* Users are only authenticated against their password on login, and to retrieve a token. * Passwords are wiped from the app and cookies after login and token retrieval * Tokens are revoked at the end of the session/logout * If the user chooses the "remember me" option, the token is stored in the cookie * A user interface to revoke tokens will be added * Tokens correctly delete themselves on logout * API documentation updated for the new user-token endpoints * Added a Manage tokens tab to the user panel * Added bullet point about the token authentication for the API * Added tests for new endpoints and tests against authentication middleware |
||
---|---|---|
.. | ||
colors.styl | ||
comment-control.styl | ||
comment-list-control.styl | ||
comment-list-view.styl | ||
core-forms.styl | ||
core-general.styl | ||
expander-control.styl | ||
help-view.styl | ||
home-view.styl | ||
mixins.styl | ||
nprogress.styl | ||
pager.styl | ||
password-reset.styl | ||
post-content-control.styl | ||
post-detail-view.styl | ||
post-list-view.styl | ||
post-main-view.styl | ||
post-notes-overlay-control.styl | ||
post-upload.styl | ||
snapshots-list-view.styl | ||
tag-categories-view.styl | ||
tag-input-control.styl | ||
tag-list-view.styl | ||
tag-view.styl | ||
user-list-view.styl | ||
user-registration.styl | ||
user-view.styl |