https://bz.apache.org/bugzilla/show_bug.cgi?id=64483

            Bug ID: 64483
           Summary: AJP connector allowedRequestAttributesPattern failures
                    not logged
           Product: Tomcat 9
           Version: unspecified
          Hardware: PC
                OS: All
            Status: NEW
          Severity: enhancement
          Priority: P2
         Component: Connectors
          Assignee: dev@tomcat.apache.org
          Reporter: s.bo...@epcc.ed.ac.uk
  Target Milestone: -----

If a request fails the allowedRequestAttributesPattern check a 403 is returned
for the request but nothing is visible in the default logging.

This check should only fail as a result of server mis-configuration or
malicious action. Both cases would benefit from something in the server logs
even if only to help people find the right part of the documentation to look
at.

-- 
You are receiving this mail because:
You are the assignee for the bug.
---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to