mirror of
https://github.com/yhirose/cpp-httplib.git
synced 2026-09-30 20:52:31 +07:00
req.path is percent-decoded, so a request like GET /%0D%0A... put a literal CR/LF into the NGINX-style log lines and let a client forge extra entries. Log the raw req.target (matching NGINX's $request) and escape '"', '\', control and non-ASCII bytes as \xHH the way NGINX does. Also note in the README logging section that req.path may contain control characters and should be escaped before logging.