Skip to content

Conversation

@wtgodbe
Copy link
Member

@wtgodbe wtgodbe commented Aug 9, 2022

No description provided.

/// Includes <see cref="RequestProperties"/> and <see cref="RequestHeaders"/>
/// </summary>
/// <remarks>
/// The HTTP Request <see cref="HttpRequest.QueryString"/> is not included with this flag as it may contain private information.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's weird to call this out as the reason why query string values are not here when headers are even more likely to contain private information (i.e. Authorize header)

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The default set of headers has also been audited to make sure it doesn't contain anything w/ private information

@wtgodbe wtgodbe merged commit 579a254 into main Aug 10, 2022
@wtgodbe wtgodbe deleted the wtgodbe/QString branch August 10, 2022 15:13
@ghost ghost added this to the 7.0-rc1 milestone Aug 10, 2022
@amcasey amcasey added area-middleware Includes: URL rewrite, redirect, response cache/compression, session, and other general middlewares and removed area-runtime labels Jun 6, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-middleware Includes: URL rewrite, redirect, response cache/compression, session, and other general middlewares

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants