]> git.vanrenterghem.biz Git - git.ikiwiki.info.git/commitdiff
doc: Document security issues involving LWP::UserAgent
authorSimon McVittie <smcv@debian.org>
Sun, 10 Feb 2019 16:56:41 +0000 (16:56 +0000)
committerSimon McVittie <smcv@debian.org>
Tue, 26 Feb 2019 22:21:31 +0000 (22:21 +0000)
Recommend the LWPx::ParanoidAgent module where appropriate.
It is particularly important for openid, since unauthenticated users
can control which URLs that plugin will contact. Conversely, it is
non-critical for blogspam, since the URL to be contacted is under
the wiki administrator's control.

Signed-off-by: Simon McVittie <smcv@debian.org>

No differences found