de2cba085b9b231135be953d7f34f74fefb82725 |
|
29-May-2015 |
Timo Sirainen <tss@iki.fi> |
auth: Make sure %{mech} and %{session} is escaped in %var expansion.
%{mech} is already very trusted and %{session} should be only from trusted
sources as well, so this doesn't fix any actual security holes. They are
also unlikely to have ever even been used in anything that requires
escaping. |