##// END OF EJS Templates
auth: don't break hashing in case of user with empty password....
auth: don't break hashing in case of user with empty password. In some cases such as LDAP user created via external scripts users might set the passwords to empty. The hashing uses the md5(password_hash) to store reference to detect password changes and forbid using the same password. In case of pure LDAP users this is not valid, and we shouldn't raise Errors in such case. This change makes it work for empty passwords now.

File last commit:

r1637:c3a8855b stable
r2203:8a18c3c3 default
Show More
release-notes-4.7.1.rst
43 lines | 576 B | text/x-rst | RstLexer

|RCE| 4.7.1 |RNS|

Release Date

  • 2017-04-13

New Features

General

Security

  • Auth plugins: don't expose sensitive information inside DEBUG log for auth plugins (such as ldap access passwords). Each plugin now defines a black-list of arguments to hide from logging.

Performance

Fixes

  • Largefiles: fix errors on fetching largefiles from web interface when viewing from specific branch.
  • User Admin: fix problem with sorting for Mysql database.

Upgrade notes