Release 2.2.58 (19th July 2017):
Important:
TL-14946 The webdav_locks table has been dropped from the database
The webdav_locks table has been dropped from the database.
It is a legacy table from Totara 1.1 and has never been used in Totara 2 or
above.
It had already been dropped from Totara 9 and 10.
The decision was made to drop the table from stable branches as it
contained a field that was using a name that had become a reserved word in
modern databases.
By dropping this unused table we can help ensure that database upgrades
will not be problematic in the supported stable releases.
Security issues:
TL-12940 Applied account lockout threshold when using webservice authentication
Previously, the account lockout threshold, for number of incorrect
passwords, was not taken into account when webservice authentication was
being used. The account lockout functionality now applies to webservice
authentication. Please note that this refers to the authentication type
that allows users to log in with username and password, not when accessing
their account using a webservice token.
TL-12942 Stopped the supplied passwords being logged in failed web services authentication
When web service authentication was used, entries recorded to the logs for
failed log in attempts included the supplied password in plain text. This
is no longer recorded.