Skip to content
Snippets Groups Projects
  1. Dec 16, 2019
    • ale's avatar
      Use securecookie for the httpsso handler · 42482e82
      ale authored
      There is no need for the complex gorilla/sessions machinery for what
      is basically a single cookie, so we switch to using
      gorilla/securecookie directly.
      42482e82
  2. Dec 15, 2019
    • ale's avatar
      Refactor the login handler · 4d70b167
      ale authored
      The login handler is now a simpler, standalone http.Handler
      wrapper. The separation between the SSO application and the login
      handler is now fairly complete.
      
      The login handler no longer forces the user to a specific workflow via
      session cookies, but it works on a request-by-request basis instead,
      which makes the "back" button works as expected (allowing the user to
      bail out of a broken 2FA process, for example).
      
      Session handling has been simplified as well: there is a single
      session for authentication and login state, which should remove the
      opportunity for session synchronization errors.
      4d70b167
  3. Aug 01, 2019
  4. Jun 20, 2019
  5. Feb 18, 2018
  6. Dec 06, 2017
  7. Dec 02, 2017
  8. Nov 12, 2017
Loading