Russell Keith-Magee
aae5a96d57
Ensure that passwords are never long enough for a DoS.
...
* Limit the password length to 4096 bytes
* Password hashers will raise a ValueError
* django.contrib.auth forms will fail validation
* Document in release notes that this is a backwards incompatible change
Thanks to Josh Wright for the report, and Donald Stufft for the patch.
This is a security fix; disclosure to follow shortly.
2013-09-15 13:42:23 +08:00
..
2012-03-13 17:53:31 +00:00
2012-12-24 15:38:05 -05:00
2012-03-13 17:53:31 +00:00
2012-03-13 17:53:31 +00:00
2012-11-24 18:10:51 +01:00
2012-03-13 17:53:31 +00:00
2013-09-09 16:03:13 -04:00
2012-06-28 10:49:07 +02:00
2010-08-19 19:27:44 +00:00
2013-04-20 17:18:35 +02:00
2013-09-06 12:57:25 -05:00
2013-09-09 16:03:13 -04:00
2012-03-13 17:53:31 +00:00
2010-08-19 19:27:44 +00:00
2011-02-10 11:55:24 +00:00
2011-10-14 00:12:01 +00:00
2013-09-09 16:03:13 -04:00
2013-03-22 13:50:07 -04:00
2013-01-02 18:32:57 -05:00
2012-03-13 17:53:31 +00:00
2013-07-27 18:46:03 -07:00
2013-09-09 16:03:13 -04:00
2011-08-26 09:31:01 +00:00
2013-05-10 23:08:45 -04:00
2012-03-13 17:53:31 +00:00
2011-09-10 03:33:54 +00:00
2011-09-11 02:28:08 +00:00
2013-03-22 13:50:07 -04:00
2013-09-09 16:03:13 -04:00
2013-07-08 13:59:54 -04:00
2011-09-10 03:33:54 +00:00
2012-08-31 20:35:50 +02:00
2013-08-12 14:05:25 -04:00
2013-08-12 14:05:25 -04:00
2013-08-12 14:05:25 -04:00
2013-08-12 14:05:25 -04:00
2013-08-12 14:05:25 -04:00
2013-09-09 16:03:13 -04:00
2013-03-29 19:15:19 -04:00
2013-03-29 19:15:19 -04:00
2012-08-31 20:35:50 +02:00
2013-08-12 14:05:25 -04:00
2013-08-12 14:05:25 -04:00
2013-09-05 20:14:58 -04:00
2013-08-12 14:05:25 -04:00
2013-09-09 16:03:13 -04:00
2013-09-10 21:07:22 -04:00
2013-05-18 19:04:34 -03:00
2013-09-06 12:57:25 -05:00
2013-09-06 12:57:25 -05:00
2013-03-28 15:03:19 -05:00
2013-09-09 16:03:13 -04:00
2013-09-10 21:07:22 -04:00
2013-09-06 12:57:25 -05:00
2013-09-13 09:34:12 -04:00
2013-09-15 13:42:23 +08:00
2013-09-10 21:07:22 -04:00