====================
1.0.4
====================

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Base Distribution
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

[BUGFIX] Fixes wrong URL to tutorials page in Readme.txt
-----------------------------------------------------------------------------------------

* Fixes: `#33031 <http://forge.typo3.org/issues/33031>`_
* Commit: `0c887eb <http://git.typo3.org/Flow/Distributions/Base.git?a=commit;h=0c887eb0e02343c7b90e512411ab2adbc4a5f760>`_

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
TYPO3.Flow
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

[SECURITY] Protect arguments of form __referrer with HMAC
-----------------------------------------------------------------------------------------

The request arguments of the referring request are
a serialized string written to one of the hidden
fields in a Fluid form. This string has to be protected
by a HMAC to protect FLOW3 from possible unserialize
attacks.

Note: For now there is no object known within the FLOW3
Distribution, that could be used for an unserialize
exploit!

This change also backports some convenience hmac methods
to the hash service from the current master, to have the
bugfix in sync.

* Security-Bulletin: `FLOW3-SA-2012-001 <http://typo3.org/teams/security/security-bulletins/flow3/flow3-sa-2012-001/>`_
* Fixes: `#35300 <http://forge.typo3.org/issues/35300>`_
* Commit: `cd39af5 <http://git.typo3.org/Flow/Packages/TYPO3.Flow.git?a=commit;h=cd39af5dddd1695b499ca038c5add38d46436e4c>`_

[BUGFIX] typo in return statement for getAccessDecisionVoters()
-----------------------------------------------------------------------------------------

Fix return value to array.
Fix type hinting for var $securityContext and $authenticationManager

* Fixes: `#34620 <http://forge.typo3.org/issues/34620>`_
* Commit: `7e055f0 <http://git.typo3.org/Flow/Packages/TYPO3.Flow.git?a=commit;h=7e055f0b2c7e2d0f92992afd0c97007b50ef4aac>`_

[BUGFIX] ResourceStreamWrapper returns wrong value for fseek
-----------------------------------------------------------------------------------------

Calling fseek will always return the wrong value, as fseek
return 0 on success otherwise -1.
The stream_wrapper expects a boolean value. So 0 will be
evaluated to false and -1 will be evaluated to true

* Fixes: `#34608 <http://forge.typo3.org/issues/34608>`_
* Commit: `461bb05 <http://git.typo3.org/Flow/Packages/TYPO3.Flow.git?a=commit;h=461bb056be2d6855aa3def46b4dcbe18fca28cd7>`_

[BUGFIX] Wrong variable name inside rename function
-----------------------------------------------------------------------------------------

Use the proper variable name to create the stream wrapper.

* Fixes: `#34547 <http://forge.typo3.org/issues/34547>`_
* Commit: `93c28d81 <http://git.typo3.org/Flow/Packages/TYPO3.Flow.git?a=commit;h=93c28d81df8721ae1facc8d720dbc7c0a4048d5e>`_

[BUGFIX] Fixes duplicate error id in StringValidator
-----------------------------------------------------------------------------------------

StringValidator uses the error id 1238108068, but that is
used in StringLengthValidator. This change makes the former
use 1238108070 instead.

* Fixes: `#33973 <http://forge.typo3.org/issues/33973>`_
* Commit: `e1f1478 <http://git.typo3.org/Flow/Packages/TYPO3.Flow.git?a=commit;h=e1f1478eba905740584e9990a68cbf6b7d4c0b4c>`_

[BUGFIX] isAuthenticated should work in authentication request
-----------------------------------------------------------------------------------------

AuthenticationManager::isAuthenticated now checks for resumable
and new sessions before returning FALSE, so it works also in the
request that triggers the authentication.

* Fixes: `#33311 <http://forge.typo3.org/issues/33311>`_
* Commit: `27f00f6 <http://git.typo3.org/Flow/Packages/TYPO3.Flow.git?a=commit;h=27f00f62768c2b322e87d815e5bef9f5bd2bb2ea>`_

[BUGFIX] Now filters correctly for '__destruct' in pointcut filter
-----------------------------------------------------------------------------------------

The filter for proxyable methods in SessionObjectMethodsPointcutFilter skips
the method '__desctruct' instead of '__destruct'

* Fixes: `#34293 <http://forge.typo3.org/issues/34293>`_
* Commit: `55150fe <http://git.typo3.org/Flow/Packages/TYPO3.Flow.git?a=commit;h=55150fe526b60d0200b6afd40731b8c36cef1bc4>`_

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
TYPO3.Fluid
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

[SECURITY] Protect arguments of form __referrer with HMAC
-----------------------------------------------------------------------------------------

The request arguments of the referring request are
a serialized string written to one of the hidden
fields in a Fluid form. This string has to be protected
by a HMAC to protect FLOW3 from possible unserialize
attacks.

Note: For now there is no object known within the FLOW3
Distribution, that could be used for an unserialize
exploit!

* Security-Bulletin: `FLOW3-SA-2012-001 <http://typo3.org/teams/security/security-bulletins/flow3/flow3-sa-2012-001/>`_
* Related: `#35300 <http://forge.typo3.org/issues/35300>`_
* Commit: `7bc4e35 <http://git.typo3.org/Flow/Packages/TYPO3.Fluid.git?a=commit;h=7bc4e35752779bab0c51fc82387088d9217277ba>`_

