Mercurial > p > roundup > code
annotate doc/security.txt @ 7211:506c86823abb
Add config argument to more password.Password invocations.
The work done to allow password_pbkdf2_default_rounds to be overridden
for testing requires that calls to password.Password include a config
argument.
This was needed because using the real value more than quadrupled
testing runtime.
However there are still a few places where config was not being set
when Password was called. I think this fixes all of the ones that are
called from a function that have access to a db.config object.
The remaining ones all call Password(encrypted=x). This results in
Password.unpack() being called. If x is not a propertly formatted
password string ("{scheme}...", it calls encodePassword. It then
should end up raising the ConfigNotSet exception. This is
probably what we want as it means the shape of "x" is not correct.
I don't understand why Password.unpack() attempts to encrypt the value
of encrypted if it doesn't match the right form. According to codecov,
this encryption branch is being used, so somewhere x is of the wrong
form. Hmmm....
| author | John Rouillard <rouilj@ieee.org> |
|---|---|
| date | Sat, 04 Mar 2023 00:17:26 -0500 |
| parents | a3223f1966fc |
| children | 186956a87ad7 |
| rev | line source |
|---|---|
| 7092 | 1 .. meta:: |
| 2 :description: | |
| 3 Documentation on how to report security issues with | |
| 4 Roundup. Also index to security related portions in other | |
| 5 Roundup documentation. | |
| 6 | |
| 7 .. index:: | |
| 8 single: Reporting Security Issues | |
| 9 single: Security Issues, Reporting | |
| 10 | |
| 11 | |
| 12 ====================================== | |
| 13 Reporting Security Issues with Roundup | |
| 14 ====================================== | |
| 15 | |
| 16 Security issues with Roundup should be reported by email to: | |
| 17 | |
| 18 rouilj@users.sourceforge.net (John Rouillard) | |
| 19 | |
|
7099
a3223f1966fc
update to use ralf's preferred email address.
John Rouillard <rouilj@ieee.org>
parents:
7095
diff
changeset
|
20 rsc@runtux.com (Ralf Schlatterbeck) |
| 7092 | 21 |
| 22 Also you can find rouilj on irc in channel #roundup at irc.oftc.net (see | |
| 23 Contact_ for more directions and web interface). | |
| 24 | |
| 25 Use these mechanisms to establish initial contact. | |
| 26 | |
| 27 .. _Contact: https://www.roundup-tracker.org/contact.html |
