From 62e0259129fa7147a3899244569c05f4e7fd3b7c Mon Sep 17 00:00:00 2001
From: Joel Johnson <joel.johnson@issinc.com>
Date: Tue, 14 Jul 2015 15:59:29 -0400
Subject: [PATCH] prevent session fixation for external authentication

---
 src/main/java/com/gitblit/wicket/panels/RepositoryUrlPanel.html |    2 +-
 1 files changed, 1 insertions(+), 1 deletions(-)

diff --git a/src/main/java/com/gitblit/wicket/panels/RepositoryUrlPanel.html b/src/main/java/com/gitblit/wicket/panels/RepositoryUrlPanel.html
index 4b28e71..a537277 100644
--- a/src/main/java/com/gitblit/wicket/panels/RepositoryUrlPanel.html
+++ b/src/main/java/com/gitblit/wicket/panels/RepositoryUrlPanel.html
@@ -95,7 +95,7 @@
        		quality="high"
        		wmode="transparent"
        		scale="noscale"
-       		allowScriptAccess="always"></object>
+       		allowScriptAccess="sameDomain"></object>
 	</wicket:fragment>
 
 	<wicket:fragment wicket:id="workingCopyFragment">

--
Gitblit v1.9.1