You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
gitea/routers/web
Giteabot d2efd2bf73
Require repo scope for PATs for private repos and basic authentication (#24362) (#24364)
Backport #24362 by @jolheiser

> The scoped token PR just checked all API routes but in fact, some web
routes like `LFS`, git `HTTP`, container, and attachments supports basic
auth. This PR added scoped token check for them.

Signed-off-by: jolheiser <john.olheiser@gmail.com>
Co-authored-by: John Olheiser <john.olheiser@gmail.com>
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
2 years ago
..
admin Fix 500 error if there is a name conflict when edit authentication source (#23832) (#23852) 2 years ago
auth Respect the REGISTER_MANUAL_CONFIRM setting when registering via OIDC (#24035) (#24333) 2 years ago
events Implement FSFE REUSE for golang files (#21840) 2 years ago
explore Add ONLY_SHOW_RELEVANT_REPOS back, fix explore page bug, make code more strict (#23766) (#23791) 2 years ago
feed User/Org Feed render description as per web (#23887) (#23906) 2 years ago
healthcheck Refactor `setting.Database.UseXXX` to methods (#23354) (#23356) 2 years ago
misc Implement FSFE REUSE for golang files (#21840) 2 years ago
org Only delete secrets belonging to its owner (#24284) (#24286) 2 years ago
repo Require repo scope for PATs for private repos and basic authentication (#24362) (#24364) 2 years ago
shared Only delete secrets belonging to its owner (#24284) (#24286) 2 years ago
user Only delete secrets belonging to its owner (#24284) (#24286) 2 years ago
auth.go Implement FSFE REUSE for golang files (#21840) 2 years ago
auth_windows.go Implement FSFE REUSE for golang files (#21840) 2 years ago
base.go Set `X-Gitea-Debug` header once (#23361) (#23381) 2 years ago
goget.go refactor some functions to support ctx as first parameter (#21878) 2 years ago
home.go Implement FSFE REUSE for golang files (#21840) 2 years ago
metrics.go Implement FSFE REUSE for golang files (#21840) 2 years ago
nodeinfo.go Implement FSFE REUSE for golang files (#21840) 2 years ago
swagger_json.go Implement FSFE REUSE for golang files (#21840) 2 years ago
web.go Support "." char as user name for User/Orgs in RSS/ATOM/GPG/KEYS path ... (#23874) (#23878) 2 years ago
webfinger.go Use User.ID instead of User.Name in ActivityPub API for Person IRI (#23823) (#23905) 2 years ago