Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Set secure user cookies and only for HTTP. | Florian Zschocke | 2016-12-10 | 1 | -0/+14 |
| | | | | | | | | | Mark the user authentication cookie to be only used for HTTP, making it inaccessible for JavaScript engines. If only HTTPS is used and no HTTP (i.e. also if HTTP is redirected to HTTPS) then mark the user cookie to be sent only over secure connections. | ||||
* | Merge pull request #990 from dbywalec/authenthication-of-federation-user | James Moger | 2016-01-16 | 1 | -0/+6 |
|\ | | | | | Fix authentication failure warning log messages for FEDERATION_USER | ||||
| * | Fix authentication failure warning log messages for FEDERATION_USER | Dariusz Bywalec | 2016-01-04 | 1 | -0/+6 |
| | | | | | | | | | | | | | | | | | | | | The AuthenticationManager did not encounter for FEDERATION_USER and would unnecessarily generate a lot of failure warning log messages, e.g: Failed login attempt for $gitblit, invalid credentials from XXX.XX.XX.XX A simple condition will prematurely return null bypassing the regular authentication path and immediately make the authentication be routed via FederationManager. | ||||
* | | Lower log level of servlet authenticate when request is already authenticated | Dariusz Bywalec | 2016-01-04 | 1 | -1/+1 |
|/ | | | | | | | | | When calling a servlet which has already been authenticated, the server would produce a lot of superfluous log entries, e.g: Called servlet authenticate when request is already authenticated. The log level for this log entry has been lowered down to DEBUG. | ||||
* | implement an HTTP header AuthenticationProvider | Joel Johnson | 2015-12-09 | 1 | -2/+20 |
| | |||||
* | Log update for Fail2Ban usage | Paul Martin | 2015-10-25 | 1 | -16/+20 |
| | | | | | + Adds standard logging for all authentication providers + Updates help page to use default GitBlit SSH port | ||||
* | prevent session fixation for external authentication | Joel Johnson | 2015-07-14 | 1 | -10/+25 |
| | | | | | + use request instead of session to flag authentication status and user, for external authentication types | ||||
* | Invalid kerberos patches, works now and with a test. | Fabrice Bacchella | 2015-05-26 | 1 | -0/+29 |
| | |||||
* | A patch that allows to extract a new user informations from the HTTP session | Fabrice Bacchella | 2015-05-15 | 1 | -0/+48 |
| | | | | if the webapp container can fill it. | ||||
* | Merge branch 'ticket/129' into develop | James Moger | 2014-09-30 | 1 | -16/+11 |
|\ | |||||
| * | Remove Wicket references from non-Wicket packages | James Moger | 2014-09-30 | 1 | -16/+11 |
| | | |||||
* | | Allow authentication providers to control user and team role changes | James Moger | 2014-09-26 | 1 | -0/+23 |
| | | |||||
* | | Merge branch 'ticket/187' into develop | James Moger | 2014-09-25 | 1 | -2/+35 |
|\| | |||||
| * | Restrict Gitblit cookie to the context path | James Moger | 2014-09-25 | 1 | -2/+35 |
| | | |||||
* | | Annotate managers with @Singleton | James Moger | 2014-07-03 | 1 | -1/+3 |
| | | |||||
* | | Use Guice annotations, not javax.inject annotations | James Moger | 2014-07-03 | 1 | -1/+1 |
| | | |||||
* | | Embrace @Inject for Managers, Servlets, and Filters | James Moger | 2014-07-03 | 1 | -0/+2 |
|/ | |||||
* | Handle ssh keys as objects, not strings, and improve the ls and rm key commands | James Moger | 2014-04-10 | 1 | -6/+6 |
| | | | | "gitblit keys ls" now defaults to showing an indexed list of fingerprints which almost matches the output of "sshadd -l". The indexes are useful specifying key(s) to remove using "gitblit keys rm <index>". This is an important improvement for key management. | ||||
* | Revise SSH public key integration with AuthenticationManager | James Moger | 2014-04-10 | 1 | -11/+14 |
| | |||||
* | Establish ssh keys folder, support multiple keys, revise key authenticator | James Moger | 2014-04-10 | 1 | -1/+1 |
| | |||||
* | SSHD: Add support for git pack commands | David Ostrovsky | 2014-04-10 | 1 | -0/+29 |
| | | | | | | | | | | | Add git-upload-pack and git-receive-pack commands. Conflicts: src/main/java/com/gitblit/manager/ServicesManager.java src/main/java/com/gitblit/transport/ssh/CommandDispatcher.java src/main/java/com/gitblit/transport/ssh/SshCommandFactory.java Change-Id: I8c057b41f1dfad6d004e6aa91f96c8c673be9be2 | ||||
* | Fix authentication security hole with external providers | James Moger | 2014-03-18 | 1 | -29/+44 |
| | |||||
* | Implement user "disabled" flag as an alternative to deleting the account | James Moger | 2014-03-04 | 1 | -8/+29 |
| | |||||
* | API adjustments and elimination of duplicate config options | James Moger | 2014-02-19 | 1 | -0/+7 |
| | |||||
* | issue-361: Reset user cookie after administrative password change | James Moger | 2014-01-28 | 1 | -26/+35 |
| | | | | | | | Cookies were not reset on administrative password change of a user account. This allowed accounts with changed passwords to continue authenticating. Cookies are now reset on password changes, they are validated on each page request, AND they will now expire 7 days after generation. | ||||
* | Fix external authentication failure | James Moger | 2013-12-11 | 1 | -2/+3 |
| | | | | Change-Id: I0f415941a4bfd5e63d85c60613cea0c7d10cbb49 | ||||
* | Added filesystem write permission check (issue-345) | James Moger | 2013-11-29 | 1 | -2/+2 |
| | | | | Change-Id: I0a3aced3b8e9887347888c85e469b74fc70931ad | ||||
* | Refactor managers and authentication for federation | James Moger | 2013-11-29 | 1 | -29/+1 |
| | | | | Change-Id: I5ff18b2768095fb14e7fbece2e756115829abbde | ||||
* | Refactor user services and separate authentication (issue-281) | James Moger | 2013-11-29 | 1 | -0/+511 |
Change-Id: I336e005e02623fc5e11a4f8b4408bea5465a43fd |