Yes. Not just for saying "yes" to every feature, but because we should let the administrator handle not so "common" requests on way or another.

We'll do wonderous and magic thing for GET and HEAD requests, but eventhing else we just pass through.

But do we want to give the VCL program a chance to mess up the transaction before we pass it to the backend ?

Intuitively I'd say we should have a special VCL function for these and if the user doesn't define it, we just pass to the backend, if the user does define it it's all in his hands.

Possible application could be stuff like DoS prevention and anti-scripting.

Comments ?

