Skip to content
Commit 5a3d3862 authored by Simon McVittie's avatar Simon McVittie
Browse files

CVE-2013-0240: Do not allow invalid SSL certificates



None of the branded providers (eg., Google, Facebook and Windows Live)
should ever have an invalid certificate; and in this version of GOA,
that's all we have. So set "ssl-strict" on the SoupSession object
being used by GoaWebView.

Reviewed-by: default avatarDebarshi Ray <debarshir@gnome.org>
Bug: https://bugzilla.gnome.org/show_bug.cgi?id=693214
parent 9559a342
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment