| #
3df1d4a6
|
| 27-Sep-2014 |
Andreas Gohr <andi@splitbrain.org> |
Merge pull request #868 from splitbrain/authclean
clean user credentials from control chars
|
| #
7b950f2d
|
| 26-Sep-2014 |
Andreas Gohr <andi@splitbrain.org> |
Merge remote-tracking branch 'origin/auth_getUserData_improvements'
* origin/auth_getUserData_improvements: KISS - remove class constants for REQUIRE_GROUPS & IGNORE_GROUPS and replace with boolea
Merge remote-tracking branch 'origin/auth_getUserData_improvements'
* origin/auth_getUserData_improvements: KISS - remove class constants for REQUIRE_GROUPS & IGNORE_GROUPS and replace with boolean values use $requireGroups constants in auth classes; comments; code improvements fix comment errors, sp. & grammar code styling - add missing braces Allow user info to be retrieved without groups Restore correct public interface of getUserData() for authldap plugin
Conflicts: inc/common.php
show more ...
|
| #
5e9e1054
|
| 26-Sep-2014 |
Andreas Gohr <andi@splitbrain.org> |
do not allow empty passwords
When a username but no password is submitted, the login is denied right away instead of relying on the backend to refuse the login.
|
| #
395c2f0f
|
| 23-Sep-2014 |
Andreas Gohr <andi@splitbrain.org> |
clean user credentials from control chars
This is to prevent zero byte attacks on external auth systems as described in http://www.freelists.org/post/dokuwiki/Fwd-Dokuwiki-maybe-security-issue-Null-
clean user credentials from control chars
This is to prevent zero byte attacks on external auth systems as described in http://www.freelists.org/post/dokuwiki/Fwd-Dokuwiki-maybe-security-issue-Null-byte-poisoning-in-LDAP-authentication
show more ...
|
| #
e5204a12
|
| 30-Jul-2014 |
Jurgen Hart <jhart@winterfell.schenkerit.com> |
Added @ALL handeling in auth_isMember
|
| #
49cd1ed0
|
| 26-Jul-2014 |
Andreas Gohr <andi@splitbrain.org> |
fix AUTH_USER_CHANGE event in profile updates
the triggered event did not allow event handlers to change the passed data
|
| #
2dc9e900
|
| 04-May-2014 |
Christopher Smith <chris@jalakai.co.uk> |
KISS - remove class constants for REQUIRE_GROUPS & IGNORE_GROUPS and replace with boolean values
|
| #
2046a654
|
| 12-Mar-2014 |
Christopher Smith <chris@jalakai.co.uk> |
Allow user info to be retrieved without groups
Some parts of dokuwiki (e.g. recent changes, old revisions) can requests lots of user info (to provide editor names) without requiring any group inform
Allow user info to be retrieved without groups
Some parts of dokuwiki (e.g. recent changes, old revisions) can requests lots of user info (to provide editor names) without requiring any group information.
This change also implements caching of user info by authmysql & authpgsql plugins to avoid repeated querying of the DB to retrieve the same user information.
show more ...
|
| #
585bf44e
|
| 06-Mar-2014 |
Christopher Smith <chris@jalakai.co.uk> |
amend $_SERVER to $INPUT->server
|
| #
f87b5dbb
|
| 05-Mar-2014 |
Christopher Smith <chris@jalakai.co.uk> |
use isset() + ?: or error suppression where value may not be set
|
| #
55a71a16
|
| 04-Mar-2014 |
Gerrit Uitslag <klapinklapin@gmail.com> |
removed pre PHP 5.2 code wrt setcookie and session setting
- moved cookiedir determination in the if-statement
|
| #
04d68ae4
|
| 20-Feb-2014 |
Gerrit Uitslag <klapinklapin@gmail.com> |
PHPDocs auth.php
|
| #
c17acc9f
|
| 05-Jan-2014 |
Andreas Gohr <andi@splitbrain.org> |
AUTH_ACL_CHECK event around ACL checking
allows to modify ACL results in the AFTER event or to implement a completely different ACL mechanism in the BEFORE event.
|
| #
21c3090a
|
| 21-Oct-2013 |
Christopher Smith <chris@jalakai.co.uk> |
replace \s, \S with [ \t], [^ \t] in regexs used with acls
|
| #
443e135d
|
| 16-Oct-2013 |
Christopher Smith <chris@jalakai.co.uk> |
replace boolean conditional checks on possibly uninitialized vars with \!empty/empty/isset as appropriate
|
| #
30f6faf0
|
| 16-Oct-2013 |
Christopher Smith <chris@jalakai.co.uk> |
update for deprecated '/e' flag in preg_replace (php 5.5)
|
| #
2f7a0e94
|
| 11-Sep-2013 |
Matt Perry <matt@mattperry.com> |
Fix CodeSniffer whitespace violoations
Removed extraneous whitespace to eliminate errors reported by the Squiz.WhiteSpace.SuperfluousWhitespace sniff.
|
| #
7ef8e99f
|
| 22-Aug-2013 |
Matt Perry <matt@mattperry.com> |
Fix CodeSniffer violations
Change indentation to ensure code confirms to CodeSniffer rules.
|
| #
b8983d3a
|
| 21-Aug-2013 |
Matt Perry <matt@mattperry.com> |
Fix CodeSniffer violations
Remove whitespace from end of lines to reduce the number of CodeSniffer violations.
|
| #
ad3d68d7
|
| 03-Aug-2013 |
Christopher Smith <chris@jalakai.co.uk> |
Fix a couple of bugs in ACL substitution mechanism
- %GROUP% & %USER% can now both be used in the same rule, e.g.
%GROUP%:%USER% 2
- rules with tokens will be skipped when the user is not logge
Fix a couple of bugs in ACL substitution mechanism
- %GROUP% & %USER% can now both be used in the same rule, e.g.
%GROUP%:%USER% 2
- rules with tokens will be skipped when the user is not logged in previously %USER% was attempted
show more ...
|
| #
836a1762
|
| 02-Aug-2013 |
Andreas Gohr <andi@splitbrain.org> |
Merge branch 'FS#2751' of git://github.com/splitbrain/dokuwiki into pull-request-245
* 'FS#2751' of git://github.com/splitbrain/dokuwiki: coding corrections. correct type hint, remove unused varia
Merge branch 'FS#2751' of git://github.com/splitbrain/dokuwiki into pull-request-245
* 'FS#2751' of git://github.com/splitbrain/dokuwiki: coding corrections. correct type hint, remove unused variable assignment de/de-informal: localization updates (delete user function) unit tests for self deleting of user accounts FS#2751 - self deletion of user account
show more ...
|
| #
73012efd
|
| 02-Aug-2013 |
Christopher Smith <chris@jalakai.co.uk> |
coding corrections. correct type hint, remove unused variable assignment
|
| #
20587314
|
| 31-Jul-2013 |
Andreas Gohr <andi@splitbrain.org> |
Merge pull request #246 from splitbrain/profileform_improvements
HTML5isation of some forms
|
| #
71422fc8
|
| 31-Jul-2013 |
Christopher Smith <chris@jalakai.co.uk> |
Change error message shown for incorrect current password on update profile form.
The current message confusingly mentions bad 'username' when username is not involved. The new message is the same
Change error message shown for incorrect current password on update profile form.
The current message confusingly mentions bad 'username' when username is not involved. The new message is the same as that introduced for an incorrect current password on the self delete profile form (FS#2751)
show more ...
|
| #
2a7abf2d
|
| 31-Jul-2013 |
Christopher Smith <chris@jalakai.co.uk> |
FS#2751 - self deletion of user account
|