Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
faf3d1e056 |
@@ -277,9 +277,7 @@ Each has an ID, and tests name the IDs they check.
|
||||
with passwords. Checked by `tests/e2e/http_basic_auth.py` against the debug
|
||||
build, 26 checks: everything above, both front ends' sign-in path, a wrong
|
||||
password answered exactly as the right one, and a redirect URI the webmail
|
||||
didn't register refused for an ordinary account. Accounts holding
|
||||
`OAuthClientOverride` (administrators) skip client and redirect checks on
|
||||
the sign-in endpoint, as upstream does; that's C-9's gap, not this one's.
|
||||
didn't register refused.
|
||||
Observed before the change, in INBUXA's production logs from 2026-09-20 to 2026-09-29:
|
||||
every HTTPS password sign-in was the operator's own, apart from
|
||||
ihasmail-inbuxa's password sign-in on 2026-09-22, before it moved to OAuth.
|
||||
|
||||
@@ -185,9 +185,9 @@ def main():
|
||||
admin, admin_pw = updated["username"], secret_file("basic-admin", updated["secret"])
|
||||
|
||||
# After setup, the default: Basic on DAV only. What follows needs a
|
||||
# tracer to stdout, to read warnings back, and an account without
|
||||
# administrator rights, which skip client checks (OAuthClientOverride).
|
||||
# Both are made with a token, since Basic no longer reaches JMAP.
|
||||
# tracer to stdout, to read warnings back, and a user account for the
|
||||
# webmail's password check. Both are made with a token, since Basic no
|
||||
# longer reaches JMAP.
|
||||
restart()
|
||||
admin_token, how = token(admin, admin_pw)
|
||||
if not admin_token:
|
||||
|
||||
Reference in New Issue
Block a user