Security Advisories (2)
CPANSA-Jifty-2011-01 (2011-03-17)

The path as passed in the fragment request data structure was used verbatim in the dispatcher and other locations. This possibly allowed requests to walk around ACLs by requesting '/some/safe/place/../../../dangerous' as a fragment.

CPANSA-Jifty-2009-01 (2009-04-09)

The REST plugin would let you call any method on the model.

NAME

Jifty::Plugin::Authentication::Password::Action::ResetPassword - Confirm and reset a lost password

DESCRIPTION

This is the action run by the link in a user's email to confirm that their email address is really theirs, when claiming that they lost their password.

arguments

ConfirmEmail has the following fields: address, code, password, and password_confirm. Note that it can get the first two from the confirm dhandler.

take_action

Resets the password.