1
0
mirror of https://github.com/oauth2-proxy/oauth2-proxy.git synced 2025-06-15 00:15:00 +02:00
Commit Graph

1449 Commits

Author SHA1 Message Date
381e878574 Add CODEOWNERS file 2019-01-02 10:22:18 +00:00
39d11b486f Fix Quay link 2018-12-20 14:30:37 +00:00
52f27f76dd Add docker image note to README 2018-12-20 14:28:13 +00:00
3253bef854 Add CONTRIBUTING guide 2018-12-20 14:14:04 +00:00
8564ab6e86 Add Issue and Pull Request templates 2018-12-20 12:02:35 +00:00
7fa913e51c Add Dockerfile 2018-12-20 11:06:26 +00:00
d37cc2889e Fix err declaration shadowing 2018-12-20 10:46:19 +00:00
e200bd5c20 Add comments to exported methods for providers package 2018-12-20 10:37:59 +00:00
a65ceb2c41 Add comments to exported methods for api package 2018-12-20 09:37:02 +00:00
ee913fb788 Add comments to exported methods for root package 2018-12-20 09:30:42 +00:00
8ee802d4e5 Lint for non-comment linter errors 2018-11-29 14:26:41 +00:00
990873eb42 Exit on first failure for travis 2018-11-27 12:17:59 +00:00
fa21208005 Fix fsnotify import 2018-11-27 12:08:22 +00:00
d41089d315 Update README to reflect new repo ownership 2018-11-27 12:08:21 +00:00
bc93198aa7 Update CI to separate linting and testing 2018-11-27 12:08:20 +00:00
847cf25228 Move imports from bitly to pusher 2018-11-27 11:45:05 +00:00
bfdccf681a Add Fork notice 2018-11-27 11:23:37 +00:00
a94b0a8b25 Merge pull request #549 from brennie/dev/bcrypt-htpasswd
Support bcrypt passwords in htpasswd
2018-03-24 23:48:45 -04:00
1c1db881c3 Merge pull request #561 from danopia/patch-1
Strip JWT base64 padding before parsing. #560
2018-03-24 23:45:15 -04:00
ae78840614 Merge pull request #555 from MiniJerome/master
typo(README): Terminiation » Termination
2018-03-24 23:44:16 -04:00
542ef54093 Strip JWT base64 padding before parsing. #560 2018-03-08 16:44:11 -08:00
2db0443e04 typo(README): Terminiation » Termination 2018-03-01 12:10:02 -05:00
008ffae3bb Support bcrypt passwords in htpasswd 2018-02-16 02:14:41 -06:00
ae49c7d23c Merge pull request #529 from fsegouin/fix/templates-css-typo
Fix typo in css for the sign in page template
2018-01-23 10:08:09 -05:00
a6e247825c Fix typo in css for the sign in page template 2018-01-23 15:04:41 +00:00
1209c63b58 Merge pull request #510 from ploxiln/clear_invalid_session
more robust ClearSessionCookie()
2018-01-16 10:57:53 -05:00
1a82180376 Merge pull request #514 from ploxiln/readme_auth_request_body
README: fix nginx auth_request example for requests with body
2018-01-16 10:47:41 -05:00
74d0fbc868 more robust ClearSessionCookie()
default domain changed from request Host to blank, recently
try to clear cookies for both
2017-12-18 21:16:51 -05:00
20e87edde8 README: fix nginx auth_request example for requests with body
Nginx never sends the body with the auth_request sub-request, but
keeps the original Content-Length header by default. Without some
config tweaks, this results in the request to /oauth2/auth hanging.
2017-12-18 20:55:37 -05:00
d75f626cdd Merge pull request #414 from relaxdiego/multi-page-org
Iterate through pages returned by List Your Organizations endpoint
2017-12-04 15:12:25 -07:00
882fcf0a01 providers: iterate across all pages from /user/orgs github endpoint.
For some GHE instances where a user can have more than 100
organizations, traversing the other pages is important otherwise
oauth2_proxy will consider the user unauthorized. This change traverses
the list returned by the API to avoid that.

