[PR] webapps/docs: fix spelling in XML files [tomcat]

2025-04-01 Thread via GitHub
jbampton opened a new pull request, #836: URL: https://github.com/apache/tomcat/pull/836 (no comment) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail

Re: [PR] test(java): fix spelling [tomcat]

2025-04-01 Thread via GitHub
markt-asf commented on PR #837: URL: https://github.com/apache/tomcat/pull/837#issuecomment-2768692141 Tx again. I'll get these back-ported. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the sp

Re: [PR] test(java): fix spelling [tomcat]

2025-04-01 Thread via GitHub
markt-asf merged PR #837: URL: https://github.com/apache/tomcat/pull/837 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.o

Re: [I] Migration of defaultNamespaceRemap / com.sun.xml.bind references [tomcat-jakartaee-migration]

2025-04-01 Thread via GitHub
markt-asf closed issue #62: Migration of defaultNamespaceRemap / com.sun.xml.bind references URL: https://github.com/apache/tomcat-jakartaee-migration/issues/62 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL abov

[PR] misc: fix grammar / spelling / remove duplicate words [tomcat]

2025-04-01 Thread via GitHub
jbampton opened a new pull request, #838: URL: https://github.com/apache/tomcat/pull/838 Docs clean ups in Java, XML and XSL -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment.

Re: [PR] Changed string comparison - need to use equals() instead of == or != [tomcat]

2025-03-28 Thread via GitHub
rmaucher commented on code in PR #834: URL: https://github.com/apache/tomcat/pull/834#discussion_r2019045345 ## java/org/apache/tomcat/util/net/openssl/panama/OpenSSLContext.java: ## @@ -503,7 +504,7 @@ public void init(KeyManager[] kms, TrustManager[] tms, SecureRandom sr) thr

Re: [PR] Changed string comparison - need to use equals() instead of == or != [tomcat]

2025-03-28 Thread via GitHub
ChristopherSchultz commented on code in PR #834: URL: https://github.com/apache/tomcat/pull/834#discussion_r2018982394 ## java/org/apache/jasper/compiler/Parser.java: ## @@ -1471,8 +1471,8 @@ private void parseBody(Node parent, String tag, String bodyType) throws JasperEx

Re: [I] Migration of defaultNamespaceRemap / com.sun.xml.bind references [tomcat-jakartaee-migration]

2025-03-31 Thread via GitHub
ahinc711 commented on issue #62: URL: https://github.com/apache/tomcat-jakartaee-migration/issues/62#issuecomment-2767405443 Thanks for the response, I didn't realize the intent was to cover only javax packages. To avoid expanding the scope by too much, I think this can be closed as "won't

[PR] misc: fix spelling [tomcat]

2025-04-01 Thread via GitHub
jbampton opened a new pull request, #840: URL: https://github.com/apache/tomcat/pull/840 (no comment) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail

Re: [PR] Fix spelling in Java files [tomcat-jakartaee-migration]

2025-04-01 Thread via GitHub
markt-asf merged PR #73: URL: https://github.com/apache/tomcat-jakartaee-migration/pull/73 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr.

Re: [PR] Fix spelling in Java and JSP files [tomcat]

2025-04-01 Thread via GitHub
markt-asf commented on PR #839: URL: https://github.com/apache/tomcat/pull/839#issuecomment-2769896875 I'd rather have these fixes in the code base than not. I didn't think the batch size had been too bad. Small enough it was easy to review but large enough there haven't been that many toda

Re: [PR] webapps/docs: fix spelling in XML files [tomcat]

2025-04-01 Thread via GitHub
markt-asf commented on PR #836: URL: https://github.com/apache/tomcat/pull/836#issuecomment-2768590677 Tx. for the PR. I'll get it back-ported to the earlier versions as well. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub an

Re: [PR] webapps/docs: fix spelling in XML files [tomcat]

2025-04-01 Thread via GitHub
markt-asf merged PR #836: URL: https://github.com/apache/tomcat/pull/836 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.o

