ivanr
2f6d1f873e
Remove description of transformation caching issues from CHANGES.
2008-07-31 09:04:05 +00:00
brectanus
9fd865b763
Add the licensing exception (a text version).
2008-07-29 04:43:59 +00:00
brectanus
6ebc5ad6e7
Transformation caching fixes. See #364 .
2008-07-29 00:18:16 +00:00
brectanus
e1342ff011
Backport trunk changes for changeset:1072 and changeset:1073 to 2.5, but leave out the error filter code until more testing is completed. See #498 .
2008-06-05 16:55:53 +00:00
brectanus
896ae59e1f
Re-enable error output filter with a fix after more testing/tracing of code. See #498 .
...
Update versions to ready for release of 2.5.5.
2008-06-03 20:28:05 +00:00
brectanus
22f1c61f1d
Fixed issue where logging was not occuring unless "auditlog" was enabled. See #497 , #4 , #451 and #445 .
2008-06-02 23:34:31 +00:00
brectanus
a9fca34107
Enable "auditlog" action by default. See #445 and #451 .
2008-06-02 23:31:27 +00:00
brectanus
0389a88b6a
Backport fix to improve request body processing error messages. See #504 .
2008-05-30 20:16:34 +00:00
brectanus
3632dae024
Backported changeset:1056 to 2.5.x which handles a lacking new line after the final multipart boundary. See #502 .
2008-05-30 20:07:47 +00:00
brectanus
3240e91140
Fixed XML multithreading crash. See #501 .
2008-05-30 20:01:44 +00:00
brectanus
603c0626f9
Fixed blocking in phase 3 by reverting changeset:591 (for now). See #65 and #498 .
2008-05-30 19:31:22 +00:00
brectanus
e9efefe33e
Added mod_rpaf-2.0 and mod_custom_header to the beforeme list.
2008-05-09 15:50:17 +00:00
brectanus
0c3f6bd2c2
Change version/date for release of 2.5.4.
2008-05-07 16:25:07 +00:00
brectanus
0c28f30876
Fix a transformation caching bug. See #490 .
2008-05-05 21:57:28 +00:00
brectanus
60af949a7a
Update CRS to 1.6.1. See #484 .
2008-04-24 16:48:08 +00:00
brectanus
c6edc2d317
Fixed crash if a persistent variable name was more than 126 characters. See #478 .
2008-04-24 16:40:14 +00:00
brectanus
a615470028
Fixed issue where the exec action may not be able to execute shell scripts. See #475 .
2008-04-24 16:30:58 +00:00
brectanus
28e2ed2068
Expand macros in expirevar and deprecatevar. See #477 .
...
Cleaned up debug logs in actions.
Warn on mismatched curly braces in macro expansion.
2008-04-24 16:23:35 +00:00
brectanus
4bdda866be
Add missing CHANGES entry for build fixes.
2008-04-02 16:19:57 +00:00
brectanus
8e75cdb884
Update versions for release.
2008-04-02 16:10:47 +00:00
brectanus
e13d3dab8b
Make sure all filehandles are closed at the end of a trasaction. See #464 and #465 .
...
Fixes a few typos in some error messages when we are over the limits.
2008-03-28 20:00:37 +00:00
brectanus
6b970c9185
Added back support for HTTP_* targets by aliasing it to REQUEST_HEADERS:*.
...
Fixed the severity warning message to only be displayed at a warn log level.
2008-03-19 21:31:41 +00:00
brectanus
b2cf7d1329
Change version to 2.5.1 for tagging.
2008-03-14 23:03:13 +00:00
brectanus
d38f5da865
Change branch version back to -rc1 for re-taging.
2008-03-07 20:50:00 +00:00
brectanus
57e8fc57d9
Change version to 2.5.1-breach2 for appliance.
2008-03-07 20:41:27 +00:00
brectanus
024e854725
Fixed a bug in transformation caching, which would prevent a match in certian cases.
