[ 
https://issues.apache.org/jira/browse/JENA-1125?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15125420#comment-15125420
 ] 

ASF subversion and git services commented on JENA-1125:
-------------------------------------------------------

Commit 04b8d861ce0b5238cba66306c518ea7d801f9496 in jena's branch 
refs/heads/master from [~andy.seaborne]
[ https://git-wip-us.apache.org/repos/asf?p=jena.git;h=04b8d86 ]

JENA-1125: Provide for all possible choices of "Server:" output.

> Suppress output of "Server:" with version information.
> ------------------------------------------------------
>
>                 Key: JENA-1125
>                 URL: https://issues.apache.org/jira/browse/JENA-1125
>             Project: Apache Jena
>          Issue Type: Improvement
>          Components: Fuseki
>            Reporter: Andy Seaborne
>            Assignee: Andy Seaborne
>            Priority: Minor
>             Fix For: Fuseki 2.4.0
>
>
> Security reports sometimes worry about revealing version information , 
> despite this being open source where every detail is available anyway.
> We could suppress or modify the output of the "Server:" header, added by 
> Jetty and by Fuseki.
> Should we omit the header?
> Have the system name but not the version?
> Keep the information anyway?
> Making it some kind of configuration feature is difficult because of the 
> variety of environments Fuseki runs in (standalone or from a war file). 
> Because of that, initialization happens quite late and the only current 
> server configuration is about the general Jena environment.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to