diff --git a/docs/simplesamlphp-upgrade-notes-1.14.txt b/docs/simplesamlphp-upgrade-notes-1.14.txt index 4f49395d4c54e748cbfc743d55c64b45cb1978cf..6278a7e2e73b81ac14b5ec5f52f61058e589fc7b 100644 --- a/docs/simplesamlphp-upgrade-notes-1.14.txt +++ b/docs/simplesamlphp-upgrade-notes-1.14.txt @@ -179,3 +179,5 @@ The following modules will no longer be shipped with the next version of SimpleS * `openidProvider` * `saml2debug` * `themefeidernd` + +The default value for trusted.url.domains in the config template has been changed from NULL to an empty array(), this sets a higher grade of default security. Resetting to NULL will re-allow untrusted routing.