mastodon/app/controllers
Eugen Rochko daf71573d0
Fix password change/reset not immediately invalidating other sessions (#12928)
While making browser requests in the other sessions after a password
change or reset does not allow you to be logged in and correctly
invalidates the session making the request, sessions have API tokens
associated with them, which can still be used until that session
is invalidated.

This is a security issue for accounts that were already compromised
some other way because it makes it harder to throw out the hijacker.
2020-01-24 00:20:38 +01:00
..
activitypub
admin Fix relationships page not showing results in admin UI (#12934) 2020-01-24 00:20:23 +01:00
api Add announcements (#12662) 2020-01-23 22:00:13 +01:00
auth Fix password change/reset not immediately invalidating other sessions (#12928) 2020-01-24 00:20:38 +01:00
concerns Fix base64-encoded file uploads not being possible (#12748) 2020-01-04 01:54:07 +01:00
oauth Fix settings pages being cacheable by the browser (#12714) 2019-12-30 04:38:30 +01:00
settings Fix base64-encoded file uploads not being possible (#12748) 2020-01-04 01:54:07 +01:00
well_known Fix uncaught unknown format errors in host meta controller (#12747) 2020-01-03 05:28:56 +01:00
about_controller.rb
account_follow_controller.rb
account_unfollow_controller.rb
accounts_controller.rb
application_controller.rb Fix base64-encoded file uploads not being possible (#12748) 2020-01-04 01:54:07 +01:00
authorize_interactions_controller.rb
custom_css_controller.rb
directories_controller.rb
emojis_controller.rb
filters_controller.rb Fix missing authentication call in filters controller (#12746) 2020-01-03 05:29:08 +01:00
follower_accounts_controller.rb Hide blocked users from more places (#12733) 2019-12-31 00:55:32 +01:00
following_accounts_controller.rb Hide blocked users from more places (#12733) 2019-12-31 00:55:32 +01:00
home_controller.rb
instance_actors_controller.rb
intents_controller.rb
invites_controller.rb
manifests_controller.rb
media_controller.rb
media_proxy_controller.rb
public_timelines_controller.rb
relationships_controller.rb Change followers page to relationships page in admin UI (#12927) 2020-01-23 20:33:20 +01:00
remote_follow_controller.rb
remote_interaction_controller.rb
shares_controller.rb
statuses_controller.rb
tags_controller.rb