Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | fix(BaseResponse): Cast XML element values to stringbackport/48013/stable28 | provokateurin | 2024-09-15 | 1 | -1/+3 |
| | | | | Signed-off-by: provokateurin <kate@provokateurin.de> | ||||
* | fix(Token): make new scope future compatible | Arthur Schiwon | 2024-06-12 | 1 | -1/+1 |
| | | | | | | | - "password-unconfirmable" is the effective name for 30, but a draft name was backported. Signed-off-by: Arthur Schiwon <blizzz@arthur-schiwon.de> | ||||
* | fix(Session): avoid password confirmation on SSO | Arthur Schiwon | 2024-06-12 | 2 | -3/+26 |
| | | | | | | | | | | | SSO backends like SAML and OIDC tried a trick to suppress password confirmations as they are not possible by design. At least for SAML it was not reliable when existing user backends where used as user repositories. Now we are setting a special scope with the token, and also make sure that the scope is taken over when tokens are regenerated. Signed-off-by: Arthur Schiwon <blizzz@arthur-schiwon.de> | ||||
* | fix: add check for app_api_system session flag to bypass rate limit | Florian Klinger | 2024-04-17 | 2 | -1/+9 |
| | | | | | Signed-off-by: Florian Klinger <florian.klinger@nextcloud.com> Signed-off-by: Andrey Borysenko <andrey18106x@gmail.com> | ||||
* | fix xml ocs response for serializable objects | Klaus | 2024-03-18 | 1 | -0/+4 |
| | | | | | Signed-off-by: sualko <klaus@jsxc.org> Signed-off-by: skjnldsv <skjnldsv@protonmail.com> | ||||
* | fix: Adjust user agent pattern for Edge | Julius Härtl | 2024-03-11 | 1 | -1/+1 |
| | | | | Signed-off-by: Julius Härtl <jus@bitgrid.net> | ||||
* | Merge pull request #43181 from nextcloud/backport/42930/stable28 | Ferdinand Thiessen | 2024-02-03 | 1 | -5/+3 |
|\ | | | | | [stable28] Fix: config param 'overwritecondaddr' not working | ||||
| * | code style: ommited space, reverted [code review] | Pavel Kryl | 2024-01-29 | 1 | -1/+1 |
| | | |||||
| * | fixing bug #6914: Config Param 'overwritecondaddr' not working | Pavel Kryl | 2024-01-29 | 1 | -6/+4 |
| | | | | | | | | | | | | | | - just ignoring/removing extra parameter 'protocol' as suggested by blizzz Signed-off-by: Pavel Kryl <pavel@kryl.eu> | ||||
* | | fix(Request): Catch exceptions in `isTrustedProxy` | Ferdinand Thiessen | 2024-01-29 | 1 | -1/+8 |
|/ | | | | | | | | | The function fails if the configured trusted proxies contain invalid characters and the underlying IpUtils will throw. But as it is used by `getRemoteAddress` which is used by logging / templating, thrown errors are not reported but silently fail with error 500. Co-authored-by: Ferdinand Thiessen <opensource@fthiessen.de> Co-authored-by: Joas Schilling <213943+nickvergessen@users.noreply.github.com> Signed-off-by: Ferdinand Thiessen <opensource@fthiessen.de> | ||||
* | chore: apply changes from Nextcloud coding standards 1.1.1 | Joas Schilling | 2023-11-23 | 20 | -71/+71 |
| | | | | | Signed-off-by: Joas Schilling <coding@schilljs.com> Signed-off-by: Benjamin Gaussorgues <benjamin.gaussorgues@nextcloud.com> | ||||
* | Reverse X-Forwarded-For list to read the correct proxy remote address | Joas Schilling | 2023-11-16 | 1 | -2/+8 |
| | | | | Signed-off-by: Joas Schilling <coding@schilljs.com> | ||||
* | feat(dependencyinjection): Allow optional (nullable) services | Christoph Wurst | 2023-11-03 | 1 | -0/+5 |
