Ian Hickson wrote:
...Incidentally, I think I would recommend removing the blacklist from AC, since AC has a whitelist. Having both seems pointless....
You mean disallowing all headers except a known list??? Nope.Again, that would mean profiling HTTP, and make it impossible to deploy new stuff.
BR, Julian