Make sure the 400 is returned to the browser. (like other connectors). The prevents a possible DOS via invalid headers and is the fix for CVE-2009-0033.
Changed paths: