kanidm/server
Firstyear 3430a1c31d
Ignore anonymous in oauth2 read allow access (#3336)
Administrators will sometimes configure oauth2 clients with `idm_all_accounts`
as an allowed scope group. Despite anonymous being *unable* to interact with
oauth2, this still allowed oauth2 clients to be read by anonymous in this
configuration. For some users, this may be considered a public info
disclosure.
2025-01-04 03:09:48 +00:00
..
core cookies don't clear unless you set domain (#3332) 2025-01-04 00:33:01 +00:00
daemon 20250102 freebsd client (#3333) 2025-01-04 09:22:44 +10:00
lib Ignore anonymous in oauth2 read allow access (#3336) 2025-01-04 03:09:48 +00:00
lib-macros OAuth2 Token Type (#3008) 2024-08-25 23:30:20 +00:00
testkit Bump the all group with 6 updates (#3324) 2024-12-29 22:46:26 +00:00
testkit-macros CLI integration test beginnings (#2261) 2023-10-30 06:10:54 +00:00
builder.sh 1399 cleanup reorg (#1412) 2023-03-01 13:10:52 +10:00
Dockerfile Remove WASM (#3148) 2024-10-26 17:19:13 +10:00