* Users are only authenticated against their password on login, and to retrieve a token. * Passwords are wiped from the app and cookies after login and token retrieval * Tokens are revoked at the end of the session/logout * If the user chooses the "remember me" option, the token is stored in the cookie * A user interface to revoke tokens will be added * Tokens correctly delete themselves on logout * API documentation updated for the new user-token endpoints * Added a Manage tokens tab to the user panel * Added bullet point about the token authentication for the API * Added tests for new endpoints and tests against authentication middleware |
||
---|---|---|
.. | ||
abstract_list.js | ||
comment.js | ||
comment_list.js | ||
info.js | ||
note.js | ||
note_list.js | ||
point.js | ||
point_list.js | ||
post.js | ||
post_list.js | ||
settings.js | ||
snapshot.js | ||
snapshot_list.js | ||
tag.js | ||
tag_category.js | ||
tag_category_list.js | ||
tag_list.js | ||
top_navigation.js | ||
user.js | ||
user_list.js | ||
user_token.js |