This functionality has never worked correctly, and the implementation contained a security vulnerability (CVE-2014-5119).
mentioned in commit b8d0acdb