|
||||
return req.respond("", .{
|
||||
|
||||
Reference in new issue
Block a user