##// END OF EJS Templates
auth: don't break hashing in case of user with empty password....
auth: don't break hashing in case of user with empty password. In some cases such as LDAP user created via external scripts users might set the passwords to empty. The hashing uses the md5(password_hash) to store reference to detect password changes and forbid using the same password. In case of pure LDAP users this is not valid, and we shouldn't raise Errors in such case. This change makes it work for empty passwords now.

File last commit:

r1:854a839a default
r2203:8a18c3c3 default
Show More
release-notes-3.3.2.rst
25 lines | 499 B | text/x-rst | RstLexer
/ docs / release-notes / release-notes-3.3.2.rst
project: added all source files and assets
r1 |RCE| 3.3.2 |RNS|
-----------------
Release Date
^^^^^^^^^^^^
- 2015-06-05
security fixes
^^^^^^^^^^^^^^
* Stored XSS attempts on user login fields, and other text input fields.
* DOM Based XSS attempts
* HTML Injection
* Cross frame scripting (XFS)
* Invalidation of concurrent sessions on password change.
* Downgrading of HTTPS connections.
fixes
^^^^^
* Generation of URLs on system with custom URL prefixes.
* VCSServer: Improved memory management of the cache data used by the server.