Security Advisories (2)
CPANSA-Jifty-2011-01 (2011-03-17)

The path as passed in the fragment request data structure was used verbatim in the dispatcher and other locations. This possibly allowed requests to walk around ACLs by requesting '/some/safe/place/../../../dangerous' as a fragment.

CPANSA-Jifty-2009-01 (2009-04-09)

The REST plugin would let you call any method on the model.

NAME

Jifty::Plugin::AuthLDAPOnly

DESCRIPTION

MUST NOT BE USED WITH Login PLUGIN

Provide authentication: only for users in your ldap.

If you need external users see Jifty::Plugin::AuthLDAPLogin

CONFIG

in etc/config.yml Plugins: - AuthLDAPOnly: LDAPhost: ldap1.univ-metz.fr # ldap host LDAPbase: ou=people, ou=... # ldap base LDAPuid: uid # optional

in your user model use base qw/Jifty::Plugin::AuthLDAPOnly::Model::LDAPUser/;

in your application use /ldaplogin and /ldaplogout

SEE ALSO

Net::LDAP