浏览代码

Add limitations.md

bubble
Kyle Shockey 6 年前
父节点
当前提交
0fe17539e1
共有 1 个文件被更改,包括 38 次插入0 次删除
  1. +38
    -0
      docs/usage/limitations.md

+ 38
- 0
docs/usage/limitations.md 查看文件

@@ -0,0 +1,38 @@
# Limitations

### Forbidden header names

Some header names cannot be controlled by web applications, due to security
features built into web browsers.

Forbidden headers include:

> - Accept-Charset
> - Accept-Encoding
> - Access-Control-Request-Headers
> - Access-Control-Request-Method
> - Connection
> - Content-Length
> - Cookie
> - Cookie2
> - Date
> - DNT
> - Expect
> - Host
> - Keep-Alive
> - Origin
> - Proxy-*
> - Sec-*
> - Referer
> - TE
> - Trailer
> - Transfer-Encoding
> - Upgrade
> - Via
>
> _[Forbidden header names (developer.mozilla.org)](https://developer.mozilla.org/en-US/docs/Glossary/Forbidden_header_name)_

The biggest impact of this is that OpenAPI 3.0 Cookie parameters cannot be
controlled when running Swagger-UI in a browser.

_For more context, see [#3956](https://github.com/swagger-api/swagger-ui/issues/3956).

正在加载...
取消
保存