##// END OF EJS Templates
security: limit the maximum password lenght to 72 characters to prevent possible...
security: limit the maximum password lenght to 72 characters to prevent possible server side resource consumption attack. - bcrypt heavy computation can lead to DOS using a very long password .eg 10**8 lenght. - we allowed this on registration or on password update

File last commit:

r1167:c0cc2e45 default
r2192:a51e727d stable
Show More
release-notes-4.4.1.rst
39 lines | 677 B | text/x-rst | RstLexer

|RCE| 4.4.1 |RNS|

Release Date

  • 2016-09-27

New Features

General

  • Channelstream: auto-generate the url to channelstream server if it's not explicitly defined in the config. It allows to use a relative server without knowing its address upfront.

Security

Performance

Fixes

  • GIT: properly extract branches on events and submit them to integrations.
  • Pull requests: fix problems with unicode in auto-generated descriptions
  • Gist: fixed bug in update functionality of Gists that auto changed them to private.
  • SVN: add proper escaping in the autogenerated svn mod_dav config