3.0-M7 released with a security fix

48 views
Skip to first unread message

Jorge Aliss

unread,
Mar 10, 2017, 1:53:40 PM3/10/17
to SecureSocial
Hi,

I just released 3.0-M7 which includes a fix for the host injection attack reported here: https://github.com/jaliss/securesocial/issues/601. There are 2 new properties that were introduced:

- applicationHost: the host of your application. This is mandatory.
- applicationPort: the port of your application. This is optional.

These values are used to compute the URLs users are pointed to within the default RoutesService implementation.

Please upgrade and let me know if you have questions.
Big thanks to Kenny (@platypii) for filing the issue. 

Jorge


Reply all
Reply to author
Forward
0 new messages