server/apps/updatenotification/lib
Lukas Reschke 5680743c2b Harden updater authentication
- Reset tokens after 2 hours as discussed at https://github.com/owncloud/updater/issues/220#issuecomment-182033453
- Used BCrypt for storing the password in the config.php. This makes it substantially harder in case of a leakage of the token to bruteforce it. In the future we can evaluate also an HMAC including the IP. That's a bit tricker though at the moment considering that we support reverse proxies. Didn't feel brave enough to touch that dragon now as well ;)
2016-02-10 16:31:11 +01:00
..
resettokenbackgroundjob.php Harden updater authentication 2016-02-10 16:31:11 +01:00
updatechecker.php Move update notification code into app 2016-02-09 18:05:51 +01:00