Uploaded image for project: 'Apache Jena'
  1. Apache Jena
  2. JENA-1125

Suppress output of "Server:" with version information.

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • None
    • Fuseki 2.4.0
    • Fuseki
    • None

    Description

      Security reports sometimes worry about revealing version information , despite this being open source where every detail is available anyway.

      We could suppress or modify the output of the "Server:" header, added by Jetty and by Fuseki.

      Should we omit the header?
      Have the system name but not the version?
      Keep the information anyway?

      Making it some kind of configuration feature is difficult because of the variety of environments Fuseki runs in (standalone or from a war file). Because of that, initialization happens quite late and the only current server configuration is about the general Jena environment.

      Attachments

        Activity

          People

            andy Andy Seaborne
            andy Andy Seaborne
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: