Commit Graph

33 Commits (311531ecce497663960877fc536ba94deff27bc0)

Author SHA1 Message Date
Lukas Reschke 9d6e01ef40
Add missing tests and fix PHPDoc 9 years ago
Christoph Wurst 6f86e468d4
inject ISecureRandom into user session and use injected config too 9 years ago
Christoph Wurst d907666232
bring back remember-me 9 years ago
Roeland Jago Douma f722640a32
Proper DI of config 9 years ago
Jörn Friedrich Dreyer f8352fcb8d
introduce callForSeenUsers and countSeenUsers (#26361) 9 years ago
Roeland Jago Douma 593d52fe91
Fix and cleanup SessionTest 9 years ago
Vincent Petry 6d1e858aa4
Fix logClientIn for non-existing users (#26292) 9 years ago
Robin Appelman 90db361827
Add test to ensure token times are updated 9 years ago
Robin Appelman 25ed6714c7
dont update the auth token twice 9 years ago
Joas Schilling 4d1acfd4ef
Only trigger postDelete hooks when the user was deleted... 9 years ago
Joas Schilling f6ff60f4cb
Make sure that comments, notifications and preferences are deleted 9 years ago
Roeland Jago Douma d616984879
Fix getMock User 9 years ago
Robin Appelman 6c93fe08f5 dont get bruteforce delay twice 9 years ago
Lukas Reschke c1589f163c
Mitigate race condition 10 years ago
Lukas Reschke ba4f12baa0
Implement brute force protection 10 years ago
Roeland Jago Douma f2d091a963
Fix failing tests after db split 10 years ago
Christoph Wurst 1710de8afb Login hooks (#25260) 10 years ago
Bjoern Schiessle 2a990a0db5
verify user password on change 10 years ago
Christoph Wurst 89198e62e8 check login name when authenticating with client token 10 years ago
Christoph Wurst b805908dca
update session token password on user password change 10 years ago
Christoph Wurst 56199eba37
fix unit test warning/errors 10 years ago
Christoph Wurst 8ef5431e7a
fix user session tests 10 years ago
Christoph Wurst 82b50d126c
add PasswordLoginForbiddenException 10 years ago
Christoph Wurst 465807490d
create session token only for clients that support cookies 10 years ago
Christoph Wurst ec929f07f2
When creating a session token, make sure it's the login password and not a device token 10 years ago
Christoph Wurst c58d8159d7
Create session tokens for apache auth users 10 years ago
Christoph Wurst 28ce7dd262
do not allow client password logins if token auth is enforced or 2FA is enabled 10 years ago
Christoph Wurst ad10485cec
when generating browser/device token, save the login name for later password checks 10 years ago
Christoph Wurst c20cdc2213
invalidate user session if the user is disabled 10 years ago
Joas Schilling 94ad54ec9b Move tests/ to PSR-4 (#24731) 10 years ago