Security Advisories (2)
CPANSA-Jifty-2011-01 (2011-03-17)

The path as passed in the fragment request data structure was used verbatim in the dispatcher and other locations. This possibly allowed requests to walk around ACLs by requesting '/some/safe/place/../../../dangerous' as a fragment.

CPANSA-Jifty-2009-01 (2009-04-09)

The REST plugin would let you call any method on the model.

NAME

Jifty::Plugin::OpenID::Mixin::Model::User

DESCRIPTION

Jifty::Plugin::OpenID mixin for the User model. Provides an 'openid' column.

has_alternative_auth

register_triggers

validate_openid

canonicalize_openid

Links User's account to the specified OpenID (bypassing ACLs)