From f88e7bc5ee5577c260b1ea263a02b2d5f68e532b Mon Sep 17 00:00:00 2001 From: Jamie Mansfield Date: Sun, 4 Aug 2024 11:52:00 +0100 Subject: [PATCH] LibWeb/Fetch: Add Set-Cookie as a forbidden header name See: - https://github.com/whatwg/fetch/commit/50d77e6 - http://wpt.live/fetch/api/request/request-headers.any.html --- Userland/Libraries/LibWeb/Fetch/Infrastructure/HTTP/Headers.cpp | 1 + 1 file changed, 1 insertion(+) diff --git a/Userland/Libraries/LibWeb/Fetch/Infrastructure/HTTP/Headers.cpp b/Userland/Libraries/LibWeb/Fetch/Infrastructure/HTTP/Headers.cpp index a8c427a33f3..f937db87082 100644 --- a/Userland/Libraries/LibWeb/Fetch/Infrastructure/HTTP/Headers.cpp +++ b/Userland/Libraries/LibWeb/Fetch/Infrastructure/HTTP/Headers.cpp @@ -702,6 +702,7 @@ bool is_forbidden_request_header(Header const& header) "Keep-Alive"sv, "Origin"sv, "Referer"sv, + "Set-Cookie"sv, "TE"sv, "Trailer"sv, "Transfer-Encoding"sv,