tree ee78c43f340bdb597cb9bef9acfc92578ad19b0e
parent f187ce68b1c0f5d2ba8434657ddd34dabf3f7ef3
author Christopher Faulet <cfaulet@haproxy.com> 1591112036 +0200
committer Christopher Faulet <cfaulet@haproxy.com> 1591172619 +0200

MINOR: mux-h1/proxy: Add a proxy option to disable clear h2 upgrade

By default, HAProxy is able to implicitly upgrade an H1 client connection to an
H2 connection if the first request it receives from a given HTTP connection
matches the HTTP/2 connection preface. This way, it is possible to support H1
and H2 clients on a non-SSL connections. It could be a problem if for any
reason, the H2 upgrade is not acceptable. "option disable-h2-upgrade" may now be
used to disable it, per proxy. The main puprose of this option is to let an
admin to totally disable the H2 support for security reasons. Recently, a
critical issue in the HPACK decoder was fixed, forcing everyone to upgrade their
HAProxy version to fix the bug. It is possible to disable H2 for SSL
connections, but not on clear ones. This option would have been a viable
workaround.
