Return-Path: Delivered-To: apmail-jakarta-tomcat-dev-archive@apache.org Received: (qmail 18944 invoked from network); 22 Mar 2002 21:15:29 -0000 Received: from unknown (HELO nagoya.betaversion.org) (192.18.49.131) by daedalus.apache.org with SMTP; 22 Mar 2002 21:15:29 -0000 Received: (qmail 23581 invoked by uid 97); 22 Mar 2002 21:15:28 -0000 Delivered-To: qmlist-jakarta-archive-tomcat-dev@jakarta.apache.org Received: (qmail 23565 invoked by uid 97); 22 Mar 2002 21:15:27 -0000 Mailing-List: contact tomcat-dev-help@jakarta.apache.org; run by ezmlm Precedence: bulk List-Unsubscribe: List-Subscribe: List-Help: List-Post: List-Id: "Tomcat Developers List" Reply-To: "Tomcat Developers List" Delivered-To: mailing list tomcat-dev@jakarta.apache.org Received: (qmail 23554 invoked from network); 22 Mar 2002 21:15:27 -0000 X-Authentication-Warning: localhost.localdomain: costinm owned process doing -bs Date: Fri, 22 Mar 2002 13:13:36 -0800 (PST) From: X-X-Sender: To: Tomcat Developers List Subject: Re: [VOTE] Tomcat 4.0.4 Beta 2 / Coyote 1.0 Beta 4 release In-Reply-To: <001001c1d1d8$8116a2d0$64859181@apache.org> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII X-Spam-Rating: daedalus.apache.org 1.6.2 0/1000/N X-Spam-Rating: daedalus.apache.org 1.6.2 0/1000/N On Fri, 22 Mar 2002, Remy Maucherat wrote: > > > below). The Coyote connector will *not* be enabled by default, but will > > > appear commented out in the default server.xml configuration file. > > > > +1 on enabling it by default, commenting out the old connector. > > I didn't propose to do that, because, although the new connector appears > robust and stable, there's the risk that it would have new bugs, or, even > worse, (re)introduce some security problems. I took great care of adding all > the URL normalization code from the old connector, so that it shouldn't > happen, but I'd say it would still be a significant risk to make it the > default without some extensive beta period. Since there will be such a beta > period for 4.1, I think it is a lot safer to postpone making it the default > for now. > > Comments ? The code is clearly better and cleaner than the old connector, that means more maintainable and easier to fix and review - if there's any problem. And cleaner code is usually more secure :-) But I agree it's safer to do it gradually, however I hope 4.0.5 and 3.3.2 will have coyote as the default connector. Costin -- To unsubscribe, e-mail: For additional commands, e-mail: