aboutsummaryrefslogtreecommitdiffstats
path: root/tests/lib/AppFramework
Commit message (Expand)AuthorAgeFilesLines
* style: update codestyle for coding-standard 1.2.3Daniel Kesselberg2024-08-2510-118/+118
* perf: delay getting (sub)admin status for user in the security middleware unt...Robin Appelman2024-08-231-2/+15
* feat: Provide CSP nonce as `<meta>` elementFerdinand Thiessen2024-08-131-1/+0
* test: Adjust tests for CSP nonceFerdinand Thiessen2024-08-133-252/+253
* fix(files_sharing): show proper share not found error messageskjnldsv2024-08-061-2/+4
* fix(AppFramework): Allow requests with OCS-APIRequest header to pass CSRF checksprovokateurin2024-07-251-0/+20
* feat(security): Add public API to allow validating IP Ranges and checking for...Joas Schilling2024-07-191-2/+2
* feat(security): restrict admin actions to IP rangesBenjamin Gaussorgues2024-07-191-1/+5
* feat(Security): Warn about using annotations instead of attributesprovokateurin2024-07-182-12/+19
* feat(AppFramework): Add ExAppRequired attributeprovokateurin2024-07-012-1/+58
* refactor(Token): introduce scope constantsArthur Schiwon2024-06-051-1/+1
* fix(Session): avoid password confirmation on SSOArthur Schiwon2024-06-052-1/+63
* chore: Add SPDX headerAndy Scherzinger2024-05-1361-1016/+153
* fix: Fix tests following OC_App migrations to IAppManagerCôme Chilliet2024-04-222-7/+15
* fix: add check for app_api_system session flag to bypass rate limitFlorian Klinger2024-03-181-1/+5
* fix xml ocs response for serializable objectsKlaus2024-02-231-0/+39
* test(request): Add tests to strip the port when forwarding requestsJoas Schilling2024-02-131-288/+119
* Add timezone getter to ITimeFactoryAnna Larch2024-02-131-0/+17
* better testsMaxence Lange2024-02-011-129/+606
* fix lintMaxence Lange2024-01-311-18/+18
* adding testMaxence Lange2024-01-311-0/+214
* test(unit): fix RequestTestArthur Schiwon2024-01-271-3/+4
* fix(API): Use a distinct exception so apps can react to it and customize the ...Joas Schilling2023-11-281-1/+2
* enh(dispatcher): enforce psalm ranges in the http dispatcherArthur Schiwon2023-11-242-0/+68
* chore: apply changes from Nextcloud coding standards 1.1.1Joas Schilling2023-11-234-11/+11
* fix(CSP): Only add `strict-dynamic` when using noncesFerdinand Thiessen2023-11-172-59/+59
* fix!(ContentSecurityPolicy): Make `strict-dynamic` enabled by default on `scr...Ferdinand Thiessen2023-11-171-76/+73
* feat(ContentSecurityPolicy): Allow to set `strict-dynamic` on `script-src-ele...Ferdinand Thiessen2023-11-172-0/+73
* Reverse X-Forwarded-For list to read the correct proxy remote addressJoas Schilling2023-11-161-6/+32
* feat(dependencyinjection): Allow optional (nullable) servicesChristoph Wurst2023-11-031-0/+24
* Merge pull request #39852 from nextcloud/pragmaHeaderFerdinand Thiessen2023-10-181-2/+0
|\
| * Stop sending deprecated Pragma headerGit'Fellow2023-08-281-2/+0
* | techdebt(DI): Use public IThrottler interface which exists since Nextcloud 25Joas Schilling2023-08-283-10/+11
|/
* Allow "wasm-unsafe-eval" in CSPDaniel Calviño Sánchez2023-08-102-0/+14
* fix!: Remove legacy event dispatching Symfony's GenericEvent from AdditionalS...Joas Schilling2023-07-271-41/+0
* feat(request): Allow to match the client version with the IRequest::USER_AGEN...Joas Schilling2023-07-111-0/+57
* Add template types to responsesjld31032023-06-301-1/+4
* Allow stdClass in XML responsesjld31032023-06-131-1/+2
* chore(appframework)!: Drop \OCP\AppFramework\Http\EmptyContentSecurityPolicy:...Christoph Wurst2023-06-123-37/+3
* fix(middleware): Also abort the request when reaching max delay in afterContr...Joas Schilling2023-05-151-7/+7
* feat(security): Add PHP \Attribute for remaining security annotationsJoas Schilling2023-04-258-250/+801
* feat(ratelimit): Add Attributes support to rate limit middlewareJoas Schilling2023-04-241-103/+170
* Merge branch 'master' into enh/type-iconfig-getter-callsCôme Chilliet2023-04-201-8/+8
|\
| * feat(app-framework): Add native argument types for middlewareChristoph Wurst2023-04-181-8/+8
* | Adapt tests to config value typingCôme Chilliet2023-04-051-6/+6
|/
* Add a debug message when throttling without definingJoas Schilling2023-03-081-6/+33
* feat(middleware): Migrate BruteForceProtection annotation to PHP Attribute an...Joas Schilling2023-03-081-61/+168
* feat(appframework): ⌚ Make ITimeFactory extend \PSR\Clock\ClockInterfaceJoas Schilling2023-03-031-0/+49
* Merge pull request #36396 from nextcloud/fix/corsJulius Härtl2023-02-171-1/+35
|\
| * fix(CORS): CORS should only be bypassed on `PublicPage` if not logged in to p...Ferdinand Thiessen2023-02-161-1/+35