Re: Variable that holds scheme

Ervin Hegedüs <[email protected]> Fri, 15 Apr 2022 20:54:00 +0200
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <[email protected]>
Hi there,

On Fri, Apr 15, 2022 at 12:51:56PM -0500, Arlen Walker wrote:
> Just a couple of thoughts:
> 
> You could try looking for the request header for HSTS (Strict-Transport-Security). Won’t catch all browsers, but if you use it on your server it’ll catch most of them. (And why wouldn’t you use it?)
> 
> Doesn’t REQUEST_URI_RAW work for this? I thought it gave the full URI as a text string.

Arlen is right, REQUEST_URI_RAW seems contain the scheme too:

https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual-(v2.x)#REQUEST_URI_RAW



a.

 


_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/