Based on "git blame" it looks like the code that effectively comments out 
enforcement of the push_method_enabled has been commented out since the code 
base moved to git (in 2009).

This has caused security problems due to deployments that assumed this 
configuration was actually doing something.  I think we have decided to 
concentrate on the IpAllow mechanism to control which methods are permitted, so 
the remnants of this mechanism should be removed to avoid confusion.

[ Full content available at: https://github.com/apache/trafficserver/pull/4304 ]
This message was relayed via gitbox.apache.org for [email protected]

Reply via email to