Repository navigation
What's Changed
Bug fixes
- Serve the whole body for a suffix range longer than it (#2615). A
Rangesuffix longer than the body, such asbytes=-500on a 100-byte body, was answered with 416. The whole body is now sent as a 206, as RFC 9110 §14.1.2 specifies. This restores the behavior before v0.15.1.bytes=-0is still answered with 416. - Windows certificate verification: accept an unknown revocation status (#2618, replaces #2617). With Windows certificate verification on, a server certificate whose revocation status could not be determined was rejected. This affected a certificate without a CRL distribution point or OCSP URL, as is common with a private CA installed in the Windows store, and one whose CRL could not be fetched. A check of the chain's trust status ran before
CertVerifyCertificateChainPolicy()and failed on any error bit, so the policy flag that ignores an unknown revocation status never applied (since v0.31.0). That check is removed, and the SSL chain policy alone judges the chain.- Revocation checking is now best-effort. A revoked certificate is still rejected, and so is every other chain error.
- On a rejected chain,
ssl_backend_error()now holds the chain policy status, anHRESULTsuch asCERT_E_UNTRUSTEDROOT, instead of the trust status bit mask.
Build
- Fix a compile error with MSVC when an unrelated
WebSocketClientclass is declared beforehttplib.his included (#2616). MSVC bound the unqualifiedfriend class WebSocketClient;inws::WebSocketto the outer class, sows::WebSocketClientlost access to the private members it uses (C2248). The friend declaration is now qualified and preceded by a forward declaration.
Documentation
- README: describe revocation checking on Windows as best-effort.
Full Changelog: v0.60.0...v0.60.1