Skip to content

mod_dav: Do not advertise disabled TRACE - #827

Open
arturobernalg wants to merge 1 commit into
apache:trunkfrom
arturobernalg:fix/httpd-dav-trace-allow
Open

arturobernalg wants to merge 1 commit into
apache:trunkfrom
arturobernalg:fix/httpd-dav-trace-allow

Conversation

@arturobernalg

Copy link
Copy Markdown
Member

dav_method_options() builds its own Allow field and currently lists TRACE unconditionally for existing DAV resources.

With TraceEnable off, an OPTIONS request therefore advertises TRACE even though an actual TRACE request is rejected.

Respect TraceEnable when building the DAV Allow field.

PR 70264.

Tests cover TraceEnable off, on, and extended.


  • This PR does not report or address a security vulnerability
    (see SECURITY.md and
    https://www.apache.org/security/#reporting-a-vulnerability).
  • Code follows the httpd style guide.
  • New log messages (level debug or higher) use an empty APLOGNO() tag;
    numbers are assigned by a committer at merge time (see docs/log-message-tags/README).
  • If the change is user-visible, a changes-entries/*.txt file is included,
    following the template in README.CHANGES (not needed otherwise).
  • Test cases based on pyhttpd are included where appropriate, in the
    test/modules/xxx directory matching the modules/xxx module source,
    or test/modules/core for core server changes. On Unix, verify these
    pass locally with e.g. make check-pytest PYTEST_DIRS=test/modules/xxx.

dav_method_options() builds its own Allow field and unconditionally
advertised TRACE for existing DAV resources, even when TraceEnable was
off.

Respect TraceEnable when constructing the DAV Allow field.

PR 70264.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant