An error occurred fetching the project authors.
  1. 23 Jun, 2017 1 commit
  2. 21 Jun, 2017 1 commit
  3. 20 Jun, 2017 1 commit
  4. 16 Jun, 2017 1 commit
  5. 14 Jun, 2017 1 commit
  6. 06 Jun, 2017 2 commits
  7. 02 Jun, 2017 1 commit
  8. 24 May, 2017 3 commits
  9. 25 Apr, 2017 1 commit
    • Timothy Andrew's avatar
      Don't display the `is_admin?` flag for user API responses. · 34b71e73
      Timothy Andrew authored
      - To prevent an attacker from enumerating the `/users` API to get a list of all
        the admins.
      
      - Display the `is_admin?` flag wherever we display the `private_token` - at the
        moment, there are two instances:
      
        - When an admin uses `sudo` to view the `/user` endpoint
        - When logging in using the `/session` endpoint
      34b71e73
  10. 21 Apr, 2017 1 commit
  11. 18 Apr, 2017 1 commit
  12. 14 Apr, 2017 2 commits
  13. 02 Apr, 2017 1 commit
  14. 06 Mar, 2017 2 commits
  15. 01 Mar, 2017 1 commit
  16. 28 Feb, 2017 5 commits
  17. 23 Feb, 2017 2 commits
  18. 20 Feb, 2017 2 commits
  19. 16 Feb, 2017 2 commits
  20. 09 Feb, 2017 1 commit
  21. 02 Feb, 2017 2 commits
  22. 11 Jan, 2017 1 commit
  23. 04 Jan, 2017 1 commit
  24. 03 Jan, 2017 1 commit
  25. 12 Dec, 2016 1 commit
  26. 07 Dec, 2016 1 commit
  27. 28 Nov, 2016 1 commit