From 0433c40eb2f535c05d3523d75ccdfc90823d6463 Mon Sep 17 00:00:00 2001
From: Joe Orton Finally, for testing and diagnostic purposes only, request
bodies may be allowed using the non-compliant TraceEnable
extended
directive. The core (as an origin server) will
- restrict the request body to 64k (plus 8k for chunk headers if
+ restrict the request body to 64Kb (plus 8Kb for chunk headers if
Transfer-Encoding: chunked
is used). The core will
reflect the full headers and all chunk headers with the response
- body. As a proxy server, the request body is not restricted to 64k.
Despite claims to the contrary, TRACE
is not
- a security vulnerability, and there is no viable reason for
- it to be disabled. Doing so necessarily makes your server
- noncompliant.
Despite claims to the contrary, enabling the TRACE
+ method does not expose any security vulnerability in Apache httpd.
+ The TRACE
method is defined by the HTTP/1.1
+ specification and implementations are expected to support it.