You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
gitea/routers/web
Shivaram Lingamneni 2f1cb1d289
fix OIDC introspection authentication (#31632)
See discussion on #31561 for some background.

The introspect endpoint was using the OIDC token itself for
authentication. This fixes it to use basic authentication with the
client ID and secret instead:

* Applications with a valid client ID and secret should be able to
  successfully introspect an invalid token, receiving a 200 response
  with JSON data that indicates the token is invalid
* Requests with an invalid client ID and secret should not be able
  to introspect, even if the token itself is valid

Unlike #31561 (which just future-proofed the current behavior against
future changes to `DISABLE_QUERY_AUTH_TOKEN`), this is a potential
compatibility break (some introspection requests without valid client
IDs that would previously succeed will now fail). Affected deployments
must begin sending a valid HTTP basic authentication header with their
introspection requests, with the username set to a valid client ID and
the password set to the corresponding client secret.
7 months ago
..
admin Refactor names (#31405) 8 months ago
auth fix OIDC introspection authentication (#31632) 7 months ago
devtest Refactor names (#31405) 8 months ago
events Move context from modules to services (#29440) 1 year ago
explore Refactor names (#31405) 8 months ago
feed Refactor names (#31405) 8 months ago
healthcheck Always enable caches (#28527) 1 year ago
misc Make sure git version&feature are always prepared (#30877) 10 months ago
org Refactor names (#31405) 8 months ago
repo Refactor webhook (#31587) 8 months ago
shared Refactor names (#31405) 8 months ago
user add skip secondary authorization option for public oauth2 clients (#31454) 7 months ago
base.go Azure blob storage support (#30995) 9 months ago
githttp.go Refactor names (#31405) 8 months ago
goget.go Move context from modules to services (#29440) 1 year ago
home.go migrate some more "OptionalBool" to "Option[bool]" (#29479) 1 year ago
metrics.go Implement FSFE REUSE for golang files (#21840) 2 years ago
nodeinfo.go Move context from modules to services (#29440) 1 year ago
passkey.go Move context from modules to services (#29440) 1 year ago
swagger_json.go Move context from modules to services (#29440) 1 year ago
web.go Add Passkey login support (#31504) 8 months ago
webfinger.go Move context from modules to services (#29440) 1 year ago