tomcat-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Aejaz Sheriff" <>
Subject RE: source code visible to world
Date Fri, 08 Jun 2001 16:17:12 GMT

I could be completely wrong here. But when I worked with other Web/App 
Servers this problem occurs if the Web Server to App Server redirection of 
the JSP pages is set based on a content type. for e.g if the JSP file 
servlet parses files based on their mime type then this problem occurs as a 
file without the .jsp extention is treated as a mine type of html/text so 
the code or the actual file gets displayed! instead of the JspFileServlet 
(or which ever jsp parser servlet) the App server uses


>From: "Swart, James (Jim) ** CTR **" <>
>To: "''" <>
>Subject: RE: source code visible to world
>Date: Fri, 8 Jun 2001 11:26:55 -0400
>I just tested mine as well (3.2.1) on redhat 6.2. Mine doens't do that
>either.  In addition, if I put in the path to one of my jsps, with or
>without the .jsp extension , it tells me it can't find the file.  Seems to
>be working?
>-----Original Message-----
>From: Randy Layman []
>Sent: Thursday, June 07, 2001 9:51 AM
>Subject: RE: source code visible to world
>	That's interesting.  I just tested my installation and this doesn't
>happen on mine.  I'm running Tomcat 3.2.1 as well.  The file
>%TOMCAT_HOME%/doc/readme starts with the line below:
>$Id: readme,v 2000/12/12 21:01:41 craigmcc Exp $
>indicating that my readme was made in Dec 2000, and all of my JAR files 
>the same timestamp.
>	Perhaps you have a later (or earlier) version?  I remember that I
>upgraded from 3.2 to 3.2.1 because 3.2.1. supposedly fixed a bug that
>allowed the JSP source to be published (I don't remember how it was
>happening, though).
>	Randy
> > -----Original Message-----
> > From: Ben Carterette []
> > Sent: Thursday, June 07, 2001 11:22 AM
> > To:
> > Subject: source code visible to world
> >
> >
> > I'm running Tomcat 3.2.1, and I've discovered something odd:  when I
> > browse to my JSP pages but leave off the .jsp extension, I see the
> > source code of the file.  Is this a bug or a feature?  If it's a
> > feature, how do I turn it off?  If it's a bug, how do I patch it?
> >
> > Thanks,
> > Ben.
> >

Get Your Private, Free E-mail from MSN Hotmail at

View raw message