Skip to content

v0.60.1

Latest

Choose a tag to compare

@yhirose yhirose released this 08 Oct 03:42

What's Changed

Bug fixes

  • Serve the whole body for a suffix range longer than it (#2615). A Range suffix longer than the body, such as bytes=-500 on a 100-byte body, was answered with 416. The whole body is now sent as a 206, as RFC 9110 §14.1.2 specifies. This restores the behavior before v0.15.1. bytes=-0 is still answered with 416.
  • Windows certificate verification: accept an unknown revocation status (#2618, replaces #2617). With Windows certificate verification on, a server certificate whose revocation status could not be determined was rejected. This affected a certificate without a CRL distribution point or OCSP URL, as is common with a private CA installed in the Windows store, and one whose CRL could not be fetched. A check of the chain's trust status ran before CertVerifyCertificateChainPolicy() and failed on any error bit, so the policy flag that ignores an unknown revocation status never applied (since v0.31.0). That check is removed, and the SSL chain policy alone judges the chain.
    • Revocation checking is now best-effort. A revoked certificate is still rejected, and so is every other chain error.
    • On a rejected chain, ssl_backend_error() now holds the chain policy status, an HRESULT such as CERT_E_UNTRUSTEDROOT, instead of the trust status bit mask.

Build

  • Fix a compile error with MSVC when an unrelated WebSocketClient class is declared before httplib.h is included (#2616). MSVC bound the unqualified friend class WebSocketClient; in ws::WebSocket to the outer class, so ws::WebSocketClient lost access to the private members it uses (C2248). The friend declaration is now qualified and preceded by a forward declaration.

Documentation

  • README: describe revocation checking on Windows as best-effort.

Full Changelog: v0.60.0...v0.60.1