[PR] misc: fix spelling [tomcat-training]

2025-04-01 Thread via GitHub
jbampton opened a new pull request, #34: URL: https://github.com/apache/tomcat-training/pull/34 Fix spelling in HTML and Text files -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific co

Re: [PR] misc: fix spelling [tomcat-training]

2025-04-01 Thread via GitHub
markt-asf commented on PR #34: URL: https://github.com/apache/tomcat-training/pull/34#issuecomment-2769537656 Thanks for the review -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific co

Re: [PR] misc: fix grammar / spelling / remove duplicate words [tomcat]

2025-04-01 Thread via GitHub
markt-asf merged PR #838: URL: https://github.com/apache/tomcat/pull/838 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.o

Re: [PR] misc: fix spelling [tomcat-training]

2025-04-01 Thread via GitHub
markt-asf merged PR #34: URL: https://github.com/apache/tomcat-training/pull/34 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr...@tomcat.a

Re: [PR] Fix spelling in Java and JSP files [tomcat]

2025-04-01 Thread via GitHub
markt-asf merged PR #839: URL: https://github.com/apache/tomcat/pull/839 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.o

[PR] Fix release [tomcat-maven-plugin]

2025-04-17 Thread via GitHub
kevin-wise opened a new pull request, #45: URL: https://github.com/apache/tomcat-maven-plugin/pull/45 (no comment) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubs

Re: [PR] Fix release [tomcat-maven-plugin]

2025-04-17 Thread via GitHub
kevin-wise closed pull request #45: Fix release URL: https://github.com/apache/tomcat-maven-plugin/pull/45 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mai

Re: [PR] fix Resolving XML external entity in user-controlled data `Digester.java` [tomcat]

2025-04-28 Thread via GitHub
ChristopherSchultz commented on PR #846: URL: https://github.com/apache/tomcat/pull/846#issuecomment-2835627565 3. The Digester is a package-renamed dependency from an upstream provider, used as a library. This change does not belong in library code. 4. The ability to expand XML entities,

[PR] not recycle when external [tomcat]

2025-04-23 Thread via GitHub
qingdaoheze opened a new pull request, #844: URL: https://github.com/apache/tomcat/pull/844 Fix for https://bz.apache.org/bugzilla/show_bug.cgi?id=69655 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to

[PR] fix Resolving XML external entity in user-controlled data `Digester.java` [tomcat]

2025-04-26 Thread via GitHub
odaysec opened a new pull request, #846: URL: https://github.com/apache/tomcat/pull/846 https://github.com/apache/tomcat/blob/b037fcfec53dda465e280d221fd5b85e50078794/java/org/apache/tomcat/util/digester/Digester.java#L1526-L1526 fix the issue external entity resolution must be explic

Re: [PR] fix Resolving XML external entity in user-controlled data `Digester.java` [tomcat]

2025-04-26 Thread via GitHub
markt-asf closed pull request #846: fix Resolving XML external entity in user-controlled data `Digester.java` URL: https://github.com/apache/tomcat/pull/846 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to

Re: [PR] fix Resolving XML external entity in user-controlled data `Digester.java` [tomcat]

2025-04-26 Thread via GitHub
markt-asf commented on PR #846: URL: https://github.com/apache/tomcat/pull/846#issuecomment-2832194146 1. This is NOT how you report a security concern responsibly. See https://tomcat.apache.org/security 2. The digester is never used for user provided data. -- This is an automated mess

Re: [PR] not recycle when external [tomcat]

2025-04-23 Thread via GitHub
markt-asf commented on PR #844: URL: https://github.com/apache/tomcat/pull/844#issuecomment-2823804453 Does not fix the issue (which has already been fixed). -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL abov

Re: [PR] not recycle when external [tomcat]

2025-04-23 Thread via GitHub
markt-asf closed pull request #844: not recycle when external URL: https://github.com/apache/tomcat/pull/844 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-m

Re: [PR] not recycle when external [tomcat]

