0
0
mirror of https://github.com/go-gitea/gitea.git synced 2025-10-24 18:40:04 +02:00
zeripath b82293270c
Add option to provide signature for a token to verify key ownership (#14054)
* Add option to provide signed token to verify key ownership

Currently we will only allow a key to be matched to a user if it matches
an activated email address. This PR provides a different mechanism - if
the user provides a signature for automatically generated token (based
on the timestamp, user creation time, user ID, username and primary
email.

* Ensure verified keys can act for all active emails for the user

* Add code to mark keys as verified

* Slight UI adjustments

* Slight UI adjustments 2

* Simplify signature verification slightly

* fix postgres test

* add api routes

* handle swapped primary-keys

* Verify the no-reply address for verified keys

* Only add email addresses that are activated to keys

* Fix committer shortcut properly

* Restructure gpg_keys.go

* Use common Verification Token code

Signed-off-by: Andrew Thornton <art27@cantab.net>
2021-07-13 15:28:07 +02:00
..
2020-03-22 11:12:55 -04:00
2019-11-12 16:33:34 +08:00
2020-03-22 11:12:55 -04:00
2020-01-13 18:33:46 +01:00
2020-03-09 00:08:05 +02:00
2020-04-01 01:14:46 -03:00
2020-05-15 15:05:18 +01:00
2021-01-28 23:58:33 +01:00
2020-09-20 00:44:55 +08:00
2021-02-20 15:02:39 +01:00
2021-01-29 23:52:13 +08:00
2021-02-11 18:32:25 +01:00
2021-03-24 19:27:22 +01:00
2021-03-24 19:27:22 +01:00
2021-04-08 18:25:57 -04:00
2021-04-14 14:02:12 +02:00
2021-06-23 17:12:38 -04:00
2021-06-23 17:12:38 -04:00
2021-06-25 16:28:55 +02:00