Main Koha release repository https://koha-community.org
Find a file
Agustin Moyano ca57674700
Bug 32178: Remove security breach introduced in bug 31378
This patch removes a security breach in C4::Auth::check_api_auth introduced by bug 31378, where when someone called an api with the parameters userid and auth_client_login, check_api_auth would automatically asume the user calling was that userid.

This patch also introduces C4::Auth::create_basic_session(), a function that creates a session and adds the minimum basic parameters.

Signed-off-by: David Cook <dcook@prosentient.com.au>

Signed-off-by: Kyle M Hall <kyle@bywatersolutions.com>

Signed-off-by: Nick Clemens <nick@bywatersolutions.com>
Signed-off-by: Tomas Cohen Arazi <tomascohen@theke.io>
2022-11-15 18:43:45 -03:00
acqui
admin Bug 32139: Set "update on login" correctly when creating new IdP 2022-11-09 13:32:46 -03:00
api Bug 32154: Missing primary key on erm_user_roles table 2022-11-11 08:54:34 -03:00
authorities Bug 30250: Use ApplyFrameworkDefaults when importing a record 2022-11-09 14:03:22 -03:00
basket
bin
C4 Bug 32178: Remove security breach introduced in bug 31378 2022-11-15 18:43:45 -03:00
catalogue
cataloguing Bug 24606: (QA follow-up) Remove duplicate include 2022-11-11 15:47:36 -03:00
circ
clubs
course_reserves
debian Bug 32030: Add Apache RewriteRule 2022-11-08 09:43:48 -03:00
docs Bug 30808: Add the 22.05 release team. 2022-05-25 23:56:12 -10:00
erm Bug 32030: Add missing sponsors 2022-11-09 12:25:44 -03:00
errors Bug 29420: HTTP status code incorrect when calling error pages directly under Plack/PSGI 2022-04-20 09:03:39 -10:00
etc
ill
installer Bug 32191: Tidy upgrade scripts output 2022-11-14 15:08:10 -03:00
Koha Bug 32178: Remove security breach introduced in bug 31378 2022-11-15 18:43:45 -03:00
koha-tmpl Bug 32188: Only show template controls above item form if templates have been defined 2022-11-14 15:07:05 -03:00
labels
lib/CGI/Session/Serialize
members
misc Bug 27920: (QA follow-up) Fix POD in cli tool 2022-11-09 14:37:27 -03:00
offline_circ
opac
patron_lists
patroncards
plugins
pos
recalls
reports
reserve
reviews
rotating_collections
serials Bug 29608: Made so doesn't require full permission 2022-09-07 13:49:53 -07:00
services
skel
suggestion
svc
t Bug 32178: Remove security breach introduced in bug 31378 2022-11-15 18:43:45 -03:00
tags
tmp/modified_authorities
tools Bug 27920: (QA follow-up) Change radios to a single select pulldown 2022-11-09 14:37:24 -03:00
virtualshelves
xt Bug 32130: Add a test to ensure vue files will be kept tidy 2022-11-11 08:49:30 -03:00
.editorconfig
.eslintrc.json
.gitignore Bug 32030: Add dist dir to .gitignore 2022-11-08 09:49:57 -03:00
.htaccess Fix file permissions: if it is not a script, it should not be executable. 2010-04-16 00:40:34 -04:00
.mailmap 22.05.00: Update mailmap 2022-05-25 23:56:12 -10:00
.perlcriticrc
.proverc.dist
.stylelintrc.json
about.pl
app.psgi
changelanguage.pl
cpanfile Bug 12758: Make LWP::Protocol::https required module 2022-11-09 09:52:13 -03:00
cypress.json Bug 32030: Move cypress to t/ 2022-11-08 09:44:51 -03:00
fix-perl-path.PL
gulpfile.js
help.pl
INSTALL
Koha.pm Bug 32154: DBRev 22.06.00.085 2022-11-11 08:56:05 -03:00
koha_perl_deps.pl
kohaversion.pl
LICENSE
mainpage.pl
Makefile.PL Bug 32030: Fix Makefile.t 2022-11-09 09:48:30 -03:00
MANIFEST.SKIP
package.json
README
README.md
README.robots
rewrite-config.PL
tsconfig.json Bug 32030: Move cypress to t - fix build_js/watch_js 2022-11-08 09:44:52 -03:00
webpack.config.js Bug 32030: Move cypress to t/ 2022-11-08 09:44:51 -03:00
yarn.lock Bug 32101: Compiled CSS 2022-11-10 09:31:48 -03:00

Koha is a free software integrated library system (ILS).

Koha is distributed under the GNU GPL version 3 or later.

Note: Koha does not accept pull requests from git hosting sites.

Note: This project has its own bug tracker, to report a bug or submit a patch visit http://bugs.koha-community.org.

For guidelines on submitting patches for Koha please visit https://wiki.koha-community.org/wiki/SubmitingAPatch

The developers handbook can be found at https://wiki.koha-community.org/wiki/Developer_handbook

http://koha-community.org/

Koha Logo