Commit graph

  • d27d731e4d Update changelog for 2.7.11 release debian/2.7.11 Alexandre Aubin 2018-05-01 23:30:58 +00:00
  • 219b278673
    Merge pull request #98 from yunohost-bot/weblate-yunohost-ssowat Alexandre Aubin 2018-05-01 23:57:12 +02:00
  • 99e7f29f67 [i18n] Translated using Weblate (Spanish) bjarkan 2018-04-28 16:30:40 +00:00
  • 710128b711 [i18n] Translated using Weblate (Dutch) Matthieu 2018-03-19 15:36:54 +00:00
  • 43cbf11f10 [i18n] Translated using Weblate (Arabic) ButterflyOfFire 2018-02-07 23:10:10 +00:00
  • ffcf553182 [i18n] Translated using Weblate (Arabic) ButterflyOfFire 2018-02-07 21:46:13 +00:00
  • 4a8ad06025 Use role=button, to have those links handled as buttons by screen readers (#97) irina11y 2018-04-16 18:45:59 +02:00
  • e943e18e83 I put role=button irina 2018-04-15 20:59:54 +02:00
  • 30ff28d1de
    Merge pull request #96 from yunohost-bot/weblate-yunohost-ssowat Laurent Peuch 2018-02-07 21:59:13 +01:00
  • cc1a279df9 [i18n] Translated using Weblate (Arabic) ButterflyOfFire 2018-02-07 20:43:04 +00:00
  • 426df8205c Added translation using Weblate (Arabic) ButterflyOfFire 2018-02-07 20:33:05 +00:00
  • 7493cce2d4 Update changelog for 2.7.7 release debian/2.7.7 Alexandre Aubin 2018-01-18 17:37:39 -05:00
  • 72f1682b71 Update changelog for 2.7.6 release debian/2.7.6 Alexandre Aubin 2018-01-16 17:10:11 -05:00
  • 8f669e9fe9
    [fix] Microdecision: fix link for support in SSOwat portal Alexandre Aubin 2017-12-26 16:16:48 +01:00
  • 0ccfe6ee5a Update changelog for 2.7.5 release debian/2.7.5 Alexandre Aubin 2017-12-02 12:23:20 -05:00
  • 3996f8000e Update changelog for 2.7.4 release debian/2.7.4 Alexandre Aubin 2017-11-28 18:47:31 -05:00
  • c28cb0000e
    Merge pull request #94 from yunohost-bot/weblate-yunohost-ssowat Laurent Peuch 2017-11-28 13:22:23 +01:00
  • 8ff784ca4b [i18n] Translated using Weblate (French) Rafi59 2017-11-05 20:55:25 +00:00
  • 8c900e4a9a
    [fix] Add whois as dependency (#95) Alexandre Aubin 2017-11-18 22:58:06 +01:00
  • 62289877d1
    Update control Alexandre Aubin 2017-11-18 22:56:09 +01:00
  • 1694139358 Update changelog for 2.7.3 release debian/2.7.3 Alexandre Aubin 2017-10-12 17:04:48 -04:00
  • d38d5e3d29 [fix] Force back_url to use HTTPS (#93) Alexandre Aubin 2017-10-12 22:06:30 +02:00
  • d6d966649c [fix] Force back_url to use HTTPS Alexandre Aubin 2017-10-11 00:44:19 +02:00
  • 1bf64408c9 portal_path must end with / (#91) tYYGH 2017-10-02 20:04:46 +02:00
  • 82a63e2e92 Merge de20c91871 into daa799111e tYYGH 2017-09-22 18:07:43 +00:00
  • de20c91871 Limited support for app-logout on SSO-logout Y 2017-09-22 20:07:02 +02:00
  • 049ad9f48a Use request_uri instead of uri; internal redirects break the latter Yves G 2017-09-19 13:40:58 +02:00
  • db8724d578 req.var.scheme broken behind a reverse-proxy. Allow the Nginx admin to set "proxy_https" to override "https" Yves G 2017-09-19 13:57:01 +02:00
  • a0d143aad9 Avoid lua error in helpers.lua: for url, name in pairs(conf["users"][user]) do Y 2017-09-17 18:23:32 +02:00
  • 1d3ee78cba Avoid lua error in helpers.lua: for k, v in pairs(conf["additional_headers"]) do Y 2017-09-17 18:18:46 +02:00
  • d1c53a6e1b Scheme check is broken behind a reverse-proxy; same can be achieved with regular Nginx conf Y 2017-09-17 17:41:30 +02:00
  • 61ca14a09a Some debug statements Y 2017-09-17 16:27:09 +02:00
  • 7698e778cf Avoid lua error in helpers.lua: if not conf["users"][user] then Y 2017-09-17 16:19:29 +02:00
  • db9059a55c let the admin decide how passwords are handled Y 2017-09-16 19:22:47 +02:00
  • 6b6fd09f34 portal_path must end with / Y 2017-09-16 18:49:37 +02:00