2025-04-23 Thread via GitHub
qingdaoheze commented on PR #844: URL: https://github.com/apache/tomcat/pull/844#issuecomment-2823942692 You can see my screenshots. I think the root cause is that the length of org.apache.coyote.http2.Http2 Protocol#recycledRequestsAndResponses gradually increases when the upgrade request

Re: [PR] Include video/mp2t mime type by default [tomcat]

2025-04-30 Thread via GitHub
michael-o commented on code in PR #848: URL: https://github.com/apache/tomcat/pull/848#discussion_r2068131344 ## conf/web.xml: ## @@ -3948,6 +3948,10 @@ trm application/x-msterminal + +ts +video/mp2t Review Comment: The canonical n

Re: [PR] Bug 69662: add name to exception message when throwing NamingException in NamingContext.lookup() [tomcat]

2025-04-30 Thread via GitHub
rmaucher closed pull request #847: Bug 69662: add name to exception message when throwing NamingException in NamingContext.lookup() URL: https://github.com/apache/tomcat/pull/847 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub an

Re: [PR] Bug 69662: add name to exception message when throwing NamingException in NamingContext.lookup() [tomcat]

2025-04-30 Thread via GitHub
rmaucher commented on PR #847: URL: https://github.com/apache/tomcat/pull/847#issuecomment-2841079923 Thanks. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe

Re: [PR] Include video/mp2t mime type by default [tomcat]

2025-04-30 Thread via GitHub
michael-o commented on PR #848: URL: https://github.com/apache/tomcat/pull/848#issuecomment-2841169333 RFC 3555 lists way more as in https://www.iana.org/assignments/media-types/media-types.xhtml#video. Does it make sense to add more? -- This is an automated message from the Apache Git S

Re: [PR] Include video/mp2t mime type by default [tomcat]

2025-04-30 Thread via GitHub
slovdahl commented on PR #848: URL: https://github.com/apache/tomcat/pull/848#issuecomment-2841452176 Ah, ok. Should I run that script and update this PR with the output of it? I assume "that script" refers to `res/scripts/check-mime.pl`. -- This is an automated message from the Apache Gi

Re: [PR] Include video/mp2t mime type by default [tomcat]

2025-04-30 Thread via GitHub
slovdahl commented on PR #848: URL: https://github.com/apache/tomcat/pull/848#issuecomment-2841726094 Awesome, thanks a lot! :bow: Looks good to me, nothing to add from my POV. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub a

Re: [PR] Include video/mp2t mime type by default [tomcat]

2025-04-30 Thread via GitHub
markt-asf closed pull request #848: Include video/mp2t mime type by default URL: https://github.com/apache/tomcat/pull/848 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To un

Re: [PR] Include video/mp2t mime type by default [tomcat]

2025-04-30 Thread via GitHub
markt-asf commented on PR #848: URL: https://github.com/apache/tomcat/pull/848#issuecomment-2841685722 I've run the script and updated `conf/web.xml`. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go

[PR] Bump commons-io:commons-io from 2.18.0 to 2.19.0 [tomcat-jakartaee-migration]

2025-04-13 Thread via GitHub
dependabot[bot] opened a new pull request, #75: URL: https://github.com/apache/tomcat-jakartaee-migration/pull/75 Bumps commons-io:commons-io from 2.18.0 to 2.19.0. [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-nam

Re: [PR] Bump commons-io:commons-io from 2.18.0 to 2.19.0 [tomcat-jakartaee-migration]

2025-04-13 Thread via GitHub
rmaucher merged PR #75: URL: https://github.com/apache/tomcat-jakartaee-migration/pull/75 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr..

Re: [PR] BUGFIX: fix an incorrect range size validation [tomcat]

2025-04-14 Thread via GitHub
Chenjp commented on PR #843: URL: https://github.com/apache/tomcat/pull/843#issuecomment-2800960190 @rmaucher Hi, it is a functional error. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the spe

Re: [PR] Adding nonstandard support for c:set and c:remove [tomcat]

2025-04-16 Thread via GitHub
jengebr commented on code in PR #842: URL: https://github.com/apache/tomcat/pull/842#discussion_r2046872254 ## java/org/apache/jasper/runtime/JspRuntimeLibrary.java: ## @@ -957,4 +957,21 @@ public static void releaseTag(Tag tag, InstanceManager instanceManager) { }

Re: [PR] Adding nonstandard support for c:set and c:remove [tomcat]

2025-04-16 Thread via GitHub
jengebr commented on code in PR #842: URL: https://github.com/apache/tomcat/pull/842#discussion_r2046881926 ## java/org/apache/jasper/compiler/Generator.java: ## @@ -3028,6 +3036,195 @@ public String generateNamedAttributeJspFragment(Node.NamedAttribute n, String ta

Re: [PR] Adding nonstandard support for c:set and c:remove [tomcat]

2025-04-16 Thread via GitHub
markt-asf commented on code in PR #842: URL: https://github.com/apache/tomcat/pull/842#discussion_r2046909111 ## java/org/apache/jasper/compiler/Generator.java: ## @@ -3028,6 +3036,195 @@ public String generateNamedAttributeJspFragment(Node.NamedAttribute n, String ta

Re: [PR] Adding nonstandard support for c:set and c:remove [tomcat]

2025-04-16 Thread via GitHub
jengebr commented on code in PR #842: URL: https://github.com/apache/tomcat/pull/842#discussion_r2046912039 ## java/org/apache/jasper/runtime/JspRuntimeLibrary.java: ## @@ -957,4 +957,21 @@ public static void releaseTag(Tag tag, InstanceManager instanceManager) { }

Re: [PR] Adding nonstandard support for c:set and c:remove [tomcat]

2025-04-16 Thread via GitHub
jengebr commented on code in PR #842: URL: https://github.com/apache/tomcat/pull/842#discussion_r2046936079 ## java/org/apache/jasper/compiler/Generator.java: ## @@ -3028,6 +3036,195 @@ public String generateNamedAttributeJspFragment(Node.NamedAttribute n, String ta

Re: [PR] Adding nonstandard support for c:set and c:remove [tomcat]

2025-04-16 Thread via GitHub
jengebr merged PR #842: URL: https://github.com/apache/tomcat/pull/842 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org

Re: [PR] BUGFIX: fix an incorrect range size validation [tomcat]

2025-04-14 Thread via GitHub
rmaucher closed pull request #843: BUGFIX: fix an incorrect range size validation URL: https://github.com/apache/tomcat/pull/843 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment.

Re: [PR] BUGFIX: fix an incorrect range size validation [tomcat]

2025-04-14 Thread via GitHub
rmaucher commented on PR #843: URL: https://github.com/apache/tomcat/pull/843#issuecomment-2801357502 Ok so this looks like it cleans up all the off by one issue. Merged. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use

[PR] BUGFIX: fix an incorrect range size validation [tomcat]

2025-04-14 Thread via GitHub
Chenjp opened a new pull request, #843: URL: https://github.com/apache/tomcat/pull/843 **semantics fix:** range size = end_pos - start_pos + 1 ## See error log ```bash curl http://localhost:64438/one.txt -d c -H "Content-Range: bytes 0-0/1" -i HTTP/1.1 405 Allow: OPTIONS, G

Re: [PR] Adding nonstandard support for c:set and c:remove [tomcat]

2025-04-16 Thread via GitHub
markt-asf commented on code in PR #842: URL: https://github.com/apache/tomcat/pull/842#discussion_r2046559471 ## java/org/apache/jasper/compiler/Generator.java: ## @@ -3028,6 +3036,195 @@ public String generateNamedAttributeJspFragment(Node.NamedAttribute n, String ta

Re: [PR] webdav testcase for special path [tomcat]

2025-05-05 Thread via GitHub
rmaucher merged PR #808: URL: https://github.com/apache/tomcat/pull/808 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.or

Re: [PR] Adding nonstandard catch, if, choose/when/otherwise [tomcat]

