Skip to content

Avoid sending send-data headers in API response body

Igor Drozdov requested to merge id-empty-body-for-send-data into master

What does this MR do and why?

If processed incorrectly it may leak sensitive data that is usually sent via headers

Closes: https://gitlab.com/gitlab-org/gitlab/-/issues/324829

Merge request reports

Loading