rzo1 opened a new pull request, #3061: URL: https://github.com/apache/tomee/pull/3061
The constraint generated for a JAX-WS endpoint with BASIC/DIGEST/CLIENT-CERT auth only listed GET and POST, leaving other verbs unauthenticated. The collection now covers every method, and uncovered methods are denied on contexts TomEE creates for the endpoint. Endpoints added to an existing webapp keep its own configuration. Note that OPTIONS (e.g. CORS preflight) now requires authentication on those contexts. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