2025-05-01 Thread via GitHub
jengebr closed pull request #845: Adding nonstandard catch, if, choose/when/otherwise URL: https://github.com/apache/tomcat/pull/845 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comm

[PR] Adding nonstandard catch, if, choose/when/otherwise [tomcat]

2025-04-25 Thread via GitHub
jengebr opened a new pull request, #845: URL: https://github.com/apache/tomcat/pull/845 Adds non-standard implementations of `c:catch`, `c:if`, `c:choose`, `c:when`, and `c:otherwise`. Note that incorrectly structured choose/when/otherwise combinations are blocked by the tag lib validation

Re: [PR] Adding nonstandard support for c:set and c:remove [tomcat]

2025-04-15 Thread via GitHub
jengebr commented on PR #842: URL: https://github.com/apache/tomcat/pull/842#issuecomment-2806882710 > Thinking long term, I am wondering whether we need to provide the ability for users to customise these optimisations. If we do then we can add something like a `GeneratorFactory` and users

Re: [PR] Adding nonstandard support for c:set and c:remove [tomcat]

2025-04-15 Thread via GitHub
jengebr commented on code in PR #842: URL: https://github.com/apache/tomcat/pull/842#discussion_r2045083458 ## java/org/apache/jasper/compiler/Generator.java: ## @@ -3028,6 +3036,195 @@ public String generateNamedAttributeJspFragment(Node.NamedAttribute n, String ta

Re: [PR] Adding nonstandard support for c:set and c:remove [tomcat]

2025-04-15 Thread via GitHub
markt-asf commented on code in PR #842: URL: https://github.com/apache/tomcat/pull/842#discussion_r2045039959 ## java/org/apache/jasper/runtime/JspRuntimeLibrary.java: ## @@ -957,4 +957,21 @@ public static void releaseTag(Tag tag, InstanceManager instanceManager) { }

Re: [PR] Adding nonstandard support for c:set and c:remove [tomcat]

2025-04-15 Thread via GitHub
jengebr commented on code in PR #842: URL: https://github.com/apache/tomcat/pull/842#discussion_r2045072065 ## java/org/apache/jasper/runtime/JspRuntimeLibrary.java: ## @@ -957,4 +957,21 @@ public static void releaseTag(Tag tag, InstanceManager instanceManager) { }

[PR] Bug 69662: add name to exception message when throwing NamingException in NamingContext.lookup() [tomcat]

2025-04-29 Thread via GitHub
dhsmith1001 opened a new pull request, #847: URL: https://github.com/apache/tomcat/pull/847 Added a parameter for name to the messages used in creating NamingException, and passed the name parameter in NamingContext.lookup() when creating a NamingException. -- This is an automated messag

Re: [PR] Adding nonstandard catch, if, choose/when/otherwise [tomcat]

2025-05-01 Thread via GitHub
jengebr commented on PR #845: URL: https://github.com/apache/tomcat/pull/845#issuecomment-2845602223 Found some significant bugs, need to rework. Closing w/o merge. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the

Re: [PR] log connectionId [tomcat]

2025-02-17 Thread via GitHub
markt-asf commented on PR #814: URL: https://github.com/apache/tomcat/pull/814#issuecomment-2663380820 That looks good for for the `ExtendedAccessLogValve`. I don't like that this is automatically added as a request attribute. Firstly, if we add this field, why not all the others? Sec

Re: [PR] log connectionId [tomcat]

2025-02-17 Thread via GitHub
rainerjung commented on PR #814: URL: https://github.com/apache/tomcat/pull/814#issuecomment-2663481464 Concerning analogies in Apache httpd land: ErrorLogFormat has ``` %{c}LLog ID of the connection %{C}LLog ID of the connection if used in connection scope

Re: [PR] Fix null stream issue for resource loading based on relative names [tomcat]

2025-02-17 Thread via GitHub
markt-asf commented on PR #816: URL: https://github.com/apache/tomcat/pull/816#issuecomment-2663329121 Fixes applied and will be included in the March releases. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL a

