view website/www/docs.txt @ 6375:c4371ec7d1c0

Call verifyPassword even if user does not exist. Address timing attack caused by not doing the password check if the user doesn't exist. Can expose valid usernames. Really only useful for a tracker that doesn't allow anonymous access to issues. Issues usually show usernames as part of the message display.
author John Rouillard <rouilj@ieee.org>
date Tue, 06 Apr 2021 22:51:55 -0400
parents 29d428927362
children 6f5054751fb6
line wrap: on
line source

Docs
====

.. toctree::
   :maxdepth: 2

   docs/features
   docs/installation
   docs/upgrading
   docs/FAQ
   docs/user_guide
   docs/customizing
   docs/admin_guide
   docs/debugging
   docs/xmlrpc
   docs/rest
   docs/tracker_templates
   docs/glossary
   docs/acknowledgements
   docs/license
   Design Overview <docs/overview>
   Design (original) <docs/design>
   docs/developers
   Notes about the MySQL Database backend <docs/mysql>
   Notes about the PostgreSQL Database backend <docs/postgresql>
   Richard Jones implementation notes <docs/implementation>

Roundup Issue Tracker: http://roundup-tracker.org/