Mercurial > p > roundup > code
diff doc/security.txt @ 5730:4aa26a9f3b47
Tighten up use of X-HTTP-Method-Override to only work with POST.
Old method allowed PUT, DELETE .. to tunnel. Now I have no clue why
you would tunnel DELETE or PATCH in PUT but...
| author | John Rouillard <rouilj@ieee.org> |
|---|---|
| date | Sat, 25 May 2019 14:33:07 -0400 |
| parents | 8ee41c7372e7 |
| children | ffe29ee47c47 |
