Security Advisories (2)
CPANSA-Jifty-2011-01 (2011-03-17)

The path as passed in the fragment request data structure was used verbatim in the dispatcher and other locations. This possibly allowed requests to walk around ACLs by requesting '/some/safe/place/../../../dangerous' as a fragment.

CPANSA-Jifty-2009-01 (2009-04-09)

The REST plugin would let you call any method on the model.

NAME

Jifty::Plugin::DumpDispatcher

DESCRIPTION

When activated in config.yml with:

Plugins:
  - DumpDispatcher: {}

it will dump all dispatcher rules in debug log.

dump_rules

Dump all defined rules in debug log. It is called by Jifty, after Jifty->dispatcher->import_plugins on startup.

_unroll_dumpable_rules LEVEL,RULE

Walk all rules defined in dispatcher starting at rule RULE and indentation level LEVEL