Commit Graph

98 Commits (ba94de2510b3858f10d60f0230a58b1252346372)

Author SHA1 Message Date
Vincent Petry 839ddaa354
feat: rename users to account or person 2 years ago
Joas Schilling aa5f037af7
chore: apply changes from Nextcloud coding standards 1.1.1 2 years ago
Alexander Piskun 0b8a3b578d fixed Drone test 2 years ago
Alexander Piskun f16c9f42c6 added CORS skip if session was created by AppAPI 2 years ago
Christoph Wurst e477bb7eaf
feat(appframework): Expose programmatic rate limiter 2 years ago
Joas Schilling 25309bcb45
techdebt(DI): Use public IThrottler interface which exists since Nextcloud 25 2 years ago
Joas Schilling 381c35080d
fix(middleware): Fix header injection for bruteforce middleware 2 years ago
Joas Schilling 2f06f2355d
feat: Add a header which signals that the request was throttled 2 years ago
jld3103 12f8543815
Rewrite OCS CSRF check to be readable 2 years ago
Joas Schilling 3a6bc7aba2
fix(middleware): Also abort the request when reaching max delay in afterController 3 years ago
Faraz Samapoor e7cc7653b8 Refactors "strpos" calls in lib/private to improve code readability. 3 years ago
Joas Schilling ecb8b55c5c
feat(security): Add PHP \Attribute for remaining security annotations 3 years ago
Joas Schilling 89c3c31402
feat(ratelimit): Add Attributes support to rate limit middleware 3 years ago
Christoph Wurst a06898a2d0 fix(security)!: Use consistent HTTP status for strict cookie checks 3 years ago
Joas Schilling 2b49861679
Add a debug message when throttling without defining 3 years ago
Joas Schilling e839eb9b5c
feat(middleware): Migrate BruteForceProtection annotation to PHP Attribute and allow multiple 3 years ago
Ferdinand Thiessen f655f83c84 fix(CORS): CORS should only be bypassed on `PublicPage` if not logged in to prevent CSRF attack vectors 3 years ago
Côme Chilliet f5c361cf44
composer run cs:fix 3 years ago
Jonas Rittershofer c8b7a233a5 Allow CSRF on CORS routes 3 years ago
Carl Schwan b70c6a128f Update core to PHP 7.4 standard 4 years ago
Vincent Petry 80388663af Add direct arg to login flow 4 years ago
Carl Schwan 6312c0df69
Check style update 4 years ago
Julius Härtl 61dd1d3d97
Pass username prefill through unauthenticated request redirects 4 years ago
Carl Schwan 6958d8005a
Add admin privilege delegation for admin settings 4 years ago
John Molakvoæ (skjnldsv) 215aef3cbd
Update php licenses 5 years ago
korelstar b38e8678e4 fix error when using CORS with no auth credentials 5 years ago
Joas Schilling 56ae87c281
Less ILogger 5 years ago
Joas Schilling 174f4dd043
Fix ratelimit template 5 years ago
Christoph Wurst d9015a8c94
Format code to a single space around binary operators 5 years ago
Christoph Wurst 2a054e6c04
Update the license headers for Nextcloud 20 5 years ago
Joas Schilling 35a8519591
Fix CS 5 years ago
Joas Schilling e66bc4a8a7
Send "429 Too Many Requests" in case of brute force protection 5 years ago
Holger Hees e70249e089
Update SecurityMiddleware.php 6 years ago
Christoph Wurst cb057829f7
Update license headers for 19 6 years ago
Christoph Wurst caff1023ea
Format control structures, classes, methods and function 6 years ago
Christoph Wurst afbd9c4e6e
Unify function spacing to PSR2 recommendation 6 years ago
Christoph Wurst 2fbad1ed72
Fix (array) indent style to always use one tab 6 years ago
Christoph Wurst 74936c49ea
Remove unused imports 6 years ago
Joas Schilling d445f9b9fe
Fix loaded controller check 6 years ago
Christoph Wurst 5bf3d1bb38
Update license headers 6 years ago
Roeland Jago Douma 68748d4f85
Some php-cs fixes 6 years ago
Daniel Kesselberg 9055f46351
Make phan happy ;) 6 years ago
Arthur Schiwon 0a1937208f
Fixes a 500 without userid 6 years ago
Joas Schilling 15f00f0126
Mark "Talk" active on /call/token URLs 6 years ago
Roeland Jago Douma b8c5008acf
Add feature policy header 7 years ago
Roeland Jago Douma 37a4282c7a
Split up security middleware 7 years ago
Christoph Wurst 22ae682823
Make it possible to show admin settings for sub admins 7 years ago
Roeland Jago Douma 60e5a5eca4
Do not do redirect handling when loggin out 7 years ago
Roeland Jago Douma 603b672a11
Update password confirmation middleware 7 years ago
Bjoern Schiessle 85d9f06cb8
add global site selector as user back-end which doesn't support password confirmation 7 years ago