[phpMyAdmin Git] [phpmyadmin/phpmyadmin] 3946db: Ensure Session::secure has empty session

Michal Čihař michal at cihar.com
Thu Nov 23 15:59:52 CET 2017


  Branch: refs/heads/master
  Home:   https://github.com/phpmyadmin/phpmyadmin
  Commit: 3946dbdf0c076e5f65910acb28dcbfc7f49c1dc5
      https://github.com/phpmyadmin/phpmyadmin/commit/3946dbdf0c076e5f65910acb28dcbfc7f49c1dc5
  Author: Michal Čihař <michal at cihar.com>
  Date:   2017-11-23 (Thu, 23 Nov 2017)

  Changed paths:
    M libraries/classes/Session.php

  Log Message:
  -----------
  Ensure Session::secure has empty session

Signed-off-by: Michal Čihař <michal at cihar.com>


  Commit: 49281037e387695d1b8b1e3c0a1a93a9d41e520b
      https://github.com/phpmyadmin/phpmyadmin/commit/49281037e387695d1b8b1e3c0a1a93a9d41e520b
  Author: Michal Čihař <michal at cihar.com>
  Date:   2017-11-23 (Thu, 23 Nov 2017)

  Changed paths:
    A js/vendor/u2f-api-polyfill.js
    R js/vendor/u2f-api.js
    M libraries/classes/Plugins/TwoFactor/Key.php

  Log Message:
  -----------
  Replace original Google u2f-api with u2f-api-polyfill

This gracefully handles Firefox 57 native API as well.

Fixes #13830

Signed-off-by: Michal Čihař <michal at cihar.com>


  Commit: 486ae2fd548cd50f1a304715057e1f6054c9ce3d
      https://github.com/phpmyadmin/phpmyadmin/commit/486ae2fd548cd50f1a304715057e1f6054c9ce3d
  Author: Michal Čihař <michal at cihar.com>
  Date:   2017-11-23 (Thu, 23 Nov 2017)

  Changed paths:
    M libraries/classes/Plugins/TwoFactor/Key.php
    A templates/login/twofactor/key-https-warning.twig
    M templates/login/twofactor/key.twig
    M templates/login/twofactor/key_configure.twig

  Log Message:
  -----------
  Warn when U2F is about to be used without https

All browsers refuse to authenticate with http.

Signed-off-by: Michal Čihař <michal at cihar.com>


Compare: https://github.com/phpmyadmin/phpmyadmin/compare/c00aa5170b24...486ae2fd548c


More information about the Git mailing list