mirror of
https://github.com/yhirose/cpp-httplib.git
synced 2026-10-01 05:02:29 +07:00
Escape request data in the docker server's access and error logs
req.path is percent-decoded, so a request like GET /%0D%0A... put a literal CR/LF into the NGINX-style log lines and let a client forge extra entries. Log the raw req.target (matching NGINX's $request) and escape '"', '\', control and non-ASCII bytes as \xHH the way NGINX does. Also note in the README logging section that req.path may contain control characters and should be escaped before logging.
This commit is contained in:
@@ -452,6 +452,9 @@ svr.set_logger([](const httplib::Request& req, const httplib::Response& res) {
|
||||
});
|
||||
```
|
||||
|
||||
> [!NOTE]
|
||||
> `req.path` is percent-decoded and may contain control characters such as CR/LF. Escape request data before writing it to a log file (see [docker/main.cc](docker/main.cc) for an example).
|
||||
|
||||
#### Pre-compression Logging
|
||||
|
||||
You can also set a pre-compression logger to capture request/response data before compression is applied:
|
||||
|
||||
Reference in New Issue
Block a user