Skip to content
Snippets Groups Projects
  1. May 13, 2017
  2. May 12, 2017
  3. Apr 24, 2017
  4. Apr 19, 2017
    • Max-Julian Pogner's avatar
      PassHash.class.php: in case of brcrypt, use the most recent variant $2y$ · dd865c4c
      Max-Julian Pogner authored
      This change breaks compatibility with php 5.3.7, but a standing
      requirement for at least php 5.6 is declared in composer.json.
      
      If the php documentation is to be believed, this change increases
      security against pass-the-hash type attacks. (I do not have the knowledge
      to assess the security differences between $2a$ and $2y$).
      
      As a Sidenote: htpasswd shipped with apache2 2.4.10 (and probably,
      other versions), when used with the -B (=bcrypt) option, produces hashes
      marked with $2y$.
      
      Nonewithstanding the actual support or non-support of $2a$ by the
      apache2 'AuthUserFile' directive, the apache 2.4 documentation only
      asserts support for the $2y$ bcrypt variant.
      Therefore, this commit would make it possible for dokuwiki and apache2
      basic authentication to share the same password file, in the case when
      bcrypt is used.
      dd865c4c
    • David Surroca's avatar
      translation update · 6475ad44
      David Surroca authored
      6475ad44
  5. Apr 18, 2017
    • Dharmik's avatar
      Fix Typo in remote API (#1938) · 32b2e368
      Dharmik authored
      * Updated remote.php
      
      Updated remote.php for retrieving all the acl details.
      
      * Updated remote.php
      
      By mistake changed in addAcl instead of listAcls.
      32b2e368
  6. Apr 05, 2017
  7. Apr 04, 2017
  8. Mar 31, 2017
  9. Mar 16, 2017
  10. Mar 14, 2017
  11. Mar 12, 2017
  12. Mar 08, 2017
  13. Mar 07, 2017
Loading