ANNOUNCE: AxKit-XSP-BasicSession-0.23_2 [security]

2005-04-28 Thread Kjetil Kjernsmo
Dear all,

I have just uploaded a new developer release of BasicSession to CPAN. A 
review performed by the original author Mike Nachbaur and myself, 
prompted by the problems Tom Kirkpatrick has reported with the module 
revealed that BasicSession was in fact not invalidating sessions 
properly. 

This may have security implications as information may be carried over, 
including authentication tokens, to a session even though the user 
believed that the previous session was exited. 

We believe that we have fixed this particular problem, as well as a 
number of smaller problems with this release. Given that there are 
security implications, I felt that it was appropriate to release this 
now, as well as this short advisory.

Note, however, that we have not tested this extensively, and while it 
seems to be OK with the File and DB_File backend, and usually OK with 
the PostgreSQL backend, we have noted problems with the latter, it has 
been seen to sit there and spin indefinitely. So, until more testing 
has been performed, one has the choice between a module that has 
security implications, and one that has seen little testing and has 
known issues. So, that's why this has been uploaded as a developer 
release and not an ordinary release. Caveat programmor. Your call. No 
warranties. Et cetera.

It appears to clear out some quite confusing issues that has been 
present in earlier releases, allthough we're not sure it corrects all 
known problems. Success or failure reports are welcome.

So to the formalities: I report that the uploaded file

AxKit-XSP-BasicSession-0.23_2.tar.gz

has entered CPAN as

  file:
 $CPAN/authors/id/K/KJ/KJETILK/AxKit-XSP-BasicSession-0.23_2.tar.gz
 size: 14668 bytes
   md5: 4e6cc5f2ab406e198bf0ddc3e33b8688

From the changelog:
0.23_2   2005-04-28 02:45
- Invalidation of session didn't work properly, which has
  obvious SECURITY issues. We found this has a result of a
  review sparked by inquires by Tom Kirkpatrick.
- Tom Kirkpatrick pointed out that get-last-accessed-time
  returned a meaningless time. Mike Nachbaur provided a patch
  for that.
- When using a Pg based backend, different defaults should
  used. 
- Actually implement the comment in enumerate.
- Some documentation cleanups.
- Added quite a lot of debugging statements. 

Cheers,

Kjetil
-- 
Kjetil Kjernsmo
Astrophysicist/IT Consultant/Skeptic/Ski-orienteer/Orienteer/Mountaineer
[EMAIL PROTECTED]  [EMAIL PROTECTED]  [EMAIL PROTECTED]
Homepage: http://www.kjetil.kjernsmo.net/OpenPGP KeyID: 6A6A0BBC


pgpou3pnJ599g.pgp
Description: PGP signature


Re: Migrating to SVN

2005-04-28 Thread Tom Schindl
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
Hi,
well I'm using Trac in at the moment at its really nice but it has in my
idea one really big disadvantage which is its privileges system. What do
I mean? You cannot give users the e.g. anonymous ones the possibility to
report and edit a bug/feature request, but avoid anonymous in the same
time to change the status of a bug. Misuse like we have seen on the wiki
~ will follow. Besides this issue I like trac. JIRA has one more
advantage as I can see from now in the idea that it links cvs/subversion
commit to a issue, trac does it the other way round.
One more disadvantage of trac is that if you have multiple different
projects in one svn-repository you cannot configure trac only to show
project1 or project2.
I like trac and before using any other bugtracking I'd go with it but
one day I'll write my own ;-)
Tom
Matt Sergeant schrieb:
| On 27 Apr 2005, at 10:30, Tom Schindl wrote:
|
| Now there would be a perfect point to move AxKit into such a Bug/Feature
| tracking system. Bugs could be scheduled, ... .
|
|
| I've talked to Dirk about the possibility of us using Trac, which seems
| to integrate lots of project management features very nicely. We'd
| probably have to get that setup ourselves, but it looks pretty easy to do.
|
| Matt.
|
|
| __
| This email has been scanned by the MessageLabs Email Security System.
| For more information please visit http://www.messagelabs.com/email
| __
|
|
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.0 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFCcH9IkVPeOFLgZFIRApQ2AJ9R53AXy3miclKxouOYzcVo9A4UmgCeI1cQ
37OEInuZvoZ9khdujC/OR9g=
=i3VF
-END PGP SIGNATURE-