This website requires JavaScript.
Explore
Help
Sign In
starred
/
warmbly
Watch
1
Star
0
Fork
0
mirror of
https://github.com/warmbly/warmbly.git
synced
2026-10-03 16:02:02 +00:00
Code
Issues
Packages
Projects
Releases
Wiki
Activity
Files
596c395cd0fe6b32ebef7671bc93041d600fcdd7
warmbly
/
internal
/
app
/
auth
T
History
Matthew Meszaros
75f764dc67
feat: require a verified Cloud Tasks token with a pinned audience on task webhooks, manage_settings on integration OAuth and a fresh membership check at every mailbox and integration OAuth finish, user verification for passkey sign-in, ended sessions before a password reset or ban reports success, and a revoked session when a rotated refresh token is replayed; remove the internal DEK delete route, log credential path parameters by name, hold remote images in received mail until the reader loads them, add Calendly and Cal.com signing keys with inbound URL rotation, keep automation signing secrets out of connection responses, and apply the password rules to the bootstrap password
2026-09-30 06:46:24 -07:00
..
account_exists_test.go
feat: answer a signup for an existing address with 409 conflict and let a concurrent SSO first sign-in resolve against the account it raced, adopt the stored organization DEK when a parallel first use stored one first, classify IMAP SERVERBUG, LIMIT, bare read-command failures and provider ALERT/EXPIRED responses as server-unreachable, throttle or credentials errors and keep the ALERT text, wait up to two minutes for a free connection slot before the boot migration gives up, guard the dashboard's DOM mutations against browser page translation, treat an aborted passkey sign-in as a cancellation, and drop posthog-js request timeouts from error tracking
2026-09-27 08:26:55 +02:00
cache.go
feat: delete the reauth attempt counter when a refund leaves it at zero or below so it always carries an expiry, and focus the first field of a 2FA dialog on open
2026-09-19 08:43:11 -07:00
config.go
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
email.go
feat: stop the password reset flow reporting success while sending nothing, by answering 200 only for an address with no account rather than for every cache and database fault, folding addresses to one case on every account lookup and write so a typed capital cannot miss the row or split an SSO account in two, refunding the two-per-four-hours budget when the failure was ours, retrying one transient send and quoting the link's real lifetime; and clear the rest of error tracking by grouping the engagement breakdown in a subquery so ORDER BY stops resolving opens against email_opens, dropping unibox_mailboxes and email_sync_state writes whose mailbox was deleted mid-sync instead of redelivering them forever, answering a corrupt argon2 hash with ErrCredentials rather than a 500, never filing a cancelled caller as a database incident, and reporting only the first websocket init failure of a streak
2026-09-18 11:42:49 +02:00
external_idtoken.go
feat: answer a signup for an existing address with 409 conflict and let a concurrent SSO first sign-in resolve against the account it raced, adopt the stored organization DEK when a parallel first use stored one first, classify IMAP SERVERBUG, LIMIT, bare read-command failures and provider ALERT/EXPIRED responses as server-unreachable, throttle or credentials errors and keep the ALERT text, wait up to two minutes for a free connection slot before the boot migration gives up, guard the dashboard's DOM mutations against browser page translation, treat an aborted passkey sign-in as a cancellation, and drop posthog-js request timeouts from error tracking
2026-09-27 08:26:55 +02:00
gen.go
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
login_code_exempt_test.go
feat: tester accounts, creatable from the admin panel (
#483
)
2026-09-13 03:07:10 -07:00
login_risk_test.go
feat: record the verdict that issued the login challenge instead of re-judging at confirm, and stop a mailbox in no warmup pool reading as healthy: the emailed code is confirmed by a second request that can carry a different address and sees history the first one did not, so re-assessing there could file a challenged sign-in as clean and drop it from the repeat count that reaches the workspace posture; the verdict now travels in the login session and every completion path takes it, while ListLifecycleCandidates returns a NULL health as unknown so leaving the pool is no longer evidence of recovery and a resting mailbox neither resumes nor accrues probation on it
2026-08-28 12:20:11 -07:00
login_risk.go
Merge remote-tracking branch 'origin/main' into fix/issue-241
2026-08-28 23:06:07 -07:00
login.go
feat: route the sso_link completion through the one login path (completeLogin) so the ban check, the 2FA gate, login recording and device memory apply before a parked identity is attached, carry the session provider into every 2FA challenge so a Google or Apple sign-in on a 2FA account is recorded as such, make IdentityRepository.Link report a pair another account holds as ErrIdentityTaken instead of silently updating nothing, refuse a spent address budget before charging a link try, drop the dead expiry check and the duplicate link fields on the web Session model
2026-09-21 03:57:29 -07:00
model.go
