##// END OF EJS Templates
security: limit the maximum password lenght to 72 characters to prevent possible...
security: limit the maximum password lenght to 72 characters to prevent possible server side resource consumption attack. - bcrypt heavy computation can lead to DOS using a very long password .eg 10**8 lenght. - we allowed this on registration or on password update

File last commit:

r182:04c494ee stable
r2192:a51e727d stable
Show More
release-notes-4.1.2.rst
16 lines | 346 B | text/x-rst | RstLexer

|RCE| 4.1.2 |RNS|

Release Date

  • 2016-06-16

Fixes

  • ssl: fixed http middleware so it works correctly with pyramid views. This fixed http -> https redirection problems on login.
  • ldap: fixed ldap usergroup authentication plugin so after upgrade it's
    possible to change the settings again (EE only).