| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: apache2-mod_auth_mellon-doc | Distribution: SUSE Linux 16 |
| Version: 0.19.1 | Vendor: SUSE LLC <https://www.suse.com/> |
| Release: 160000.2.2 | Build date: Wed Dec 11 13:21:07 2024 |
| Group: Productivity/Networking/Web/Servers | Build host: reproducible |
| Size: 1863549 | Source RPM: apache2-mod_auth_mellon-0.19.1-160000.2.2.src.rpm |
| Packager: https://www.suse.com/ | |
| Url: https://github.com/latchset/mod_auth_mellon | |
| Summary: Documentation for mod_auth_mellon module | |
This package contains a documentation for mod_auth_mellon module.
GPL-2.0-or-later
* Wed Dec 11 2024 pgajdos@suse.com
- version update to 0.19.1
* Remove legacy code that is unused because of minimum requirements.
* Cleanup HTML in rendered forms.
* Documentation cleanups and improvements.
* Mon Mar 25 2024 pgajdos@suse.com
- version update to 0.19.0
Enhancements:
* Support for HTTP-POST binding on Singe Logout endpoint.
* Update documentation.
Cleanup:
* Raise minimum Lasso version to 2.4, cleaning up legacy code for
compatibility with older versions, including the obsolete
`MellonIdPPublicKeyFile` setting which was not working with recent
Lasso versions.
* Mon Jul 31 2023 elimat@opensuse.org
- Update to 0.18.1
* Logout endpoint should handle idP POST response
* mellon_create_metadata.sh: Fix compatibility with OpenSSL 3
* Add some clarification to the documentation
* Add encryption certificate to generated metadata
- Changes in 0.18.0
* CVE-2021-3639 Redirect URL validation bypass - Version 0.17.0 and
older of mod_auth_mellon allows the redirect URL validation to be
bypassed by specifying an URL formatted as ///fishing-site.example.com/logout.html.
In this case, the browser would interpret the URL differently
than the APR parsing utility mellon uses and redirect to
fishing-site.example.com. This could be reproduced with:
https://rp.example.co.jp/mellon/logout?ReturnTo=///fishing-site.example.com/logout.html
This version fixes that issue by rejecting all URLs that start with "///".
* A new option MellonSessionIdleTimeout that represents the amount of
time a user can be inactive before the user's session times out in seconds.
* Several build-time fixes
* The CookieTest SameSite attribute was only set to None if mellon configure option
MellonCookieSameSite was set to something other than default. This is now fixed.
- add libtool and xmlsec1-openssl-devel as new dependencies
- set Buildarch to noarch for docs sub-package
* Thu May 05 2022 archie.cobbs@gmail.com
- Wrap default config in <IfModule> to avoid reload error
* Thu Sep 10 2020 kstreitova@suse.com
- Update to 0.17.0
* New option MellonSendExpectHeader (default On) which allows to
disable sending the Expect header in the HTTP-Artifact binding to
improve performance when the remote party does not support this
header.
* Set SameSite attribute to None on on the cookietest cookie.
* Bump default generated keysize to 3072 bits in
mellon_create_metadata
* Validate if the assertion ID has not been used earlier before
creating a new session.
* Release session cache after calling invalidate endpoint.
* In MellonCond directives, fix a bug that setting the NC option
would also activate substring match and that REG would activate
REF.
* Fix MellonCond substring match to actually match the substring on
the attribute value
* Thu Jun 04 2020 kstreitova@suse.com
- update mod_auth_mellon-0.16.0-env-script-interpreter.patch
use /bin/bash instead of /usr/bin/bash
* Mon May 11 2020 kstreitova@suse.com
- replace version_path with the fixed value
* Tue Apr 28 2020 kstreitova@suse.com
- initial packaging
/usr/share/doc/packages/README.diagnostics /usr/share/doc/packages/user_guide /usr/share/doc/packages/user_guide/Guardfile /usr/share/doc/packages/user_guide/README /usr/share/doc/packages/user_guide/images /usr/share/doc/packages/user_guide/images/chrome_SAML_Chrome_Panel.png /usr/share/doc/packages/user_guide/images/chrome_SAML_Chrome_Panel.svg /usr/share/doc/packages/user_guide/images/saml-tracer.png /usr/share/doc/packages/user_guide/images/saml-tracer.svg /usr/share/doc/packages/user_guide/images/saml-web-sso.svg /usr/share/doc/packages/user_guide/mellon_user_guide.adoc /usr/share/doc/packages/user_guide/mellon_user_guide.html
Generated by rpm2html 1.8.1
Fabrice Bellet, Tue Sep 30 22:36:46 2025