[ 
https://issues.apache.org/jira/browse/AMBARI-18871?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15671179#comment-15671179
 ] 

Robert Levas commented on AMBARI-18871:
---------------------------------------

[~u39kun], [~jaimin],  Can you take a look at this and make sure the location 
for setting the character set is ok.  I am doubtful that setting the character 
set for the UI in the backend is appropriate. However there may be no other 
place for this. 


> HTTP responses needs to have the character encoding specified in the content 
> type header
> ----------------------------------------------------------------------------------------
>
>                 Key: AMBARI-18871
>                 URL: https://issues.apache.org/jira/browse/AMBARI-18871
>             Project: Ambari
>          Issue Type: Bug
>          Components: ambari-server
>    Affects Versions: trunk
>            Reporter: Anita Gnanamalar Jebaraj
>            Assignee: Anita Gnanamalar Jebaraj
>             Fix For: trunk
>
>         Attachments: AMBARI-18871-updated.patch, AMBARI-18871.patch
>
>
> The charset information(UTF-8) can be added to all the response headers to 
> harden the security for the client. When the charset information is not 
> specified the web browser may choose a different encoding by guessing which 
> encoding is actually being used by the web page. 
> This specific issue is mentioned in the section 3.1.1.5 of RFC7231



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to