This is an automated email from the ASF dual-hosted git repository.

rmaucher pushed a commit to branch 9.0.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git

commit a398d60c4eb5195dbb03f2d3e02300f9bbc6a812
Author: opencode <[email protected]>
AuthorDate: Thu Oct 8 14:56:59 2026 +0200

    Require both var and value attributes for the SSI #set directive
    
    Apache mod_include requires both the var and the value attribute for
    the #set directive, in any order. Tomcat already collects the
    attributes before validating them so any order is accepted, but a
    missing value attribute was silently ignored: no variable was set, no
    message was logged and processing continued, while a missing var
    attribute produced the configured error message and stopped
    processing. The same logical error was therefore handled two
    different ways depending on which attribute was omitted.
    
    Validation is now symmetric: a missing value attribute is logged via
    the new ssiSet.noValue message, the configured error message is
    written to the response and SSIStopProcessingException is thrown,
    mirroring the existing missing-var and invalid-attribute paths. An
    empty value attribute (value="") continues to work, since the parsed
    parameter value is an empty string rather than null.
    
    Update TestSSISet.testVarOnly to assert the new error behaviour.
---
 .../apache/catalina/ssi/LocalStrings.properties    |  1 +
 java/org/apache/catalina/ssi/SSISet.java           | 24 +++++++++++++---------
 test/org/apache/catalina/ssi/TestSSISet.java       |  4 ++--
 3 files changed, 17 insertions(+), 12 deletions(-)

diff --git a/java/org/apache/catalina/ssi/LocalStrings.properties 
b/java/org/apache/catalina/ssi/LocalStrings.properties
index 0fbbc0d9e4..5cb718e6bd 100644
--- a/java/org/apache/catalina/ssi/LocalStrings.properties
+++ b/java/org/apache/catalina/ssi/LocalStrings.properties
@@ -49,4 +49,5 @@ ssiServletExternalResolver.normalizationError=Normalization 
returned null for pa
 ssiServletExternalResolver.removeFilenameError=Cannot remove filename from 
path [{0}]
 ssiServletExternalResolver.requestDispatcherError=Cannot get request 
dispatcher for path [{0}]
 
+ssiSet.noValue=No value specified
 ssiSet.noVariable=No variable specified
diff --git a/java/org/apache/catalina/ssi/SSISet.java 
b/java/org/apache/catalina/ssi/SSISet.java
index 5b364d82c0..b21b303520 100644
--- a/java/org/apache/catalina/ssi/SSISet.java
+++ b/java/org/apache/catalina/ssi/SSISet.java
@@ -69,17 +69,21 @@ public class SSISet implements SSICommand {
                 throw new SSIStopProcessingException();
             }
         }
+        // Both attributes are required, as Apache requires, but they may be
+        // given in any order
         if (variableName == null) {
-            if (variableValue != null) {
-                ssiMediator.log(sm.getString("ssiSet.noVariable"));
-                writer.write(errorMessage);
-                throw new SSIStopProcessingException();
-            }
-        } else if (variableValue != null) {
-            String substitutedValue = 
ssiMediator.substituteVariables(variableValue);
-            ssiMediator.setVariableValue(variableName, substitutedValue);
-            lastModified = System.currentTimeMillis();
+            ssiMediator.log(sm.getString("ssiSet.noVariable"));
+            writer.write(errorMessage);
+            throw new SSIStopProcessingException();
+        }
+        if (variableValue == null) {
+            ssiMediator.log(sm.getString("ssiSet.noValue"));
+            writer.write(errorMessage);
+            throw new SSIStopProcessingException();
         }
+        String substitutedValue = 
ssiMediator.substituteVariables(variableValue);
+        ssiMediator.setVariableValue(variableName, substitutedValue);
+        lastModified = System.currentTimeMillis();
         return lastModified;
     }
-}
\ No newline at end of file
+}
diff --git a/test/org/apache/catalina/ssi/TestSSISet.java 
b/test/org/apache/catalina/ssi/TestSSISet.java
index 77e351bf3f..300c1fc017 100644
--- a/test/org/apache/catalina/ssi/TestSSISet.java
+++ b/test/org/apache/catalina/ssi/TestSSISet.java
@@ -49,10 +49,10 @@ public class TestSSISet {
 
     @Test
     public void testVarOnly() throws Exception {
-        // Setting only the variable name does nothing and is not an error
+        // The value attribute is required, as it is for Apache
         SSIMediator mediator = newMediator();
         String output = process(mediator, new String[] { "var" }, new String[] 
{ "foo" });
-        Assert.assertEquals("", output);
+        Assert.assertEquals(mediator.getConfigErrMsg(), output);
         Assert.assertNull(mediator.getVariableValue("foo"));
     }
 


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to