Bill Barker wrote:
Replying to an older version of the thread, since I share messages the other
way around.
Personally, I think that Remy needs to work on his people skills. Keith has
been a very valuable committer on the 3.3 branch. Rather than shooting him
down, you could have given him pointers on how to improve his patch (which
I'll probably do, but it takes me much longer then it does you :). Just
remember that Keith has the right to veto (although I doubt that he'll use
it) any 4.x release until his bug is fixed.
I just woke up (yawn). I'd like to apologize to Keith if he's been offended. I didn't see any reason to: since he's new to the codebase, I don't see how you can expect to get everything right the first time. So I agree to fix the bug (as I understand the issue thanks to his explnations), but don't think the patch is right at the moment.
It's just that in 4.1 and 5.0, you have to be careful about using the decodedURI rather than the original URI to do any mapping or check. Otherwise, it leaves the door open to hacks using URI encoding.
Rémy
--
To unsubscribe, e-mail: <mailto:tomcat-dev-unsubscribe@;jakarta.apache.org>
For additional commands, e-mail: <mailto:tomcat-dev-help@;jakarta.apache.org>