# Feature Request: Legacy HTTP Support

**URL:** <https://meta.discourse.org/t/feature-request-legacy-http-support/73375>\
**Category:** Feature\
**Created:** [2017年十一月3日 18:03 UTC](https://meta.discourse.org/t/feature-request-legacy-http-support/73375 "2017-11-03T18:03:44Z")\
**Posts on this page:** 5\
**Page:** 2

<div class="post-metadata">

**Author:** ![schungx](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/schungx/32/70989_2.png) [@schungx](https://meta.discourse.org/u/schungx)\
**Post date:** [2017年十一月6日 03:50 UTC](https://meta.discourse.org/t/feature-request-legacy-http-support/73375/21 "2017-11-06T03:50:35Z")

</div>

It is a strange filter to block certain headers from PUT while letting them through POST. Must be a setting somewhere.

It is not inconceivable that the default setting will sanitize PUTs because, years ago, PUTs are seldomly used.

---

<div class="post-metadata">

**Author:** ![nsuchy](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nsuchy/32/166530_2.png) [@nsuchy](https://meta.discourse.org/u/nsuchy)\
**Post date:** [2017年十一月10日 01:42 UTC](https://meta.discourse.org/t/feature-request-legacy-http-support/73375/22 "2017-11-10T01:42:30Z")

</div>

I think I’m going to keep it available just as a last resort, nginx rate limits + fail2ban is going a good job fighting current attacks at the moment.

---

<div class="post-metadata">

**Author:** ![nsuchy](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nsuchy/32/166530_2.png) [@nsuchy](https://meta.discourse.org/u/nsuchy)\
**Post date:** [2017年十一月10日 01:43 UTC](https://meta.discourse.org/t/feature-request-legacy-http-support/73375/23 "2017-11-10T01:43:29Z")

</div>

> [@schungx](#):
>
> It is a strange filter to block certain headers from PUT while letting them through POST. Must be a setting somewhere.
> 
> It is not inconceivable that the default setting will sanitize PUTs because, years ago, PUTs are seldomly used.

Again it’s legacy crap that’s a last resort so you know. If we are getting hit with 1,000,000s of reqs per second it’s amazing that the site loads at all. (❤ you ipsets)

---

<div class="post-metadata">

**Author:** ![MakaryGo](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/makarygo/32/187426_2.png) [@MakaryGo](https://meta.discourse.org/u/MakaryGo)\
**Post date:** [2017年十一月10日 03:29 UTC](https://meta.discourse.org/t/feature-request-legacy-http-support/73375/24 "2017-11-10T03:29:11Z")

</div>

Perhaps something is messed up with reverse proxy (as you’re using unix socket I assume you have some proxy set up)?

---

<div class="post-metadata">

**Author:** ![nsuchy](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nsuchy/32/166530_2.png) [@nsuchy](https://meta.discourse.org/u/nsuchy)\
**Post date:** [2017年十一月11日 03:19 UTC](https://meta.discourse.org/t/feature-request-legacy-http-support/73375/25 "2017-11-11T03:19:24Z")

</div>

This is an inline proxy that I have zero control over - I have a toggle in my network control center to MITM port 80 and 443 to go through the proxy, it’s legacy hardware HTTP(s) DDoS Filtering. It’s a last resort now, I’ve seen quite a few unique HTTP Based Attacks and writing fail2ban filters to thwart them is a pretty standard task for me. That being said having the proxy always on would reduce my work load.

[上一頁](https://meta.discourse.org/t/feature-request-legacy-http-support/73375.md?page=1)
