Haoliang Gao 70d5898fc7 fix: don't allow x-forwarded-host header (#2162)
It's a security issue, x-forwarded-host can be retreived
from ctx.host when app.config.proxy is true, and be injected
to cookie domain.
2018-03-05 17:28:37 +08:00
..