This is an automated email from the ASF dual-hosted git repository.
rmaucher pushed a change to branch 9.0.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git
from 59ef2708a3 Update to Bouncy Castle 1.86
new 11be2fec91 Ignore a null charset in the AddDefaultCharsetFilter
response wrapper rather than storing it and later appending a literal
charset=null parameter to the Content-Type header
new d0bfe29133 Make the content-type checks in the AddDefaultCharsetFilter
response wrapper case-insensitive as required by RFC 9110 for media types and
parameter names
new a3c0bc010b Use an instanceof check when instantiating the configured
randomClass in CsrfPreventionFilterBase.init() so a class that is not a Random
subclass produces the intended ServletException rather than a raw
ClassCastException
new bc253c9e2a Use an instanceof check when instantiating the configured
rateLimitClassName in RateLimitFilter.init() so a class that does not implement
RateLimiter produces the intended ServletException rather than a raw
ClassCastException
new 154ecc3045 Synchronise the check for an existing nonce cache with its
creation in CsrfPreventionFilter to prevent concurrent requests on the same
session discarding a cache containing already-issued nonces, which could
trigger spurious rejections
new 30fb66d99f Clamp the max-age value generated by the ExpiresFilter to a
minimum of zero to avoid emitting the invalid negative delta-seconds value when
the computed expiration time is already in the past
new 8afb2d0981 Validate the port header value in RemoteIpFilter and
RemoteIpValve so that values outside the 1-65535 range fall back to the default
server port rather than being applied as an invalid port
new 606a7a00cf Remove the placeholder from the http.403 message of the
filters package which was rendered literally in the non-HTTP deny response of
RequestFilter since no argument was ever provided
new 041c531d54 Fix compilation errors
The 9 revisions listed above as "new" are entirely new to this
repository and will be described in separate emails. The revisions
listed as "add" were already present in the repository and have only
been added to this reference.
Summary of changes:
.../catalina/filters/AddDefaultCharsetFilter.java | 24 +++++---
.../catalina/filters/CsrfPreventionFilter.java | 7 ++-
.../catalina/filters/CsrfPreventionFilterBase.java | 7 ++-
.../org/apache/catalina/filters/ExpiresFilter.java | 7 ++-
.../catalina/filters/LocalStrings.properties | 2 +-
.../catalina/filters/LocalStrings_cs.properties | 2 +-
.../catalina/filters/LocalStrings_de.properties | 2 +-
.../catalina/filters/LocalStrings_es.properties | 2 +-
.../catalina/filters/LocalStrings_fr.properties | 2 +-
.../catalina/filters/LocalStrings_ja.properties | 2 +-
.../catalina/filters/LocalStrings_ko.properties | 2 +-
.../catalina/filters/LocalStrings_pt_BR.properties | 2 +-
.../catalina/filters/LocalStrings_ru.properties | 2 +-
.../catalina/filters/LocalStrings_zh_CN.properties | 2 +-
.../apache/catalina/filters/RateLimitFilter.java | 7 ++-
.../apache/catalina/filters/RemoteIpFilter.java | 4 ++
java/org/apache/catalina/valves/RemoteIpValve.java | 6 ++
.../catalina/filters/TestRemoteIpFilter.java | 54 +++++++++++++++++
.../apache/catalina/valves/TestRemoteIpValve.java | 68 ++++++++++++++++++++++
19 files changed, 181 insertions(+), 23 deletions(-)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]