##// END OF EJS Templates
auth: add scope and login restrictions to rhodecode plugin, and scope restriction to token plugin....
auth: add scope and login restrictions to rhodecode plugin, and scope restriction to token plugin. - allows limiting the usage of builtin auth to HTTP only (so force usage of tokens) - allows migration to something like saml keeping only super-admin for login.

File last commit:

r1:854a839a default
r3392:5cc5c872 default
Show More
release-notes-3.6.1.rst
23 lines | 533 B | text/x-rst | RstLexer

|RCE| 3.6.1 |RNS|

Release Date

  • 2015-10-19

Security

  • HTTP response splitting on login redirection has been secured to prevent header injection.

Fixes

  • Alphabetically sort the external license dependencies overview for quicker reading.
  • Change directory permissions checks for Windows.
  • Fixed a login redirection issue when using a custom prefix to improve the user experience when using a proxy server.
  • Skip reading |repos| with names that contain special characters.