There are also 2 small new features. You can now tell Auth to inform the user if he entered the username or the password wrong by setting auth.settings.login_specify_error = True
Web2py now supports Same-Site in cookies and uses it by default set to Lax which should improve the security of all applications. For extra security check if your application can be used with strict and set it using session.samesite('Strict') -- Resources: - http://web2py.com - http://web2py.com/book (Documentation) - http://github.com/web2py/web2py (Source code) - https://code.google.com/p/web2py/issues/list (Report Issues) --- You received this message because you are subscribed to the Google Groups "web2py-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to web2py+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.