pomerium/authorize
Kenneth Jenkins e7b4cc9a9b auth: prevent caching of sign-in redirect
Add a 'Cache-Control: no-store' header to the sign-in redirect at the
start of the authentication flow. This should discourage browsers from
caching this redirect.
2024-01-12 15:19:51 -08:00
..
evaluator core/ci: update linting (#4844) 2023-12-14 09:07:54 -08:00
internal/store authorize: move sign out and jwks urls to route, update issuer for JWT (#4046) 2023-03-08 12:40:15 -07:00
access_tracker.go rework session updates to use new patch method (#4705) 2023-11-06 09:43:07 -08:00
access_tracker_test.go databroker: add support for putting multiple records (#3291) 2022-04-26 16:41:38 -06:00
authorize.go authorize: reuse policy evaluators where possible (#4710) 2023-11-06 13:57:59 -08:00
authorize_test.go authenticateflow: move stateless flow logic (#4820) 2023-12-06 16:55:57 -08:00
check_response.go auth: prevent caching of sign-in redirect 2024-01-12 15:19:51 -08:00
check_response_test.go auth: prevent caching of sign-in redirect 2024-01-12 15:19:51 -08:00
databroker.go core/authorize: check for expired tokens (#4543) 2023-09-15 16:06:13 -06:00
databroker_test.go core/authorize: check for expired tokens (#4543) 2023-09-15 16:06:13 -06:00
grpc.go core/authorize: check for expired tokens (#4543) 2023-09-15 16:06:13 -06:00
grpc_test.go chore(deps): bump github.com/spf13/viper from 1.16.0 to 1.18.2 (#4861) 2023-12-27 16:16:38 -07:00
log.go authorize: log id token claims separately from id token (#4394) 2023-07-26 11:45:10 -06:00
log_test.go authorize: log id token claims separately from id token (#4394) 2023-07-26 11:45:10 -06:00
state.go support both stateful and stateless authenticate (#4765) 2023-12-07 14:24:13 -08:00