From f411e9cc5bb04248aa412214e780d3af24d0da3d Mon Sep 17 00:00:00 2001 From: Andrey Andreev Date: Sat, 31 May 2014 21:02:23 +0300 Subject: [ci skip] Update changelog --- user_guide_src/source/changelog.rst | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/user_guide_src/source/changelog.rst b/user_guide_src/source/changelog.rst index e2b37561a..8492be289 100644 --- a/user_guide_src/source/changelog.rst +++ b/user_guide_src/source/changelog.rst @@ -726,7 +726,6 @@ Bug fixes for 3.0 - Fixed a bug (#2737) - :doc:`XML-RPC Library ` used objects as array keys, which triggered E_NOTICE messages. - Fixed a bug (#2729) - :doc:`Security Library ` internal method ``_validate_entities()`` used overly-intrusive ``preg_replace()`` patterns that produced false-positives. - Fixed a bug (#2771) - :doc:`Security Library ` method ``xss_clean()`` didn't take into account HTML5 entities. -- Fixed a bug in the :doc:`Session Library ` 'cookie' driver where authentication was not performed for encrypted cookies. - Fixed a bug (#2856) - ODBC method ``affected_rows()`` passed an incorrect value to ``odbc_num_rows()``. - Fixed a bug (#43) :doc:`Image Manipulation Library ` method ``text_watermark()`` didn't properly determine watermark placement. - Fixed a bug where :doc:`HTML Table Library ` ignored its *auto_heading* setting if headings were not already set. @@ -743,6 +742,7 @@ Release Date: June 2, 2014 - General Changes - Security: :doc:`Encrypt Library ` method ``xor_encode()`` has been removed. The Encrypt Class now requires the Mcrypt extension to be installed. + - Security: The :doc:`Session Library ` now uses HMAC authentication instead of a simple MD5 checksum. Bug fixes for 2.2.0 ------------------- @@ -751,6 +751,7 @@ Bug fixes for 2.2.0 - Fixed a bug (#696) - make ``oci_execute()`` calls inside ``num_rows()`` non-committing, since they are only there to reset which row is next in line for oci_fetch calls and thus don't need to be committed. - Fixed a bug (#2689) - :doc:`Database Force ` methods ``create_table()``, ``drop_table()`` and ``rename_table()`` produced broken SQL for tge 'sqlsrv' driver. - Fixed a bug (#2427) - PDO :doc:`Database driver ` didn't properly check for query failures. +- Fixed a bug in the :doc:`Session Library ` where authentication was not performed for encrypted cookies. Version 2.1.4 ============= -- cgit v1.2.3-24-g4f1b