wu-sheng commented on PR #8917:
URL: https://github.com/apache/skywalking/pull/8917#issuecomment-1104686669

   In my mind, I prefer to generate this setting from all declaration of 
handlers, and set this when server start. This is not a setting, this is a 
expose limitation, which is good. 
   I know this was introduced by jetty, but this kind of CVE happenned from 
time to time for any HTTP server.
   @wankai123 Let's not check it, and accept this as a part of handler 
registration, and lock it just before server starts.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to