Kay0u
|
a756462e6c
|
parse auth header at the end
|
2020-12-23 15:20:55 +01:00 |
|
Titoko
|
1747da0571
|
Update access.lua
|
2020-12-17 20:12:22 +01:00 |
|
titoko
|
2ca6847d4d
|
Update helpers.lua
|
2020-12-13 12:05:27 +01:00 |
|
titoko
|
a0129b437e
|
fix(Authorization): Skipped Autorization Header that are not Basic
|
2020-12-12 14:23:46 +01:00 |
|
Alexandre Aubin
|
6a7a9d668e
|
Restore ngx logging used by fail2ban to detect failed logging attempt
|
2020-10-31 13:53:19 +01:00 |
|
Alexandre Aubin
|
ed6fa1aa49
|
Add a small helper to check if an element is in a table ... in turn fixing a bug related to calling has_access
|
2020-09-21 14:42:26 +02:00 |
|
Alexandre Aubin
|
41ed91bbcb
|
Misc cosmetics / debug tweaks
|
2020-09-20 18:00:49 +02:00 |
|
Alexandre Aubin
|
a11d8f0d87
|
Move identification of relevant permission from helpers.lua to access.lua
|
2020-09-20 17:58:26 +02:00 |
|
Alexandre Aubin
|
abc38bbffe
|
Move handling of login through HTTP headers to is_logged_in helper
|
2020-09-20 17:53:18 +02:00 |
|
Kay0u
|
41ac2e5bf8
|
Merge remote-tracking branch 'origin/dev' into permission_protection
|
2020-09-01 20:56:20 +02:00 |
|
Kay0u
|
fb45cd0441
|
do not compare the same thing several times
|
2020-06-18 14:48:14 +02:00 |
|
Kay0u
|
397f7b3910
|
authUser is defined only if authHash is accepted
|
2020-05-21 22:57:57 +02:00 |
|
Kay0u
|
6a240e1dea
|
better log message
|
2020-05-21 22:57:05 +02:00 |
|
SilverViper
|
728620778e
|
prevent SSOwAuthRedirect=;;
|
2020-04-30 17:39:07 +02:00 |
|
SilverViper
|
e4b415a64e
|
Remove all ;; in Set-Cookie
|
2020-04-30 15:45:41 +02:00 |
|
Laurent Peuch
|
e0a66428ea
|
[fix] invalid more cookies
|
2020-04-17 00:56:40 +02:00 |
|
Kay0u
|
0fc89d0fc9
|
Rework access
|
2020-04-01 00:43:59 +02:00 |
|
Kay0u
|
d8c74604c0
|
portal with the new config file
|
2020-03-31 02:20:40 +02:00 |
|
Kay0u
|
8cc2bd4b28
|
Avoid unnecessarily reloading the config file
|
2020-03-29 18:02:49 +02:00 |
|
Kay0u
|
bf0dc73381
|
using permissions, not users directive
|
2020-03-04 11:34:24 +01:00 |
|
Kay0u
|
97620aaac7
|
Unused condition
|
2020-03-04 11:32:53 +01:00 |
|
Kay0u
|
af892991af
|
refactor legacy url protections
|
2020-02-13 10:06:32 +07:00 |
|
Kay0u
|
f74619020d
|
Fix if no permission exist
|
2020-01-29 18:24:25 +07:00 |
|
Kay0u
|
02b4ecec8c
|
Fix legacy/new permissions
|
2020-01-20 22:59:25 +07:00 |
|
Kay0u
|
19ae10200d
|
fix string.match
|
2020-01-17 14:56:32 +07:00 |
|
Alexandre Aubin
|
ff700062a5
|
At least one rule should exist + should be the longest match
|
2019-10-09 18:45:50 +02:00 |
|
Alexandre Aubin
|
a13a2fee1e
|
More extensive check between allowed rules vs. protected rules
|
2019-10-03 23:11:52 +02:00 |
|
Alexandre Aubin
|
1eb322df17
|
Many tweaks in log system + implement many log messages in low-level functions
|
2019-10-03 20:42:01 +02:00 |
|
Alexandre Aubin
|
474b922089
|
Be consistent : either we use log() everywhere or we don't ... But imho just logger.info() is fine
|
2019-09-24 17:33:19 +02:00 |
|
Alexandre Aubin
|
7cb61f1619
|
Merge branch 'logging' into logging-reloaded
|
2019-09-24 17:27:44 +02:00 |
|
Alexandre Aubin
|
fc688418ce
|
info.html -> portal.html
|
2019-03-19 23:29:46 +01:00 |
|
Alexandre Aubin
|
32a9229ef4
|
Enable cache for 1 hour for static assets
|
2019-03-19 16:52:43 +01:00 |
|
Alexandre Aubin
|
2bdc12b0a0
|
Let's keep it simple ... have a folder asserts/{theme}/ containing a stylesheet.css and global.js
|
2019-02-21 18:27:28 +01:00 |
|
Lukas Fülling
|
d33cd97556
|
Add theming support, add vapor theme
|
2019-02-21 18:12:24 +01:00 |
|
chateau
|
94e15d9fe6
|
Simplify ynhpanel.js and ynhpanel.css making the YNH inapp panel an iframe that loads the info.html page.
|
2019-02-21 16:47:11 +01:00 |
|
Josué Tille
|
441f323094
|
Fix string helper if string is empty
|
2019-01-23 10:23:12 +01:00 |
|
Alexandre Aubin
|
a52ed73a11
|
Typo
|
2019-01-17 23:21:30 +01:00 |
|
Josué Tille
|
437f3c238a
|
Fix when the user stay connected
|
2019-01-17 22:54:25 +01:00 |
|
Josué Tille
|
32d04dbac9
|
Fix SSOwat crash after password change
|
2019-01-07 11:45:29 +01:00 |
|
Laurent Peuch
|
253cde4b9a
|
[fix] CVE-2018-11347 http header injection
|
2018-12-06 23:50:21 +01:00 |
|
Alexandre Aubin
|
7be6e76cb8
|
SameSite=Strict breaks multisite
|
2018-11-19 16:06:12 +00:00 |
|
Alexandre Aubin
|
2699aa8db7
|
Clarify Set-Cookie syntax
|
2018-11-19 16:03:35 +00:00 |
|
Alexandre Aubin
|
2ff41d9920
|
Merge remote-tracking branch 'tYYGH/PR_choiceRewritePW+fixes' into stretch-unstable
|
2018-11-05 03:15:43 +01:00 |
|
Alexandre Aubin
|
b68ebc04c7
|
Merge pull request #103 from frju365/patch-1
[fix] Secure cookie setting
|
2018-11-04 16:20:59 +01:00 |
|
Alexandre Aubin
|
99c108f362
|
Merge pull request #104 from YunoHost/enh-pwd-validate
[enh] Validate password strength
|
2018-11-04 15:59:39 +01:00 |
|
Alexandre Aubin
|
cb96f848d3
|
This got removed
|
2018-10-31 18:55:07 +00:00 |
|
tituspijean
|
11d0e0689a
|
[mod] Redirect after logout if r URI argument exists
|
2018-09-15 09:25:48 +02:00 |
|
ljf
|
e4ee83cc8e
|
[fix] Add a small comment
|
2018-08-29 03:00:13 +02:00 |
|
ljf
|
deeb30637e
|
[fix] Remove nginx log
|
2018-08-29 02:58:17 +02:00 |
|
ljf
|
410ba2e4a7
|
[fix] Remove extra end line of the cmd run with popen
|
2018-08-29 02:55:02 +02:00 |
|