<?xml version="1.0" encoding="UTF-8"?>
<commit>
  <added type="array"/>
  <modified type="array">
    <modified>
      <diff>@@ -1,3 +1,9 @@
+*1.2.6* (November 24th, 2007)
+
+* Fix :cookie_only to correctly avoid session fixation attacks (CVE-2007-6077)
+
+* Fix regression where the association would not construct new finder SQL on save causing bogus queries for &quot;WHERE owner_id = NULL&quot; even after owner was saved. 
+
 *1.2.5* (October 12th, 2007)
 
 * Correct RAILS_GEM_VERSION regexp. Use =version gem requirement instead of ~&gt;version so you don't get surprised by a beta gem in production. This change means upgrading to 1.2.5 will require a boot.rb upgrade.  [Jeremy Kemper]</diff>
      <filename>railties/CHANGELOG</filename>
    </modified>
  </modified>
  <removed type="array"/>
  <parents type="array">
    <parent>
      <id>d421bb96f7620a52ede74407f0e36af1a03016a0</id>
    </parent>
  </parents>
  <author>
    <name>Michael Koziarski</name>
    <email>michael@koziarski.com</email>
  </author>
  <url>http://github.com/rails/rails/commit/9c190098e0f80cf2638223142f335ffb25212b86</url>
  <id>9c190098e0f80cf2638223142f335ffb25212b86</id>
  <committed-date>2007-11-23T16:04:37-08:00</committed-date>
  <authored-date>2007-11-23T16:04:37-08:00</authored-date>
  <message>Forgot railties changelog


git-svn-id: http://svn-commit.rubyonrails.org/rails/branches/1-2-stable@8196 5ecf4fe2-1ee6-0310-87b1-e25e094e27de</message>
  <tree>7caa3ea26ba9e9edc8e37e95c967fb3c35303753</tree>
  <committer>
    <name>Michael Koziarski</name>
    <email>michael@koziarski.com</email>
  </committer>
</commit>