  • daa799111e Merge pull request #89 from tYYGH/unstable Laurent Peuch 2017-09-16 16:58:36 +02:00
  • c24a5ecd20 skipped_urls is mandatory Y 2017-09-16 15:00:11 +02:00
  • 41c8997255 Update changelog for 2.7.2 release debian/2.7.2 Alexandre Aubin 2017-08-22 21:18:02 -04:00
  • 227ef2a6fc Update changelog for 2.7.1 release debian/2.7.1 2.7.1 root 2017-08-19 22:06:35 +00:00
  • 87dbee3e8d Merge pull request #88 from yunohost-bot/weblate-yunohost-ssowat Laurent Peuch 2017-08-19 21:20:58 +02:00
  • 0e47b1f0a1 Merge remote-tracking branch 'origin/unstable' into unstable Weblate 2017-08-19 21:09:10 +02:00
  • 9b7fee7a1b [fix] attempt to fix https://github.com/YunoHost/SSOwat/pull/86#issuecomment-323417926 Laurent Peuch 2017-08-19 04:39:51 +02:00
  • 98b1b53fbf Merge pull request #87 from YunoHost/hash_algo Laurent Peuch 2017-08-18 02:42:00 +02:00
  • d440d06ae7 [fix] be paranoid and prevent shell injections here also while input is supposed to be safe Laurent Peuch 2017-08-18 02:35:08 +02:00
  • c8c7fe7fc7 [fix] prevent shell injections Laurent Peuch 2017-08-18 02:34:46 +02:00
  • 37938fd0f4 Merge pull request #86 from MCMic/unstable Laurent Peuch 2017-08-17 23:13:34 +02:00
  • d16f3f81d0 [enh] auto rehash in sha-512 users passwords on login Laurent Peuch 2017-08-15 11:41:24 +02:00
  • 2ff2fb92f3 [enh] encode password using sha512 on user modification of password Laurent Peuch 2017-08-15 01:30:39 +02:00
  • 97df24e794 [i18n] Translated using Weblate (Esperanto) MCMic 2017-08-10 18:04:38 +02:00
  • 47f01b3f6f Fixed support for incomplete translations (fallback to default language for missing strings) Côme Chilliet 2017-08-10 16:31:00 +02:00
  • 044aa1d8eb Update changelog for 2.7.0 release debian/2.7.0 Alexandre Aubin 2017-08-07 12:59:52 -04:00
  • 3ecdb97bf6 Update from Weblate. (#85) YunoHost Bot 2017-08-07 18:24:55 +02:00
  • a4445a862b [i18n] Translated using Weblate (Russian) Evgeniy Ozhiganov 2017-07-21 05:25:41 +02:00
  • c7bc762ea3 Added translation using Weblate (Russian) Ozhiganov 2017-07-21 05:20:01 +02:00
  • e30b9a3505 Merge 292cf628c7 into 50fcc831bf Maniack Crudelis 2017-05-30 14:56:03 +00:00
  • eeb2fc87d2 Merge 0dd52f0a55 into 50fcc831bf Laurent Peuch 2017-05-30 14:56:02 +00:00
  • 866f1e8d72 Merge 0ef02dcce4 into 50fcc831bf YunoHost Bot 2017-05-30 14:56:02 +00:00
  • 50fcc831bf [mod] comment didn't matched reality Laurent Peuch 2017-05-27 19:19:48 +02:00
  • aca5f054ab Update changelog for 2.6.8 release debian/2.6.8 opi 2017-05-23 21:46:14 +02:00
  • c1a388ccf0 Merge pull request #84 from YunoHost/caching_for_hash Laurent Peuch 2017-05-23 21:40:30 +02:00
  • 5157415ce3 [fix] remove tabs Laurent Peuch 2017-05-23 07:26:41 +02:00
  • 76677fab0d [enh] uses caching for hash to avoid heavy recalculation and process spawning Laurent Peuch 2017-05-22 23:01:18 +02:00
  • e47a3e60a5 Merge 0c079c8502 into 37c0980155 Laurent Peuch 2017-05-18 07:15:49 +00:00
  • 37c0980155 Update changelog for 2.6.7 release debian/2.6.7 opi 2017-05-18 09:14:33 +02:00
  • d105b28ccf [fix] sidddy takes 3 d opi 2017-05-18 08:56:48 +02:00
  • 25ce273120 [love] Add siddy to contributors file. opi 2017-05-18 08:54:45 +02:00
  • 0ef02dcce4 [mod] remove python script and talk directly to openssl Laurent Peuch 2017-05-15 20:57:23 +02:00
  • 886bec89ec [fix] uses hmac_sha512 for hasing the token and don't store the key in it anymore Laurent Peuch 2017-05-15 03:52:53 +02:00
  • fc52f05459 Quick fix for CDA security issue sidddy 2017-05-17 10:44:26 +02:00
