This is an automated email from the ASF dual-hosted git repository.

rmaucher pushed a change to branch 9.0.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git


    from 59ef2708a3 Update to Bouncy Castle 1.86
     new 11be2fec91 Ignore a null charset in the AddDefaultCharsetFilter 
response wrapper rather than storing it and later appending a literal 
charset=null parameter to the Content-Type header
     new d0bfe29133 Make the content-type checks in the AddDefaultCharsetFilter 
response wrapper case-insensitive as required by RFC 9110 for media types and 
parameter names
     new a3c0bc010b Use an instanceof check when instantiating the configured 
randomClass in CsrfPreventionFilterBase.init() so a class that is not a Random 
subclass produces the intended ServletException rather than a raw 
ClassCastException
     new bc253c9e2a Use an instanceof check when instantiating the configured 
rateLimitClassName in RateLimitFilter.init() so a class that does not implement 
RateLimiter produces the intended ServletException rather than a raw 
ClassCastException
     new 154ecc3045 Synchronise the check for an existing nonce cache with its 
creation in CsrfPreventionFilter to prevent concurrent requests on the same 
session discarding a cache containing already-issued nonces, which could 
trigger spurious rejections
     new 30fb66d99f Clamp the max-age value generated by the ExpiresFilter to a 
minimum of zero to avoid emitting the invalid negative delta-seconds value when 
the computed expiration time is already in the past
     new 8afb2d0981 Validate the port header value in RemoteIpFilter and 
RemoteIpValve so that values outside the 1-65535 range fall back to the default 
server port rather than being applied as an invalid port
     new 606a7a00cf Remove the placeholder from the http.403 message of the 
filters package which was rendered literally in the non-HTTP deny response of 
RequestFilter since no argument was ever provided
     new 041c531d54 Fix compilation errors

The 9 revisions listed above as "new" are entirely new to this
repository and will be described in separate emails.  The revisions
listed as "add" were already present in the repository and have only
been added to this reference.


Summary of changes:
 .../catalina/filters/AddDefaultCharsetFilter.java  | 24 +++++---
 .../catalina/filters/CsrfPreventionFilter.java     |  7 ++-
 .../catalina/filters/CsrfPreventionFilterBase.java |  7 ++-
 .../org/apache/catalina/filters/ExpiresFilter.java |  7 ++-
 .../catalina/filters/LocalStrings.properties       |  2 +-
 .../catalina/filters/LocalStrings_cs.properties    |  2 +-
 .../catalina/filters/LocalStrings_de.properties    |  2 +-
 .../catalina/filters/LocalStrings_es.properties    |  2 +-
 .../catalina/filters/LocalStrings_fr.properties    |  2 +-
 .../catalina/filters/LocalStrings_ja.properties    |  2 +-
 .../catalina/filters/LocalStrings_ko.properties    |  2 +-
 .../catalina/filters/LocalStrings_pt_BR.properties |  2 +-
 .../catalina/filters/LocalStrings_ru.properties    |  2 +-
 .../catalina/filters/LocalStrings_zh_CN.properties |  2 +-
 .../apache/catalina/filters/RateLimitFilter.java   |  7 ++-
 .../apache/catalina/filters/RemoteIpFilter.java    |  4 ++
 java/org/apache/catalina/valves/RemoteIpValve.java |  6 ++
 .../catalina/filters/TestRemoteIpFilter.java       | 54 +++++++++++++++++
 .../apache/catalina/valves/TestRemoteIpValve.java  | 68 ++++++++++++++++++++++
 19 files changed, 181 insertions(+), 23 deletions(-)


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to