Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								bffddf5e31 
								
							 
						 
						
							
							
								
								[ #923 ] Merge remote-tracking branch 'remotes/upstream/develop' into twitter_oauth  
							
							... 
							
							
							
							# Conflicts:
#	docs/config.md
#	test/support/factory.ex 
							
						 
						
							2019-04-08 12:20:26 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									eugenijm 
								
							 
						 
						
							
							
							
							
								
							
							
								7aa53d52bd 
								
							 
						 
						
							
							
								
								Return 403 on oauth token exchange for a deactivated user  
							
							
							
						 
						
							2019-04-06 23:27:55 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								47a236f753 
								
							 
						 
						
							
							
								
								[ #923 ] OAuth consumer mode refactoring, new tests, tests adjustments, readme.  
							
							
							
						 
						
							2019-04-05 15:12:02 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								3e7f2bfc2f 
								
							 
						 
						
							
							
								
								[ #923 ] OAuthController#callback adjustments (with tests).  
							
							
							
						 
						
							2019-04-05 09:19:17 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								f7cd9131d4 
								
							 
						 
						
							
							
								
								[ #923 ] OAuth consumer controller tests. Misc. improvements.  
							
							
							
						 
						
							2019-04-04 22:41:03 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								37925cbe78 
								
							 
						 
						
							
							
								
								Merge remote-tracking branch 'remotes/upstream/develop' into twitter_oauth  
							
							... 
							
							
							
							# Conflicts:
#	lib/pleroma/web/oauth/oauth_controller.ex
#	lib/pleroma/web/router.ex 
							
						 
						
							2019-04-02 14:05:34 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									lambda 
								
							 
						 
						
							
							
							
							
								
							
							
								091baf9316 
								
							 
						 
						
							
							
								
								Merge branch 'features/mastoapi/2.6.0-force-login-option' into 'develop'  
							
							... 
							
							
							
							MastoAPI 2.6.0 `force_login` option
Closes  #734 
See merge request pleroma/pleroma!999  
							
						 
						
							2019-04-02 10:57:38 +00:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Egor Kislitsyn 
								
							 
						 
						
							
							
							
							
								
							
							
								1b3d921921 
								
							 
						 
						
							
							
								
								change Repo.get(User, id) => User.get_by_id(id)  
							
							
							
						 
						
							2019-04-02 17:01:26 +07:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								6910fb371b 
								
							 
						 
						
							
							
								
								Fixed local MastoFE authentication / force_login option.  
							
							
							
						 
						
							2019-04-01 17:25:25 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								cbe09d94d1 
								
							 
						 
						
							
							
								
								Added force_login authentication option (previously applied by default).  
							
							
							
						 
						
							2019-04-01 14:46:50 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								eadafc88b8 
								
							 
						 
						
							
							
								
								[ #923 ] Deps config adjustment (no override for httpoison), code analysis issues fixes.  
							
							
							
						 
						
							2019-04-01 09:28:56 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								baffdcc480 
								
							 
						 
						
							
							
								
								[ #923 ] Merge remote-tracking branch 'remotes/upstream/develop' into twitter_oauth  
							
							... 
							
							
							
							# Conflicts:
#	mix.exs 
							
						 
						
							2019-04-01 08:49:32 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								2a95014b9d 
								
							 
						 
						
							
							
								
								[ #923 ] OAuth consumer improvements, fixes, refactoring.  
							
							
							
						 
						
							2019-03-27 15:39:35 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								b0759f821b 
								
							 
						 
						
							
							
								
								Comments split.  
							
							
							
						 
						
							2019-03-26 15:24:29 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								263ca3dea2 
								
							 
						 
						
							
							
								
								Mastodon-based auth error messages. Defaulted User#auth_active?/1 to true.  
							
							
							
						 
						
							2019-03-26 15:09:06 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								af68a42ef7 
								
							 
						 
						
							
							
								
								[ #923 ] Support for multiple OAuth consumer strategies.  
							
							
							
						 
						
							2019-03-20 20:25:48 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								e17a9a1f66 
								
							 
						 
						
							
							
								
								[ #923 ] Nickname & email selection for external registrations, option to connect to existing account.  
							
							
							
						 
						
							2019-03-20 10:35:31 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								26b6354095 
								
							 
						 
						
							
							
								
								[ #923 ] Support for multiple (external) registrations per user via Registration.  
							
							
							
						 
						
							2019-03-18 17:23:38 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								2a96283efb 
								
							 
						 
						
							
							
								
								[ #923 ] Merge remote-tracking branch 'remotes/upstream/develop' into twitter_oauth  
							
							... 
							
							
							
							# Conflicts:
#	config/config.exs
#	lib/pleroma/web/auth/pleroma_authenticator.ex 
							
						 
						
							2019-03-18 10:26:41 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									lambda 
								
							 
						 
						
							
							
							
							
								
							
							
								28df397454 
								
							 
						 
						
							
							
								
								Merge branch 'feature/oauth-me' into 'develop'  
							
							... 
							
							
							
							oauth: add me property to token responses
See merge request pleroma/pleroma!942  
							
						 
						
							2019-03-16 08:44:02 +00:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									William Pitcock 
								
							 
						 
						
							
							
							
							
								
							
							
								e0edc706cf 
								
							 
						 
						
							
							
								
								oauth: add me property to token responses  
							
							
							
						 
						
							2019-03-16 01:12:50 +00:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								2739057442 
								
							 
						 
						
							
							
								
								Merge remote-tracking branch 'remotes/upstream/develop' into twitter_oauth  
							
							
							
						 
						
							2019-03-15 17:11:00 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								aacbf0f570 
								
							 
						 
						
							
							
								
								[ #923 ] OAuth: prototype of sign in / sign up with Twitter.  
							
							
							
						 
						
							2019-03-15 17:08:03 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									link0ff 
								
							 
						 
						
							
							
							
							
								
							
							
								54e7087ab4 
								
							 
						 
						
							
							
								
								Merge remote-tracking branch 'upstream/develop' into feature/openldap-support  
							
							
							
						 
						
							2019-03-14 17:43:30 +02:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Haelwenn (lanodan) Monnier 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								a3a9cec483 
								
							 
						 
						
							
							
								
								[Credo] fix Credo.Check.Readability.AliasOrder  
							
							
							
						 
						
							2019-03-13 04:26:54 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								63ab61ed3f 
								
							 
						 
						
							
							
								
								Sign in via Twitter (WIP).  
							
							
							
						 
						
							2019-03-11 20:37:26 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									link0ff 
								
							 
						 
						
							
							
							
							
								
							
							
								88a672fe88 
								
							 
						 
						
							
							
								
								Move LDAP code to LDAPAuthenticator.  Use Authenticator for token_exchange with grant_type as well  
							
							
							
						 
						
							2019-03-03 21:20:36 +02:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									link0ff 
								
							 
						 
						
							
							
							
							
								
							
							
								19e2b85247 
								
							 
						 
						
							
							
								
								Merge remote-tracking branch 'upstream/develop' into feature/openldap-support  
							
							
							
						 
						
							2019-03-03 18:29:37 +02:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									rinpatch 
								
							 
						 
						
							
							
							
							
								
							
							
								f38c316e6e 
								
							 
						 
						
							
							
								
								Merge branch 'bugfix/oauth-scopes-join' into 'develop'  
							
							... 
							
							
							
							Bugfix: OAuth scopes formatting
Closes  #702 
See merge request pleroma/pleroma!881  
							
						 
						
							2019-03-02 06:39:07 +00:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Haelwenn (lanodan) Monnier 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								b6a001a34c 
								
							 
						 
						
							
							
								
								Web.OAuth.OAuthController: Fix scopes Enum.join for OAuth response  
							
							
							
						 
						
							2019-03-02 04:04:16 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								3281a3f074 
								
							 
						 
						
							
							
								
								Renamed *DatabaseAuthenticator to *Authenticator.  
							
							
							
						 
						
							2019-02-28 14:12:41 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								4e77f68414 
								
							 
						 
						
							
							
								
								Added auth_template/0 to DatabaseAuthenticator.  
							
							
							
						 
						
							2019-02-28 13:58:58 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								b6f915313f 
								
							 
						 
						
							
							
								
								Made auth customization be runtime-configurable.  
							
							
							
						 
						
							2019-02-28 13:00:54 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								e82b70eb53 
								
							 
						 
						
							
							
								
								Database authenticator behaviour / Pleroma implementation refactoring.  
							
							
							
						 
						
							2019-02-26 15:27:01 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									link0ff 
								
							 
						 
						
							
							
							
							
								
							
							
								e278d47023 
								
							 
						 
						
							
							
								
								OpenLDAP support  
							
							
							
						 
						
							2019-02-22 15:03:43 +02:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								1097ce6d9f 
								
							 
						 
						
							
							
								
								Auth customization support.  
							
