Hacker News new | past | comments | ask | show | jobs | submit login

Parameters I'm not sure, but there was a hot minute back before Rails 2.0 shipped where it was using them:

https://github.com/rails/rails/commit/0cac2806a6fd9f1f63cdce...

That 2007 commit rolled back to just using slashes.




I'm sure there's some sites, but even if the percentage is in the low single digits (i.e. a smallish but still very significant percentage), I still think that browsers is probably the right place for this to be fixed.

Getting everyone to go through every part of their app and properly harden up their url routing to protect against this seems unlikely to happen - it's simply too much work for many companies.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: