Commit graph

11761 commits

Author SHA1 Message Date
Joas Schilling
1facb21df5
fix(core): Add password confirmation requirement for getapppassword
Signed-off-by: Joas Schilling <coding@schilljs.com>
2023-07-17 12:15:26 +02:00
Joas Schilling
83b9109425
fix(lostpassword): Also rate limit the setPassword endpoint
Signed-off-by: Joas Schilling <coding@schilljs.com>
2023-05-15 16:04:25 +02:00
Arthur Schiwon
d78baf4c63
Merge pull request #36744 from nextcloud/backport/35419/stable23
[stable23] Fix login loop if login CSRF fails and user is not logged in
2023-03-14 14:23:18 +01:00
Joas Schilling
438e860f0a
Fail the repair command when an error happened
Signed-off-by: Joas Schilling <coding@schilljs.com>
2023-02-28 09:20:42 +01:00
Christoph Wurst
b9baa624bc
Fix login loop if login CSRF fails and user is not logged in
If CSRF fails but the user is logged in that they probably logged in in
another tab. This is fine. We can just redirect.
If CSRF fails and the user is also not logged in then something is
fishy. E.g. because Nextcloud contantly regenrates the session and the
CSRF token and the user is stuck in an endless login loop.

Signed-off-by: Christoph Wurst <christoph@winzerhof-wurst.at>
2023-02-16 09:42:11 +01:00
Joas Schilling
638b1fb4bc
Add bruteforce protection to password reset page
Signed-off-by: Joas Schilling <coding@schilljs.com>
2023-02-07 07:46:12 +01:00
Simon L
006ed2fa47 add a safeguard for Version23000Date20210721100600.php
Signed-off-by: Simon L <szaimen@e.mail.de>
2023-02-01 08:13:33 +00:00
Nextcloud bot
d675e52350
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-20 02:22:44 +00:00
Vincent Petry
2d449ba5bb
Merge pull request #35675 from nextcloud/stable23-audit-fix
[stable23] Update handlebars-loader to 1.7.3 + others
2022-12-19 12:06:41 +01:00
Nextcloud bot
64d4790864
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-19 02:21:54 +00:00
Nextcloud bot
bc6bb6036d
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-17 02:20:03 +00:00
Vincent Petry
bdec46dc30 Update handlebars-loader to 1.7.3 + others
Signed-off-by: Vincent Petry <vincent@nextcloud.com>
Signed-off-by: nextcloud-command <nextcloud-command@users.noreply.github.com>
2022-12-16 15:49:02 +00:00
Nextcloud bot
43e36cec70
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-16 02:20:17 +00:00
Nextcloud bot
19a0f11458
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-14 02:22:21 +00:00
Nextcloud bot
fa261d00a1
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-13 02:33:19 +00:00
Nextcloud bot
161c1e0a5e
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-12 02:20:18 +00:00
Nextcloud bot
a9924a00df
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-11 02:31:34 +00:00
Nextcloud bot
fc06379df9
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-10 02:21:18 +00:00
Nextcloud bot
2ef6557790
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-09 02:35:27 +00:00
Nextcloud bot
9c65fd7188
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-07 02:20:09 +00:00
Nextcloud bot
bca7a5634a
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-06 02:26:29 +00:00
Nextcloud bot
93c583a741
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-05 02:15:47 +00:00
Nextcloud bot
e490d816c4
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-04 02:15:15 +00:00
Nextcloud bot
aa58ac5d1a
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-03 02:15:27 +00:00
Nextcloud bot
3123364d82
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-02 02:15:44 +00:00
Nextcloud bot
8afbf0cbeb
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-12-01 02:15:44 +00:00
Nextcloud bot
669ae09603
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-29 02:14:51 +00:00
Nextcloud bot
d34c584523
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-25 02:19:55 +00:00
Vincent Petry
f268a5232d
Update some libs
Signed-off-by: Vincent Petry <vincent@nextcloud.com>
2022-11-24 11:58:04 +01:00
blizzz
80c63dc395
Merge pull request #35040 from nextcloud/backport/32211/stable23
[stable23] Add repair command to fix wrong share ownership
2022-11-23 21:08:07 +01:00
Nextcloud bot
42a50ede86
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-23 02:18:36 +00:00
Nextcloud bot
f3bfa072fc
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-21 02:15:54 +00:00
Nextcloud bot
b12f121ea3
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-20 02:16:12 +00:00
Nextcloud bot
b47e9c6628
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-19 02:18:03 +00:00
Nextcloud bot
0564ebc56e
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-17 02:14:49 +00:00
Nextcloud bot
026a99e9ce
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-16 02:15:06 +00:00
Nextcloud bot
f697e8e321
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-15 02:15:55 +00:00
Nextcloud bot
1e5c2b34eb
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-14 02:15:53 +00:00
Nextcloud bot
fc8575a774
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-12 02:15:17 +00:00
Nextcloud bot
e453e5820f
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-11 02:14:24 +00:00
Robin Appelman
adfdb960ee
fix php 7.3 compat
Signed-off-by: Robin Appelman <robin@icewind.nl>
2022-11-10 16:28:29 +01:00
Robin Appelman
8c097afbdc
fix concat usage
Signed-off-by: Robin Appelman <robin@icewind.nl>
2022-11-10 16:05:42 +01:00
Nextcloud bot
8caac5309a
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-10 02:15:50 +00:00
Nextcloud bot
348af70efc
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-09 02:14:53 +00:00
Robin Appelman
c6a9a83ec3 fix repairing non user shares when repairing all shares
Signed-off-by: Robin Appelman <robin@icewind.nl>
2022-11-08 22:38:59 +00:00
Robin Appelman
3b6a37b371 split repairing into two stages to prevent long open transaction
Signed-off-by: Robin Appelman <robin@icewind.nl>
2022-11-08 22:38:52 +00:00
Robin Appelman
b694313929 update shares directly in db
Signed-off-by: Robin Appelman <robin@icewind.nl>
2022-11-08 22:38:48 +00:00
Vincent Petry
c8a25d467e More verbose output for repair share ownership cmd
Signed-off-by: Vincent Petry <vincent@nextcloud.com>
2022-11-08 22:38:45 +00:00
Robin Appelman
33545230ef move share owner repair to occ command
Signed-off-by: Robin Appelman <robin@icewind.nl>
2022-11-08 22:38:42 +00:00
Nextcloud bot
6afbbc42d9
[tx-robot] updated from transifex
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
2022-11-08 02:14:38 +00:00