Skip to content

mod_cache: Parse comma separated Cache-Control directives again. - #821

Open
arturobernalg wants to merge 1 commit into
apache:trunkfrom
arturobernalg:fix/httpd-70028-cache-control-comma-list
Open

arturobernalg wants to merge 1 commit into
apache:trunkfrom
arturobernalg:fix/httpd-70028-cache-control-comma-list

Conversation

@arturobernalg

Copy link
Copy Markdown
Member

cache_strqtok() did not end a token at a comma or whitespace unless an argument followed, so "private, no-store" was read as one token and the response was stored. Stop at any non-token character, after the '=' test. BZ 70028.


  • [X ] This PR does not report or address a security vulnerability
    (see SECURITY.md and
    https://www.apache.org/security/#reporting-a-vulnerability).
  • [X ] Code follows the httpd style guide.
  • [X ] New log messages (level debug or higher) use an empty APLOGNO() tag;
    numbers are assigned by a committer at merge time (see docs/log-message-tags/README).
  • [X ] If the change is user-visible, a changes-entries/*.txt file is included,
    following the template in README.CHANGES (not needed otherwise).
  • [X ] Test cases based on pyhttpd are included where appropriate, in the
    test/modules/xxx directory matching the modules/xxx module source,
    or test/modules/core for core server changes. On Unix, verify these
    pass locally with e.g. make check-pytest PYTEST_DIRS=test/modules/xxx.

cache_strqtok() did not end a token at a comma or whitespace unless an argument followed, so "private, no-store" was read as one token and the response was stored. Stop at any non-token character, after the '=' test. BZ 70028.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant