瀏覽代碼

Merge pull request #1237 from dsander/upgrade-devise

Upgrade devise to 3.5.4 to address CVE-2015-8314
Dominik Sander 9 年之前
父節點
當前提交
e65cb8937d
共有 3 個文件被更改,包括 9 次插入9 次删除
  1. 1 1
      Gemfile
  2. 5 5
      Gemfile.lock
  3. 3 3
      config/initializers/devise.rb

+ 1 - 1
Gemfile

@@ -72,7 +72,7 @@ gem 'coffee-rails', '~> 4.1.0'
 gem 'daemons', '~> 1.1.9'
 gem 'delayed_job', '~> 4.1.0'
 gem 'delayed_job_active_record', github: 'collectiveidea/delayed_job_active_record', branch: 'master'
-gem 'devise', '~> 3.4.0'
+gem 'devise', '~> 3.5.4'
 gem 'em-http-request', '~> 1.1.2'
 gem 'faraday', '~> 0.9.0'
 gem 'faraday_middleware', github: 'lostisland/faraday_middleware', branch: 'master'  # '>= 0.10.1'

+ 5 - 5
Gemfile.lock

@@ -173,7 +173,7 @@ GEM
       activesupport (>= 3.0, < 5.0)
     delorean (2.1.0)
       chronic
-    devise (3.4.1)
+    devise (3.5.4)
       bcrypt (~> 3.0)
       orm_adapter (~> 0.1)
       railties (>= 3.2.6, < 5)
@@ -415,8 +415,8 @@ GEM
     rb-inotify (0.9.5)
       ffi (>= 0.5.0)
     ref (2.0.0)
-    responders (2.1.0)
-      railties (>= 4.2.0, < 5)
+    responders (2.1.1)
+      railties (>= 4.2.0, < 5.1)
     rest-client (1.8.0)
       http-cookie (>= 1.0.2, < 2.0)
       mime-types (>= 1.16, < 3.0)
@@ -543,7 +543,7 @@ GEM
       macaddr (~> 1.0)
     uuidtools (2.1.5)
     vcr (2.9.2)
-    warden (1.2.3)
+    warden (1.2.4)
       rack (>= 1.0)
     webmock (1.17.4)
       addressable (>= 2.2.7)
@@ -572,7 +572,7 @@ DEPENDENCIES
   delayed_job (~> 4.1.0)
   delayed_job_active_record!
   delorean
-  devise (~> 3.4.0)
+  devise (~> 3.5.4)
   dotenv!
   dotenv-rails!
   dropbox-api

+ 3 - 3
config/initializers/devise.rb

@@ -94,6 +94,9 @@ Devise.setup do |config|
   # Setup a pepper to generate the encrypted password.
   # config.pepper = "SOME LONG HASH GENERATED WITH rake secret"
 
+  # Send a notification email when the user's password is changed
+  # config.send_password_change_notification = false
+
   # ==> Configuration for :confirmable
   # A period that the user is allowed to access the website even without
   # confirming their account. For instance, if set to 2.days, the user will be
@@ -151,9 +154,6 @@ Devise.setup do |config|
   # time the user will be asked for credentials again. Default is 30 minutes.
   # config.timeout_in = 30.minutes
 
-  # If true, expires auth token on session timeout.
-  # config.expire_auth_token_on_timeout = false
-
   # ==> Configuration for :lockable
   # Defines which strategy will be used to lock an account.
   # :failed_attempts = Locks an account after a number of failed attempts to sign in.