Security Advisories (2)
CPANSA-Jifty-2011-01 (2011-03-17)

The path as passed in the fragment request data structure was used verbatim in the dispatcher and other locations. This possibly allowed requests to walk around ACLs by requesting '/some/safe/place/../../../dangerous' as a fragment.

CPANSA-Jifty-2009-01 (2009-04-09)

The REST plugin would let you call any method on the model.

NAME

Jifty::Plugin::Login

SYNOPSIS

in etc/config.yml
   Plugins:
     - Login: {}

in your application Model/User.pm
  use strict;
  package YourApp::Model::User;
  use base qw/Jifty::Plugin::Login::Model::User/;
  1;

in your application, you can use
 http://localhost:8888/login
                      /logout
                      /signup
                      /chgpasswd
                      /passwordreminder

DESCRIPTION