##// END OF EJS Templates
shadow-repos: use safer way to destroy shadow repositories....
shadow-repos: use safer way to destroy shadow repositories. we had reported errors on removal of shadow repos. Not reproduced, however suspecting are filesystem sync/symlink race-conditions on shared storage. End result were existing shadow-repo directories that tricked rhodecode into thinking shadow repos is existing, but infact it was a dummy structure semi-removed. Using shutil.move we ENSURE rhodecode doesn't read those back even if removal fails.

File last commit:

r2665:f42f8690 stable
r2791:27d869d5 stable
Show More
release-notes-4.11.6.rst
41 lines | 489 B | text/x-rst | RstLexer

|RCE| 4.11.6 |RNS|

Release Date

  • 2018-03-28

New Features

General

Security

  • api(high): fixed unauthorized access to repositories using forged api requests.

Performance

Fixes

Upgrade notes

  • Unscheduled security release addressing found vulnerability in the API that allows attackers to gain access to repositories in unauthorized way by forging data in the API request.