[Bug 199842] [maintainer update] security/p5-Dancer-Plugin-Auth-Extensible update to 0.40

bugzilla-noreply at freebsd.org bugzilla-noreply at freebsd.org
Fri May 1 15:48:45 UTC 2015


https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=199842

            Bug ID: 199842
           Summary: [maintainer update]
                    security/p5-Dancer-Plugin-Auth-Extensible update to
                    0.40
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Some People
          Priority: ---
         Component: Individual Port(s)
          Assignee: freebsd-ports-bugs at FreeBSD.org
          Reporter: hvo.pm at xs4all.nl

Created attachment 156215
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=156215&action=edit
diff -ruN

portlint -A, QA-test, portmaster,... all fine.

 Changes for version 0.40

    ENHANCEMENTS
        Login handlers go straight to homepage if user was already logged in
(thanks to @colinmkeith, GH-32)
        Kwalitee improvements from Michael Gray (mjg17) as part of the awesome
pull request challenge (GH-43, GH-44, GH-45, GH-46)
    SECURITY
        Ensure the username and password we got were straight scalars, to avoid
potential for "JSON SQL injection" if they came from a deserialised JSON POST
body, and contained a hashref that, if fed to e.g. SQL::Abstract or such, would
cause a different query to what we'd expect.

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the freebsd-ports-bugs mailing list