roller-commits mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "David Johnson (JIRA)" <>
Subject [jira] [Created] (ROL-2137) Require setting rememberme.key
Date Mon, 06 May 2019 22:58:00 GMT
David Johnson created ROL-2137:

             Summary: Require setting rememberme.key 
                 Key: ROL-2137
             Project: Apache Roller
          Issue Type: Improvement
            Reporter: David Johnson
            Assignee: Roller Unassigned

If you are going to enable rememberMe in Roller then you really MUST set a unique (and secret)
key for Spring Security's remember me feature.

Change Roller so that remember-me will not work unless a ''rememberme.key' property set and
it is set to something other than the old default value 'springRocks'

This message was sent by Atlassian JIRA

View raw message