Project

General

Profile

« Previous | Next » 

Revision 7c67cfe4

Added by Dominic Cleal about 10 years ago

fixes #4457 - Session fixation, new session IDs are not generated on login (CVE-2014-0090)

(cherry picked from commit cfa4b52638173b9cf77ee1a5fd0c3a273f875209)

Conflicts:
test/functional/users_controller_test.rb

View differences:

test/lib/foreman/access_permissions_test.rb
# Apipie
"apipie/apipies/index",
# API app controller stub
"api/testable/index", "api/testable/raise_error"
# App controller stubs
"testable/index", "api/testable/index", "api/testable/raise_error"
]
MAY_SKIP_AUTHORIZED = [ "about/index" ]

Also available in: Unified diff