Re: [openstack-dev] [horizon][bug] Mitigation to BREACH vulnerability

2015-11-23 Thread Matthias Runge
On Fri, Nov 20, 2015 at 10:00:30PM +, BARTRA, RICK wrote: > Until django releases an official patch for the BREACH vulnerability, I think > we should take a look at django-debreach. The django-debreach package > provides some, possibly enough, protection against a BREACH attack. Its > integr

[openstack-dev] [horizon][bug] Mitigation to BREACH vulnerability

2015-11-20 Thread BARTRA, RICK
Until django releases an official patch for the BREACH vulnerability, I think we should take a look at django-debreach. The django-debreach package provides some, possibly enough, protection against a BREACH attack. Its integration to Horizon is clear by following the configuration found here: