I idly wondered today, in the middle of another task, if we were correctly clearing HTTP headers unconditionally to avoid spoofing. Instead of ignoring the thought, I asked an agent to investigate.
An hour later while closing old windows I learned that, no, we are not clearing headers correctly.
28 days ago