From 4e242645be40e52ed781943e2948f7a56ec51141 Mon Sep 17 00:00:00 2001 From: Philippe Antoine Date: Mon, 13 Jul 2020 11:06:58 +0200 Subject: [PATCH] doc: explicit header normalization further And their concatenation as described in RFC 2616 --- doc/userguide/rules/http-keywords.rst | 3 +++ 1 file changed, 3 insertions(+) diff --git a/doc/userguide/rules/http-keywords.rst b/doc/userguide/rules/http-keywords.rst index c97fb0a5d2..85a3225851 100644 --- a/doc/userguide/rules/http-keywords.rst +++ b/doc/userguide/rules/http-keywords.rst @@ -303,6 +303,9 @@ modifiers, like ``depth``, ``distance``, ``offset``, ``nocase`` and **Note**: the header buffer is *normalized*. Any trailing whitespace and tab characters are removed. See: https://lists.openinfosecfoundation.org/pipermail/oisf-users/2011-October/000935.html. + If there are multiple values for the same header name, they are + concatenated with a comma and space (", ") between each of them. + See RFC 2616 4.2 Message Headers. To avoid that, use the ``http.header.raw`` keyword. Example of a header in a HTTP request: