This website requires JavaScript.
Explore
Help
Sign In
starred
/
warmbly
Watch
1
Star
0
Fork
0
mirror of
https://github.com/warmbly/warmbly.git
synced
2026-10-08 00:02:12 +00:00
Code
Issues
Packages
Projects
Releases
Wiki
Activity
Files
db8efd04d74c772c82f45e7ba00d14da337cf5df
warmbly
/
internal
/
app
/
token
T
History
Matthew Meszaros
8910b02198
feat: redesign the admin panel in a black and white dark-first theme with grouped sidebar sections, header tabs, a collapsible animated sidebar and a rebuilt sign-in, alert operators on admin sign-ins and admin access changes through opsnotify, and carry first-touch attribution from the marketing site to every dashboard link
2026-10-05 03:01:22 -07:00
..
cache.go
fix: stop a Redis outage locking everyone out, and let the tracking encoder register its schema (
#537
)
2026-09-15 21:19:03 -07:00
config.go
Merge remote-tracking branch 'origin/main' into fix/password-change-session-revocation
2026-09-21 04:56:50 -07:00
gen.go
feat: redesign the admin panel in a black and white dark-first theme with grouped sidebar sections, header tabs, a collapsible animated sidebar and a rebuilt sign-in, alert operators on admin sign-ins and admin access changes through opsnotify, and carry first-touch attribution from the marketing site to every dashboard link
2026-10-05 03:01:22 -07:00
logout.go
feat: end every session on sign-out-everywhere through RevokeOtherSessions with cache eviction after commit, refuse refresh on a revoked session, close a user's realtime sockets on any session revocation via a SESSIONS_REVOKED event, and verify tokens without a purpose claim for no flow
2026-10-04 02:56:18 -07:00
purpose_test.go
feat: end every session on sign-out-everywhere through RevokeOtherSessions with cache eviction after commit, refuse refresh on a revoked session, close a user's realtime sockets on any session revocation via a SESSIONS_REVOKED event, and verify tokens without a purpose claim for no flow
2026-10-04 02:56:18 -07:00
reauth.go
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
refresh.go
feat: end every session on sign-out-everywhere through RevokeOtherSessions with cache eviction after commit, refuse refresh on a revoked session, close a user's realtime sockets on any session revocation via a SESSIONS_REVOKED event, and verify tokens without a purpose claim for no flow
2026-10-04 02:56:18 -07:00
service.go
feat: redesign the admin panel in a black and white dark-first theme with grouped sidebar sections, header tabs, a collapsible animated sidebar and a rebuilt sign-in, alert operators on admin sign-ins and admin access changes through opsnotify, and carry first-touch attribution from the marketing site to every dashboard link
2026-10-05 03:01:22 -07:00
sessions.go
feat: end every session on sign-out-everywhere through RevokeOtherSessions with cache eviction after commit, refuse refresh on a revoked session, close a user's realtime sockets on any session revocation via a SESSIONS_REVOKED event, and verify tokens without a purpose claim for no flow
2026-10-04 02:56:18 -07:00
verify_test.go
fix: stop a Redis outage locking everyone out, and let the tracking encoder register its schema (
#537
)
2026-09-15 21:19:03 -07:00
verify.go
feat: end every session on sign-out-everywhere through RevokeOtherSessions with cache eviction after commit, refuse refresh on a revoked session, close a user's realtime sockets on any session revocation via a SESSIONS_REVOKED event, and verify tokens without a purpose claim for no flow
2026-10-04 02:56:18 -07:00