Commit Graph

21 Commits (311531ecce497663960877fc536ba94deff27bc0)

Author SHA1 Message Date
Joas Schilling 2cd92d0abb
Fix missing update of session, when it was already used. 9 years ago
Leon Klingele e5d78a3523
Fix CSRF token generation / validation 9 years ago
Joas Schilling c20ab0049f
Identify Chromium as Chrome 9 years ago
Lukas Reschke 015affb082
Missing returns + autoloader file 9 years ago
Roeland Jago Douma e351ba56f1
Move browserSupportsCspV3 to CSPNonceManager 9 years ago
Lukas Reschke 38b3ac8213
Add ContentSecurityPolicyNonceManager 9 years ago
Lukas Reschke 9e6634814e
Add support for CSP nonces 9 years ago
Robin Appelman 6c93fe08f5 dont get bruteforce delay twice 10 years ago
Joas Schilling 0215b004da
Update with robin 10 years ago
Joas Schilling ba87db3fcc
Fix others 10 years ago
Lukas Reschke adf67fac96
JSON encode the values 10 years ago
Lukas Reschke ba4f12baa0
Implement brute force protection 10 years ago
Bjoern Schiessle 7c64e1973f
add test for needsRebundling() check 10 years ago
Bjoern Schiessle 49cad153af
always check the mtime of the system bundle and additionally the user specific certificate bundle if a user is given 10 years ago
Johannes Ernst 66a134e69e Disallow certain malformed domain names even if they match the trusted domain expression 10 years ago
Johannes Ernst 2b4ceae620 Trusted domain wildcard checking made shorter, supporting multiple * 10 years ago
Johannes Ernst 3516b58be6 Duh, no 'next' in PHP. 10 years ago
Johannes Ernst b1867dc8d1 Allow wildcard * to be used in trusted domains, to support setups where no reliable DNS entry is available (e.g. mDNS) or for simple-to-setup aliasing (e.g. *.example.com) 10 years ago
Lukas Reschke aba539703c
Update license headers 10 years ago
Lukas Reschke 06a4da43ec
[master] Ignore certificate file if it starts with file:// 10 years ago
Roeland Jago Douma 9050e76d95
Move \OC\Security to PSR-4 10 years ago