3117 Commits (0ee17660d065dea198ec214654d2db1c302e4b8a)
 

Author SHA1 Message Date
Tom 0ee17660d0
Merge 570c385cb5 into 0cefa4cca7 2 days ago
tom27052006 570c385cb5 Apply custom-role review follow-ups 2 days ago
tom27052006 8136691ad3 Close a manage-grant laundering path and harden the rollback tooling 6 days ago
Tom f28b8c27b7
Merge branch 'main' into feature/custom-role-permissions 6 days ago
tom27052006 7542f3d4e9 Provide a supported rollback path for the Custom-role change 6 days ago
tom27052006 634d9b2bd3 Fix migration portability and preserve legacy group collection authority 6 days ago
lmogthb 0cefa4cca7
Include user email in successful login logs (#7496) 1 week ago
Mathijs van Veluw b30cc08562
Misc fixes and updates (#7558) 1 week ago
Tom 94bb397cfa
Merge branch 'main' into feature/custom-role-permissions 1 week ago
Timshel 55f883a566
Fix playwright test (#7548) 1 week ago
Alex · ASEnough 74ceaf2354
Fix Debian cross-linking with xx-cargo (#7524) 1 week ago
tom27052006 f61e4fe727 Address custom-role review findings 1 week ago
tom27052006 35f54d76fb Fix client event whitelist and stored collection manage serialization 2 weeks ago
tom27052006 a1abd7d0ff Fix custom-role review follow-ups 2 weeks ago
tom27052006 ceeba0bf35 Fix custom-role audit findings 2 weeks ago
Tom 10df8c7439
Merge branch 'main' into feature/custom-role-permissions 2 weeks ago
Victor J. Fox 2629bcbe13
Always send initOrganization and orgUserHasExistingUser in org invite URL (#7482) 2 weeks ago
tom27052006 71349529ab Merge experiment/custom-role-complete into feature/custom-role-permissions 3 weeks ago
tom27052006 52c02ce416 Document accessReports scope and drop the unused reports guard 3 weeks ago
tom27052006 df6087f94a Allow accessReports users to load organization ciphers 3 weeks ago
tom27052006 222f662e0b Show accessReports custom permission in web vault 3 weeks ago
tom27052006 3c5b846d03 Implement accessReports custom permission 3 weeks ago
tom27052006 af2e180e02 Remove custom-role recovery document 3 weeks ago
tom27052006 fc96fbe8d3 Harden custom-role authorization and migrations 3 weeks ago
tom27052006 aa58ef576c Scope the organization export to what the caller may actually read 3 weeks ago
tom27052006 017789dd36 Merge branch 'main' into experiment/custom-role-complete 3 weeks ago
tom27052006 79ce68db02 Merge main into feature/custom-role-permissions 3 weeks ago
Daniel García 46ae59eaf4
Trusted proxy support, unauthenticated rate limit & other fixes (#7472) 3 weeks ago
Mathijs van Veluw a6a88e7929
Update API response, crates and GHA (#7470) 3 weeks ago
Timshel 5040bcb7c0
Remove unused fields (#7458) 3 weeks ago
tom27052006 cd1a4713e5 Merge Custom access permissions (point 1) into access_all removal + Manager fold (points 2+3) 3 weeks ago
tom27052006 bf56c9b169 Add accessEventLogs, accessImportExport and accessReports Custom permissions 3 weeks ago
tom27052006 5558b41801 Remove membership access_all flag and fold Manager role into Custom 3 weeks ago
tom27052006 e467062c94 Fix privilege escalation: collection manage grants bypassed delete gate 3 weeks ago
tom27052006 2243922517 Quote reserved `groups` identifier in MySQL collection-permissions migration 3 weeks ago
tom27052006 fe3111d9b5 Align bulk collection-access authorization with single-collection edit 3 weeks ago
tom27052006 031051b61c Fix privilege escalation: Edit any collection could reach Delete any collection 3 weeks ago
Tom aae6294ce2
Merge branch 'main' into feature/custom-role-permissions 3 weeks ago
Tom 660faee68e
Fix custom role dialog selectors (#7442) 3 weeks ago
Daniel 683a23e43c
Fix compilation with newer `rust-musl` version (#7453) 3 weeks ago
Tom a2de466f84
Merge branch 'main' into feature/custom-role-permissions 3 weeks ago
Timshel 4a9bcb0694
Remove old compatibility code (#7434) 3 weeks ago
tom27052006 8289e2dcff Fix custom-role privilege escalation and align read guards (security review) 4 weeks ago
tom27052006 84edbf23b0 Fix Custom Role selectors for new dialogs 4 weeks ago
tom27052006 3cd4dd8bfa Fix custom collection authorization 4 weeks ago
tom27052006 1cc4238654 Fix collection delete for legacy Managers migrated to Custom 4 weeks ago
tom27052006 a992695c00 Fix cross-tenant and revoke authorization bypasses from security audit 4 weeks ago
tom27052006 e67fb30c5f Fix delete-only collection access in web vault 4 weeks ago
tom27052006 44139eb0c7 Add granular custom collection permissions 4 weeks ago
tom27052006 4b90b47dec Fix privilege escalation: restrict role-type changes to Admins/Owners in edit_member 1 month ago