Comment 77 for bug 1409142

Revision history for this message
Tony Breeds (o-tony) wrote : Re: Websocket Hijacking Vulnerability in Nova VNC Server (CVE-2015-0259)

I think a new option would be better. I concede that the 2 concepts are related I think borrowing the existing option may cause surprise to users that have stab;e deployed and that option is active and yet don't care about matching origin headers.

I guess it boils down to principle of least surprise.

just my $0.02.