Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
faf3d1e056 |
@@ -277,9 +277,7 @@ Each has an ID, and tests name the IDs they check.
|
|||||||
with passwords. Checked by `tests/e2e/http_basic_auth.py` against the debug
|
with passwords. Checked by `tests/e2e/http_basic_auth.py` against the debug
|
||||||
build, 26 checks: everything above, both front ends' sign-in path, a wrong
|
build, 26 checks: everything above, both front ends' sign-in path, a wrong
|
||||||
password answered exactly as the right one, and a redirect URI the webmail
|
password answered exactly as the right one, and a redirect URI the webmail
|
||||||
didn't register refused for an ordinary account. Accounts holding
|
didn't register refused.
|
||||||
`OAuthClientOverride` (administrators) skip client and redirect checks on
|
|
||||||
the sign-in endpoint, as upstream does; that's C-9's gap, not this one's.
|
|
||||||
Observed before the change, in INBUXA's production logs from 2026-09-20 to 2026-09-29:
|
Observed before the change, in INBUXA's production logs from 2026-09-20 to 2026-09-29:
|
||||||
every HTTPS password sign-in was the operator's own, apart from
|
every HTTPS password sign-in was the operator's own, apart from
|
||||||
ihasmail-inbuxa's password sign-in on 2026-09-22, before it moved to OAuth.
|
ihasmail-inbuxa's password sign-in on 2026-09-22, before it moved to OAuth.
|
||||||
|
|||||||
@@ -185,9 +185,9 @@ def main():
|
|||||||
admin, admin_pw = updated["username"], secret_file("basic-admin", updated["secret"])
|
admin, admin_pw = updated["username"], secret_file("basic-admin", updated["secret"])
|
||||||
|
|
||||||
# After setup, the default: Basic on DAV only. What follows needs a
|
# After setup, the default: Basic on DAV only. What follows needs a
|
||||||
# tracer to stdout, to read warnings back, and an account without
|
# tracer to stdout, to read warnings back, and a user account for the
|
||||||
# administrator rights, which skip client checks (OAuthClientOverride).
|
# webmail's password check. Both are made with a token, since Basic no
|
||||||
# Both are made with a token, since Basic no longer reaches JMAP.
|
# longer reaches JMAP.
|
||||||
restart()
|
restart()
|
||||||
admin_token, how = token(admin, admin_pw)
|
admin_token, how = token(admin, admin_pw)
|
||||||
if not admin_token:
|
if not admin_token:
|
||||||
|
|||||||
Reference in New Issue
Block a user