https://bz.apache.org/bugzilla/show_bug.cgi?id=64180
--- Comment #9 from Christopher Schultz <ch...@christopherschultz.net> --- (In reply to Remy Maucherat from comment #6) > This is mostly wontfix as I am certain the request of the reporter is that > secretRequired disables the need for the client to send the secret. > > 10.0.0-M2, 9.0.32, 8.5.52 and 7.0.101 will now allow setting a secret as "", > and it will be treated as it it had not been set (= null). No doc fix was > needed, secretRequired was properly documented already. Is this how mod_jk/mod_proxy_ajp are working as well? For example, in mod_* is it possible to use a "secret" which is the empty-string? Or do they also treat empty-secret as "no secret"? -- You are receiving this mail because: You are the assignee for the bug. --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org