forgejo-federation/routers/api/v1
zeripath b82293270c
Add option to provide signature for a token to verify key ownership (#14054)
* Add option to provide signed token to verify key ownership

Currently we will only allow a key to be matched to a user if it matches
an activated email address. This PR provides a different mechanism - if
the user provides a signature for automatically generated token (based
on the timestamp, user creation time, user ID, username and primary
email.

* Ensure verified keys can act for all active emails for the user

* Add code to mark keys as verified

* Slight UI adjustments

* Slight UI adjustments 2

* Simplify signature verification slightly

* fix postgres test

* add api routes

* handle swapped primary-keys

* Verify the no-reply address for verified keys

* Only add email addresses that are activated to keys

* Fix committer shortcut properly

* Restructure gpg_keys.go

* Use common Verification Token code

Signed-off-by: Andrew Thornton <art27@cantab.net>
2021-07-13 15:28:07 +02:00
..
admin Add Visible modes function from Organisation to Users too (#16069) 2021-06-26 20:53:14 +01:00
misc Refactor renders (#15175) 2021-04-19 18:25:08 -04:00
notify [API] expose repo.GetReviewers() & repo.GetAssignees() (#16168) 2021-06-17 16:02:34 +02:00
org Add Visible modes function from Organisation to Users too (#16069) 2021-06-26 20:53:14 +01:00
repo Let branch/tag name be a valid ref to get CI status (#16400) 2021-07-13 08:14:14 +01:00
settings Add custom emoji support (#16004) 2021-06-29 16:28:38 +02:00
swagger Creating a repo from a template repo via API (#15958) 2021-07-05 17:29:08 +02:00
user Add option to provide signature for a token to verify key ownership (#14054) 2021-07-13 15:28:07 +02:00
utils Let branch/tag name be a valid ref to get CI status (#16400) 2021-07-13 08:14:14 +01:00
api.go Add option to provide signature for a token to verify key ownership (#14054) 2021-07-13 15:28:07 +02:00