  • 98a6879ab4 [fix] don't include ip in token, this is useless and make infinite redirection\n\nIt has been confirmed by a security friend that this was nearly useless here since the token is marked as Secure and can only be exchanged on https so if someone managed to steal it the user have way more important problems. Laurent Peuch 2017-05-17 21:48:19 +02:00
  • 2456eda200 [fix] Use hmac_sha512 instead of md5 for cookie hashing. Don't store the key in token anymore (#80) Laurent Peuch 2017-05-18 08:34:36 +02:00
  • 0c079c8502 [fix] don't include ip in token, this is useless and make infinite redirection\n\nIt has been confirmed by a security friend that this was nearly useless here since the token is marked as Secure and can only be exchanged on https so if someone managed to steal it the user have way more important problems. Laurent Peuch 2017-05-17 21:48:19 +02:00
  • 96b077fe02 Merge pull request #79 from YunoHost/crypto_random Laurent Peuch 2017-05-17 21:37:55 +02:00
  • 490ecfb594 Quick fix for CDA security issue sidddy 2017-05-17 10:44:26 +02:00
  • 782d81fbfe [mod] remove python script and talk directly to openssl Laurent Peuch 2017-05-15 20:57:23 +02:00
  • d71b5bc2a1 [fix] uses hmac_sha512 for hasing the token and don't store the key in it anymore Laurent Peuch 2017-05-15 03:52:53 +02:00
  • c5bb6ef2ae [fix] uses a cryptographically secure source of randomness Laurent Peuch 2017-05-15 03:29:34 +02:00
  • 054b7d1752 [mod] remove things not related to logging Laurent Peuch 2017-05-13 15:08:56 +02:00
  • ad39e3ded5 Added access log, ignore IP, check acl for basic auth sidddy 2017-05-12 13:54:39 +02:00
  • 46b6d1048e Update changelog for 2.6.6 release debian/2.6.6 opi 2017-05-12 22:51:24 +02:00
  • 737ebba474 Merge branch 'acl_on_basic_http_auth' into stable opi 2017-05-12 22:49:12 +02:00
  • c019f9d208 [fix] check users ACL on http basic auth Laurent Peuch 2017-05-12 15:42:29 +02:00
  • 442147bbbe Update changelog for 2.6.5 release Alexandre Aubin 2017-04-24 13:03:07 -04:00
  • 2a648b8475 [i18n] Translated using Weblate (Dutch) Jeroen Keerl 2017-04-07 22:57:30 +02:00
  • 4450ba8f95 [i18n] Translated using Weblate (German) Fabian Gruber 2017-03-21 15:41:02 +01:00
  • d0709ff1f3 Adding link to bugtracker Alexandre Aubin 2017-04-03 01:35:16 +02:00
  • 5228bf4f0c [fix] Fix tile not displayed when app is installed on root (bug #285) (#71) JimboJoe 2017-04-02 23:47:54 +02:00
  • 0dd52f0a55 [fix] check users ACL on http basic auth Laurent Peuch 2017-05-12 15:42:29 +02:00
  • 3a04c42ae6 Update changelog for 2.6.5 release debian/2.6.5 Alexandre Aubin 2017-04-24 13:03:07 -04:00
  • eba9c6ede2 Merge pull request #76 from yunohost-bot/weblate-yunohost-ssowat opi 2017-04-24 17:34:20 +02:00
  • d7ed67a586 [i18n] Translated using Weblate (Dutch) Jeroen Keerl 2017-04-07 22:57:30 +02:00
  • ad274017d9 [i18n] Translated using Weblate (German) Fabian Gruber 2017-03-21 15:41:02 +01:00
  • 25eeff041d Adding link to bugtracker Alexandre Aubin 2017-04-03 01:35:16 +02:00
  • b1a1d55e66 [fix] Fix tile not displayed when app is installed on root (bug #285) (#71) JimboJoe 2017-04-02 23:47:54 +02:00
  • edb1ea079c Update changelog for 2.6.4 release debian/2.6.4 opi 2017-03-14 15:39:44 +01:00
  • f68c7f9e44 [fix] Remove help-link in portal as they don't link to nothing. Fix #68 opi 2017-03-14 15:32:49 +01:00
  • ee971b453d Update changelog for 2.6.3 release debian/2.6.3 opi 2017-03-08 11:13:50 +01:00
  • 16923ffc95 Merge pull request #75 from yunohost-bot/weblate-yunohost-ssowat opi 2017-03-08 11:12:29 +01:00
  • a6911d9037 [i18n] Translated using Weblate (French) opi 2017-03-08 11:11:10 +01:00
  • 9956a7c1c1 [fix] Validate domain & url before redirection on login. opi 2017-02-23 23:15:30 +01:00