* Don't allow for plain username/password authentication when 2FA is enabled * Removed debugging statement * Don't assume a token belongs to a given user, handle two-factor errors properly * Simplified user/token matching, refactored error handling for two-factor authentication * Change authentication response to avoid bruteforcing * Add TODO item as a comment for changing the response for security purposes |
||
|---|---|---|
| .. | ||
| attachment.go | ||
| branch.go | ||
| commit.go | ||
| download.go | ||
| editor.go | ||
| http.go | ||
| issue.go | ||
| issue_label.go | ||
| issue_watch.go | ||
| middlewares.go | ||
| pull.go | ||
| release.go | ||
| repo.go | ||
| setting.go | ||
| view.go | ||
| webhook.go | ||
| wiki.go | ||