Repository navigation
Expand file tree
/
Copy pathindex.md
More file actions
108 lines (86 loc) · 3.44 KB
/
Copy pathindex.md
File metadata and controls
108 lines (86 loc) · 3.44 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
---
title: TRACE request method
short-title: TRACE
slug: Web/HTTP/Reference/Methods/TRACE
page-type: http-method
spec-urls: https://www.rfc-editor.org/info/rfc9110/#TRACE
sidebar: http
---
The **`TRACE`** HTTP method performs a message loop-back test along the path to the target resource.
The final recipient of the request should reflect the message as received (excluding any fields that might include sensitive data) back to the client as the message body of a {{HTTPStatus("200", "200 OK")}} response with a {{HTTPHeader("Content-Type")}} of `message/http`.
The final recipient is either the origin server or the first server to receive a {{HTTPHeader("Max-Forwards")}} value of `0` in the request.
The client must not send {{Glossary("HTTP Content", "content")}} in the request, or generate headers that might include sensitive data such as user credentials or cookies.
Not all servers implement the `TRACE` method, and some server owners have historically disallowed the use of the `TRACE` method due to security concerns.
In such cases, a {{HTTPStatus("405", "405 Method Not Allowed")}} [client error response](/en-US/docs/Web/HTTP/Reference/Status#client_error_responses) will be sent.
<table class="properties">
<tbody>
<tr>
<th scope="row">Request has body</th>
<td>No</td>
</tr>
<tr>
<th scope="row">Successful response has body</th>
<td>Yes</td>
</tr>
<tr>
<th scope="row">{{Glossary("Safe/HTTP", "Safe")}}</th>
<td>Yes</td>
</tr>
<tr>
<th scope="row">{{Glossary("Idempotent")}}</th>
<td>Yes</td>
</tr>
<tr>
<th scope="row">{{Glossary("Cacheable")}}</th>
<td>No</td>
</tr>
<tr>
<th scope="row">Allowed in <a href="/en-US/docs/Learn_web_development/Extensions/Forms">HTML forms</a></th>
<td>No</td>
</tr>
</tbody>
</table>
## Syntax
```http
TRACE <request-target>["?"<query>] HTTP/1.1
```
- `<request-target>`
- : Identifies the target resource of the request when combined with the information provided in the {{HTTPHeader("Host")}} header.
This is an absolute path (e.g., `/path/to/file.html`) in requests to an origin server, and an absolute URL in requests to proxies (e.g., `http://www.example.com/path/to/file.html`).
- `<query>` {{optional_inline}}
- : An optional query component preceded by a question-mark `?`.
Often used to carry identifying information in the form of `key=value` pairs.
## Examples
### Successful TRACE request
A `TRACE` request can be performed using `curl`:
```bash
curl -v -X TRACE example.com
```
This produces the following HTTP request:
```http
TRACE / HTTP/1.1
Host: example.com
User-Agent: curl/8.7.1
Accept: */*
```
A {{HTTPStatus("200", "200 OK")}} response with the request headers contained in response body is sent back to the client:
```http
HTTP/1.1 200 OK
Content-Length: 123
Date: Wed, 04 Sep 2024 11:50:24 GMT
Server: Apache/2.4.59 (Unix)
Content-Type: message/http
TRACE / HTTP/1.1
Host: example.com
User-Agent: curl/8.7.1
Accept: */*
```
## Specifications
{{Specifications}}
## Browser compatibility
The browser doesn't use the `TRACE` method for user-initiated actions, so "browser compatibility" doesn't apply.
## See also
- [HTTP request methods](/en-US/docs/Web/HTTP/Reference/Methods)
- [HTTP response status codes](/en-US/docs/Web/HTTP/Reference/Status)
- [HTTP headers](/en-US/docs/Web/HTTP/Reference/Headers)
- [Cross-Site Tracing (XST)](https://community.owasp.org/attacks/Cross_Site_Tracing)