Commit Graph

17 Commits

Author SHA1 Message Date
Eric Schultz
994a60a7d3 Fix: properly set samesite cookie
Logging in with Safari works again 🥞
2021-02-17 02:03:24 -06:00
Eric Schultz
d8f6dead2b fix: login prompt when switching between servers 2021-01-21 11:28:57 -07:00
bergware
c8148442d2 Multi-language support 2020-03-04 17:33:46 +01:00
Rob Vella
7108f4ed3b Escape shell arg to remove potential malicious injection 2020-01-06 17:10:50 -08:00
Larry Meaney
0e3f8bdd0f Only create session when user successfully logs in
Also, enable session.use_strict_mode to prevent session fixation attacks
2019-10-18 22:53:06 -07:00
Eric Schultz
0f03ad6f98 remove csrf token from login page 2019-09-20 14:57:36 -05:00
Eric Schultz
1afb3513cf Remove debug code from local_prepend 2019-08-17 15:23:10 -05:00
Tom Mortensen
4c6c950042 Support forms-based authentication for login/logout.
Username 'admin' is alias for 'root'.
2019-08-17 13:08:41 -07:00
bergware
eff9b2abde Copyright year update 2018-12-25 10:05:54 +01:00
Tom Mortensen
81f3339179 Eliminate warning produced when php script invoked from command line. 2017-12-13 15:29:05 -08:00
bergware
dda96dff80 Copyright 2017 update 2017-10-30 09:26:06 +01:00
Tom Mortensen
29a7c83ba9 do not log actual csrf token values when missing or wrong 2017-10-03 08:04:16 -07:00
Tom Mortensen
0bdefac498 Log csrf token values when there's a mismatch. 2017-06-14 12:47:46 -07:00
Eric Schultz
a5012583ce local_prepend and template changes for nginx/php-fpm 2017-03-20 21:03:15 -05:00
bergware
e7032eaff3 Update copyright [6]
2005 it is....
2016-06-14 13:31:56 +02:00
bergware
600930a263 Made copyright consistent and updated to 2016 2016-06-12 08:01:52 +02:00
Eric Schultz
30ca111094 initial commit 2015-10-24 10:17:28 -07:00