Browse Source
I've never liked the chain-specific exception to having to set a password. It gives issues with #6388 which makes it valid to set no password in every case (as it enables random cookie authentication). This pull removes the flag, so that all chains are regarded the same. It also removes the username==password test, which doesn't provide any substantial extra security.0.13
Wladimir J. van der Laan
10 years ago
3 changed files with 1 additions and 7 deletions
Loading…
Reference in new issue