Security Advisories (2)
CPANSA-Jifty-2011-01 (2011-03-17)

The path as passed in the fragment request data structure was used verbatim in the dispatcher and other locations. This possibly allowed requests to walk around ACLs by requesting '/some/safe/place/../../../dangerous' as a fragment.

CPANSA-Jifty-2009-01 (2009-04-09)

The REST plugin would let you call any method on the model.

NAME

Jifty::Plugin::AuthCASOnly

DESCRIPTION

MUST BE USED WITH Login PLUGIN

Add cas users in Jifty::Plugin::Login::Model::User. Distinct id for cas users is email field with login@CAS.user

CONFIG

in etc/config.yml
 Plugins: 
   - Login: {}
   - AuthCASLogin: 
      CASserver: https://auth.univ-metz.fr
      CAFile: /home/agostini/univ.crt

SEE ALSO

AuthCAS