summaryrefslogtreecommitdiffstats
path: root/lib/private/User/Session.php
Commit message (Expand)AuthorAgeFilesLines
* Fix failing csp/nonce check due to timed out sessionChristoph Wurst2017-09-041-5/+8
* Add basic implementation for OAuth 2.0 Authorization Code FlowLukas Reschke2017-05-181-2/+2
* Fix encryption + remembered login due to missing login hookChristoph Wurst2017-05-161-1/+7
* handle permissions errors when copying the skeleton for a read only userRobin Appelman2017-05-051-2/+7
* Improve PHPDocMorris Jobke2017-04-131-1/+1
* use known LockdownManagerArthur Schiwon2017-04-061-1/+1
* Save correct login nameArthur Schiwon2017-04-061-1/+8
* don't regenerate Session ID twice, also fixes testsArthur Schiwon2017-04-061-4/+7
* regenerate session id on successful login, fixes integration testArthur Schiwon2017-04-061-0/+4
* do login routine only once when done via LoginControllerArthur Schiwon2017-04-061-43/+40
* Save the scope of an auth token in the sessionRobin Appelman2017-04-051-18/+27
* Add postLogout hook to finish sessions from external session managers (#27048)Felix Rupp2017-03-191-0/+3
* Merge pull request #2606 from temparus/masterblizzz2017-02-151-3/+6
|\
| * Update license headerSandro Lutz2017-02-071-0/+2
| * Merge remote-tracking branch 'nextcloud/master'Sandro Lutz2017-02-071-3/+4
| |\
| * | Add check if UserManager is of type PublicEmitter before calling preLogin hookSandro Lutz2017-02-011-1/+3
| * | Change where preLogin hook gets calledSandro Lutz2017-02-011-3/+2
* | | Save the used token id in the session so it can be used later onJoas Schilling2017-02-091-2/+20
| |/ |/|
* | add action to existing brute force protectionBjoern Schiessle2017-01-181-3/+3
* | Make sure the loginname is set when logging in via cookieJoas Schilling2017-01-051-0/+1
|/
* Set last-login-check on basic authRoeland Jago Douma2016-12-051-0/+5
* do not remember session tokens by defaultChristoph Wurst2016-11-271-1/+1
* fix warning with token loginRobin Appelman2016-11-161-1/+1
* read lockdown scope from tokenRobin Appelman2016-11-161-2/+1
* basic lockdown logicRobin Appelman2016-11-161-0/+2
* Introduce an event for first time login based on the last login time stampThomas Müller2016-11-141-6/+19
* inject ISecureRandom into user session and use injected config tooChristoph Wurst2016-11-021-11/+18
* bring back remember-meChristoph Wurst2016-11-021-19/+51
* Fix logClientIn for non-existing users (#26292)Vincent Petry2016-10-251-0/+3
* dont update the auth token twiceRobin Appelman2016-10-111-2/+0
* dont get bruteforce delay twiceRobin Appelman2016-08-291-2/+1
* missing PHPDocJörn Friedrich Dreyer2016-08-141-0/+1
* Type compatabilityJörn Friedrich Dreyer2016-08-141-1/+1
* Unreachable statementJörn Friedrich Dreyer2016-08-141-4/+1
* Update with robinJoas Schilling2016-07-211-1/+1
* Fix othersJoas Schilling2016-07-211-1/+2
* Mitigate race conditionLukas Reschke2016-07-201-1/+4
* Implement brute force protectionLukas Reschke2016-07-201-5/+18
* Login hooks (#25260)Christoph Wurst2016-06-271-40/+61
* check login name when authenticating with client tokenChristoph Wurst2016-06-241-2/+11
* Merge pull request #25172 from owncloud/token-login-validationVincent Petry2016-06-221-67/+108
|\
| * fix unit test warning/errorsChristoph Wurst2016-06-201-11/+9
| * fix nitpickChristoph Wurst2016-06-201-2/+3
| * dont create a session token for clients, validate the app password insteadChristoph Wurst2016-06-171-8/+24
| * store last check timestamp in token instead of sessionChristoph Wurst2016-06-171-52/+92
| * use token last_activity instead of session valueChristoph Wurst2016-06-171-16/+2
* | update session token password on user password changeChristoph Wurst2016-06-211-0/+17
* | add PasswordLoginForbiddenExceptionChristoph Wurst2016-06-171-17/+20
|/
* create session token only for clients that support cookiesChristoph Wurst2016-06-131-2/+11
* create session token on all APIsChristoph Wurst2016-06-131-2/+7