Re: [PR] Fix null stream issue for resource loading based on relative names [tomcat]

2025-02-17 Thread via GitHub
markt-asf closed pull request #816: Fix null stream issue for resource loading based on relative names URL: https://github.com/apache/tomcat/pull/816 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-17 Thread via GitHub
markt-asf commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2663571607 There are many ways to configure the JNDI realm and the SPNEGO authenticator I am unable to recreate the issue you are reporting with the sub-set of configuration provided. Please provide

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-18 Thread via GitHub
natalia-s-ivanova commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2667570079 > I am still getting my head around the complexities of this. I do think that changes will be required but I am still working through what I think those changes should be. T

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-18 Thread via GitHub
markt-asf commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2666209525 I have your example working with Tomcat's `SpnegoAuthenticator` and `JNDIRealm`. A few tweaks were required to both the Tomcat configuration and the web application configuration to handle

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-18 Thread via GitHub
michael-o commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2666256036 > I have your example working with Tomcat's `SpnegoAuthenticator` and `JNDIRealm`. A few tweaks were required to both the Tomcat configuration and the web application configuration to hand

Re: [PR] Enhance case sensitivity check [tomcat]

2025-02-18 Thread via GitHub
rmaucher commented on PR #820: URL: https://github.com/apache/tomcat/pull/820#issuecomment-2665798221 If we start going crazy and creating some file, would it be enough to simply try creating a second file with a different case, or check if the file with another case exists ? But I don't

Re: [PR] Enhance case sensitivity check [tomcat]

2025-02-18 Thread via GitHub
markt-asf commented on PR #820: URL: https://github.com/apache/tomcat/pull/820#issuecomment-2665819124 There are still issues with the updated approach. That Windows allows case sensitivity to be controlled on a per directory basis is ... unhelpful. I've updated the case sensitivity check a

Re: [PR] Enhance case sensitivity check [tomcat]

2025-02-18 Thread via GitHub
Chenjp commented on PR #820: URL: https://github.com/apache/tomcat/pull/820#issuecomment-2665144518 Updated. Incorrect results of current source code V0 received: ``` V0: Case sensitivity of 'D:\case-sensitivity-verification' is false V1: Case sensitivity of 'D:\case-sensitivity-v

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-18 Thread via GitHub
natalia-s-ivanova commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2665172175 > @natalia-s-ivanova I do now understand your problem and it not related to the `SpnegoAuthenticator` at all. It is design flaw in the realm system which assumes that the realm ver

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-18 Thread via GitHub
michael-o commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2665300573 > As per logout method: I am not quite sure when it is really needed when using pure SpnegoAuthenticator. Could you, please, provide a use case of using logout. Here: https://githu

Re: [PR] Enhance case sensitivity check [tomcat]

2025-02-18 Thread via GitHub
Chenjp commented on PR #820: URL: https://github.com/apache/tomcat/pull/820#issuecomment-2665942186 > There are still issues with the updated approach. That Windows allows case sensitivity to be controlled on a per directory basis is ... unhelpful. I've updated the case sensitivity check an

Re: [PR] Enhance case sensitivity check [tomcat]

2025-02-18 Thread via GitHub
Chenjp commented on PR #820: URL: https://github.com/apache/tomcat/pull/820#issuecomment-2665959653 More: Linux allows us mounting a case-insensitive file system. Latest code treats those linux case-insensitive directory as "case-sensitive" , concurrent writes bypassed, a bug fix is expecte

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-18 Thread via GitHub
michael-o commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2665078872 @natalia-s-ivanova I do now understand your problem and it not related to the `SpnegoAuthenticator` at all. It is design flaw in the realm system which assumes that the realm verifies cred

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-18 Thread via GitHub
natalia-s-ivanova commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2665013625 > There are many ways to configure the JNDI realm and the SPNEGO authenticator I am unable to recreate the issue you are reporting with the sub-set of configuration provided. Pleas