| | | | | | | Allows working with classes that might or might not be available. Signed-off-by: Christoph Wurst <christoph@winzerhof-wurst.at> | ||||
* | Merge pull request #40326 from nextcloud/enh/text-to-image-api | Joas Schilling | 2023-10-26 | 1 | -0/+24 |
|\ | | | | | Implement TextToImage OCP API | ||||
| * | Implement TextToImage OCP API | Marcel Klehr | 2023-10-18 | 1 | -0/+24 |
| | | | | | | | | Signed-off-by: Marcel Klehr <mklehr@gmx.net> | ||||
* | | Add api to register setup checks | Carl Schwan | 2023-10-19 | 1 | -3/+27 |
|/ | | | | Signed-off-by: Carl Schwan <carl@carlschwan.eu> | ||||
* | Merge pull request #40865 from nextcloud/bugfix/noid/fix-version-comment | Joas Schilling | 2023-10-16 | 1 | -1/+1 |
|\ | | | | | Fix version number in ITimeFactory after it was delayed | ||||
| * | Fix version number in ITimeFactory after it was delayed | Joas Schilling | 2023-10-11 | 1 | -1/+1 |
| | | | | | | | | Signed-off-by: Joas Schilling <coding@schilljs.com> | ||||
* | | fix(docs): Fix parameter types in docs | Joas Schilling | 2023-10-13 | 1 | -8/+2 |
|/ | | | | Signed-off-by: Joas Schilling <coding@schilljs.com> | ||||
* | fixed Drone test | Alexander Piskun | 2023-10-06 | 1 | -1/+2 |
| | | | | Signed-off-by: Alexander Piskun <bigcat88@icloud.com> | ||||
* | added CORS skip if session was created by AppAPI | Alexander Piskun | 2023-10-02 | 1 | -0/+4 |
| | | | | Signed-off-by: Alexander Piskun <bigcat88@icloud.com> | ||||
* | Convert isset ternary to null coalescing operator | Hamid Dehnavi | 2023-09-28 | 1 | -6/+2 |
| | | | | Signed-off-by: Hamid Dehnavi <hamid.dev.pro@gmail.com> | ||||
* | Remove deprecated methods Util::writeLog and DIContainer::log | Côme Chilliet | 2023-09-25 | 1 | -27/+0 |
| | | | | Signed-off-by: Côme Chilliet <come.chilliet@nextcloud.com> | ||||
* | feat(appframework): Expose programmatic rate limiter | Christoph Wurst | 2023-09-20 | 1 | -0/+3 |
| | | | | Signed-off-by: Christoph Wurst <christoph@winzerhof-wurst.at> | ||||
* | techdebt(DI): Use public IThrottler interface which exists since Nextcloud 25 | Joas Schilling | 2023-08-28 | 4 | -17/+12 |
| | | | | Signed-off-by: Joas Schilling <coding@schilljs.com> | ||||
* | fix(middleware): Fix header injection for bruteforce middleware | Joas Schilling | 2023-08-22 | 1 | -5/+1 |
| | | | | | | | Calling setHeaders(getHeaders()) breaks the CSP nonce for unknown reasons So shifting back to old standard practise for now Signed-off-by: Joas Schilling <coding@schilljs.com> | ||||
* | feat: Add a header which signals that the request was throttled | Joas Schilling | 2023-08-21 | 1 | -4/+14 |
| | | | | Signed-off-by: Joas Schilling <coding@schilljs.com> | ||||
* | add separate event for rendering login page template | Robin Appelman | 2023-08-17 | 1 | -2/+8 |
| | | | | Signed-off-by: Robin Appelman <robin@icewind.nl> | ||||
* | Rewrite OCS CSRF check to be readable | jld3103 | 2023-08-16 | 1 | -7/+15 |
| | | | | Signed-off-by: jld3103 <jld3103yt@gmail.com> | ||||
* | fix!: Remove legacy event dispatching Symfony's GenericEvent from ↵ | Joas Schilling | 2023-07-27 | 1 | -30/+5 |
| | | | | | | AdditionalScripts Signed-off-by: Joas Schilling <coding@schilljs.com> | ||||
* | Merge pull request #38854 from nextcloud/enh/llm-api | Marcel Klehr | 2023-07-21 | 1 | -0/+21 |
|\ | |||||
| * | Massive refactoring: Turn LanguageModel OCP API into TextProcessing API | Marcel Klehr | 2023-07-14 | 1 | -10/+10 |
| | | | | | | | | Signed-off-by: Marcel Klehr <mklehr@gmx.net> | ||||
| * | LLM OCP API: Add to RegistrationContext | Marcel Klehr | 2023-07-07 | 1 | -0/+21 |
| | | | | | | | | Signed-off-by: Marcel Klehr <mklehr@gmx.net> | ||||
* | | fix(CardDAV): catch right exception when checking for federated app classes | Anna Larch | 2023-07-06 | 1 | -1/+0 |
|/ | | | | Signed-off-by: Anna Larch <anna@nextcloud.com> | ||||
* | Add template types to responses | jld3103 | 2023-06-30 | 3 | -1/+27 |
| | | | | Signed-off-by: jld3103 <jld3103yt@gmail.com> | ||||
* | Allow stdClass in XML responses | jld3103 | 2023-06-13 | 1 | -0/+4 |
| | | | | Signed-off-by: jld3103 <jld3103yt@gmail.com> | ||||
* | Merge pull request #38261 from fsamapoor/replace_strpos_calls_in_lib_private | Robin Appelman | 2023-06-01 | 6 | -17/+17 |
|\ | | | | | Refactors "strpos" calls in lib/private to improve code readability. | ||||
| * | Refactors "strpos" calls in lib/private to improve code readability. | Faraz Samapoor | 2023-05-15 | 6 | -17/+17 |
| | | | | | | | | Signed-off-by: Faraz Samapoor <fsamapoor@gmail.com> | ||||
* | | chore: Drop \OC_App::getAppInfo | Christoph Wurst | 2023-06-01 | 1 | -1/+2 |
| | | | | | | | | Signed-off-by: Christoph Wurst <christoph@winzerhof-wurst.at> | ||||
* | | fix(middleware): Also abort the request when reaching max delay in ↵ | Joas Schilling | 2023-05-15 | 1 | -22/+30 |
|/ | | | | | | afterController Signed-off-by: Joas Schilling <coding@schilljs.com> | ||||
* | feat(security): Add PHP \Attribute for remaining security annotations | Joas Schilling | 2023-04-25 | 4 | -27/+132 |
| | | | | Signed-off-by: Joas Schilling <coding@schilljs.com> | ||||
* | feat(ratelimit): Add Attributes support to rate limit middleware | Joas Schilling | 2023-04-24 | 1 | -41/+77 |
| | | | | Signed-off-by: Joas Schilling <coding@schilljs.com> | ||||
* | Merge branch 'master' into enh/type-iconfig-getter-calls | Côme Chilliet | 2023-04-20 | 2 | -0/+25 |
|\ | | | | | Signed-off-by: Côme Chilliet <91878298+come-nc@users.noreply.github.com> | ||||
| * | Merge pull request #37674 from nextcloud/feature/speech-to-text | Joas Schilling | 2023-04-19 | 1 | -0/+22 |
| |\ | | | | | | | feat(SpeechToText): Add SpeechToText OCP provider API | ||||
| | * | feat(SpeechToText): Add SpeechToText provider API | Marcel Klehr | 2023-04-11 | 1 | -0/+22 |
| | | | | | | | | | | | | Signed-off-by: Marcel Klehr <mklehr@gmx.net> | ||||
| * | | fix(security)!: Use consistent HTTP status for strict cookie checks | Christoph Wurst | 2023-04-17 | 1 | -0/+3 |
| |/ | | | | | | | | | | | | | Before: 503/412 Now: 412 + json body explaining the error Signed-off-by: Christoph Wurst <christoph@winzerhof-wurst.at> | ||||
* / | Use typed version of IConfig::getSystemValue as much as possible | Côme Chilliet | 2023-04-05 | 1 | -7/+7 |
|/ | | | | Signed-off-by: Côme Chilliet <come.chilliet@nextcloud.com> | ||||
* | Add a debug message when throttling without defining | Joas Schilling | 2023-03-08 | 2 | -11/+11 |
| | | | | Signed-off-by: Joas Schilling <coding@schilljs.com> | ||||
* | feat(middleware): Migrate BruteForceProtection annotation to PHP Attribute ↵ | Joas Schilling | 2023-03-08 | 1 | -5/+43 |
| | | | | | | and allow multiple Signed-off-by: Joas Schilling <coding@schilljs.com> | ||||
* | feat(appframework): ⌚ Make ITimeFactory extend \PSR\Clock\ClockInterface | Joas Schilling | 2023-03-03 | 1 | -1/+25 |
| | | | | Signed-off-by: Joas Schilling <coding@schilljs.com> |