Skip to content
  1. Jul 03, 1999
  2. Jul 02, 1999
  3. Jun 29, 1999
  4. Jun 27, 1999
  5. Jun 26, 1999
  6. Jun 25, 1999
  7. Jun 24, 1999
  8. Jun 23, 1999
  9. Jun 22, 1999
  10. Jun 20, 1999
  11. Jun 19, 1999
  12. Jun 18, 1999
  13. Jun 17, 1999
  14. Jun 14, 1999
  15. Jun 13, 1999
  16. Jun 04, 1999
    • Ken Coar's avatar
      · daeb4a20
      Ken Coar authored
      	A minor enhancement to SetEnvIf*: allow it to test envariables
      	as well as request attributes.
      
      
      git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@83292 13f79535-47bb-0310-9956-ffa450edef68
      daeb4a20
    • dgaudet's avatar
      This patch removes the processing of `mxb' parameters in Accept · 6857b46a
      dgaudet authored
      headers in mod_negotiation.  A second patch updates the manual to
      reflect this (mxb is not documented directly in the manual but support
      for it is implied in one place).
      
      Reasons for removing this feature:
      
      1) As currently implemented, the 'mxb' feature makes possible certain
      denial-of-service attacks on negotiated content.  These attacks are
      posssible for user communities which access an Apache server from
      behind a HTTP/1.1 proxy which implements `Vary' related optimisations.
      Plugging this denial of service hole without removing `mxb' is fairly
      expensive in terms of degrading caching efficiency.
      
      2) `mxb' is not in HTTP/1.0 or HTTP/1.1 or any other standard
      
      3) Nobody seems to make use of 'mxb'.  (Balachander Krishnamurthy
      kindly offered to grep some of his web traffic traces -- he did not
      find a single Accept with mxb in a whole day of recent traffic, nor in
      older traces)
      
      4) Removing a feature makes a nice change from adding features.
      
      Submitted by:	Koen Holtman <Koen.Holtman@cern.ch>
      
      
      git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@83288 13f79535-47bb-0310-9956-ffa450edef68
      6857b46a