users@glassfish.java.net

Re: Application Server 9.1 update 2 Put and Delete method

From: Jeanfrancois Arcand <Jeanfrancois.Arcand_at_Sun.COM>
Date: Thu, 18 Jun 2009 11:06:35 -0400

Salut,

glassfish_at_javadesktop.org wrote:
> Trying to pass a security scan anyone know how to disable the Delete and Put methods?

We just support disabling TRACE right now. But you can always write a
Valve of Filter to disable the other. Which security tool are you using?

A+

-- Jeanfrancois


>
> Information found on port http (80)
> Options allowed : GET, HEAD, POST, PUT, DELETE, TRACE, OPTIONS
>
> Please ensure PUT and DELETE method are disabled and removed
> [Message sent by forum member 'markwal229' (markwal229)]
>
> http://forums.java.net/jive/thread.jspa?messageID=351845
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: users-unsubscribe_at_glassfish.dev.java.net
> For additional commands, e-mail: users-help_at_glassfish.dev.java.net
>