The proposed Apache Tomcat 9.0.121 release is now available for voting.

The notable changes compared to 9.0.120 are:

- Add a new attribute to the Context, urlPatternsProvidedInDecodedForm.
   This attribute controls whether URLs and URL patterns provided in the
   deployment descriptor (web.xml), annotations and/or their programmatic
   equivalents are treated as being provided in URL-encoded form (i.e.
   using %nn encoding) or in decoded form. The Servlet specification
   requires that they are provided in decoded form. However, Tomcat has
   historically treated them as if they are provided in encoded form. In
   Tomcat 12, they will always be treated as if they are provided in
   decoded form. This setting enables migration from encoded form to
   decoded form on an application by application basis. This attribute
   will be removed in Tomcat 12 where it will effectively be hard-coded
   to true.
- Require every HTTP/2 request to provide an authority (either an
   :authority pseudo header or a Host header)
- Change the default encryptionAlgorithm for the EncryptInterceptor to
   AES/GCM/NoPadding. This is a breaking change for the
   EncryptInterceptor.

For full details, see the changelog:
https://nightlies.apache.org/tomcat/tomcat-9.0.x/docs/changelog.html

It can be obtained from:
https://dist.apache.org/repos/dist/dev/tomcat/tomcat-9/v9.0.121/

The Maven staging repo is:
https://repository.apache.org/content/repositories/orgapachetomcat-1601

The tag is:
https://github.com/apache/tomcat/tree/9.0.121
dc00a53100b38c8eb8befce5855e3b152eed9353

The proposed 9.0.121 release is:
[ ] -1, Broken - do not release
[ ] +1, Stable - go ahead and release as 9.0.121

Rémy

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to