BookStackApp_BookStack/app/Access
Dan Brown 5632fef621
Auth: Added specific guards against guest account login
Hardened things to enforce the intent that the guest account should not
be used for logins.
Currently this would not be allowed due to empty set password, and no
password fields on user edit forms, but an error could occur if the
login was attempted.

This adds:
- Handling to show normal invalid user warning on login instead of a
  hash check error.
- Prevention of guest user via main login route, in the event that
  inventive workarounds would be used by admins to set a password for
  this account.
- Test for guest user login.
2024-12-11 14:22:48 +00:00
..
Controllers Auth: Changed email confirmations to use login attempt user 2024-05-20 17:23:15 +01:00
Guards Played around with a new app structure 2023-05-17 17:56:55 +01:00
Mfa Framework: Addressed deprecations 2024-03-17 16:52:19 +00:00
Notifications Locales: More use of locale objects, Addressed failing tests 2023-09-17 16:20:21 +01:00
Oidc OIDC: Added extra userinfo content-type normalisation and test 2024-11-28 16:58:06 +00:00
EmailConfirmationService.php Auth: Changed email confirmations to use login attempt user 2024-05-20 17:23:15 +01:00
ExternalBaseUserProvider.php Played around with a new app structure 2023-05-17 17:56:55 +01:00
GroupSyncService.php Played around with a new app structure 2023-05-17 17:56:55 +01:00
Ldap.php LDAP: Updated recursive group search to query by DN 2024-08-28 15:39:05 +01:00
LdapService.php LDAP: Review and testing of mulitple-display-name attr support 2024-12-01 18:42:54 +00:00
LoginService.php Auth: Added specific guards against guest account login 2024-12-11 14:22:48 +00:00
RegistrationService.php Theme System: Added AUTH_PRE_REGISTER logical event 2024-02-21 15:30:29 +00:00
Saml2Service.php SAML: Set static type to pass static checks 2024-06-10 10:31:35 +01:00
SocialAccount.php Played around with a new app structure 2023-05-17 17:56:55 +01:00
SocialAuthService.php Auth: Refactored OIDC RP-logout PR code, Extracted logout 2023-12-06 13:49:53 +00:00
SocialDriverManager.php Auth: Refactored OIDC RP-logout PR code, Extracted logout 2023-12-06 13:49:53 +00:00
UserInviteException.php Users: Improved user response for failed invite sending 2024-09-29 16:41:18 +01:00
UserInviteService.php Users: Improved user response for failed invite sending 2024-09-29 16:41:18 +01:00
UserTokenService.php Played around with a new app structure 2023-05-17 17:56:55 +01:00