bneradt commented on PR #12876:
URL: https://github.com/apache/trafficserver/pull/12876#issuecomment-3881584460

   
   > The diags.log validations already verify:
   > 
   > * The block rule matched (`Matched rule: xxe_request_block`)
   > * The blocking action was taken (`Blocking request due to rule`)
   > 
   > These are the meaningful checks -- the HTTP status code to the client is a 
side effect of the race.
   
   I disagree, Claude. The meaningful check is whether the body got blocked or 
whether it incorrectly leaked to the origin. If the body gets to the origin, 
but our logs say we blocked it, who cares? If the offensive body triggers a 
crash on the origin, or remote executes code, for example, but ATS said it 
blocked it, no one is going to be happy with ATS's behavior.
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to