Conversation
|
Cool idea, but don't most people disable server headers? |
|
I dunno about most. But lots do I think. Disabling it has no benefit, mostly an old wives tale so to speak. But I still think it's worthwhile to set it. |
# Conflicts: # caddy/module.go # frankenphp.go
a4965b1 to
dad632c
Compare
I've had to argue against external pen-testing providers contracted by customers because for them finding a I found your reasoning against removing the header some time ago in some discussion. Maybe a wiki entry one can point to like "See what the people behind Caddy officially think about your snake-oil" might help? |
|
For the record, adding |
|
@aleho Yikes, that's alarming... sigh. Anyway, yeah, the header is easy to remove if insistent upon it. It just hurts the feedback cycle. |
Will allow to track FrankenPHP usage in the wild (currently, it is identified as Caddy).
cc @mholt