Kenneth Skovhede
aee07c54e6
Change to using the custom webexception for unauthorized to avoid reporting on system exceptions
2024-09-03 09:26:39 +02:00
Kenneth Skovhede
f962bfc89b
Added constraint on the issue timestamp to limit the window where
...
token drift is considered acceptable
2024-09-02 11:40:26 +02:00
Kenneth Skovhede
bc9ed71ff8
Added support for drifts in JWT refresh tokens. This can happen if the user refreshes the browser during the login.
2024-08-31 11:22:10 +02:00
Kenneth Skovhede
c687b93738
Added additional name to list of always allowed
2024-08-20 11:44:31 +02:00
Kenneth Skovhede
2b55b3449d
Add custom hostname validation
...
This adds a manually implemented hostname check that is applied as an endpoint filter.
With the implemented filter, the validation rules are similar to those before Kestrel was introduced.
This fixes #5469
2024-08-19 14:07:48 +02:00
Kenneth Skovhede
2b61e30add
Clean up usings
2024-08-15 14:51:03 +02:00
Kenneth Skovhede
28c53ab9f6
Fixed error message reading update version.
...
This fixes #5434
2024-08-15 14:50:31 +02:00
Kenneth Skovhede
cf757c5efb
Merge remote-tracking branch 'origin/master' into feature/add-option-to-disable-captcha
2024-08-14 21:32:00 +02:00
Kenneth Skovhede
e980d7daee
This adds back the missing ProposedSchedule to the server state.
...
This handles the missing information part in #5436
2024-08-13 22:24:15 +02:00
Kenneth Skovhede
5c8af042e9
Merge remote-tracking branch 'origin/master' into feature/add-option-to-disable-captcha
2024-08-13 13:56:26 +02:00
Kenneth Skovhede
9ecb3a0f17
Added option to disable visual captcha from commandline.
...
This fixes #5098
2024-08-13 13:50:21 +02:00
Kenneth Skovhede
87e01e97d2
Added additional possible fonts for Captcha.
...
This fixes #5363
2024-08-13 12:41:57 +02:00
natan
27ce549e75
cleanup WebsocketAccessor.cs and StatusService.cs a bit.
...
Remove /serverstate endpoint
2024-07-12 17:59:21 +02:00
Kenneth Skovhede
6917030417
Treat all auth operation failures as Unauthorized - 401
2024-07-07 10:36:42 +02:00
Kenneth Skovhede
3f29642f6c
Implemented JWT tokens.
...
Added auth requirement on all endpoints.
Added SignIn-, Access- and Refresh-Tokens based on JWT.
Upgraded stored password to be based on PBKDF2.
Added default password assignment.
Updated logic to support auth-header and re-sign-in for tray-icon and web-ui.
2024-06-19 13:54:10 +02:00
Kenneth Skovhede
9f79025744
Removed HttpServer.
...
Re-implemented everything using ASP.NET.
Changed some requests to use JSON instead of FORM data.
Some work towards deleting the FIXMEGlobal instance.
Auth is missing, XSRF does not work correctly.
2024-06-07 15:56:43 +02:00
natan
6e16e1d9ed
fix multiple WS messages bug
2024-04-25 17:06:10 +02:00
natan
0fefb316eb
Selenium Tests
2024-04-22 10:15:56 +02:00
natan
d78b9f2c63
WIP
2024-04-03 10:40:29 +02:00
natan
5d53eddb32
WIP
2024-03-26 18:32:56 +01:00