Re: [PR] Enhance case sensitivity check [tomcat]

2025-02-18 Thread via GitHub
markt-asf closed pull request #820: Enhance case sensitivity check URL: https://github.com/apache/tomcat/pull/820 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe

Re: [PR] Enhance case sensitivity check [tomcat]

2025-02-18 Thread via GitHub
markt-asf commented on PR #820: URL: https://github.com/apache/tomcat/pull/820#issuecomment-2664897626 This enhanced check doesn't work. If the target file doesn't exist, the part of the canonical name that represents the file will be whatever value is provided to the File constructor

Re: [PR] log connectionId [tomcat]

2025-02-17 Thread via GitHub
Dmole commented on PR #814: URL: https://github.com/apache/tomcat/pull/814#issuecomment-2663891024 Add %{c}L and x-H(connectionId) to AccessLogValve and ExtendedAccessLogValve to cross reference errors from catalina.log -- This is an automated message from the Apache Git Service. To respo

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-19 Thread via GitHub
michael-o commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2668513322 > I think the current support for `logout()` can stay. I don't see a reason to change it. > > I think the issue with `login()` is slightly different. The `JNDIRealm` attempts to swi

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-19 Thread via GitHub
natalia-s-ivanova commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2668518211 > 2. If user/password auth is attempted when `authentication="GSSAPI"` then remove the environment properties that configured GSSAPI, perform user/password authentication and then

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-19 Thread via GitHub
markt-asf commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2668483655 I think the current support for `logout()` can stay. I don't see a reason to change it. I think the issue with `login()` is slightly different. The `JNDIRealm` attempts to switch be

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-19 Thread via GitHub
markt-asf commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2668831744 > It is not that easy and I do not agree with that. Here are cases which will not work: As the OP has indicated, they are already using a solution along these lines and it works for

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-19 Thread via GitHub
michael-o commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2668906926 > > It is not that easy and I do not agree with that. Here are cases which will not work: > > As the OP has indicated, they are already using a solution along these lines and it wor

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-19 Thread via GitHub
markt-asf commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2668964117 I don't expect the bind to use kerberos, I am debugging my way through the code and seeing kerberos being used. -- This is an automated message from the Apache Git Service. To respond to

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-19 Thread via GitHub
markt-asf commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2669268717 Thanks for the test case and the detailed configuration settings. That made working on this a lot easier. I have applied a fairly narrow fix for this issue that is similar to the `M

Re: [PR] SpnegoAuthenticator allows wrong calls to login/logout methods [tomcat]

2025-02-19 Thread via GitHub
markt-asf closed pull request #819: SpnegoAuthenticator allows wrong calls to login/logout methods URL: https://github.com/apache/tomcat/pull/819 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

Re: [PR] Enhance case sensitivity check [tomcat]

2025-02-19 Thread via GitHub
markt-asf commented on PR #820: URL: https://github.com/apache/tomcat/pull/820#issuecomment-2669367602 Mounting case insensitive file systems on Linux adds yet more complexity. And I don't see an easy way to address that - especially if we want to avoid creating files to test case sensitivi

Re: [PR] Ensure partial put data range not exceed ContentRange declared [tomcat]

2025-03-02 Thread via GitHub
rmaucher commented on PR #810: URL: https://github.com/apache/tomcat/pull/810#issuecomment-2692889514 Surprisingly, I verified that there's no specification language on what to do if content-length (or whatever similar like chunking) conflicts with content-range. -- This is an automated

Re: [PR] Ensure partial put data range not exceed ContentRange declared [tomcat]

2025-03-03 Thread via GitHub
Chenjp commented on PR #810: URL: https://github.com/apache/tomcat/pull/810#issuecomment-2694798531 This part is semantically ambiguous, and yet undefined in RFC. We have to make decision when edge case happen: 1. payload length is larger than content-range. (e.g. payload="01234567

Re: [PR] enhancement: RateLimitFilter - Provides an exact rate limiting mechanism [tomcat]

