Commit 2626cf5b authored by Paul Querna's avatar Paul Querna
Browse files

Backport of AuthDigestEnableQueryStringHack

Needs a doc update to explain what it does.

PR: 27785
Reviewed by: Andr� Malo, Geoffrey Young, Paul Querna


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/APACHE_2_0_BRANCH@104218 13f79535-47bb-0310-9956-ffa450edef68
parent dfee2b1a
Loading
Loading
Loading
Loading
+7 −2
Changes for CHANGES: 7 added lines, 2 removed lines.
Original line number Diff line number Diff line
Changes with Apache 2.0.51
  *) Allow URLs for ServerAdmin. PR 28174. 
     [Paul Querna]
  *) work around MSIE Digest auth bug - if AuthDigestEnableQueryStringHack
     is set in r->subprocess_env allow mismatched query strings to pass.
     PR 27758.  [Paul Querna, Geoffrey Young]
  *) Accept URLs for the ServerAdmin directive. If the supplied
     argument is not recognized as an URL, assume it's a mail address.
     PR 28174.  [Andr Malo, Paul Querna]
  *) initialize server arrays prior to calling ap_setup_prelinked_modules
     so that static modules can push Defines values when registering
+1 −7
Changes for STATUS: 1 added line, 7 removed lines.
Original line number Diff line number Diff line
APACHE 2.0 STATUS:                                              -*-text-*-
Last modified at [$Date: 2004/07/10 05:01:31 $]
Last modified at [$Date: 2004/07/10 07:47:22 $]

Release:

@@ -206,12 +206,6 @@ PATCHES TO BACKPORT FROM 2.1
           support/ab.c: r1.143
       +1: jjclar, nd

    *) work around MSIE Digest auth bug - if AuthDigestEnableQueryStringHack
       is set in r->subprocess_env allow mismatched query strings to pass.
       PR: 27758
       http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/aaa/mod_auth_digest.c?r1=1.86&r2=1.87
       +1: geoff, nd, pquerna

    *) mod_dav: Send an EOS at the end of the multistatus brigade.
       http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/dav/main/mod_dav.c?r1=1.105&r2=1.106
       +1: jorton
+21 −0
Changes for modules/aaa/mod_auth_digest.c: 21 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -1607,6 +1607,27 @@ static int authenticate_digest_user(request_rec *r)
        if (d_uri.query) {
            ap_unescape_url(d_uri.query);
        }
        else if (r_uri.query) {
            /* MSIE compatibility hack.  MSIE has some RFC issues - doesn't 
             * include the query string in the uri Authorization component
             * or when computing the response component.  the second part
             * works out ok, since we can hash the header and get the same
             * result.  however, the uri from the request line won't match
             * the uri Authorization component since the header lacks the 
             * query string, leaving us incompatable with a (broken) MSIE.
             * 
             * the workaround is to fake a query string match if in the proper
             * environment - BrowserMatch MSIE, for example.  the cool thing
             * is that if MSIE ever fixes itself the simple match ought to 
             * work and this code won't be reached anyway, even if the
             * environment is set.
             */
            
            if (apr_table_get(r->subprocess_env, 
                              "AuthDigestEnableQueryStringHack")) {
                d_uri.query = r_uri.query;
            }
        }

        if (r->method_number == M_CONNECT) {
            if (strcmp(resp->uri, r_uri.hostinfo)) {