							... 
							
							
							
							OAuthController#create_authorization user retrieval / creation, errors handling, template & layout selection. 
							
						 
						
							2019-02-21 18:55:19 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								bc4f77b10b 
								
							 
						 
						
							
							
								
								[ #468 ] Merged upstream/develop, resolved conflicts.  
							
							
							
						 
						
							2019-02-17 14:07:04 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								dcf24a3233 
								
							 
						 
						
							
							
								
								[ #468 ] Refactored OAuth scopes' defaults & missing selection handling.  
							
							
							
						 
						
							2019-02-17 13:49:14 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								2a4a4f3342 
								
							 
						 
						
							
							
								
								[ #468 ] Defined OAuth restrictions for all applicable routes.  
							
							... 
							
							
							
							Improved missing "scopes" param handling.
Allowed "any of" / "all of" mode specification in OAuthScopesPlug.
Fixed auth UI / behavior when user selects no permissions at /oauth/authorize. 
							
						 
						
							2019-02-15 19:54:37 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								027adbc9e5 
								
							 
						 
						
							
							
								
								[ #468 ] Refactored OAuth scopes parsing / defaults handling.  
							
							
							
						 
						
							2019-02-14 17:03:19 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									William Pitcock 
								
							 
						 
						
							
							
							
							
								
							
							
								e9ef4b8da6 
								
							 
						 
						
							
							
								
								oauth: never use base64 padding when returning tokens to applications  
							
							... 
							
							
							
							The normal Base64 alphabet uses the equals sign (=) as a padding character.  Since
Base64 strings are self-synchronizing, padding characters are unnecessary, so don't
generate them in the first place. 
							
						 
						
							2019-02-14 01:10:04 +00:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								063baca5e4 
								
							 
						 
						
							
							
								
								[ #468 ] User UI for OAuth permissions restriction. Standardized storage format for scopes fields, updated usages.  
							
							
							
						 
						
							2019-02-14 00:29:29 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Haelwenn (lanodan) Monnier 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								6a6a5b3251 
								
							 
						 
						
							
							
								
								de-group alias/es  
							
							
							
						 
						
							2019-02-09 16:31:17 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								4ad843fb9d 
								
							 
						 
						
							
							
								
								[ #468 ] Prototype of OAuth2 scopes support. TwitterAPI scope restrictions.  
							
							
							
						 
						
							2019-02-09 17:09:08 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								2c68cf7e9e 
								
							 
						 
						
							
							
								
								OAuth2 security fixes: redirect URI validation, "Mastodon-Local" security breach fix.  
							
							... 
							
							
							
							(`POST /api/v1/apps` could create "Mastodon-Local" app wth any redirect_uris,
and if that happened before /web/login is accessed for the first time
then Pleroma used this externally created record with arbitrary
redirect_uris and client_secret known by creator). 
							
						 
						
							2019-02-07 22:14:06 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									William Pitcock 
								
							 
						 
						
							
							
							
							
								
							
							
								980b5288ed 
								
							 
						 
						
							
							
								
								update copyright years to 2019  
							
							
							
						 
						
							2018-12-31 15:41:47 +00:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									William Pitcock 
								
							 
						 
						
							
							
							
							
								
							
							
								2791ce9a1f 
								
							 
						 
						
							
							
								
								add license boilerplate to pleroma core  
							
							
							
						 
						
							2018-12-23 20:56:42 +00:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								b096e30cff 
								
							 
						 
						
							
							
								
								[ #114 ] Added email confirmation resend action. Added tests  
							
							... 
							
							
							
							for registration, authentication, email confirmation, confirmation resending.
Made admin methods create confirmed users. 
							
						 
						
							2018-12-18 17:22:46 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Ivan Tashkinov 
								
							 
						 
						
							
							
							
							
								
							
							
								1de0aa2f10 
								
							 
						 
						
							
							
								
								[ #114 ] Account confirmation email, registration as unconfirmed (config-based), auth prevention for unconfirmed.  
							
							
							
						 
						
							2018-12-18 17:21:05 +03:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Maksim Pechnikov 
								
							 
						 
						
							
							
							
							
								
							
							
								074fa790ba 
								
							 
						 
						
							
							
								
								fix compile warnings  
							
							
							
						 
						
							2018-12-09 20:50:08 +03:00