2025-03-07 Thread via GitHub
markt-asf commented on code in PR #794: URL: https://github.com/apache/tomcat/pull/794#discussion_r1984984885 ## java/org/apache/catalina/util/TimeBucketCounterBase.java: ## @@ -0,0 +1,214 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one or more + * contribu

Re: [PR] enhancement: RateLimitFilter - Provides an exact rate limiting mechanism [tomcat]

2025-03-07 Thread via GitHub
markt-asf commented on PR #794: URL: https://github.com/apache/tomcat/pull/794#issuecomment-2706759471 It turns out the `TimeBucketCounter ` was by far the most complex. Once that was reviewed, the rest followed quite quickly. I'm leaving this PR open as there are some changes - particularl

Re: [PR] Add unit tests for AsyncStateMachine's asyncPostProcess method [tomcat]

2025-03-08 Thread via GitHub
koust6u closed pull request #828: Add unit tests for AsyncStateMachine's asyncPostProcess method URL: https://github.com/apache/tomcat/pull/828 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the sp

Re: [PR] Ensure partial put data range not exceed ContentRange declared [tomcat]

2025-03-04 Thread via GitHub
rmaucher commented on PR #810: URL: https://github.com/apache/tomcat/pull/810#issuecomment-2698217679 I'm not sure. Since this is writing to a temporary file rather than the real resource, it is possible to back out without consequences. As a result, I think I will implement throwing an IOE

Re: [PR] enhancement: RateLimitFilter - Provides an exact rate limiting mechanism [tomcat]

2025-03-09 Thread via GitHub
Chenjp commented on code in PR #794: URL: https://github.com/apache/tomcat/pull/794#discussion_r1986702168 ## java/org/apache/catalina/util/TimeBucketCounterBase.java: ## @@ -0,0 +1,214 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one or more + * contributor

Re: [PR] enhancement: RateLimitFilter - Provides an exact rate limiting mechanism [tomcat]

2025-03-10 Thread via GitHub
Chenjp commented on code in PR #794: URL: https://github.com/apache/tomcat/pull/794#discussion_r1986715975 ## java/org/apache/catalina/util/TimeBucketCounterBase.java: ## @@ -0,0 +1,214 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one or more + * contributor

Re: [PR] enhancement: RateLimitFilter - Provides an exact rate limiting mechanism [tomcat]

2025-03-10 Thread via GitHub
markt-asf commented on code in PR #794: URL: https://github.com/apache/tomcat/pull/794#discussion_r1986890371 ## java/org/apache/catalina/util/TimeBucketCounterBase.java: ## @@ -0,0 +1,214 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one or more + * contribu

Re: [PR] enhancement: RateLimitFilter - Provides an exact rate limiting mechanism [tomcat]

2025-03-10 Thread via GitHub
markt-asf closed pull request #794: enhancement: RateLimitFilter - Provides an exact rate limiting mechanism URL: https://github.com/apache/tomcat/pull/794 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to

Re: [PR] enhancement: RateLimitFilter - Provides an exact rate limiting mechanism [tomcat]

2025-03-10 Thread via GitHub
markt-asf commented on PR #794: URL: https://github.com/apache/tomcat/pull/794#issuecomment-2709904059 Closing as I believe all points raised in this PR have now been addressed. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub

[PR] [Bug 69607] - MD5 algorithm insecure usage in tomcat-util [tomcat]

2025-03-11 Thread via GitHub
ShivamVerma380 opened a new pull request, #831: URL: https://github.com/apache/tomcat/pull/831 https://bz.apache.org/bugzilla/show_bug.cgi?id=69607 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

Re: [PR] [Bug 69607] - MD5 algorithm insecure usage in tomcat-util [tomcat]

2025-03-11 Thread via GitHub
rmaucher closed pull request #831: [Bug 69607] - MD5 algorithm insecure usage in tomcat-util URL: https://github.com/apache/tomcat/pull/831 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specif

<    13   14   15   16   17   18   19   20   21   >