docs: add description of effect of --location-trusted on cookie

Closes #14471
This commit is contained in:
XYenon 2024-08-09 17:30:40 +08:00 committed by Daniel Stenberg
parent 88727f7ed0
commit 5fcf96930e
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
3 changed files with 15 additions and 9 deletions

View file

@ -2,7 +2,7 @@
c: Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
SPDX-License-Identifier: curl
Long: location-trusted
Help: As --location, but send auth to other hosts
Help: As --location, but send secrets to other hosts
Protocols: HTTP
Category: http auth
Added: 7.10.4
@ -11,11 +11,16 @@ See-also:
- user
Example:
- --location-trusted -u user:password $URL
- --location-trusted -H "Cookie: session=abc" $URL
---
# `--location-trusted`
Like --location, but allows sending the name + password to all hosts that the
site may redirect to. This may or may not introduce a security breach if the
site redirects you to a site to which you send your authentication info (which
is clear-text in the case of HTTP Basic authentication).
Instructs curl to like --location follow HTTP redirects, but permits it to
send credentials and other secrets along to other hosts than the initial one.
This may or may not introduce a security breach if the site redirects you to a
site to which you send this sensitive data to. Another host means that one or
more of hostname, protocol scheme or port number changed.
This option also allows curl to pass long cookies set explicitly with --header.