##// END OF EJS Templates
security: limit the maximum password lenght to 72 characters to prevent possible...
security: limit the maximum password lenght to 72 characters to prevent possible server side resource consumption attack. - bcrypt heavy computation can lead to DOS using a very long password .eg 10**8 lenght. - we allowed this on registration or on password update

File last commit:

r1:854a839a default
r2192:a51e727d stable
Show More
release-notes-3.0.1.rst
22 lines | 505 B | text/x-rst | RstLexer

|RCE| 3.0.1 |RNS|

General

  • 2015-02-03

News

  • Server info: added more details into server info page.

Fixes

  • Security: fixed severe issue with leaking of auth_tokens(api_keys) on certain API calls.
  • VCS Client: Improved reconnection logic.
  • SVN: forbid certain actions like pull requests on svn repositories.
  • Style: fixed comments with Markdown, and also multiple styling issues.
  • Style: fixed re-captcha html issues.
  • Style: fixed large inputs.