-
Notifications
You must be signed in to change notification settings - Fork 425
feat: set a custom Server header #1959
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. Many, many people remove the Server header unfortunately (for bizarre reasons), so I admit it's not a great metric, but it's worth a shot.
|
Cool idea, but don't most people disable server headers? |
|
I dunno about most. But lots do I think. Disabling it has no benefit, mostly an old wives tale so to speak. But I still think it's worthwhile to set it. |
# Conflicts: # caddy/module.go # frankenphp.go
a4965b1 to
dad632c
Compare
I've had to argue against external pen-testing providers contracted by customers because for them finding a I found your reasoning against removing the header some time ago in some discussion. Maybe a wiki entry one can point to like "See what the people behind Caddy officially think about your snake-oil" might help? |
|
For the record, adding |
|
@aleho Yikes, that's alarming... sigh. Anyway, yeah, the header is easy to remove if insistent upon it. It just hurts the feedback cycle. |
Will allow to track FrankenPHP usage in the wild (currently, it is identified as Caddy).
cc @mholt