tRPCttRPC
Powered by
BeBoREB
tRPC•2y ago•
8 replies
BeBoRE

tRPC doesn't explicitly check Content-Type

OWASP recommends explicitly checking the Content-Type header to be the expected one, but when I pass Content-Type: 'application/xml' to tRPC with JSON, it just parses it like it's JSON, instead of throwing a 400 or something. Is there a reason why this is done this way, and how can I change this behavior?
tRPCJoin
Move Fast & Break Nothing. End-to-end typesafe APIs made easy.
5,015Members
Resources
Recent Announcements

Similar Threads

Was this page helpful?

Similar Threads

tRPC doesn't support redirect
backboneBbackbone / ❓-help
3y ago
TRPC type aliasing
larryx01Llarryx01 / ❓-help
4mo ago
useContext won't infer type from tRPC client
kosilicaKkosilica / ❓-help
3y ago
trpc doesn't work after migrating to next 15
PinkiePiePPinkiePie / ❓-help
14mo ago