##// END OF EJS Templates
security: limit the maximum password lenght to 72 characters to prevent possible...
security: limit the maximum password lenght to 72 characters to prevent possible server side resource consumption attack. - bcrypt heavy computation can lead to DOS using a very long password .eg 10**8 lenght. - we allowed this on registration or on password update

File last commit:

r1208:0db7c57b stable
r2192:a51e727d stable
Show More
release-notes-4.5.1.rst
48 lines | 800 B | text/x-rst | RstLexer

|RCE| 4.5.1 |RNS|

Release Date

  • 2016-12-06

New Features

General

  • Pull requests: save dates of updates when creating updates. This will help with later pull request versioning functionality.

Security

Performance

Fixes

  • VCSServer: improve error detection of servers pushed from VCSServer.
  • VCSServer: reduce redundant logging.
  • VCSServer: improved obfuscation logic in logs in case of no passwords.
  • Pull Requests: fixed outdated comments displaying.
  • Diffs: few fixes for new diffs discovered.
  • Repository groups: improved detection of repository groups parent.
  • Default Reviewers: fixed missing templates in installer that caused 500 errors on first display.

Upgrade notes