This commit is contained in:
Dominik Picheta 2016-06-02 19:50:26 +01:00
commit ca7dd345da
2 changed files with 12 additions and 0 deletions

View file

@ -153,6 +153,11 @@ proc processClient(client: AsyncSocket, address: string,
if lineFut.mget == "\c\L": break
let (key, value) = parseHeader(lineFut.mget)
request.headers[key] = value
# Ensure the client isn't trying to DoS us.
if request.headers.len > headerLimit:
await client.sendStatus("400 Bad Request")
request.client.close()
return
if request.reqMethod == "post":
# Check for Expect header