feat: attach a Google, Apple or OIDC identity to an existing password account only after that account's password is presented: resolveFederatedUser parks the sign-in as link_required with a single-use sso_link pending token, POST /auth/sso/link checks the password against the provider-asserted address on the sign-in failure budget and links then issues the session through finishLoginAs, the dashboard collects it on a new login step, and the API reference, endpoints list, security guide and OpenAPI spec describe the third login result
2026-09-21 03:25:29 -07:00
provision.go
feat: answer a signup for an existing address with 409 conflict and let a concurrent SSO first sign-in resolve against the account it raced, adopt the stored organization DEK when a parallel first use stored one first, classify IMAP SERVERBUG, LIMIT, bare read-command failures and provider ALERT/EXPIRED responses as server-unreachable, throttle or credentials errors and keep the ALERT text, wait up to two minutes for a free connection slot before the boot migration gives up, guard the dashboard's DOM mutations against browser page translation, treat an aborted passkey sign-in as a cancellation, and drop posthog-js request timeouts from error tracking
2026-09-27 08:26:55 +02:00
registration.go
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
reset_password_test.go
feat: stamp users.password_changed_at on every password write and refuse a password reset link issued at or before it, so a link requested earlier dies when the password is changed from settings, by another reset link or by warmblyctl, with the rule documented on the reset endpoint and the security guide
2026-09-21 03:23:14 -07:00
reset_password.go
feat: require a verified Cloud Tasks token with a pinned audience on task webhooks, manage_settings on integration OAuth and a fresh membership check at every mailbox and integration OAuth finish, user verification for passkey sign-in, ended sessions before a password reset or ban reports success, and a revoked session when a rotated refresh token is replayed; remove the internal DEK delete route, log credential path parameters by name, hold remote images in received mail until the reader loads them, add Calendly and Cal.com signing keys with inbound URL rotation, keep automation signing secrets out of connection responses, and apply the password rules to the bootstrap password
2026-09-30 06:46:24 -07:00
service.go
Merge remote-tracking branch 'origin/main' into fix/password-change-session-revocation
2026-09-21 04:56:50 -07:00
signup_origin_test.go
feat: add cookieless PostHog analytics for the hosted marketing site and dashboard with server-side signup and subscription events, a first-party acquisition record written once at signup on a new organization_acquisition table registered in the org-transfer spec, an acquisition column and channel filter in the admin org list, and never a single request from a self-host because every key is unset by default
2026-09-07 04:18:33 -07:00
sso_link_test.go
feat: route the sso_link completion through the one login path (completeLogin) so the ban check, the 2FA gate, login recording and device memory apply before a parked identity is attached, carry the session provider into every 2FA challenge so a Google or Apple sign-in on a 2FA account is recorded as such, make IdentityRepository.Link report a pair another account holds as ErrIdentityTaken instead of silently updating nothing, refuse a spent address budget before charging a link try, drop the dead expiry check and the duplicate link fields on the web Session model
2026-09-21 03:57:29 -07:00
sso_link.go
feat: route the sso_link completion through the one login path (completeLogin) so the ban check, the 2FA gate, login recording and device memory apply before a parked identity is attached, carry the session provider into every 2FA challenge so a Google or Apple sign-in on a 2FA account is recorded as such, make IdentityRepository.Link report a pair another account holds as ErrIdentityTaken instead of silently updating nothing, refuse a spent address budget before charging a link try, drop the dead expiry check and the duplicate link fields on the web Session model
2026-09-21 03:57:29 -07:00
sso_test.go
feat: bind a browser sign-in to the browser that started it, so a handoff link cannot be forwarded: one-time state proves the callback answers a request this server made, not one THIS browser made, so anyone could run the flow against their own Google or OIDC account and send the resulting URL to someone else, whose browser would then hold the sender's session (RFC 9700 4.7.1); begin now mints a binding secret that never reaches the provider and never appears in a URL, the callback carries it into the handoff, and the exchange refuses a collection that cannot present it with sso_wrong_browser, while the comments this PR added are condensed to the constraint they exist to state
2026-08-28 01:44:39 -07:00
sso.go
feat: attach a Google, Apple or OIDC identity to an existing password account only after that account's password is presented: resolveFederatedUser parks the sign-in as link_required with a single-use sso_link pending token, POST /auth/sso/link checks the password against the provider-asserted address on the sign-in failure budget and links then issues the session through finishLoginAs, the dashboard collects it on a new login step, and the API reference, endpoints list, security guide and OpenAPI spec describe the third login result
2026-09-21 03:25:29 -07:00