0
0
Fork 0
mirror of https://github.com/go-gitea/gitea synced 2024-12-25 19:34:38 +01:00
gitea/routers/web
John Olheiser 5e36024105
Require repo scope for PATs for private repos and basic authentication (#24362)
> The scoped token PR just checked all API routes but in fact, some web
routes like `LFS`, git `HTTP`, container, and attachments supports basic
auth. This PR added scoped token check for them.

---------

Signed-off-by: jolheiser <john.olheiser@gmail.com>
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
2023-04-26 19:24:03 -05:00
..
admin Use auto-updating, natively hoverable, localized time elements (#23988) 2023-04-11 01:01:20 +02:00
auth Respect the REGISTER_MANUAL_CONFIRM setting when registering via OIDC (#24035) 2023-04-25 14:40:48 +08:00
devtest Remove untranslatable on_date key (#24106) 2023-04-15 13:01:54 +02:00
events
explore
feed Improve RSS (#24335) 2023-04-25 22:53:44 -04:00
healthcheck
misc
org Fix 404 error when leaving the last private org team (#24322) 2023-04-26 12:27:46 -04:00
repo Require repo scope for PATs for private repos and basic authentication (#24362) 2023-04-26 19:24:03 -05:00
shared Only delete secrets belonging to its owner (#24284) 2023-04-23 21:35:14 +08:00
user Only delete secrets belonging to its owner (#24284) 2023-04-23 21:35:14 +08:00
auth.go
auth_windows.go
base.go Improve Wiki TOC (#24137) 2023-04-17 15:05:19 -04:00
goget.go
home.go Refactor cookie (#24107) 2023-04-13 15:45:33 -04:00
metrics.go
nodeinfo.go
swagger_json.go Group template helper functions, remove Printf, improve template error messages (#23982) 2023-04-08 21:15:22 +08:00
web.go Improve RSS (#24335) 2023-04-25 22:53:44 -04:00
webfinger.go Use User.ID instead of User.Name in ActivityPub API for Person IRI (#23823) 2023-04-04 10:08:23 +08:00