- Dec 15, 2019
-
-
ale authored
The login handler is now a simpler, standalone http.Handler wrapper. The separation between the SSO application and the login handler is now fairly complete. The login handler no longer forces the user to a specific workflow via session cookies, but it works on a request-by-request basis instead, which makes the "back" button works as expected (allowing the user to bail out of a broken 2FA process, for example). Session handling has been simplified as well: there is a single session for authentication and login state, which should remove the opportunity for session synchronization errors.
-
- Oct 24, 2019
-
-
ale authored
-
- Aug 18, 2019
-
-
ale authored
-
- Aug 17, 2019
- Aug 01, 2019
- Jul 03, 2019
-
-
ale authored
-
- Jun 30, 2019
-
-
ale authored
-
- Jun 28, 2019
-
-
godog authored
- Jun 24, 2019
-
-
blallo authored
- Jun 22, 2019
- Jun 21, 2019
-
-
ale authored
This allows eventual future usage of 307 redirects and us accepting POST requests without having to decode the request body.
-
- Jun 20, 2019
- May 24, 2019
- May 04, 2019
- Apr 17, 2019
- Mar 18, 2019
- Feb 24, 2019
-
-
ale authored
-
- Feb 23, 2019
-
-
ale authored
This caused the SSO server to generate bad form links, which caused a 302, preventing POST requests to succeed.
-
- Feb 16, 2019
-