Re: Spam attack, observations, how to repair

Ralf Schlatterbeck <[email protected]>
Newsgroups gmane.comp.bug-tracking.roundup.user
Message-ID <[email protected]>
On Fri, Jul 04, 2014 at 01:09:29PM -0400, John P. Rouillard wrote:
[...]
> to let an agent (javascript on a roundup page for example) get an
> index of possible actions/state changes etc.
> 
> Now with that understanding, I claim that a trailing '/' in the
> current roundup is an error.
> 
> Ralf, is there some historic reason the trailing '/' is allowed for
> files given that it returns the same data as a url without the trailing
> '/'? I.E> both:
> 
> http://issues.roundup-tracker.org/file1496/roundupdb.py
> http://issues.roundup-tracker.org/file1496/roundupdb.py/
> 
> return the same page.

No, I don't think so. Probably only keeping the parser simple.
So removing this behaviour is probably a good idea, I don't think
anything currently depends on this.

> I would like the trailing / form for files to return a 404 personally
> so in the future it can be used as part of a REST (or other)
> interface.
> 
> Also it would be consistent with:
> 
> http://issues.roundup-tracker.org/issue2550671/ (returns 404)
> http://issues.roundup-tracker.org/issue2550671 (doesn't return 404)
> 
> http://issues.roundup-tracker.org/user5/ (returns 404)
> http://issues.roundup-tracker.org/user5 (doesn't return 404)

Fine with me.

Ralf

-- 
Dr. Ralf Schlatterbeck                  Tel:   +43/2243/26465-16
Open Source Consulting                  www:   http://www.runtux.com
Reichergasse 131, A-3411 Weidling       email: [email protected]
allmenda.com member                     email: [email protected]

------------------------------------------------------------------------------
Open source business process management suite built on Java and Eclipse
Turn processes into business applications with Bonita BPM Community Edition
Quickly connect people, data, and systems into organized workflows
Winner of BOSSIE, CODIE, OW2 and Gartner awards
http://p.sf.net/sfu/Bonitasoft
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.