Skip to content

Conversation

hackoh
Copy link
Contributor

@hackoh hackoh commented Mar 5, 2013

This fix is about fuel/core@5d79967

I think this issue is very important.
So I PR to 1.5/develop.

@kenjis
Copy link
Contributor

kenjis commented Mar 5, 2013

The change was made in 1.5.

It is a major security policy change. So it should be also documented in Changelog.

WanWizard added a commit to fuel/fuel that referenced this pull request Mar 6, 2013
@WanWizard
Copy link
Member

It should not be a policy change. Very bad idea. Issue in the Security class is fixed, so this can go back in.

@WanWizard WanWizard closed this Mar 6, 2013
@kenjis
Copy link
Contributor

kenjis commented Mar 7, 2013

Even if you guys didn't intend it was a policy change, the default of FuelPHP 1.5 was already changed to no filters.
It was very important change. Should have been known to users.

I hope 1.5.3 with default filters the same as 1.4 or older.

@WanWizard
Copy link
Member

I'll discuss it to see if we're going to hotfix it, or wait for 1.6.

WanWizard added a commit to fuel/fuel that referenced this pull request Mar 7, 2013
Conflicts:
	fuel/app/config/config.php
@orcaaoshi
Copy link
Contributor

It needs hotfix, I think.
I think that it would be better.
I'm afraid someone will keep using v1.5 and minor versions on his new project without knowing this information, so it will be a security problem.

Also I don't want that FuelPHP receives bad reputation!

@WanWizard
Copy link
Member

Hotfix will go out tonight (GMT).

@orcaaoshi
Copy link
Contributor

It's good news. Thanks a lot!

@kenjis
Copy link
Contributor

kenjis commented Mar 7, 2013

Thank you!

@WanWizard
Copy link
Member

with a bit of a delay, 1.5.3. hotfix has just been released.

@kenjis
Copy link
Contributor

kenjis commented Mar 8, 2013

I appreciate your job. Thank you.

wata727 pushed a commit to wata727/fuel-docs that referenced this pull request Nov 4, 2015
general/viewmodels.html 翻訳完了
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants