[imp] 2.2.4-cvs forces charset encoding in HTTP headers

Alain Fauconnet alain@cscoms.net
Tue, 31 Oct 2000 08:58:46 +0700


On Mon, Oct 30, 2000 at 02:36:17PM -0500, Chuck Hagenbuch wrote:
> Quoting Alain Fauconnet <alain@cscoms.net>:
> 
> > That's  why I still this that this "use US english messages, don't mess
> > with encoding" locale setting would be a good idea.
> 
> The only problem is that not setting a charset can be a security problem in
> some cases. See the whole mess of the cross-site-scripting vulnerabilities
> that came out a bit ago.
> 

OK, I'll keep my local patches and don't hope that'll become a feature
anymore :-)

BTW, I don't quite  see  what  you're  referring  to.  Has  this  been
discussed on the list ? must have escaped me. Would you have an URL to
point me at ?

Thanks,
_Alain_

-- 
Alain FAUCONNET
Sr. System Administrator
CS Internet Co. Ltd. (Shin Corp) - Thailand