mirror of https://github.com/go-gitea/gitea.git
You cannot select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
See discussion on #31561 for some background. The introspect endpoint was using the OIDC token itself for authentication. This fixes it to use basic authentication with the client ID and secret instead: * Applications with a valid client ID and secret should be able to successfully introspect an invalid token, receiving a 200 response with JSON data that indicates the token is invalid * Requests with an invalid client ID and secret should not be able to introspect, even if the token itself is valid Unlike #31561 (which just future-proofed the current behavior against future changes to `DISABLE_QUERY_AUTH_TOKEN`), this is a potential compatibility break (some introspection requests without valid client IDs that would previously succeed will now fail). Affected deployments must begin sending a valid HTTP basic authentication header with their introspection requests, with the username set to a valid client ID and the password set to the corresponding client secret. |
7 months ago | |
---|---|---|
.. | ||
e2e | 8 months ago | |
fuzz | 1 year ago | |
gitea-lfs-meta | 2 years ago | |
gitea-repositories-meta | 11 months ago | |
integration | 7 months ago | |
testdata/data/attachments/a/0 | 1 year ago | |
mssql.ini.tmpl | 9 months ago | |
mysql.ini.tmpl | 1 year ago | |
pgsql.ini.tmpl | 9 months ago | |
sqlite.ini.tmpl | 1 year ago | |
test_utils.go | 10 months ago |