Security Advisories (1)
CVE-2026-5083 (2026-04-08)

Ado::Sessions versions through 0.935 for Perl generates insecure session ids. The session id is generated from a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. Predicable session ids could allow an attacker to gain access to systems. Note that Ado is no longer maintained, and has been removed from the CPAN index. It is still available on BackPAN.

NAME

Ado - a rapid active commotion (framework for web-projects on Mojolicious)

SYNOPSIS

require Mojolicious::Commands;
Mojolicious::Commands->start_app('Ado');

DESCRIPTION

Ado is a framework for web-projects based on Mojolicious, written in the Perl programming language. This is the base application class. Ado ISA Mojolicious. For a more detailed description on how to get started with Ado see Ado::Manual.

ATTRIBUTES

Ado inherits all attributes from Mojolicious and implements the following ones.

CODENAME

Returns the current CODENAME.

sessions

Access the Ado::Sessions instance. Instantiates one of Ado::Sessions::File, Ado::Sessions::Database or Mojolicious::Sessions depending on configuration and returns it. By default (no configuration in etc/ado.conf) a Mojolicious::Sessions is returned.

METHODS

Ado inherits all methods from Mojolicious and implements the following new ones.

startup

The startup method is where everything begins. Returns void. The following methods are listed in the order they are innvoked in "startup".

load_config

Loads the configuration file $app->home/etc/ado.conf. Returns $app.

load_plugins

Does not accept any parameters. Loads plugins listed in $config->{plugins}. $config->{plugins} is an ARRAYREF in which each element is a HASHREF with keys name and config or string representing the plugin name. The name of the plugin is expected to be string that can be passed to "plugin" in Mojolicious. The config values is another HASHREF containing the configuration for the plugin. Plugins can be Mojolicious or Ado specific plugins. Every Ado::Plugin::Foo must inherit from Ado::Plugin which ISA Mojolicious::Plugin. Of course Mojolicious plugins can be used - we count on this. There are plenty of examples on CPAN. Returns $app.

load_routes

Does not accept any parameters. Loads predefined routes from $config->routes. $config->routes is an ARRAYREF in which each element is a HASHREF with keys corresponding to a method name and value the parameters that will be passed to the method. Currently we use the route value to pass it to "route" in Mojolicious::Routes,params value is the second parameter to instantiate the route. via and to values are passed to the newly created route. See Mojolicious::Routes::Route and Mojolicious::Guides::Routing for more.

Returns $app.

define_mime_types

Defines any MIME types listed in ado.conf in types => {...}. Returns $app.

define_hooks

May be never implemented. Plugins can define code which is run in "hooks" in Mojolicious. Returns $app.

SPONSORS

The original author.

Become a sponsor and help make Ado the ERP for the enterprise!

SEE ALSO

Mojolicious, Ado::Manual, http://www.thefreedictionary.com/ado,

AUTHOR

Красимир Беров (Krasimir Berov)

COPYRIGHT AND LICENSE

Copyright 2013-2014 Красимир Беров (Krasimir Berov).

This program is free software, you can redistribute it and/or modify it under the terms of the GNU Lesser General Public License v3 (LGPL-3.0). You may copy, distribute and modify the software provided that modifications are open source. However, software that includes the license may release under a different license.

See http://opensource.org/licenses/lgpl-3.0.html for more information.