mirror of
https://github.com/puma/puma.git
synced 2022-11-09 13:48:40 -05:00
c36491756f
header value could inject a CR or LF and inject their own HTTP response.
9 lines
194 B
Ruby
9 lines
194 B
Ruby
require 'securerandom'
|
|
|
|
long_header_hash = {}
|
|
|
|
30.times do |i|
|
|
long_header_hash["X-My-Header-#{i}"] = SecureRandom.hex(1000)
|
|
end
|
|
|
|
run lambda { |env| [200, long_header_hash, ["Hello World"]] }
|