Skip to content

Comment on Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)parent

Comments

I could easily imagine myself missing this when reviewing the PR "oh it's just changing a whole bunch of specs, go ahead".

That's one of the major benefits of the "tree view" in MRs, because one can collapse the "spec" folder, collapse the "ee/spec" folder, and it leaves "db" and "lib/gitlab/auth" visible which should for sure set off mental alarm bells: https://docs.gitlab.com/ee/user/project/merge_requests/chang...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.