Tag: http
-
Re: How I made...
Noah S shared how he used some PHP code to block specific badly-behaved bots from his website. I've got a few suggestions to help him make his block faster, easier-to-maintain, and more-thorough, either using PHP code or webserver configuration.
-
F-Day plus 204 (no content??)
HTTP status code 204 means "no content". No update. Nothing to tell you. F-Day plus 204 brings the same meaning: a disappointing lack of updates to the efforts to repair our house following getting flooded-out in February.
-
I Am Experimenting with Blocking HTTP1.1
Andrew Stephens has added Caddy configuration to prohibit HTTP/1 clients from accessing most of the pages of his website. I decided to probe it and see how that works.
-
Highlight of my workday was debugging an issue that turned out to be nothing like what the reporter had diagnosed.
The report suggested that our system was having problems parsing URLs with colons in the pathname, suggesting perhaps an encoding issue. It wasn't until I took a deep dive into the logs that I realised that this was a secondary characteristic of many URLs found in customers' SharePoint installations. And many of those URLs get redirected. And SharePoint often uses relative URLs when it sends redirections. And it turned out that our systems' redirect handler... wasn't correctly handling relative URLs.
It all turned into a hundred line automated test to mock SharePoint and demonstrate the problem... followed by a tiny two-line fix to the actual code. And probably the most-satisfying part of my workday!
-
HTTP is not simple
After discovering it through a Gemini newsgroup, I very much enjoyed Daniel Stenberg's (of cURL fame) explanation that contrary to what you might think, HTTP (even version 1) is not a 'simple' protocol, and is full of weird and knotty underspecified loose ends.
-
I reimplemented Al Sweigart's "Pipe Swap" scrolling-ASCII-art in plain-text-over-HTTP by exploiting the HTTP
Refreshheader:https://textplain.blog/scroll-art-viewer/pipe-swap
This was a stupid idea, but it was about the level of code sophistication that my illness-brainfog can handle today.
-
Internet Services^H Provider
When you signed up with an ISP, you used to get Web space, email, shared FTP access, a nearby IRC node, newsgroups, and a software bundle. Nowadays you get a shit router, a voucher for a free month of a streaming service you didn't want, and crap customer service. Where did we go wrong?
-
Reply to Vika, re: Content-Security-Policy
Vika shared her frustrations with Content-Security-Policy nonces when delivering pre-generated/cached content. I've had a similar fight, so I've written-up a few of the things I tried and what I learned as a result.
-
I'm pretty impressed with running WordPress on Caddy so far.
It took a little jiggerypokery to configure it with an equivalent of the Nginx configuration I use for DanQ.me. But off the back of it I get the capability for HTTP/3, 103 Early Hints, and built-in "batteries included" infrastructure for things like certificate renewal and log rotation.
Alt
Browser network debugger showing danq.me being served over protocol 'h3' (HTTP/3) and an 'Early Hints Headers' section loading a WOFF2 font and a JavaScript file.
(why yes, I am celebrating my birthday by doing selfhosting server configuration, why do you ask? ๐ )
-
Breakups as HTTP Response Codes
408: Request Timeout = "You keep saying you'll propose, but you never do", and 18 other HTTP response codes expressed as relationship breakdowns.


