-
-
Notifications
You must be signed in to change notification settings - Fork 437
Closed
Description
Hackney send authorization header on redirect, similar issue as CVE-2018-1000007 in cURL.
cURL uses the flag --location-trusted. Should we implement something like this?
This can be seen on redirect to S3 from an API that needs Authorization.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels