Skip to content

test: add test for ignoring comma-separated X-Forwarded-Host when trust proxy disabled#6893

Open
Ayoub-Mabrouk wants to merge 1 commit intoexpressjs:masterfrom
Ayoub-Mabrouk:test/add-req-host-ignore-comma-separated
Open

test: add test for ignoring comma-separated X-Forwarded-Host when trust proxy disabled#6893
Ayoub-Mabrouk wants to merge 1 commit intoexpressjs:masterfrom
Ayoub-Mabrouk:test/add-req-host-ignore-comma-separated

Conversation

@Ayoub-Mabrouk
Copy link
Contributor

Verify that req.host ignores comma-separated X-Forwarded-Host values
when trust proxy is disabled, ensuring security by using Host header
instead of potentially malicious forwarded headers

…st proxy disabled

Verify that req.host ignores comma-separated X-Forwarded-Host values
when trust proxy is disabled, ensuring security by using Host header
instead of potentially malicious forwarded headers.
@Ayoub-Mabrouk Ayoub-Mabrouk force-pushed the test/add-req-host-ignore-comma-separated branch from 475b00c to 1f860fb Compare November 10, 2025 22:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant