[Bug 241630] [maintainer-update] www/wt update 4.1.2
bugzilla-noreply at freebsd.org
bugzilla-noreply at freebsd.org
Thu Oct 31 22:51:06 UTC 2019
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=241630
Bug ID: 241630
Summary: [maintainer-update] www/wt update 4.1.2
Product: Ports & Packages
Version: Latest
Hardware: Any
OS: Any
Status: New
Severity: Affects Only Me
Priority: ---
Component: Individual Port(s)
Assignee: ports-bugs at FreeBSD.org
Reporter: info at babaei.net
Created attachment 208750
--> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=208750&action=edit
www/wt3 v4.1.1 to v4.1.2 patch file
Release 4.1.2 (October 30, 2019)
This release fixes the following issues:
wthttp security issues:
Wt internally used an SSL-Client-Certificates header to send client
certificates to child processes when using dedicated process mode. It was
however always accepted even when Wt was not behind a reverse proxy, and sent
to child processes as-is. wthttp now correctly disregards it when not received
from a reverse proxy. The header was also renamed to
X-Wt-Ssl-Client-Certificates to clarify that it is a non-standard internal Wt
header.
When using dedicated session processes with wthttp, the parent process
would trust X-Forwarded-Proto and X-Forwarded-Port even when Wt was not
configured to be behind a reverse proxy. These are now discarded.
Fixed an issue raised on the forum causing WTreeView to not properly react
to certain size changes.
Fixed issue #7291: wtfcgi would not properly match default entry point
Fixed a few issues found by clang-analyzer:
Fixed an issue in WAnchor that would cause image() to return nullptr if
it was provided in the constructor.
Fixed WCssDecorationStyle self-assignment
Made tests succeed even if Wt is built with ENABLE_UNWIND=ON.
issue #7292: OAuthService now correctly uses refresh_token instead of
refreshToken
Http::Client fixes:
fixed issue #7272: support @ character in the path of a URL
fixed 204 No Content response code behavior (would hang before, waiting
for content) (issue #7273)
More informative error and exception messages:
QueryModel's "geometry inconsistent with database" exception now
contains row and cache start and size information
WebSession's "not serving this" info message contains more context so
it's less confusing
Documentation fixes:
The release notes for Wt 3.3.8 incorrectly referred to allowed-hosts,
while this property is actually named allowed-origins
Updated WLocale::setTimeZone() documentation
--
You are receiving this mail because:
You are the assignee for the bug.
More information about the freebsd-ports-bugs
mailing list