Commit Graph

165 Commits

Author SHA1 Message Date
ivanr
2f6d1f873e Remove description of transformation caching issues from CHANGES. 2008-07-31 09:04:05 +00:00
brectanus
9fd865b763 Add the licensing exception (a text version). 2008-07-29 04:43:59 +00:00
brectanus
6ebc5ad6e7 Transformation caching fixes. See #364. 2008-07-29 00:18:16 +00:00
brectanus
e1342ff011 Backport trunk changes for changeset:1072 and changeset:1073 to 2.5, but leave out the error filter code until more testing is completed. See #498. 2008-06-05 16:55:53 +00:00
brectanus
896ae59e1f Re-enable error output filter with a fix after more testing/tracing of code. See #498.
Update versions to ready for release of 2.5.5.
2008-06-03 20:28:05 +00:00
brectanus
22f1c61f1d Fixed issue where logging was not occuring unless "auditlog" was enabled. See #497, #4, #451 and #445. 2008-06-02 23:34:31 +00:00
brectanus
a9fca34107 Enable "auditlog" action by default. See #445 and #451. 2008-06-02 23:31:27 +00:00
brectanus
0389a88b6a Backport fix to improve request body processing error messages. See #504. 2008-05-30 20:16:34 +00:00
brectanus
3632dae024 Backported changeset:1056 to 2.5.x which handles a lacking new line after the final multipart boundary. See #502. 2008-05-30 20:07:47 +00:00
brectanus
3240e91140 Fixed XML multithreading crash. See #501. 2008-05-30 20:01:44 +00:00
brectanus
603c0626f9 Fixed blocking in phase 3 by reverting changeset:591 (for now). See #65 and #498. 2008-05-30 19:31:22 +00:00
brectanus
e9efefe33e Added mod_rpaf-2.0 and mod_custom_header to the beforeme list. 2008-05-09 15:50:17 +00:00
brectanus
0c3f6bd2c2 Change version/date for release of 2.5.4. 2008-05-07 16:25:07 +00:00
brectanus
0c28f30876 Fix a transformation caching bug. See #490. 2008-05-05 21:57:28 +00:00
brectanus
60af949a7a Update CRS to 1.6.1. See #484. 2008-04-24 16:48:08 +00:00
brectanus
c6edc2d317 Fixed crash if a persistent variable name was more than 126 characters. See #478. 2008-04-24 16:40:14 +00:00
brectanus
a615470028 Fixed issue where the exec action may not be able to execute shell scripts. See #475. 2008-04-24 16:30:58 +00:00
brectanus
28e2ed2068 Expand macros in expirevar and deprecatevar. See #477.
Cleaned up debug logs in actions.
Warn on mismatched curly braces in macro expansion.
2008-04-24 16:23:35 +00:00
brectanus
4bdda866be Add missing CHANGES entry for build fixes. 2008-04-02 16:19:57 +00:00
brectanus
8e75cdb884 Update versions for release. 2008-04-02 16:10:47 +00:00
brectanus
e13d3dab8b Make sure all filehandles are closed at the end of a trasaction. See #464 and #465.
Fixes a few typos in some error messages when we are over the limits.
2008-03-28 20:00:37 +00:00
brectanus
6b970c9185 Added back support for HTTP_* targets by aliasing it to REQUEST_HEADERS:*.
Fixed the severity warning message to only be displayed at a warn log level.
2008-03-19 21:31:41 +00:00
brectanus
b2cf7d1329 Change version to 2.5.1 for tagging. 2008-03-14 23:03:13 +00:00
brectanus
d38f5da865 Change branch version back to -rc1 for re-taging. 2008-03-07 20:50:00 +00:00
brectanus
57e8fc57d9 Change version to 2.5.1-breach2 for appliance. 2008-03-07 20:41:27 +00:00
brectanus
024e854725 Fixed a bug in transformation caching, which would prevent a match in certian cases.
Updated docs on "pass" action to explicitly state that we execute all targets.
2008-03-07 20:23:16 +00:00
brectanus
69a547ccf9 Create a 2.5.1-breach1 for the M1100. 2008-03-05 18:16:23 +00:00
brectanus
20274563fb Make a severity in a default action just a warning instead of a fatal error. 2008-03-04 22:55:39 +00:00
brectanus
628321bb86 Cleaned up "make test" and document as still experimental. 2008-03-03 16:50:40 +00:00
brectanus
1e991d6fcd Add searching for lua in /usr/lib{64|32}.
Do not default to using -Werror (warnings are errors).
2008-02-27 23:18:03 +00:00
brectanus
1fbf0c97f2 Update CHANGES, versions and dates for 2.5.0. 2008-02-15 22:51:01 +00:00
brectanus
8cf74f5c91 Update version dates.
Fix a small typo in Lua example: nil, not null.
2008-02-14 22:16:21 +00:00
brectanus
f00e15cc0a More updates for Windows builds suggested by Tom Donovan at apachelounge. 2008-02-13 18:10:04 +00:00
brectanus
cc2110b187 Updates to build on Windows with MS VC++ 8. 2008-02-13 07:10:54 +00:00
brectanus
20bc34a53f Update core rules to 1.6.0-rc3. 2008-02-11 22:57:54 +00:00
brectanus
731ac3321b Update version date for 2.5.0-rc3. 2008-02-11 22:49:08 +00:00
brectanus
94f617ae1c Update CHANGES and release dates. 2008-02-09 01:22:01 +00:00
brectanus
45e85e4c89 Update CHANGES and version dates. 2008-02-08 01:24:46 +00:00
brectanus
fd8f4e319f Update CHANGES and versions for 2.5.0-rc3. 2008-02-05 00:55:16 +00:00
brectanus
4535b2e67b Cleanup CHANGES and set release dates for 2.5.0-rc2. 2008-01-29 16:36:36 +00:00
brectanus
52ccced72b Cleanup building actionsets and use minimal default. See #445.
Fully resolve all rules before logging.
2008-01-25 04:52:49 +00:00
brectanus
946a350043 Fixed removing cained rules with ctl action. 2008-01-24 22:39:13 +00:00
brectanus
f8adea949c Implemented SecUploadFileMode. See #448. 2008-01-24 22:10:37 +00:00
brectanus
a3584993f5 Implement "block" pseudo-action. See #441. 2008-01-24 05:16:35 +00:00
brectanus
9dbc7807d9 Remove query string from error log. See #447. 2008-01-23 18:12:59 +00:00
brectanus
c72057bc57 Cleanup CHANGES. 2008-01-22 06:59:06 +00:00
brectanus
18e9ef0808 Remove default transformations. See #445. 2008-01-22 05:50:42 +00:00
brectanus
0d24a08f33 Implemented SecRuleUpdateActionById. See #442. 2008-01-19 02:23:41 +00:00
brectanus
9fb03d277d Fixing code based on review comments...
Cleaned up what vars are cacheable.
Added parens around "*foo++" where it clarified the operation to be "*(foo++)".
Added " at VARNAME" to operator matches where needed.
Escaped var->name in the var generation (user-supplied data).
Marked a bunch of TODOs as ENHs instead.
Transformed some C++ style comments to C style.
Removed the %0-9 macros code which was commented out.
Optimized some ctl action code so that multiple ifs are else ifs.
Implemented some error messages marked as ENH.
Make commented out acmp debugging a configure-time option.
Cleanup GEO debug log messages.
Added relative filename support for geo dbs.
Added help text to Sec* directives.
2008-01-18 00:47:30 +00:00
brectanus
31e3ada844 Fixed phase 5 rules not being excludable. 2008-01-08 20:45:54 +00:00