##// END OF EJS Templates
auth: don't break hashing in case of user with empty password....
auth: don't break hashing in case of user with empty password. In some cases such as LDAP user created via external scripts users might set the passwords to empty. The hashing uses the md5(password_hash) to store reference to detect password changes and forbid using the same password. In case of pure LDAP users this is not valid, and we shouldn't raise Errors in such case. This change makes it work for empty passwords now.

File last commit:

r1249:ee3db851 stable
r2203:8a18c3c3 default
Show More
release-notes-4.5.2.rst
46 lines | 752 B | text/x-rst | RstLexer

|RCE| 4.5.2 |RNS|

Release Date

  • 2016-12-19

New Features

General

  • Github authentication: no longer require repository permissions when connecting RhodeCode account with Github login.
  • Api: added new function get_repo_refs. This was accidentally exposed in our documentation as valid function, but wasn't implemented. This function is now backported from next major release due the documentation issues.

Security

Performance

Fixes

  • Api: Fixed a regression in API validation on create_* functions. Before this fix it always converted given data to lowercase.
  • System info: fixed reporting of free inodes as taken.

Upgrade notes