Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

Gregg Kellogg's latest activity

Wednesday, July 08 2009
2334 Hash.from_xml fieldnames uncamelizing was updated in Ruby on Rails
  • Gregg Kellogg
    • Assigned user set to Jeremy Kemper
    by Gregg Kellogg at 6:13 PM

    Seems to have been fixed in commit eb201e64c0b68aee6d0715d44cf48178204c4133 "Fixed Hash#from_xml with keys that are all caps."

Saturday, June 06 2009
2755 Security hole found in Rails 2.3's http_authentication.rb was updated in Ruby on Rails
  • Gregg Kellogg
    Gregg Kellogg commented at 6:04 PM

    Note that authenticate_or_request_http_digest can take either the clear-text password or the HA1 digest hash of the username and password: MD5(username:realm:pa...

Thursday, March 26 2009
2334 Hash.from_xml fieldnames uncamelizing was updated in Ruby on Rails
  • Gregg Kellogg
    Gregg Kellogg commented at 11:28 PM

    Okay, here's an updated activesupport/test/core_ext/hash_ext_test.rb with new test test_single_record_from_xml_with_camel_case

  • Gregg Kellogg
    Gregg Kellogg commented at 11:19 PM

    See if this works.

    @@@ruby xml = %(<blah_blah> 1 2 <dasherized_tag> 3 </dasherized_tag> </blah_blah>)

    
    
  • Gregg Kellogg
    Gregg Kellogg commented at 11:16 PM

    Oops! It seems that it's getting eaten on the submit. I'll modify the appropriate unit test and upload it.

  • Gregg Kellogg
    Gregg Kellogg commented at 11:15 PM

    It would probably help if i used the whole test string:

    xml = %(<blah_blah> 1 2 <dasherized_tag> 3 </dasherized_tag> </blah_blah>)

Wednesday, March 25 2009
2334 Hash.from_xml fieldnames uncamelizing was created in Ruby on Rails
Thursday, March 12 2009
2209 Patch #3 for HTTP Digest Auth was updated in Ruby on Rails
  • Gregg Kellogg
    Gregg Kellogg commented at 6:09 AM

    I think it's important to get these patches in, but there should be a follow up to deal with the potential unavailability of the session_id. This could be done ...

Wednesday, February 25 2009
2000 Patch for HTTP Digest Authentication URI comparison was updated in Ruby on Rails
  • Gregg Kellogg
    Gregg Kellogg commented at 4:02 PM

    I think using ETag is problematic: We'd have to avoid header calculation and authentication detection until after the ETag's been generated: i.e., in an after_f...

  • Gregg Kellogg
    Gregg Kellogg commented at 7:24 AM

    Looking within ActionController, it looks like the session secret is an attribute of the CookieSessionStore, and not included in other session stores (e.g., mem...