Update github provider tests to include this case.
2017-12-04 15:51:48 -05:00
faff555c55 Merge pull request #423 from Jimdo/configure_accesslog_format
Make Request Logging Format Configurable
2017-12-04 12:56:54 -05:00
1cefc96311 Test request logging 2017-12-04 12:52:47 -05:00
69550cbb23 Document request-logging-format option 2017-12-04 12:52:47 -05:00
9341dcbf79 Make request logging format configurable 2017-12-04 12:52:47 -05:00
085c6cf79b Merge pull request #503 from talam/add_checksum_for_binary_releases
distribution: create sha256sum.txt file when creating version releases
2017-12-04 10:39:33 -05:00
842a45b1db distribution: remove gpm references and update to use dep 2017-12-04 09:54:31 -05:00
dc65ff800f distribution: create sha256sum.txt file when creating binaries to allow validation of checksums.
* update README.md to include instructions on how to verify prebuilt binaries for new releases.
2017-11-21 15:00:30 -05:00
b0c1c85177 Merge pull request #466 from clobrano/github-use-login-as-user
GitHub use login as user
2017-11-20 12:48:14 -07:00
731fa9f8e0 Github provider: use login as user
- Save both user and email in session state:
    Encoding/decoding methods save both email and user
    field in session state, for use cases when User is not derived from
    email's local-parth, like for GitHub provider.

    For retrocompatibility, if no user is obtained by the provider,
    (e.g. User is an empty string) the encoding/decoding methods fall back
    to the previous behavior and use the email's local-part

    Updated also related tests and added two more tests to show behavior
    when session contains a non-empty user value.

- Added first basic GitHub provider tests

- Added GetUserName method to Provider interface
    The new GetUserName method is intended to return the User
    value when this is not the email's local-part.

    Added also the default implementation to provider_default.go

- Added call to GetUserName in redeemCode

    the new GetUserName method is used in redeemCode
    to get SessionState User value.

    For backward compatibility, if GetUserName error is
    "not implemented", the error is ignored.

- Added GetUserName method and tests to github provider.
2017-11-20 20:02:27 +01:00
6ddbb2c572 Merge pull request #502 from talam/update_options_parsing
options: update options parsing for better handling of incorrect values
2017-11-20 11:00:48 -07:00
e955d2be0e options: update options parsing for better handling of incorrect values
* don't add in failed compiled regexes for skip auth regex option
* improve test coverage for skip auth regex option to handle partial
success case
* add tests for incorrect upstream options parsing errors
2017-11-20 11:37:53 -05:00
a7c5d9c478 Merge pull request #421 from arnottcr/raw-url-encode
raw url encoding
2017-11-20 10:50:56 -05:00
781bd0851e Merge pull request #491 from jehiah/dep_491
Switch from gpm -> dep for dependency management
2017-11-17 15:55:15 -05:00
c4905f2347 Switch from gpm -> dep for dependency management 2017-11-16 20:58:11 -05:00
363a0dda16 Merge pull request #448 from mbland/hmacauth
Switch from 18F/hmacauth to mbland/hmacauth
2017-11-07 09:46:06 -05:00
e241fe86d3 Switch from 18F/hmacauth to mbland/hmacauth
Since I'm no longer with 18F, I've re-released hmacauth under the ISC
license as opposed to the previous CC0 license. There have been no
changes to the hmacauth code itself, and all tests still pass.
2017-11-07 07:55:24 -05:00
28e217dc8f Merge pull request #496 from talam/update_gitlab_api_endpoint
providers: update gitlab api endpoint to use latest version, v4
2017-11-06 13:15:45 -05:00
f2a995b8d9 providers: update gitlab api endpoint to use latest version, v4 2017-11-06 12:05:58 -05:00
bfda078caa Merge pull request #376 from reedloden/make-cookie-domain-optional
Don't set the cookie domain to the host by default, as it breaks Cookie Prefixes
2017-10-23 14:14:45 -04:00