1
0
mirror of https://github.com/Mailu/Mailu.git synced 2024-12-14 10:53:30 +02:00
Mailu/towncrier/newsfragments
bors[bot] 25e8910b89
Merge #1783
1783: Switch to server-side sessions r=mergify[bot] a=nextgens

## What type of PR?

bug-fix

## What does this PR do?

It simplifies session management.
- it ensures that sessions will eventually expire (*)
- it implements some mitigation against session-fixation attacks
- it switches from client-side to server-side sessions (in Redis)

It doesn't prevent us from (re)-implementing a "remember_me" type of feature if that's considered useful by some.


Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
2021-03-10 09:44:31 +00:00
..
1607.feature add towncrier for #1607 2020-08-30 01:19:42 +02:00
1610.feature add towncrier for 1610 2020-09-01 21:50:21 +02:00
1618.feature add newsfragemnt for #1618 2020-09-12 01:38:37 +02:00
1638.fix Add changelog 2020-09-24 16:53:42 +02:00
1662.feature Improve the towncrier messages 2021-03-09 12:05:46 +01:00
1669.bugfix Fix extract_host_port port separation 2020-10-24 21:52:21 +01:00
1686.bugfix Fix letsencrypt access to certbot for the mail-letsencrypt flavour 2020-11-17 10:26:41 +01:00
1696.misc fix changelog entry from feature to misc 2020-11-23 09:27:55 +02:00
1712.misc Add newsfragment 2020-12-23 18:53:56 +01:00
1720.bugfix Use alpine 3.13 to fix CVE-2020-25275 and CVE-2020-24386 2021-01-15 10:56:49 +01:00
1753.feature Improve the towncrier messages 2021-03-09 12:05:46 +01:00
1783.misc towncrier 2021-03-09 20:13:31 +01:00