##// END OF EJS Templates
security: limit the maximum password lenght to 72 characters to prevent possible...
security: limit the maximum password lenght to 72 characters to prevent possible server side resource consumption attack. - bcrypt heavy computation can lead to DOS using a very long password .eg 10**8 lenght. - we allowed this on registration or on password update

File last commit:

r1:854a839a default
r2192:a51e727d stable
Show More
release-notes-2.2.1.rst
15 lines | 343 B | text/x-rst | RstLexer

|RCE| 2.2.1 |RNS|

General

  • released 2013-10-25

News

  • No news

Fixes

  • Fixed issue with forking.
  • Fixed redirection to previous location which was lost via container auth login.
  • API: removed urllib.unquote_plus on raw body. This caused a bug with '+' chars beeing stripped out of sent JSON BODY.