...
Updated docs on "pass" action to explicitly state that we execute all targets.
2008-03-07 20:23:16 +00:00
brectanus
69a547ccf9
Create a 2.5.1-breach1 for the M1100.
2008-03-05 18:16:23 +00:00
brectanus
20274563fb
Make a severity in a default action just a warning instead of a fatal error.
2008-03-04 22:55:39 +00:00
brectanus
628321bb86
Cleaned up "make test" and document as still experimental.
2008-03-03 16:50:40 +00:00
brectanus
1e991d6fcd
Add searching for lua in /usr/lib{64|32}.
...
Do not default to using -Werror (warnings are errors).
2008-02-27 23:18:03 +00:00
brectanus
1fbf0c97f2
Update CHANGES, versions and dates for 2.5.0.
2008-02-15 22:51:01 +00:00
brectanus
8cf74f5c91
Update version dates.
...
Fix a small typo in Lua example: nil, not null.
2008-02-14 22:16:21 +00:00
brectanus
f00e15cc0a
More updates for Windows builds suggested by Tom Donovan at apachelounge.
2008-02-13 18:10:04 +00:00
brectanus
cc2110b187
Updates to build on Windows with MS VC++ 8.
2008-02-13 07:10:54 +00:00
brectanus
20bc34a53f
Update core rules to 1.6.0-rc3.
2008-02-11 22:57:54 +00:00
brectanus
731ac3321b
Update version date for 2.5.0-rc3.
2008-02-11 22:49:08 +00:00
brectanus
94f617ae1c
Update CHANGES and release dates.
2008-02-09 01:22:01 +00:00
brectanus
45e85e4c89
Update CHANGES and version dates.
2008-02-08 01:24:46 +00:00
brectanus
fd8f4e319f
Update CHANGES and versions for 2.5.0-rc3.
2008-02-05 00:55:16 +00:00
brectanus
4535b2e67b
Cleanup CHANGES and set release dates for 2.5.0-rc2.
2008-01-29 16:36:36 +00:00
brectanus
52ccced72b
Cleanup building actionsets and use minimal default. See #445 .
...
Fully resolve all rules before logging.
2008-01-25 04:52:49 +00:00
brectanus
946a350043
Fixed removing cained rules with ctl action.
2008-01-24 22:39:13 +00:00
brectanus
f8adea949c
Implemented SecUploadFileMode. See #448 .
2008-01-24 22:10:37 +00:00
brectanus
a3584993f5
Implement "block" pseudo-action. See #441 .
2008-01-24 05:16:35 +00:00
brectanus
9dbc7807d9
Remove query string from error log. See #447 .
2008-01-23 18:12:59 +00:00
brectanus
c72057bc57
Cleanup CHANGES.
2008-01-22 06:59:06 +00:00
brectanus
18e9ef0808
Remove default transformations. See #445 .
2008-01-22 05:50:42 +00:00
brectanus
0d24a08f33
Implemented SecRuleUpdateActionById. See #442 .
2008-01-19 02:23:41 +00:00
brectanus
9fb03d277d
Fixing code based on review comments...
...
Cleaned up what vars are cacheable.
Added parens around "*foo++" where it clarified the operation to be "*(foo++)".
Added " at VARNAME" to operator matches where needed.
Escaped var->name in the var generation (user-supplied data).
Marked a bunch of TODOs as ENHs instead.
Transformed some C++ style comments to C style.
Removed the %0-9 macros code which was commented out.
Optimized some ctl action code so that multiple ifs are else ifs.
Implemented some error messages marked as ENH.
Make commented out acmp debugging a configure-time option.
Cleanup GEO debug log messages.
Added relative filename support for geo dbs.
Added help text to Sec* directives.
2008-01-18 00:47:30 +00:00
brectanus
31e3ada844
Fixed phase 5 rules not being excludable.
2008-01-08 20:45:54 +00:00