Nicola Murino
ba8f7823f1
don't allow DSA keys
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-12-18 19:01:55 +01:00
Nicola Murino
ecf7e0b49c
dataprovider events: fix string formatting for program hook
...
Fixes #1845
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-12-18 18:35:51 +01:00
Nicola Murino
503508d962
update deps
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-12-15 12:02:56 +01:00
Nicola Murino
814f5022b1
set stat: remove unecessary check
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-12-15 11:58:14 +01:00
Nicola Murino
cface046dd
replace fnv with sha256
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-12-14 14:47:48 +01:00
Nicola Murino
29cccddce1
EventManager: check file size for more events
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-12-14 13:25:11 +01:00
Nicola Murino
386448e6cb
set version to 2.6.4
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
v2.6.4
2024-11-27 19:08:13 +01:00
Nicola Murino
39c30c7d14
use GenerateOpaqueString also for node secrets
...
this method will use rand.Text() with Go 1.24
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-27 19:06:25 +01:00
Nicola Murino
d1d7ab25ad
CI: skip signing Windows binaries for pull requests
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-23 19:27:13 +01:00
Nicola Murino
cf1e650d53
CI: update workflows to use Azure Trusted Signing
...
Fixes #1778
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-22 18:51:41 +01:00
Nicola Murino
cb6609e468
sftpd: disable allocator
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-21 07:54:48 +01:00
Nicola Murino
3a47ba3ff9
silence lint warning
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-21 07:45:23 +01:00
Nicola Murino
5212095b89
EventManager: always close the connection filesystem
...
closing the user filesystem is not enough here
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-20 21:17:16 +01:00
Nicola Murino
2fad0467d9
upgrade nfpm to 2.41.1
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-20 18:26:41 +01:00
Nicola Murino
2658d06682
IDC cookie: use a cryptographically secure random string
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-20 18:26:23 +01:00
Nicola Murino
cf3e1d3ec0
update deps
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
v2.6.3
2024-11-15 17:26:44 +01:00
Nicola Murino
ebad3f93f5
fix license in Windows installer
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-15 17:04:02 +01:00
Nicola Murino
c056c4e52c
fix links to docs, add NOTICE to build artifacts
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-15 15:48:59 +01:00
Nicola Murino
e48b76821f
provider rule events: allows you to filter by user groups
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-15 13:54:08 +01:00
Nicola Murino
a3ed0f2d14
prepare v2.6.3
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-14 21:05:24 +01:00
Nicola Murino
d7d08c3d2f
oidc/oauth2: use an opaque state
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-11 19:44:39 +01:00
Nicola Murino
f3a58b8ecc
fix new lint warnings
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-10 20:59:30 +01:00
Nicola Murino
3b68d0343a
events: add copy action
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-10 15:00:16 +01:00
Nicola Murino
fc4527354b
update css and js deps
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-10 12:34:17 +01:00
Nicola Murino
f07c9a7e01
EventManager: disable commands by default
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-10 12:09:25 +01:00
Nicola Murino
d0f348a46a
WebAdmin and REST API: remove too granular permissions
...
Our permissions system for admin users is too granular and some
permissions overlap. For example, you can define an administrator
with the "manage_system" permission and not with the "manage_admins"
or "manage_user" permission, but the "manage_system" permission
allows you to restore a backup and then create users and
administrators. The following permissions will be removed:
"manage_admins", "manage_apikeys", "manage_system", "retention_checks",
"manage_event_rules", "manage_roles", "manage_ip_lists". Now you
need to add the "*" permission to replace the removed granular
permissions because the removed permissions allow actions that
should only be allowed to super administrators.
There is no point in having separate, overlapping permissions.
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-10 10:51:27 +01:00
Nicola Murino
65e8e2c1d4
don't allow admins to change their own permissions
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-09 20:33:03 +01:00
Nicola Murino
5c163ed592
EventManager: allow to define the allowed system commands
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-09 19:14:45 +01:00
Nicola Murino
1df1b8e4b5
update deps
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-09 18:56:07 +01:00
Nicola Murino
feaf3ac459
WebAdmin: check CSRF header when deleting blocked hosts
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-09 18:50:31 +01:00
Nicola Murino
f363d037a7
remove fallback if rand.Reader fails
...
Failing to read from rand.Reader essentially can't happen, and if it
does is not possible to fallback securely, so just panic
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-09 18:48:48 +01:00
Nicola Murino
f13eab1caf
CI: re-enable build packages with Go latest
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-07 20:17:48 +01:00
Nicola Murino
dda89185fb
plugins: fix passing additional environment variables
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-11-05 18:07:24 +01:00
Nicola Murino
b4acae85b8
proxy protocol: improve logging
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-31 14:30:49 +01:00
Nicola Murino
bc317775d2
plugin: remove invalid chars from error message
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-29 18:12:42 +01:00
Nicola Murino
10e4843a18
WebAdmin active connections: fix active transfer display
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-28 20:13:26 +01:00
Nicola Murino
256e3c1e3e
node: use a plain string as key
...
Some KMS providers only allow UTF-8 characters
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-28 14:33:38 +01:00
Nicola Murino
b4eabda7ad
update deps
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-26 21:31:38 +02:00
Nicola Murino
5f659aa7b1
OpenAPI: document password_strength
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-26 21:12:23 +02:00
Nicola Murino
b8fa4e72b4
update translations
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-21 20:41:53 +02:00
Nicola Murino
ccfe71b3fc
update README
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-18 19:22:29 +02:00
Nicola Murino
d3c15b0d6f
add License NOTICE
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-18 19:22:23 +02:00
Nicola Murino
9c744da620
DirLister: returns appropriate protocol errors
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-16 19:05:11 +02:00
Nicola Murino
7d24a4852c
WebAdmin SMTP: ensure current config is not nil
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-15 18:23:28 +02:00
Nicola Murino
87fdc1dec1
Web: add CheckRedirect to pages using baselogin.html
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-12 12:54:32 +02:00
Nicola Murino
cdbb376376
EventManager: add escaped virtual path
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-12 11:28:03 +02:00
Rafał Bielawski
07616f7b7a
Update translation.json ( #1781 )
...
Signed-off-by: Rafał Bielawski <hello@rbielawski.pl >
2024-10-12 11:27:12 +02:00
Nicola Murino
5d087f6abe
CI: update FreeBSD version to 14.1
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-08 19:21:21 +02:00
Nicola Murino
18a014b95e
CI: disable GRPC modules
...
we don't use this feature for now
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-08 19:15:25 +02:00
Nicola Murino
472bfac5fe
EventManager: add datetime placeholder
...
Signed-off-by: Nicola Murino <nicola.murino@gmail.com >
2024-10-08 19:15:07 +02:00