play1
play1 copied to clipboard
[#1770] prevent request body from being flashed (security)
found this issue when doing the _feild tag fix noticing the password was redisplaying which is only possible if it is in the cookie(and it was in clear text). This fixes that issue so that playframework is secure again.
play-1-3-x-pull-requests #127 SUCCESS This pull request looks good
ok, I redid this now with modifying params.flash() to skip storing the body.
play-1-3-x-pull-requests #128 SUCCESS This pull request looks good