##// END OF EJS Templates
security: limit the maximum password lenght to 72 characters to prevent possible...
security: limit the maximum password lenght to 72 characters to prevent possible server side resource consumption attack. - bcrypt heavy computation can lead to DOS using a very long password .eg 10**8 lenght. - we allowed this on registration or on password update

File last commit:

r1249:ee3db851 stable
r2192:a51e727d stable
Show More
release-notes-4.5.2.rst
46 lines | 752 B | text/x-rst | RstLexer

|RCE| 4.5.2 |RNS|

Release Date

  • 2016-12-19

New Features

General

  • Github authentication: no longer require repository permissions when connecting RhodeCode account with Github login.
  • Api: added new function get_repo_refs. This was accidentally exposed in our documentation as valid function, but wasn't implemented. This function is now backported from next major release due the documentation issues.

Security

Performance

Fixes

  • Api: Fixed a regression in API validation on create_* functions. Before this fix it always converted given data to lowercase.
  • System info: fixed reporting of free inodes as taken.

Upgrade notes