tomcat-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Mark Thomas" <>
Subject RE: HTTPOnly in Tomcat -- Yes please!
Date Mon, 12 Jan 2009 20:27:47 GMT
> Hey Gents, just wanted to follow-up on this. I haven't seen any
> activity on the buzilla issue below so I wanted to know if there is
> anything we can do to help. I've got a bunch of devs ready and willing
> to chip in for testing, ideas, or even submitting patches. Also I can
> chip in to get other big-name application security folks to chip in on
> this if that is what it takes to get some more visiblity.

trunk has been updated to provide this as per the 3.0 spec. What is needed
to a review of the current proposed patch for 6.0.x (which has to stick to
the 2.5 spec) to check that it still makes sense given what is now in trunk.

Review comments welcome.

Assuming all is OK, it needs 3 +1's from committers to get into the next
6.0.x release.


To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message