CHANGES revision d0db5addb1858b640bebc27d738ba556f3a04362
fa9e4066f08beec538e775443c5be79dd423fcabahrens -*- coding: utf-8 -*-
fa9e4066f08beec538e775443c5be79dd423fcabahrensChanges with Apache 2.3.0
fa9e4066f08beec538e775443c5be79dd423fcabahrens[ When backported to 2.2.x, remove entry from this file ]
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock *) http_protocol: Escape request method in 413 error reporting.
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock Determined to be not generally exploitable, but a flaw in any case.
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) rotatelogs: Improve atomicity when using -l and cleaup code.
fa9e4066f08beec538e775443c5be79dd423fcabahrens PR 44004 [Rainer Jung]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) mod_ssl: Add support for OCSP validation of client certificates.
fa9e4066f08beec538e775443c5be79dd423fcabahrens PR 41123. [Marc Stern <marc.stern approach.be>, Joe Orton]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) mod_filter: Don't segfault on (unsupported) chained FilterProvider usage.
fa9e4066f08beec538e775443c5be79dd423fcabahrens PR 43956 [Nick Kew, Ruediger Pluem]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) mod_unique_id: Fix timestamp value in UNIQUE_ID.
fa9e4066f08beec538e775443c5be79dd423fcabahrens PR 37064 [Kobayashi <kobayashi firstserver.co.jp>]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) core: Handle unrecognised transfer-encodings.
26fd77009b17f8c8fb32eb362584cfd635e87ad9Krishnendu Sadhukhan - Sun Microsystems PR 43882 [Nick Kew]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) mod_serf: New module for Reverse Proxying. [Paul Querna]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) core: Add the option to keep aside a request body up to a certain
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock size that would otherwise be discarded, to be consumed by filters
fa9e4066f08beec538e775443c5be79dd423fcabahrens such as mod_include. When enabled for a directory, POST requests
088e9d477eee66081e407fbc5a33c4da25f66f6aeschrock to shtml files can be passed through to embedded scripts as POST
fa9e4066f08beec538e775443c5be79dd423fcabahrens requests, rather being downgraded to GET requests. [Graham Leggett]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) mod_ssl: Fix TLS upgrade (RFC 2817) support. PR 41231. [Joe Orton]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) scoreboard: Correctly declare ap_time_process_request.
26fd77009b17f8c8fb32eb362584cfd635e87ad9Krishnendu Sadhukhan - Sun Microsystems PR 43789 [Tom Donovan <Tom.Donovan acm.org>]
26fd77009b17f8c8fb32eb362584cfd635e87ad9Krishnendu Sadhukhan - Sun Microsystems *) mod_status: Add SeeRequestTail directive, which determines if
26fd77009b17f8c8fb32eb362584cfd635e87ad9Krishnendu Sadhukhan - Sun Microsystems ExtendedStatus displays the 1st 63 characters of the request
26fd77009b17f8c8fb32eb362584cfd635e87ad9Krishnendu Sadhukhan - Sun Microsystems or the last 63. Useful for those requests with large string
26fd77009b17f8c8fb32eb362584cfd635e87ad9Krishnendu Sadhukhan - Sun Microsystems lengths and which only vary with the last several characters.
fa9e4066f08beec538e775443c5be79dd423fcabahrens [Jim Jagielski]
26fd77009b17f8c8fb32eb362584cfd635e87ad9Krishnendu Sadhukhan - Sun Microsystems *) core; scoreboard: ap_get_scoreboard_worker(sbh) now takes the sbh member
b7b97454b9b1f6625e7e655e9651e744a8dee09dperrin from the connection rec, ap_get_scoreboard_worker(proc, thread) will now
b7b97454b9b1f6625e7e655e9651e744a8dee09dperrin provide the unusual legacy lookup. [William Rowe]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) mpm winnt: fix null pointer dereference
fa9e4066f08beec538e775443c5be79dd423fcabahrens PR 42572 [Davi Arnaut]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) mod_proxy_http: Correctly forward unexpected interim (HTTP 1xx)
fa9e4066f08beec538e775443c5be79dd423fcabahrens responses from the backend according to RFC2616. But make it
fa9e4066f08beec538e775443c5be79dd423fcabahrens configurable in case something breaks on it.
fa9e4066f08beec538e775443c5be79dd423fcabahrens PR 16518 [Nick Kew]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) mod_deflate: Don't leave a strong ETag in place while transforming
fa9e4066f08beec538e775443c5be79dd423fcabahrens the entity.
fa9e4066f08beec538e775443c5be79dd423fcabahrens PR 39727 [Nick Kew]
26fd77009b17f8c8fb32eb362584cfd635e87ad9Krishnendu Sadhukhan - Sun Microsystems *) core: reinstate location walk to fix config for subrequests
fa9e4066f08beec538e775443c5be79dd423fcabahrens PR 41960 [Jose Kahan <jose w3.org>]
26fd77009b17f8c8fb32eb362584cfd635e87ad9Krishnendu Sadhukhan - Sun Microsystems *) mod_log_config: Add format options for %p so that the actual local
26fd77009b17f8c8fb32eb362584cfd635e87ad9Krishnendu Sadhukhan - Sun Microsystems or remote port can be logged. PR 43415. [Adam Hasselbalch Hansen
26fd77009b17f8c8fb32eb362584cfd635e87ad9Krishnendu Sadhukhan - Sun Microsystems <ahh@one.com>, Ruediger Pluem, Jeff Trawick]
088e9d477eee66081e407fbc5a33c4da25f66f6aeschrock *) mod_rewrite: Add the novary flag to RewriteCond.
fa9e4066f08beec538e775443c5be79dd423fcabahrens [Ruediger Pluem]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) mod_include: Add an "if" directive syntax to test whether an URL
088e9d477eee66081e407fbc5a33c4da25f66f6aeschrock is accessible, and if so, conditionally display content. This
fa9e4066f08beec538e775443c5be79dd423fcabahrens allows a webmaster to hide a link to a private page when the user
fa9e4066f08beec538e775443c5be79dd423fcabahrens has no access to that page. [Graham Leggett]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) mod_authnz_ldap, mod_authn_dbd: Tidy up the code to expose authn
fa9e4066f08beec538e775443c5be79dd423fcabahrens parameters to the environment. Improve portability to
fa9e4066f08beec538e775443c5be79dd423fcabahrens EBCDIC machines by using apr_toupper(). [Martin Kraemer]
fa9e4066f08beec538e775443c5be79dd423fcabahrens *) mod_ldap, mod_authnzldap: Add support for nested groups (i.e. the ability
fa9e4066f08beec538e775443c5be79dd423fcabahrens to authorize an authenticated user via a "require ldap-group X" directive
fa9e4066f08beec538e775443c5be79dd423fcabahrens where the user is not in group X, but is in a subgroup contained in X.
fa9e4066f08beec538e775443c5be79dd423fcabahrens PR 42891 [Paul J. Reder]
[Filip Hanik <devlist hanik.com>]
[David Jones <oscaremma gmail.com>]
[David M. Lee <dmlee crossroads.com>]
[Niklas Edmundsson <nikke acc.umu.se>]
[Stijn Hoop <stijn sandcat.nl>]
[Darryl Miles <darryl darrylmiles.org>]
[Niklas Edmundsson <nikke acc.umu.se>]
PR 39713. [Owen Taylor <otaylor redhat.com>]
final name. [Davi Arnaut <davi haxent.com.br>]
[Markus Schiegl <ms schiegl.com>]
*) Remove incorrect comments from scoreboard.h regarding conditional
[Chris Darroch <chrisd pearsoncmg.com>]
in ap_init_scoreboard(). [Chris Darroch <chrisd pearsoncmg.com>]
[Chris Darroch <chrisd pearsoncmg.com>]
and 'Reject' to mod_authz_core. The new directives introduce 'AND/OR'
*) mod_authz_dbd: SQL authz with Login/Session support [Nick Kew]
Apache 2.2.xx tree as documented, and except as noted, below.]
Changes with Apache 2.2.x and later:
Changes with Apache 2.0.x and later:
Changes with Apache 1.3.x and later: