AgeCommit message (Expand)AuthorLines
Move the cookie-signing secret out of the cachev2.3.0Bryce Kwon-1/+1
Trim the lua headers and fix the Scintillua notesBryce Kwon-30/+3
Fix cookie name escaping and stored hash trimmingBryce Kwon-1/+10
Reorganize the tree into vendor/ and custom/Bryce Kwon-0/+0
Harden and reorganize the auth filtersBryce Kwon-147/+322
Harden the auth filter headers and session cookieBryce Kwon-5/+31
Prune and rename the filter extensionsBryce Kwon-2/+15
Reorganize into source, assets and librariesBryce Kwon-0/+0
filters: migrate from luacrypto to luaosslJason A. Donenfeld-12/+19
auth-filters: use crypt() in simple-authenticationJason A. Donenfeld-13/+6
auth-filters: generate secret securelyJason A. Donenfeld-8/+42
auth-filters: do not use HMAC-SHA1Jason A. Donenfeld-2/+2
simple-authentication.lua: tie secure cookies to field namesJason A. Donenfeld-13/+21
simple-authentication: styleJason A. Donenfeld-1/+1
auth: document tweakables in lua scriptJason A. Donenfeld-0/+10
auth: have cgit calculate login addressJason A. Donenfeld-6/+1
auth: lua string comparisons are time invariantJason A. Donenfeld-2/+2
authentication: use hidden form instead of refererJason A. Donenfeld-79/+121
auth: add basic authentication filter frameworkJason A. Donenfeld-0/+225