rzo1 opened a new pull request, #3061:
URL: https://github.com/apache/tomee/pull/3061

   The constraint generated for a JAX-WS endpoint with BASIC/DIGEST/CLIENT-CERT 
auth only listed GET and POST, leaving other verbs unauthenticated. The 
collection now covers every method, and uncovered methods are denied on 
contexts TomEE creates for the endpoint. Endpoints added to an existing webapp 
keep its own configuration. Note that OPTIONS (e.g. CORS preflight) now 
requires authentication on those contexts.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to