On Sat, 5 Mar 2005, Andrew Bartlett wrote:
Should squid filter such responses, and turn them back into a generic protocol error? In the same way that my scripts were not expecting these status codes, I wonder if squid should protect clients by ensuring that the HTTP status code is in the range normally acceptable? Or is this a can of worms you would rather not open :-)
I am not aware of any security issues related to this, and it isn't Squids job to act as a secure firewall imho.
It is already being filtered down to a integer due to the forwarding process.
Regards Henrik
