Re: Create a Tomcat 12 branch?

2024-08-26 Thread Mark Thomas
26 Aug 2024 14:50:23 Christopher Schultz : Is there anything in Jakarta EE 12 that would actually be _inappropriate_ for us to put into Tomcat 11? It is very early days for Jakarta EE 12. The release of 11 is still in progress (but is complete for the specifications Tomcat implements). Gene

[Bug 69289] SPAM SPAM SPAM SPAM

2024-08-26 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69289 Chuck Caldarale changed: What|Removed |Added URL|http://pureharmacare.com/ | -- You are receiving this mail bec

[Bug 69289] SPAM SPAM SPAM SPAM

2024-08-26 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69289 Chuck Caldarale changed: What|Removed |Added Resolution|--- |INVALID Status|NEW

[Bug 69289] Crystal Meth: Wat U Moet Weten

2024-08-26 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69289 Spencer Rice changed: What|Removed |Added OS||All Keywords|

[Bug 69289] New: Crystal Meth: Wat U Moet Weten

2024-08-26 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69289 Bug ID: 69289 Summary: Crystal Meth: Wat U Moet Weten Product: Tomcat Native Version: 2.0.7 Hardware: PC Status: NEW Severity: normal Priority: P2 Co

[Bug 69285] Performance improvement to ApplicationHttpRequest.parseParameters()

2024-08-26 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69285 --- Comment #1 from John Engebretson --- FWIW the impact difference seems larger on AArch64 than x64. -- You are receiving this mail because: You are the assignee for the bug. --

Re: [QUESTION] Purchase UML tool using Google security funding

2024-08-26 Thread Christopher Schultz
Mark, On 8/25/24 04:36, Mark Thomas wrote: All, You have probably seen that I am working on updating the UML diagrams we have in the architecture section of the Tomcat documentation. The original diagrams were written in IBM Rational Rose. They were donated by a contributor. I don't thnk an

Re: svn commit: r1920023 - in /tomcat/site/trunk: docs/security-model.html xdocs/security-model.xml

2024-08-26 Thread Christopher Schultz
Mark, On 8/19/24 07:23, ma...@apache.org wrote: Author: markt Date: Mon Aug 19 11:23:05 2024 New Revision: 1920023 URL: http://svn.apache.org/viewvc?rev=1920023&view=rev Log: Add first draft of security model Added: tomcat/site/trunk/docs/security-model.html tomcat/site/trunk/xdocs/s

Re: Cookie parsing and upcoming updates to RFC6265

2024-08-26 Thread Christopher Schultz
All, On 8/16/24 11:25, Mark Thomas wrote: On 16/08/2024 13:40, Tim Funk wrote: How about  missingEqualsCookie="allow | ignore"? The proposed options were: - ignore - name - value By using [allow | ignore] instead of yes/no, it opens the door to additional behaviors. (such as reject which tr

Re: Cookie parsing and upcoming updates to RFC6265

2024-08-26 Thread Christopher Schultz
Mark, On 8/16/24 04:32, Mark Thomas wrote: On 14/08/2024 19:12, Konstantin Kolinko wrote: I think that 1) We would better switch to "ignore" mode right now, in all supported versions. Based on past experience I am extremely hesitant to change anything related to cookie handling behaviour

Re: Cookie parsing and upcoming updates to RFC6265

2024-08-26 Thread Christopher Schultz
Mark, On 8/14/24 10:29, Mark Thomas wrote: Hi all, The IETF HTTP working group is working on RFC 6265bis (the RFC that will replace RFC 6265). I have been reviewing the changes to see what impact they might have on Tomcat and our users. There are a few changes (e.g. SameSite) we have alread

Re: Retirement of people.a.o

2024-08-26 Thread Christopher Schultz
Mark, On 8/13/24 07:01, Mark Thomas wrote: All, Mostly an FYI but if there are objections do speak up. Infra has recently informed committers that people.a.o is being retired without replacement. A number of us have been hosted presentations on people.a.o which are linked from tomcat.a.o.

Re: Create a Tomcat 12 branch?

2024-08-26 Thread Christopher Schultz
Mark, On 8/12/24 14:30, Mark Thomas wrote: All, As I mentioned earlier, I am starting work on some new EL API features that will be part of Jakarta EE 12 so implemented in Tomcat 12. How do we want to handle this? My current thinking is: - create a 11.0.x branch from current main - main be