Its there "for convenience" (and been there "forever") - but it is a great big security whole if we ignore case (Try asking for /web-INF/wEb.xml - or even more evil "/web-INF/wEb.xm%6c")

-Tim

André Warnier wrote:
Even that wouldn't work.
Since the filesystem is case-sensitive, it may well have both "abc.html" and "ABC.HTML" in the same directory. So which one would it pick to keep ?

So, back to the Tomcat developers. What /is/ the point of the caseSensitive attribute in the <Context> element ?


---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org
For additional commands, e-mail: users-h...@tomcat.apache.org

Reply via email to