Credentials in a URI is one (perhaps the only?) standard way for supplying the contents of that header field that is cross-application.
"The RFCs say I can get away with this" doesn't mean that doing something isn't stupid. The RFCs do not aim to forbid all stupid behavior.
-
-
Except in this case, the RFCs say you shouldn't do the stupid thing, but you're insisting on the right to do the stupid thing because it's convenient, and then have software take special steps to protect you.
-
I'm insisting in software *not* taking dumb steps like silently shoving URIs into xattrs for no reason. This has been a thing for *years* and I only just found out. This is broken. It's not just about userdata passwords. Nobody expects download URIs to tag along files!
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.