Security Advisories (1)
CPANSA-Jifty-2011-01 (2011-03-17)

The path as passed in the fragment request data structure was used verbatim in the dispatcher and other locations. This possibly allowed requests to walk around ACLs by requesting '/some/safe/place/../../../dangerous' as a fragment.

NAME

Jifty::Plugin::Authentication::Password - password authentication plugin

SYNOPSIS

# In your jifty config.yml under the framework section:

Plugins:
  - LetMe: {}
  - User: {}
  - Authentication::Password:
      login_by: email

# we now support two login_by: email or username

DESCRIPTION

CAUTION: This plugin is experimental.

This may be combined with the Jifty::Plugin::User and Jifty::Plugin::LetMe plugins to provide user accounts and form-based password authentication to your application.

METHODS

prereq_plugins

This plugin depends on the User and LetMe plugins.

init

SEE ALSO

Jifty::Manual::AccessControl, Jifty::Plugin::User, Jifty::Plugin::LetMe, Jifty::Plugin::Authentication::Password::Mixin::Model::User

LICENSE

Jifty is Copyright 2005-2010 Best Practical Solutions, LLC. Jifty is distributed under the same terms as Perl itself.