##// END OF EJS Templates
shadow-repos: use safer way to destroy shadow repositories....
shadow-repos: use safer way to destroy shadow repositories. we had reported errors on removal of shadow repos. Not reproduced, however suspecting are filesystem sync/symlink race-conditions on shared storage. End result were existing shadow-repo directories that tricked rhodecode into thinking shadow repos is existing, but infact it was a dummy structure semi-removed. Using shutil.move we ENSURE rhodecode doesn't read those back even if removal fails.

File last commit:

r1:854a839a default
r2777:f1cc2e3d default
Show More
release-notes-3.3.2.rst
25 lines | 499 B | text/x-rst | RstLexer

|RCE| 3.3.2 |RNS|

Release Date

  • 2015-06-05

security fixes

  • Stored XSS attempts on user login fields, and other text input fields.
  • DOM Based XSS attempts
  • HTML Injection
  • Cross frame scripting (XFS)
  • Invalidation of concurrent sessions on password change.
  • Downgrading of HTTPS connections.

fixes

  • Generation of URLs on system with custom URL prefixes.
  • VCSServer: Improved memory management of the cache data used by the server.