aboutsummaryrefslogtreecommitdiff
path: root/cmd/anubis
diff options
context:
space:
mode:
authorXe Iaso <me@xeiaso.net>2025-01-24 15:34:10 -0500
committerXe Iaso <me@xeiaso.net>2025-01-24 15:34:15 -0500
commit2eae2a4cf5ed2507f6525e2f3c2e055935eeda0e (patch)
tree90a387184d942333468f4e48c25786ef085d04a8 /cmd/anubis
parent1cab72372520f232a64a37aaebbc42068af6151e (diff)
downloadx-2eae2a4cf5ed2507f6525e2f3c2e055935eeda0e.tar.xz
x-2eae2a4cf5ed2507f6525e2f3c2e055935eeda0e.zip
cmd/anubis: don't include Accept-Encoding in challenge
Browsers are known to change the Accept-Encoding header based on what media type is being accepted. I kinda hate this too, but such is life. Signed-off-by: Xe Iaso <me@xeiaso.net>
Diffstat (limited to 'cmd/anubis')
-rw-r--r--cmd/anubis/main.go3
1 files changed, 1 insertions, 2 deletions
diff --git a/cmd/anubis/main.go b/cmd/anubis/main.go
index bda4892..4de13ed 100644
--- a/cmd/anubis/main.go
+++ b/cmd/anubis/main.go
@@ -131,8 +131,7 @@ func (s *Server) challengeFor(r *http.Request) string {
fp := sha256.Sum256(s.priv.Seed())
data := fmt.Sprintf(
- "Accept-Encoding=%s,Accept-Language=%s,X-Real-IP=%s,User-Agent=%s,WeekTime=%s,Fingerprint=%x",
- r.Header.Get("Accept-Encoding"),
+ "Accept-Language=%s,X-Real-IP=%s,User-Agent=%s,WeekTime=%s,Fingerprint=%x",
r.Header.Get("Accept-Language"),
r.Header.Get("X-Real-Ip"),
r.UserAgent(),