~bigbes/core-go

900693b8 — Drew DeVault 5 years ago
crypto: harden API surface

Make it explicit that expiration is not being tested with Decrypt, and
test that the expiration is meaningful with DecryptWithExpiration.
12996e4a — Simon Ser 5 years ago
client: add config option to override API origin

If the config file contains an "api-origin" key for a service, prefer it
instead of "origin". This allows users to directly point the Python
frontend to the Go backend for local development, without having to
setup a reverse proxy.

This is the Go port of [1].

While at it, use GetOrigin for symmetry with the Python code.

[1]: https://git.sr.ht/~sircmpwn/meta.sr.ht/commit/6c2ee03923fe65423a2c55e6648f555c08db827a
52d6dc99 — Drew DeVault 5 years ago
Fix bug with internal authentication
7be038e7 — Drew DeVault 5 years ago
Make authorization errors more specific
6bcaea61 — Drew DeVault 5 years ago
server: set max upload size to 1 GiB
906acc05 — Drew DeVault 5 years ago
client: populate NodeID from service name
4cc9b34f — Drew DeVault 5 years ago
database.Apply: add support for non-pointer fields
33562018 — Drew DeVault 5 years ago
database.WithTx: rollback if func returns error

Previously, this only rolled back if the called function panicked. This
updates it to also roll back if the called function returns an error.
31fc9fce — Drew DeVault 5 years ago
Fetch user PGP key for meta.sr.ht
e1acd5a8 — Drew DeVault 5 years ago
Correct TODO for context which is invariant
407afe7d — Drew DeVault 5 years ago
Update dependencies
a30dcb39 — Drew DeVault 5 years ago
Prohibit OAuth client auth for revoked clients
5de4cd8e — Drew DeVault 5 years ago
Stash remote address in context
177d60f9 — Drew DeVault 5 years ago
Encrypt outgoing emails
606ff2ef — Drew DeVault 5 years ago
Sign outgoing emails
bdd0eb3d — Thorben Günther 5 years ago
Print IP with "invalid source IP" authError
0d5262df — Drew DeVault 5 years ago
config: add GetOrigin function

This implements the same behavior as Python's srht.config.get_origin.
910a8619 — Drew DeVault 5 years ago
webhooks/legacy_test: verify headers are recorded
b98647b6 — Drew DeVault 5 years ago
Deduplicate webhook headers on subsequent attempts

This also updates the database with the final payload headers, including
the signature and nonce, which are generated afresh for each attempt.
70c7fe3b — Drew DeVault 5 years ago
webhooks/legacy: increase specificity of logging
Next