Skip to content

Commit

Permalink
fix changelog skip 4.5.1
Browse files Browse the repository at this point in the history
  • Loading branch information
mtrezza committed Aug 18, 2021
1 parent 3c42584 commit a3483d8
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
[Full Changelog](https://github.com/parse-community/parse-server/compare/4.5.2...master)

### 4.5.2
[Full Changelog](https://github.com/parse-community/parse-server/compare/4.5.1...4.5.2)
[Full Changelog](https://github.com/parse-community/parse-server/compare/4.5.0...4.5.2)

### Security Fixes
- SECURITY FIX: Fixes incorrect session property `authProvider: password` of anonymous users. When signing up an anonymous user, the session field `createdWith` indicates incorrectly that the session has been created using username and password with `authProvider: password`, instead of an anonymous sign-up with `authProvider: anonymous`. This fixes the issue by setting the correct `authProvider: anonymous` for future sign-ups of anonymous users. This fix does not fix incorrect `authProvider: password` for existing sessions of anonymous users. Consider this if your app logic depends on the `authProvider` field. (Corey Baker) [GHSA-23r4-5mxp-c7g5](https://github.com/parse-community/parse-server/security/advisories/GHSA-23r4-5mxp-c7g5)
Expand Down

0 comments on commit a3483d8

Please sign in to comment.