Skip to content

docs(changelog): note the empty-password hardening in 3.3.7 - #8262

Merged
JohnMcLear merged 1 commit into
developfrom
docs/changelog-3.3.7-auth
Sep 21, 2026
Merged

JohnMcLear merged 1 commit into
developfrom
docs/changelog-3.3.7-auth

Conversation

@JohnMcLear

Copy link
Copy Markdown
Member

Adds the 3.3.7 entry for #8261, which was merged without one.

Refusing an empty-string password on the OIDC and HTTP Basic login paths, reported by Wenhao Wu (Southeast University) while verifying the GHSA-62cj-9j72-mfrh fix. Changelog only.

🤖 Generated with Claude Code

https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Document empty-password authentication hardening in 3.3.7

📝 Documentation 🕐 Less than 5 minutes

Grey Divider

AI Description

• Adds the missing 3.3.7 changelog entry for empty-password authentication hardening.
• Credits the reporter and explains the affected OIDC and HTTP Basic login paths.
High-Level Assessment

A concise changelog entry is the appropriate approach because the underlying authentication fix is already merged. No architectural alternative is relevant to this documentation-only PR.

Files changed (1) +1 / -0

Documentation (1) +1 / -0
CHANGELOG.mdAdd 3.3.7 empty-password hardening note +1/-0

Add 3.3.7 empty-password hardening note

• Documents that empty-string passwords are rejected by OIDC and HTTP Basic authentication. Explains the explicit misconfiguration scenario, references #8261 and GHSA-62cj-9j72-mfrh, and credits the reporter.

CHANGELOG.md

@JohnMcLear
JohnMcLear merged commit 957efb6 into develop Sep 21, 2026
33 checks passed
@JohnMcLear
JohnMcLear deleted the docs/changelog-3.3.7-auth branch September 21, 2026 18:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant