Commit Graph

291 Commits (08e62bece99ab59624b363aec64400a499991561)

Author SHA1 Message Date
Joas Schilling bc4a102f52
fix(session): Avoid race condition for cache::get() vs. cache::hasKey() 2 years ago
Ferdinand Thiessen e8452d9ef1
fix(deps): Bump web-auth/webauthn-lib from 3.3.9 to 4.8.5 2 years ago
Côme Chilliet ab6afe0111 fix: Fix new psalm errors from update 2 years ago
Côme Chilliet ec5133b739 fix: Apply new coding standard to all files 2 years ago
Benjamin Gaussorgues d1189f923c
feat(perf): add cache for authtoken lookup 2 years ago
Vincent Petry 839ddaa354
feat: rename users to account or person 2 years ago
Côme Chilliet 8bcc2d352e chore: Fix missing template parameter for IEventListener 2 years ago
Côme Chilliet a526a382bf
Import OCP IToken as OCPIToken to avoid a name clash in lib/private 2 years ago
Côme Chilliet 37a6e15f87 Use OCP version of IToken in AppPasswordCreatedEvent 2 years ago
Côme Chilliet 8fc39aeb1c Use IToken from OCP instead of OC 2 years ago
Côme Chilliet 95ea6188dc Suppress or fix psalm errors related to InvalidTokenException 2 years ago
Côme Chilliet eee9f1eec4 Always catch OCP versions of authentication exceptions 2 years ago
Alexander Piskun 26d343d33a
AppAPI: allowed to bypass Two-Factor 2 years ago
Joas Schilling aa5f037af7
chore: apply changes from Nextcloud coding standards 1.1.1 2 years ago
Christoph Wurst a5422a3998
fix: Show error message when CSRF check fails at login 2 years ago
Côme Chilliet d8b42c6131
Allow passing null to PublicKeyToken::setScope, fixes tests 2 years ago
Côme Chilliet 33a24134a7
Improve docblock annotations for tokens and their exceptions 2 years ago
Côme Chilliet 58a57a714e
Use more precise typing for setScope method parameter 2 years ago
Côme Chilliet 1bdf952fde
Make sure that OC interfaces returns OC interfaces for backward compatibility 2 years ago
Côme Chilliet b82e25ea7a
Move Exceptions used in OCP to OCP 2 years ago
Côme Chilliet 356f0291a2
Align PublicKeyToken with interface changes 2 years ago
Côme Chilliet f94fb33062
Move IToken and IProvider::getToken to OCP 2 years ago
Benjamin Gaussorgues 4361019f2f
fix(twofactor): avoid error in pgsql for duplicate entry 2 years ago
Lucas Azevedo 2a36acfc2b Fix typo 2 years ago
Lucas Azevedo c93b1634d3
Fixes from static analysis 2 years ago
Lucas Azevedo fe9b9c1955 Add last-used-before option 2 years ago
Daniel Kesselberg 32303b6ed5 docs: remove superfluous phpdocs 2 years ago
Joas Schilling dac31ad101
fix!: Remove legacy event dispatching Symfony's GenericEvent from 2FA Manager 2 years ago
Christoph Wurst 14719110b9 chore: Replace \OC::$server->query with \OCP\Server::get in /lib 3 years ago
Joas Schilling 05aa39d777
Fix event names of 2FA related typed events 3 years ago
Christoph Wurst 5eb768ac5e
fix(auth): Run token statements in atomic transaction 3 years ago
Côme Chilliet 426c0341ff
Use typed version of IConfig::getSystemValue as much as possible 3 years ago
jld3103 d9f8522003
Fix types for reading and writing config values 3 years ago
Artur Neumann f634badf12
public interface to invalidate tokens of user 3 years ago
Ember 'n0emis' Keske 6881d2f2f1
Don't try to hash a nonexisting password 3 years ago
Joas Schilling 6417ea0265
fix(authentication): Handle null or empty string password hash 3 years ago
Julius Härtl 580feecdbf
fix(authtoken): Store only one hash for authtokens with the current password per user 3 years ago
Joas Schilling 7a85a1596e
fix(authentication): Check minimum length when creating app tokens 3 years ago
Joas Schilling 03a585ab4f
fix(performance): Only search for auth tokens when the provided login is long enough 3 years ago
Côme Chilliet f5c361cf44
composer run cs:fix 3 years ago
Joas Schilling 2fb4dac7ad
fix(authentication): Update the token when the hash is null or can not be verified 3 years ago
Joas Schilling 28b18d561c
fix(authentication): Only hash the new password when needed 3 years ago
Joas Schilling c5bb19641c
fix(authentication): Invert the logic to the original intention 3 years ago
Joas Schilling 55d8aec759
fix(authentication): Only verify each hash once 3 years ago
Thomas Citharel 6b7da88b0b
Validate user timezone given from login data before saving it 3 years ago
Joas Schilling b4a29644cc
Add a const for the max user password length 3 years ago
Marcel Klehr adfe367106
PublickKeyTokenProvider: Fix password update routine with password hash 3 years ago
Julius Härtl 6abb37317f
Do not setup a session when not required on WebDAV requests 3 years ago
Roeland Jago Douma 77df92cabf
feat: add event for failed logins 3 years ago
Julius Härtl 298d2b9b58
Skip general login with email for non-valid addresses and LDAP 3 years ago