Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Disallow HTML entity escaping in headers
Response headers shall not convert ampersands into HTML entities (such as having an ampersand and a semicolon in a header value). This may be the case for the CSP headers, where there are URLs that may have query params, and there are multiple sections separated by semicolons.
- Loading branch information