<feed xmlns='http://www.w3.org/2005/Atom'>
<title>leap_web.git/users/lib, branch 0.2.5</title>
<subtitle>[leap_web] 
</subtitle>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_web.git/'/>
<entry>
<title>security fix: clear srp data from db asap (#3686)</title>
<updated>2013-09-23T09:38:20+00:00</updated>
<author>
<name>Azul</name>
<email>azul@leap.se</email>
</author>
<published>2013-09-23T08:20:02+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_web.git/commit/?id=80bcb7d273395af614730024e21a92a1c568228d'/>
<id>80bcb7d273395af614730024e21a92a1c568228d</id>
<content type='text'>
This is a quick fix for iSEC issue #13.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This is a quick fix for iSEC issue #13.
</pre>
</div>
</content>
</entry>
<entry>
<title>close srp vulnerability and report error in webapp</title>
<updated>2013-08-08T08:44:33+00:00</updated>
<author>
<name>Azul</name>
<email>azul@leap.se</email>
</author>
<published>2013-08-07T16:09:20+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_web.git/commit/?id=a0b276e4b8ae86dec7deee898e85b65784d89933'/>
<id>a0b276e4b8ae86dec7deee898e85b65784d89933</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>use ruby-srp 0.2.0 which has a hex based api</title>
<updated>2013-07-16T10:32:43+00:00</updated>
<author>
<name>Azul</name>
<email>azul@leap.se</email>
</author>
<published>2013-07-16T10:32:43+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_web.git/commit/?id=6e47ea438cf35c6cad00e65e2817cb57d07db111'/>
<id>6e47ea438cf35c6cad00e65e2817cb57d07db111</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>print debug info on failed login attempts</title>
<updated>2013-07-12T07:34:37+00:00</updated>
<author>
<name>Azul</name>
<email>azul@leap.se</email>
</author>
<published>2013-06-24T10:16:04+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_web.git/commit/?id=76e36080ed56c33f220509bd67a3693bf9d7567b'/>
<id>76e36080ed56c33f220509bd67a3693bf9d7567b</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Want to tweak some, but start to displaying base generic message via javascript.</title>
<updated>2013-06-27T19:31:39+00:00</updated>
<author>
<name>jessib</name>
<email>jessib@leap.se</email>
</author>
<published>2013-06-27T19:31:39+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_web.git/commit/?id=a01e7686ea7c046a9cd544b618b30727f2a41b3b'/>
<id>a01e7686ea7c046a9cd544b618b30727f2a41b3b</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge branch 'master' into feature/limit_user_leak</title>
<updated>2013-03-05T12:35:05+00:00</updated>
<author>
<name>Azul</name>
<email>azul@leap.se</email>
</author>
<published>2013-03-05T12:35:05+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_web.git/commit/?id=27c16ccceffa1d8eaaf02612cf29a60bfe6ced01'/>
<id>27c16ccceffa1d8eaaf02612cf29a60bfe6ced01</id>
<content type='text'>
Conflicts:
	users/lib/warden/strategies/secure_remote_password.rb
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Conflicts:
	users/lib/warden/strategies/secure_remote_password.rb
</pre>
</div>
</content>
</entry>
<entry>
<title>When attempting to login, the error messages should not leak information about whether a username is valid.</title>
<updated>2013-02-28T19:54:24+00:00</updated>
<author>
<name>jessib</name>
<email>jessib@leap.se</email>
</author>
<published>2013-02-28T19:54:24+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_web.git/commit/?id=a1279ecca51fbe7014d841ed6bca8842d3441814'/>
<id>a1279ecca51fbe7014d841ed6bca8842d3441814</id>
<content type='text'>
This also means the error message is more appropriate if somebody tries to login with somebody else's username and their password.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This also means the error message is more appropriate if somebody tries to login with somebody else's username and their password.
</pre>
</div>
</content>
</entry>
<entry>
<title>api for sessions fixed</title>
<updated>2013-02-26T10:45:56+00:00</updated>
<author>
<name>Azul</name>
<email>azul@leap.se</email>
</author>
<published>2013-02-26T10:42:19+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_web.git/commit/?id=4a92bab4d8c231a17a14afc81c391f9a1f91c063'/>
<id>4a92bab4d8c231a17a14afc81c391f9a1f91c063</id>
<content type='text'>
* now we return the user id on login
* allow a destroy request for logging out
* added test for api sessions controller
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* now we return the user id on login
* allow a destroy request for logging out
* added test for api sessions controller
</pre>
</div>
</content>
</entry>
<entry>
<title>using ruby-srp 0.1.5 SRP::Client to wrap user in session</title>
<updated>2013-02-06T15:16:34+00:00</updated>
<author>
<name>Azul</name>
<email>azul@leap.se</email>
</author>
<published>2013-02-06T15:16:34+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_web.git/commit/?id=1bf82535b25cb17c58a196fdaab639040f48e769'/>
<id>1bf82535b25cb17c58a196fdaab639040f48e769</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Removing aliases from webfinger as the link wouldn't work anyway, and don't want to leak ID information.</title>
<updated>2013-01-24T19:38:11+00:00</updated>
<author>
<name>jessib</name>
<email>jessib@leap.se</email>
</author>
<published>2013-01-24T19:38:11+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_web.git/commit/?id=9d053b6c9b61c68bf11f95bcb37631a518f1fba4'/>
<id>9d053b6c9b61c68bf11f95bcb37631a518f1fba4</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
</feed>
