Hi Otto!

> Do you agree it makes sense to have a new error that can tell clients
> to go to another server (similar to how HTTP 301 redirects work)?
>

> I would very much like to hear your opinion on this one. If you are in
> agreement, Daniel can spend more time polishing the feature and also
> taking care of implementation details such as preventing redirect
> loops and other corner cases.
>

If we want to implement redirection via error message, then the client
needs an option to enable redirecting, it should be disabled by default.
The current PR  introduces a new vulnerability, since the client redirects
automatically under the hood.

/Georg
-- 
Georg Richter, Staff Software Engineer
Client Connectivity
MariaDB Corporation Ab
_______________________________________________
developers mailing list -- developers@lists.mariadb.org
To unsubscribe send an email to developers-le...@lists.mariadb.org

Reply via email to