Commit Graph
20 Commits
Author SHA1 Message Date
Kenneth Skovhede aee07c54e6 Change to using the custom webexception for unauthorized to avoid reporting on system exceptions 2024-09-03 09:26:39 +02:00
Kenneth Skovhede f962bfc89b Added constraint on the issue timestamp to limit the window where
token drift is considered acceptable
2024-09-02 11:40:26 +02:00
Kenneth Skovhede bc9ed71ff8 Added support for drifts in JWT refresh tokens. This can happen if the user refreshes the browser during the login. 2024-08-31 11:22:10 +02:00
Kenneth Skovhede c687b93738 Added additional name to list of always allowed 2024-08-20 11:44:31 +02:00
Kenneth Skovhede 2b55b3449d Add custom hostname validation
This adds a manually implemented hostname check that is applied as an endpoint filter.
With the implemented filter, the validation rules are similar to those before Kestrel was introduced.
This fixes #5469
2024-08-19 14:07:48 +02:00
Kenneth Skovhede 2b61e30add Clean up usings 2024-08-15 14:51:03 +02:00
Kenneth Skovhede 28c53ab9f6 Fixed error message reading update version.
This fixes #5434
2024-08-15 14:50:31 +02:00
Kenneth Skovhede cf757c5efb Merge remote-tracking branch 'origin/master' into feature/add-option-to-disable-captcha 2024-08-14 21:32:00 +02:00
Kenneth Skovhede e980d7daee This adds back the missing ProposedSchedule to the server state.
This handles the missing information part in #5436
2024-08-13 22:24:15 +02:00
Kenneth Skovhede 5c8af042e9 Merge remote-tracking branch 'origin/master' into feature/add-option-to-disable-captcha 2024-08-13 13:56:26 +02:00
Kenneth Skovhede 9ecb3a0f17 Added option to disable visual captcha from commandline.
This fixes #5098
2024-08-13 13:50:21 +02:00
Kenneth Skovhede 87e01e97d2 Added additional possible fonts for Captcha.
This fixes #5363
2024-08-13 12:41:57 +02:00
natan 27ce549e75 cleanup WebsocketAccessor.cs and StatusService.cs a bit.
Remove /serverstate endpoint
2024-07-12 17:59:21 +02:00
Kenneth Skovhede 6917030417 Treat all auth operation failures as Unauthorized - 401 2024-07-07 10:36:42 +02:00
Kenneth Skovhede 3f29642f6c Implemented JWT tokens.
Added auth requirement on all endpoints.
Added SignIn-, Access- and Refresh-Tokens based on JWT.
Upgraded stored password to be based on PBKDF2.
Added default password assignment.
Updated logic to support auth-header and re-sign-in for tray-icon and web-ui.
2024-06-19 13:54:10 +02:00
Kenneth Skovhede 9f79025744 Removed HttpServer.
Re-implemented everything using ASP.NET.
Changed some requests to use JSON instead of FORM data.
Some work towards deleting the FIXMEGlobal instance.
Auth is missing, XSRF does not work correctly.
2024-06-07 15:56:43 +02:00
natan 6e16e1d9ed fix multiple WS messages bug 2024-04-25 17:06:10 +02:00
natan 0fefb316eb Selenium Tests 2024-04-22 10:15:56 +02:00
natan d78b9f2c63 WIP 2024-04-03 10:40:29 +02:00
natan 5d53eddb32 WIP 2024-03-26 18:32:56 +01:00