BigW Consortium Gitlab

  1. 24 May, 2017 3 commits
  2. 25 Apr, 2017 1 commit
    • Don't display the `is_admin?` flag for user API responses. · 34b71e73
      Timothy Andrew authored
      - To prevent an attacker from enumerating the `/users` API to get a list of all
        the admins.
      
      - Display the `is_admin?` flag wherever we display the `private_token` - at the
        moment, there are two instances:
      
        - When an admin uses `sudo` to view the `/user` endpoint
        - When logging in using the `/session` endpoint
  3. 21 Apr, 2017 1 commit
  4. 18 Apr, 2017 1 commit
  5. 14 Apr, 2017 2 commits
  6. 02 Apr, 2017 1 commit
  7. 06 Mar, 2017 2 commits
  8. 01 Mar, 2017 1 commit
  9. 28 Feb, 2017 5 commits
  10. 23 Feb, 2017 2 commits
  11. 20 Feb, 2017 2 commits
  12. 16 Feb, 2017 2 commits
  13. 09 Feb, 2017 1 commit
  14. 02 Feb, 2017 2 commits
  15. 11 Jan, 2017 1 commit
  16. 04 Jan, 2017 1 commit
  17. 03 Jan, 2017 1 commit
  18. 12 Dec, 2016 1 commit
  19. 07 Dec, 2016 1 commit
  20. 28 Nov, 2016 1 commit
  21. 21 Nov, 2016 1 commit
  22. 08 Nov, 2016 1 commit
  23. 24 Oct, 2016 3 commits
  24. 21 Oct, 2016 1 commit
  25. 11 Oct, 2016 2 commits