##// END OF EJS Templates
comments: fix extracing auth_user from the passed in objects. Before if auth_user is empty we could relly on INT or STR passed in
comments: fix extracing auth_user from the passed in objects. Before if auth_user is empty we could relly on INT or STR passed in

File last commit:

r1:854a839a default
r3026:71b96937 stable
Show More
release-notes-2.2.7.rst
13 lines | 256 B | text/x-rst | RstLexer

|RCE| 2.2.7 |RNS|

General

  • 2015-02-03

Fixes

  • Security: fixed severe issue with leaking of auth_tokens(api_keys) on the following API calls; get_repo, update_repo, get_locks, and get_user_groups.