This is an automated email from the ASF dual-hosted git repository. rmaucher pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git
commit 68788f48ff53e70aac88544e428a76335c083365 Author: opencode <[email protected]> AuthorDate: Thu Oct 8 14:56:59 2026 +0200 Require both var and value attributes for the SSI #set directive Apache mod_include requires both the var and the value attribute for the #set directive, in any order. Tomcat already collects the attributes before validating them so any order is accepted, but a missing value attribute was silently ignored: no variable was set, no message was logged and processing continued, while a missing var attribute produced the configured error message and stopped processing. The same logical error was therefore handled two different ways depending on which attribute was omitted. Validation is now symmetric: a missing value attribute is logged via the new ssiSet.noValue message, the configured error message is written to the response and SSIStopProcessingException is thrown, mirroring the existing missing-var and invalid-attribute paths. An empty value attribute (value="") continues to work, since the parsed parameter value is an empty string rather than null. Update TestSSISet.testVarOnly to assert the new error behaviour. --- .../apache/catalina/ssi/LocalStrings.properties | 1 + java/org/apache/catalina/ssi/SSISet.java | 24 +++++++++++++--------- test/org/apache/catalina/ssi/TestSSISet.java | 4 ++-- 3 files changed, 17 insertions(+), 12 deletions(-) diff --git a/java/org/apache/catalina/ssi/LocalStrings.properties b/java/org/apache/catalina/ssi/LocalStrings.properties index 0fbbc0d9e4..5cb718e6bd 100644 --- a/java/org/apache/catalina/ssi/LocalStrings.properties +++ b/java/org/apache/catalina/ssi/LocalStrings.properties @@ -49,4 +49,5 @@ ssiServletExternalResolver.normalizationError=Normalization returned null for pa ssiServletExternalResolver.removeFilenameError=Cannot remove filename from path [{0}] ssiServletExternalResolver.requestDispatcherError=Cannot get request dispatcher for path [{0}] +ssiSet.noValue=No value specified ssiSet.noVariable=No variable specified diff --git a/java/org/apache/catalina/ssi/SSISet.java b/java/org/apache/catalina/ssi/SSISet.java index 5b364d82c0..b21b303520 100644 --- a/java/org/apache/catalina/ssi/SSISet.java +++ b/java/org/apache/catalina/ssi/SSISet.java @@ -69,17 +69,21 @@ public class SSISet implements SSICommand { throw new SSIStopProcessingException(); } } + // Both attributes are required, as Apache requires, but they may be + // given in any order if (variableName == null) { - if (variableValue != null) { - ssiMediator.log(sm.getString("ssiSet.noVariable")); - writer.write(errorMessage); - throw new SSIStopProcessingException(); - } - } else if (variableValue != null) { - String substitutedValue = ssiMediator.substituteVariables(variableValue); - ssiMediator.setVariableValue(variableName, substitutedValue); - lastModified = System.currentTimeMillis(); + ssiMediator.log(sm.getString("ssiSet.noVariable")); + writer.write(errorMessage); + throw new SSIStopProcessingException(); + } + if (variableValue == null) { + ssiMediator.log(sm.getString("ssiSet.noValue")); + writer.write(errorMessage); + throw new SSIStopProcessingException(); } + String substitutedValue = ssiMediator.substituteVariables(variableValue); + ssiMediator.setVariableValue(variableName, substitutedValue); + lastModified = System.currentTimeMillis(); return lastModified; } -} \ No newline at end of file +} diff --git a/test/org/apache/catalina/ssi/TestSSISet.java b/test/org/apache/catalina/ssi/TestSSISet.java index 77e351bf3f..300c1fc017 100644 --- a/test/org/apache/catalina/ssi/TestSSISet.java +++ b/test/org/apache/catalina/ssi/TestSSISet.java @@ -49,10 +49,10 @@ public class TestSSISet { @Test public void testVarOnly() throws Exception { - // Setting only the variable name does nothing and is not an error + // The value attribute is required, as it is for Apache SSIMediator mediator = newMediator(); String output = process(mediator, new String[] { "var" }, new String[] { "foo" }); - Assert.assertEquals("", output); + Assert.assertEquals(mediator.getConfigErrMsg(), output); Assert.assertNull(mediator.getVariableValue("foo")); } --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
