Skip to content

mod_allowmethods: Populate Allow for denied methods - #823

Open
arturobernalg wants to merge 1 commit into
apache:trunkfrom
arturobernalg:fix/mod_allowmethods-405-allow
Open

arturobernalg wants to merge 1 commit into
apache:trunkfrom
arturobernalg:fix/mod_allowmethods-405-allow

Conversation

@arturobernalg

Copy link
Copy Markdown
Member

Publish the configured methods through allowed_methods when AllowMethods rejects a request, so 405 responses contain the methods actually supported by the resource.


  • [X ] This PR does not report or address a security vulnerability
    (see SECURITY.md and
    https://www.apache.org/security/#reporting-a-vulnerability).
  • [ X] Code follows the httpd style guide.
  • New log messages (level debug or higher) use an empty APLOGNO() tag;
    numbers are assigned by a committer at merge time (see docs/log-message-tags/README).
  • [X ] If the change is user-visible, a changes-entries/*.txt file is included,
    following the template in README.CHANGES (not needed otherwise).
  • [X ] Test cases based on pyhttpd are included where appropriate, in the
    test/modules/xxx directory matching the modules/xxx module source,
    or test/modules/core for core server changes. On Unix, verify these
    pass locally with e.g. make check-pytest PYTEST_DIRS=test/modules/xxx.

Publish the configured methods through allowed_methods when
AllowMethods rejects a request, so 405 responses contain the
methods actually supported by the resource.
@arturobernalg

Copy link
Copy Markdown
Member Author

I found an important limitation with the current approach.

For example, with AllowMethods GET PATCH on a static resource, a denied PUT would advertise PATCH in Allow, even though a PATCH request is rejected by the default handler.

AllowMethods describes an access policy, while Allow is supposed to describe methods supported by the target resource. At the point where mod_allowmethods rejects the request, httpd has no generic mechanism to query the selected handler's supported methods.

So the current implementation cannot produce an exact Allow value in all cases without broader handler-capability support. I am leaving the PR open for feedback before changing the approach.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant