Commit Graph

  • 1e05c41a0c Remove useless comment from first factor page Clement Michaud 2017-10-21 23:33:20 +0200
  • 42019bf67d Improve UX of the TOTP registration page Clement Michaud 2017-10-21 23:23:32 +0200
  • 7b68a543bf Strengthen password in LDAP using SHA512 crypt algorithm Clement Michaud 2017-10-20 00:42:33 +0200
  • 22d56b1faa Change basicauth.test.local into single_factor.test.local Clement Michaud 2017-10-19 22:33:10 +0200
  • 969561f4ad Add Content-Security-Policy in Authelia web pages Clement Michaud 2017-10-19 22:30:59 +0200
  • a3560ef8d3 Add possible security measures in README Clement Michaud 2017-10-19 21:51:22 +0200
  • 869d55dfd1 Add a meta tag to avoid search engine indexing Clement Michaud 2017-10-19 21:28:15 +0200
  • cd0a93f027 Rename authentication method from 'basic_auth' to 'single_factor' Clement Michaud 2017-10-19 00:33:02 +0200
  • 563e2da323 Add default_redirection_url as configuration option Clement Michaud 2017-10-17 23:24:02 +0200
  • 99b04809a5 Provide information about fake webmail in home page of example Clement Michaud 2017-10-18 00:48:57 +0200
  • 2b65680774 Remove TOTP secret from endpoint logs Clement Michaud 2017-10-17 23:09:17 +0200
  • dacdce6c50 Implement session inactivity timeout Clement Michaud 2017-10-17 00:38:10 +0200
  • b9fa786df6 Refactor endpoints to get server variables as input parameters Clement Michaud 2017-10-17 00:35:34 +0200
  • 34a595863a
    Merge pull request #181 from Chemsmith/add-email-handeler-2 Clément Michaud 2017-10-31 07:01:30 +0100
  • c62b85e37d Less restrictive email handler - replace gmail with generic Dylan Smith 2017-10-25 19:28:56 +1100
  • 8970b7c9e4 Fix npm package versions with package-lock.json Clement Michaud 2017-10-23 22:38:55 +0200
  • 4ba1cd4654 Merge pull request #172 from clems4ever/disable-notifiers Clément Michaud 2017-10-23 00:50:18 +0200
  • 64d8c4b3e5 Add shared/ directory in .npmignore Clement Michaud 2017-10-22 23:59:02 +0200
  • 430d998006 Disable notifiers when server uses single factor method only Clement Michaud 2017-10-22 17:42:05 +0200
  • 3cdae0927d Merge pull request #170 from clems4ever/ux-enhancement Clément Michaud 2017-10-22 13:37:29 +0200
  • 1b1b9554ec Improve UX of the second factor page Clement Michaud 2017-10-22 01:23:26 +0200
  • 1531179fe5 Remove useless comment from first factor page Clement Michaud 2017-10-21 23:33:20 +0200
  • 184175e4dd Improve UX of the TOTP registration page Clement Michaud 2017-10-21 23:23:32 +0200
  • 14e18d3cab Merge pull request #169 from clems4ever/password-security-enhancement Clément Michaud 2017-10-21 22:27:16 +0200
  • 35d9fff6ad Strengthen password in LDAP using SHA512 crypt algorithm Clement Michaud 2017-10-20 00:42:33 +0200
  • 3d2c95c060 Merge 462418e123 into 004a55ea2f Clément Michaud 2017-10-21 19:47:56 +0000
  • 462418e123 Strengthen password in LDAP using SHA512 crypt algorithm Clement Michaud 2017-10-20 00:42:33 +0200
  • 004a55ea2f Merge pull request #166 from clems4ever/no-search-engine-indexing Clément Michaud 2017-10-20 01:28:06 +0200
  • 472bcdad91 Change basicauth.test.local into single_factor.test.local Clement Michaud 2017-10-19 22:33:10 +0200
  • bfbbdec89d Add Content-Security-Policy in Authelia web pages Clement Michaud 2017-10-19 22:30:59 +0200
  • 6441a18b5b Add possible security measures in README Clement Michaud 2017-10-19 21:51:22 +0200
  • 1377eb15be Add a meta tag to avoid search engine indexing Clement Michaud 2017-10-19 21:28:15 +0200
  • b9b0973488 Merge pull request #165 from clems4ever/rename-basic-auth Clément Michaud 2017-10-19 21:21:14 +0200
  • 9d4153809b Rename authentication method from 'basic_auth' to 'single_factor' Clement Michaud 2017-10-19 00:33:02 +0200
  • c2dd244c9f Merge pull request #164 from clems4ever/default-redirection Clément Michaud 2017-10-19 01:03:57 +0200
  • 1a0b5009b5 Add default_redirection_url as configuration option Clement Michaud 2017-10-17 23:24:02 +0200
  • a1c9e802ff Merge pull request #163 from clems4ever/home-fake-mail Clément Michaud 2017-10-18 00:52:17 +0200
  • abc4335d2f Provide information about fake webmail in home page of example Clement Michaud 2017-10-18 00:48:57 +0200
  • 8def9bb1a9 Merge pull request #162 from clems4ever/remove-totp-secret-logs Clément Michaud 2017-10-18 00:45:41 +0200
  • 67096cfb9d Remove TOTP secret from endpoint logs Clement Michaud 2017-10-17 23:09:17 +0200
  • 5300f67217 Merge pull request #161 from clems4ever/inactivity_timeout Clément Michaud 2017-10-18 00:09:07 +0200
  • b842792a16 Implement session inactivity timeout Clement Michaud 2017-10-17 00:38:10 +0200
  • 9e275441c9 Refactor endpoints to get server variables as input parameters Clement Michaud 2017-10-17 00:35:34 +0200
  • 5570ac3d84 3.6.0 v3.6.0 Clement Michaud 2017-10-16 22:32:55 +0200
  • 19c846a366 Merge pull request #160 from clems4ever/develop Clément Michaud 2017-10-16 22:32:18 +0200
  • 39b3898908 Merge pull request #152 from clems4ever/cookie-theft Clément Michaud 2017-10-16 21:11:58 +0200
  • 056565a968 Add X-Frame-Options header to avoid ability to embed websites in iframes Clement Michaud 2017-10-15 18:03:18 +0200
  • 0b33982701 Add notes on security measures deployed in Authelia in README Clement Michaud 2017-10-15 17:57:12 +0200
  • f523e5335f Use HSTS in example Clement Michaud 2017-10-15 17:18:15 +0200
  • 92b78f7c15 Enable secure and httpOnly option for sessions Clement Michaud 2017-10-15 16:34:39 +0200
  • 6e3a9494ce Merge pull request #158 from clems4ever/anonymous-smtp Clément Michaud 2017-10-16 00:09:55 +0200
  • 35b934ecea Merge branch 'develop' into anonymous-smtp Clément Michaud 2017-10-15 23:25:47 +0200
  • 5bac2b75b0 Merge pull request #159 from clems4ever/publish-develop-to-docker Clément Michaud 2017-10-15 23:24:28 +0200
  • 565fc35f07 Merge branch 'develop' into anonymous-smtp Clément Michaud 2017-10-15 22:50:05 +0200
  • 15615b2741 Merge branch 'develop' into publish-develop-to-docker Clément Michaud 2017-10-15 22:49:58 +0200
  • 3236b97ffd Merge pull request #156 from clems4ever/remove-schema-from-source Clément Michaud 2017-10-15 22:49:23 +0200
  • e8e8c8f7da Publish 'develop' tag to dockerhub Clement Michaud 2017-10-15 22:48:56 +0200
  • d3a2251d4a Allow anonymous user in SMTP notifier Clement Michaud 2017-10-15 22:41:18 +0200
  • b6aca2619b Merge branch 'develop' into remove-schema-from-source Clément Michaud 2017-10-15 22:31:06 +0200
  • 329927b865 Merge pull request #157 from clems4ever/already-logged-username Clément Michaud 2017-10-15 22:30:55 +0200
  • e8a1e7c52c Remove configuration schema from source since it is generated Clement Michaud 2017-10-15 22:08:24 +0200
  • daee042368 Add username to the 'already logged in' page Clement Michaud 2017-10-15 22:15:54 +0200
  • 35b66ba630 Merge pull request #155 from clems4ever/block-logged-in-page Clément Michaud 2017-10-15 22:03:11 +0200
  • f2ae1cd044 Block 'already logged in' page to unauthenticated user Clement Michaud 2017-10-15 21:51:21 +0200
  • 8fa50482df Merge pull request #153 from clems4ever/opt-subdomain-methods Clément Michaud 2017-10-15 21:39:24 +0200
  • 12a8626ef7 Make per_subdomain_methods optional in configuration file Clement Michaud 2017-10-15 20:01:16 +0200
  • b3479c19da Merge pull request #149 from clems4ever/npm-package-fix Clément Michaud 2017-10-15 16:09:50 +0200
  • e599ac78ae Do not include client/ and server/ in npm package Clement Michaud 2017-10-15 15:52:34 +0200
  • 4b51ae30cc Merge pull request #147 from clems4ever/userdn-ldap-filter Clément Michaud 2017-10-15 15:02:46 +0200
  • ce264ff4d3 Add {dn} as an available matcher in LDAP groups filter Clement Michaud 2017-10-15 14:27:20 +0200
  • 15fa6286ad Merge pull request #143 from clems4ever/protect-ldap-injection Clément Michaud 2017-10-15 13:36:38 +0200
  • 2e087f12f4 Fix out of bound access in LDAP results array Clement Michaud 2017-10-15 02:05:15 +0200
  • 9fe202f227 Merge pull request #144 from clems4ever/test-forward-headers Clément Michaud 2017-10-15 01:55:31 +0200
  • 1dd0343860 Add input sanitizer to LDAP client to protect against LDAP injections Clement Michaud 2017-10-14 13:49:25 +0200
  • bf3e71d732 Fix unhandled rejections in unit tests Clement Michaud 2017-10-15 01:34:23 +0200
  • cb139997d2 Merge pull request #142 from clems4ever/test-forward-headers Clément Michaud 2017-10-15 01:13:57 +0200
  • 3a88ca95b8 Check TOTP token with window of 1 Clement Michaud 2017-10-14 15:23:00 +0200
  • c02d9b4a6e Display current URL when redirection step fails in integration tests Clement Michaud 2017-10-14 15:16:14 +0200
  • 8cf58d7b31 Add tests on headers forwarded to backend Clement Michaud 2017-10-14 15:04:43 +0200
  • f041b946d9 Merge pull request #140 from clems4ever/improve-endpoint-errors Clément Michaud 2017-10-14 12:22:24 +0200
  • 56fdc40290 Every public endpoints return 200 with harmonized error messages or 401 Clement Michaud 2017-10-10 23:03:30 +0200
  • 3bea8a290a Merge pull request #137 from clems4ever/mail-sender Clément Michaud 2017-10-10 23:08:55 +0200
  • ab8aaeda25 Add configuration schema validation before starting Authelia Clement Michaud 2017-10-10 21:59:20 +0200
  • 2a3fde5ee7 Add a schema validator to check user configuration Clement Michaud 2017-10-10 01:14:36 +0200
  • 1ab09b71d4 Specify the sender email in Gmail and Smtp notifier configuration Clement Michaud 2017-10-10 00:07:12 +0200
  • d5035b8704 Merge pull request #131 from clems4ever/disable-second-factor Clément Michaud 2017-10-09 23:27:36 +0200
  • 9624aa6311 Adapt authentication methods configuration to be backward compatible Clement Michaud 2017-10-09 23:13:57 +0200
  • bc8fe623df Use minified version of Authelia in npm package Clement Michaud 2017-10-09 01:57:32 +0200
  • 9559bff5de Remove artifacts of only_basic_auth query param Clement Michaud 2017-10-09 01:55:51 +0200
  • 2641fb1620 Merge pull request #130 from clems4ever/revert-filesystem-notifier Clément Michaud 2017-10-09 01:58:06 +0200
  • 46deb765bb 3.5.0 v3.5.0 Clement Michaud 2017-10-09 01:15:40 +0200
  • a0aab77449 Add a section dealing with basic auth in README Clement Michaud 2017-10-09 01:14:19 +0200
  • 9ddc0949b6 Add a way to logout at second factor stage Clement Michaud 2017-10-09 00:41:44 +0200
  • 1cf4e57bb1 Redirect user when he has already validated some factors Clement Michaud 2017-10-09 00:28:46 +0200
  • c061dbfda4 Customize the authentication method to be used by a sub-domain Clement Michaud 2017-10-07 18:37:08 +0200
  • e4274fbe1b Add a note about filesystem notifier option Clement Michaud 2017-10-08 22:58:56 +0200
  • 6940e15ffa Merge pull request #125 from clems4ever/improve-logs Clément Michaud 2017-10-08 22:49:50 +0200
  • 83348f49c2 Merge pull request #129 from clems4ever/dockerhub-deployment Clément Michaud 2017-10-08 22:49:41 +0200
  • 346c559141 Make file system an available notifier option for testing purpose Clement Michaud 2017-10-08 22:48:20 +0200
  • 78f6028c1b Improve logging format for clarity Clement Michaud 2017-10-08 00:46:57 +0200