Commit Graph

61 Commits (311531ecce497663960877fc536ba94deff27bc0)

Author SHA1 Message Date
Robin Appelman 2389e0f250
read lockdown scope from token 9 years ago
Robin Appelman b56f2c9ed0
basic lockdown logic 9 years ago
Thomas Müller 506ccdbd8d
Introduce an event for first time login based on the last login time stamp 9 years ago
Christoph Wurst 6f86e468d4
inject ISecureRandom into user session and use injected config too 9 years ago
Christoph Wurst d907666232
bring back remember-me 9 years ago
Vincent Petry 6d1e858aa4
Fix logClientIn for non-existing users (#26292) 9 years ago
Robin Appelman 25ed6714c7
dont update the auth token twice 9 years ago
Robin Appelman 6c93fe08f5 dont get bruteforce delay twice 9 years ago
Jörn Friedrich Dreyer 291b3fd8b4
missing PHPDoc 10 years ago
Jörn Friedrich Dreyer da5633c31a
Type compatability 10 years ago
Jörn Friedrich Dreyer 5aef60d2ca
Unreachable statement 10 years ago
Joas Schilling 0215b004da
Update with robin 10 years ago
Joas Schilling ba87db3fcc
Fix others 10 years ago
Lukas Reschke c1589f163c
Mitigate race condition 10 years ago
Lukas Reschke ba4f12baa0
Implement brute force protection 10 years ago
Christoph Wurst 1710de8afb Login hooks (#25260) 10 years ago
Christoph Wurst 89198e62e8 check login name when authenticating with client token 10 years ago
Christoph Wurst b805908dca
update session token password on user password change 10 years ago
Christoph Wurst 56199eba37
fix unit test warning/errors 10 years ago
Christoph Wurst 9d74ff02a4
fix nitpick 10 years ago
Christoph Wurst 1889df5c7c
dont create a session token for clients, validate the app password instead 10 years ago
Christoph Wurst 0c0a216f42
store last check timestamp in token instead of session 10 years ago
Christoph Wurst c4149c59c2
use token last_activity instead of session value 10 years ago
Christoph Wurst 82b50d126c
add PasswordLoginForbiddenException 10 years ago
Christoph Wurst 465807490d
create session token only for clients that support cookies 10 years ago
Christoph Wurst 331d88bcab
create session token on all APIs 10 years ago
Thomas Müller f20c617154
Allow login by email address via webdav as well - fixes #24791 10 years ago
Christoph Wurst 46e26f6b49
catch sessionnotavailable exception if memory session is used 10 years ago
Christoph Wurst ec929f07f2
When creating a session token, make sure it's the login password and not a device token 10 years ago
Christoph Wurst c58d8159d7
Create session tokens for apache auth users 10 years ago
Lukas Reschke aba539703c
Update license headers 10 years ago
Christoph Wurst a922957f76
add default token auth config on install, upgrade and add it to sample config 10 years ago
Christoph Wurst 28ce7dd262
do not allow client password logins if token auth is enforced or 2FA is enabled 10 years ago
Christoph Wurst ad10485cec
when generating browser/device token, save the login name for later password checks 10 years ago
Christoph Wurst 4128b853e5
login explicitly 10 years ago
Christoph Wurst dfb4d426c2
Add two factor auth to core 10 years ago
Christoph Wurst c20cdc2213
invalidate user session if the user is disabled 10 years ago
Christoph Wurst 11dc97da43
try token login first 10 years ago
Christoph Wurst f824f3e5f3
don't allow token login for disabled users 10 years ago
Christoph Wurst 98b465a8b9
a single token provider suffices 10 years ago
Christoph Wurst 0486d750aa
use the UID for creating the session token, not the login name 10 years ago
Christoph Wurst 69dafd727d
delete the token in case an exception is thrown when decrypting the password 10 years ago
Christoph Wurst 46bdf6ea2b
fix PHPDoc and other minor issues 10 years ago
Christoph Wurst a9b500c03b
catch possible SessionNotAvailableExceptions 10 years ago
Christoph Wurst f0f8bdd495
PHPDoc and other minor fixes 10 years ago
Christoph Wurst 699289cd26
pass in $request on OCS api 10 years ago
Christoph Wurst 168ccf90a6
try apache auth too 10 years ago
Christoph Wurst 8cc5f6036f
Fix existing tests 10 years ago
Christoph Wurst 7aa16e1559
fix setup 10 years ago
Christoph Wurst 7e7d5a2ef2
Add fallback to allow user:token basic auth 10 years ago