7. 安全考虑事项 (Security Considerations)
7.1. 可靠性和一致性 (Reliability and Consistency)
URI 的可靠性取决于 resource owner 的意图和实现.
7.2. 恶意构造 (Malicious Construction)
攻击者可能构造恶意 URI, 用于:
- 利用解析器脆弱性
- 绕过安全检查
- 执行注入攻击
7.3. 后端转码 (Back-End Transcoding)
字符编码转换可能引入安全脆弱性.
7.4. 少见 IP 地址格式 (Rare IP Address Formats)
某些 IP 地址格式可能被用于欺骗.
7.5. 敏感信息 (Sensitive Information)
警告 (Warning): 不要在 URI 中包含敏感信息, 例如密码, 原因包括:
- URI 可能被记录到日志中
- URI 可能出现在 referrer header 中
- URI 可能被缓存
7.6. 语义攻击 (Semantic Attacks)
视觉上相似的字符可能被用于欺骗用户.
示例 (Examples):
- Cyrillic "а" 看起来像 Latin "a"
example.com与examp1e.com, 即 l 与 1
下一章 (Next Chapter): 8. IANA 考虑事项 (IANA Considerations) - URI scheme registration