2937 Commits (56e7b76db1d95e34637338e71c1506e44d77c156)
 

Author SHA1 Message Date
kalvinparker 56e7b76db1 chore(experiment): remove openidconnect reqwest feature to avoid reqwest/rustls pull-in (experiment) 3 months ago
kalvinparker 03eb5a2ab0 ci(audit): trigger dependency audit workflow 3 months ago
kalvinparker 3acda59afd chore(audit): temporarily allow MPL-2.0 and CDLA-Permissive-2.0 to unblock CI; timebox and track remediation 3 months ago
kalvinparker b0ee507743 chore(experiment): try reqwest with native-tls to avoid webpki-roots 3 months ago
kalvinparker fe4f9ce212 docs(audit): record webauthn upgrade experiment results 3 months ago
kalvinparker 64f402b6af chore(audit): add Dockerfile and scripts for cargo audit and deny integration 3 months ago
kalvinparker d9db30e4b9 docs(audit): add feasibility report for webauthn-rs and webpki-roots remediation 3 months ago
kalvinparker 6ed3d31cc0 chore(audit): add temporary license allowlist for common OSI-approved licenses; document in tracking issue 3 months ago
kalvinparker c97fc90f40 chore(audit): ignore RUSTSEC-2023-0071 and RUSTSEC-2024-0436 in deny.toml (temporary) 3 months ago
kalvinparker a305cf3d6d chore(audit): add advisory exceptions for RUSTSEC-2023-0071 and RUSTSEC-2024-0436 under [advisories] (timeboxed) 3 months ago
kalvinparker a64bf18935 chore(audit): format deny.toml license exceptions as [[licenses.exceptions]] (cargo-deny compatible) 3 months ago
kalvinparker f16723c8d8 chore(audit): add temporary deny exceptions for rsa and paste; add tracking issue and document in audit note 3 months ago
kalvinparker 22ff36919c chore(deps): allow caret ranges for rmpv and openidconnect to permit safe published bumps 3 months ago
kalvinparker eb077610b8 chore(deps): revert attempted openidconnect/rmpv bumps (incompatible with crates.io) 3 months ago
kalvinparker f84d861746 chore(audit): make deny.toml parseable by cargo-deny 3 months ago
kalvinparker 5818cbfff9 chore(audit): fix deny.toml to valid cargo-deny format 3 months ago
kalvinparker e3d25181b5 chore(deps): attempt bump openidconnect and rmpv to avoid transitive rsa/paste 3 months ago
kalvinparker 1f2cadc8b2 chore(audit): add cargo-deny policy, CI audit workflow and security note (2025-11-09) 3 months ago
kalvinparker 54053f7e28 Add audit and deny command error messages to respective files 3 months ago
kalvinparker 0951c8d220 Add supply chain audit workflow with cargo-audit and cargo-deny steps 3 months ago
Mathijs van Veluw 9017ca265a
Optimizations and build speedup (#6339) 3 months ago
Mathijs van Veluw 8d30285160
Fix issue with key-rotation and emergency-access (#6421) 3 months ago
Daniel García 3cd3d33d00
Improve protected actions (#6411) 3 months ago
Mathijs van Veluw 2ee5819b56
Use Diesels MultiConnections Derive (#6279) 3 months ago
Timshel 7c597e88f9
[Playwright] Improvements around node (#6321) 3 months ago
Stefan Melmuk a85b48512c
add seat limit for the invite dialog (#6371) 3 months ago
Stefan Melmuk fe1a8f7738
add missing media-src directive (#6381) 3 months ago
Stefan Melmuk d43edb8f17
add mail address change warning for invited accounts (#6377) 3 months ago
Timshel 8043f7eca7
Fix Org identifier (#6364) 3 months ago
Timshel e659a61581
Add auth_request pending endpoint (#6368) 3 months ago
Stefan Melmuk 2d54cc61df
add new billing warnings endpoint (#6369) 3 months ago
Timshel 3f010a50af
Change OIDC dummy identifier (#6263) 3 months ago
Timshel e83faad8d2
Fix `sso_user` dropped on `User::save` (#6262) 3 months ago
Stefan Melmuk a79cd40ea9
improve permission check for collections (#6278) 3 months ago
Stefan Melmuk b1d84298cc
update web vault to v2025.9.1 and allow new policy (#6340) 3 months ago
Stefan Melmuk a2ad1dc7c3
update trivy-action to v0.33.0 (#6248) 5 months ago
Mathijs van Veluw 7cc4dfabbf
Fix 2fa recovery endpoint (#6240) 5 months ago
Stefan Melmuk 5a8736e116
make webauthn more optional (#6160) 5 months ago
Timshel f76362ff89
Fix panic around sso_master_password_policy (#6233) 5 months ago
Mathijs van Veluw 6db5b7115d
Update crates, gha and web-vault (#6234) 5 months ago
Timshel 3510351f4d
Show SSO_ALLOW_UNKNOWN_EMAIL_VERIFICATION in admin (#6235) 5 months ago
Helmut K. C. Tessarek 7161f612a1
refactor(config): update template, add validation (#6229) 5 months ago
Mathijs van Veluw 5ee908517f
Fix Webauthn/Passkey 2FA migration/validation issues (#6190) 5 months ago
Daniel 55577fa4eb
Re-add `if` check to release workflow (#6227) 5 months ago
Thomas Violent 843c063649
Make database connection pool dynamic (#6166) 5 months ago
Daniel 550b670dba
Switch to GHA's concurrency control (#6164) 5 months ago
Timshel de808c5ad9
Fix Playwright docker (#6206) 5 months ago
Justus Dicker 1f73630136
fix typo in description of helo_name (#6194) 5 months ago
Mathijs van Veluw 77008a91e9
Misc updates (#6185) 5 months ago
Timshel 7f386d38ae
Fix Playwright test conf and update deps (#6176) 5 months ago