Commit Graph

64 Commits (2e4cc6da17028e777dc223689f1b9964ff2a4d8f)

Author SHA1 Message Date
Holger Hees e70249e089
Update SecurityMiddleware.php 6 years ago
Christoph Wurst cb057829f7
Update license headers for 19 6 years ago
Christoph Wurst caff1023ea
Format control structures, classes, methods and function 6 years ago
Christoph Wurst afbd9c4e6e
Unify function spacing to PSR2 recommendation 6 years ago
Christoph Wurst 2fbad1ed72
Fix (array) indent style to always use one tab 6 years ago
Christoph Wurst 74936c49ea
Remove unused imports 6 years ago
Joas Schilling d445f9b9fe
Fix loaded controller check 6 years ago
Christoph Wurst 5bf3d1bb38
Update license headers 6 years ago
Roeland Jago Douma 68748d4f85
Some php-cs fixes 6 years ago
Daniel Kesselberg 9055f46351
Make phan happy ;) 6 years ago
Arthur Schiwon 0a1937208f
Fixes a 500 without userid 6 years ago
Joas Schilling 15f00f0126
Mark "Talk" active on /call/token URLs 6 years ago
Roeland Jago Douma b8c5008acf
Add feature policy header 7 years ago
Roeland Jago Douma 37a4282c7a
Split up security middleware 7 years ago
Christoph Wurst 22ae682823
Make it possible to show admin settings for sub admins 7 years ago
Roeland Jago Douma 60e5a5eca4
Do not do redirect handling when loggin out 7 years ago
Roeland Jago Douma 603b672a11
Update password confirmation middleware 7 years ago
Bjoern Schiessle 85d9f06cb8
add global site selector as user back-end which doesn't support password confirmation 7 years ago
Roeland Jago Douma 8c1e75e052
Do not use file as template parameter 8 years ago
Arthur Schiwon 38a90130ce
move log constants to ILogger 8 years ago
Roeland Jago Douma 3ad7daeda5
Add tests 8 years ago
Roeland Jago Douma 340e8ef16c
Make SecurityMiddleware strict 8 years ago
Julien Veyssier 7da0812186 Do not throw AppNotEnabledException for app public pages - refs #6962, refs #5309 8 years ago
Morris Jobke cf35c4b03a
Provide translated error message for permission error 8 years ago
Morris Jobke d3d045dd5c
Remove unused import statements 8 years ago
Roeland Jago Douma c0adfa4375
Don't perform CSRF check on OCS routes with Bearer auth 8 years ago
Morris Jobke 2a38605545
Properly log the full exception instead of only the message 8 years ago
Roeland Jago Douma 57050146f6
Move passwordconfirmation to its own midleware 8 years ago
Bjoern Schiessle 1bcbeb24bc
disable password confirmation with SSO 8 years ago
Morris Jobke 0eebff152a
Update license headers 8 years ago
Morris Jobke ce0c45a4ea
Use proper DI for security middleware for app enabled check 8 years ago
Roeland Jago Douma c257cd57d4
Handle SameSiteCookie check for index.php in AppFramework Middleware 8 years ago
Lukas Reschke f93a82b8b0
Remove explicit type hints for Controller 9 years ago
Roeland Jago Douma 3548603a88
Fix middleware implementations signatures 9 years ago
Lukas Reschke f22ab3e665
Add metadata to \OCP\AppFramework\Http\Response::throttle 9 years ago
Joas Schilling 72c1b24844
Check whether the $_SERVER['REQUEST_*'] vars exist before using them 9 years ago
Morris Jobke c54a59d51e
Remove unused use statements 9 years ago
Lukas Reschke 8149945a91
Make BruteForceProtection annotation more clever 9 years ago
Lukas Reschke a1ae5275f9
Move to dedicated MiddleWare 9 years ago
Lukas Reschke 66835476b5
Add support for ratelimiting via annotations 9 years ago
Bjoern Schiessle 32e0ec3e58
handle optional annotation parameters 9 years ago
Bjoern Schiessle df296249d6
introduce brute force protection for api calls 9 years ago
Joas Schilling 61e15988a0
Allow to overwrite the message which we already do in SubadminMiddleware 9 years ago
Joas Schilling bb7787a157
Add the 15 seconds to the window, instead of removing 9 years ago
Joas Schilling 827b6a610e
Introduce PasswordConfirmRequired annotation 9 years ago
Christoph Wurst 0ebffa4a5f do not double encode the redirect url 9 years ago
Roeland Jago Douma e351ba56f1
Move browserSupportsCspV3 to CSPNonceManager 9 years ago
Lukas Reschke 9e6634814e
Add support for CSP nonces 9 years ago
Roeland Jago Douma 7c078a81b4
Add trict CSP to OCS responses 9 years ago
Roeland Jago Douma 5c718b13b8
We should properly check for 'true' instaed of the bool 10 years ago