Jeremy Lin
d5c760960a
Sync global_domains.json to bitwarden/server@af85e17 (eBay India updates)
4 years ago
Jeremy Lin
2c6ef2bc68
Sync global_domains.json to bitwarden/server@2c43019 (eBay updates)
4 years ago
Jeremy Lin
7032ae5587
Sync global_domains.json to bitwarden/server@6aed80a (Amazon updates)
4 years ago
Jeremy Lin
6d9f03e84b
Sync global_domains.json to bitwarden/server@61b11e3
4 years ago
Daniel García
6a972e4b19
Make the admin URL redirect try to use the referrer first, and use /admin when DOMAIN is not configured and the referrer check doesn't work, to allow users without DOMAIN configured to use the admin page correctly
4 years ago
Daniel García
93b7ded1e6
Remove unneccessary shim for backtrace
4 years ago
Daniel García
29c6b145ca
Remove redundant user fetching from login
4 years ago
Daniel García
a7a479623c
Merge pull request #1087 from jjlin/org-creation-users
...
Add support for restricting org creation to certain users
4 years ago
Jeremy Lin
05b308b8b4
Sync global_domains.json with upstream
4 years ago
Jeremy Lin
570d6c8bf9
Add support for restricting org creation to certain users
4 years ago
Daniel García
ad48e9ed0f
Fix unlock on desktop clients
4 years ago
Jeremy Lin
a846f6c610
Fix soft delete notifications
...
A soft-deleted entry should now show up in the trash folder immediately
(previously, an extra sync was required).
4 years ago
Daniel García
fd1354d00e
Merge pull request #1067 from jjlin/log-time-fmt
...
Add config option for log timestamp format
4 years ago
Jeremy Lin
071a3b2a32
Log timestamps with milliseconds by default
4 years ago
Daniel García
32cfaab5ee
Updated dependencies and changed rocket request imports
4 years ago
Jeremy Lin
d348f12a0e
Add config option for log timestamp format
4 years ago
Jeremy Lin
de70fbf88a
Use `strip_prefix()` instead of `trim_start_matches()` as appropriate
...
As of Rust 1.45.0, `strip_prefix()` is now stable.
4 years ago
Daniel García
1e950c7dbc
Replace IP support in preparation for compiling on stable, included some tests to check that the code matches the unstable implementation
4 years ago
Daniel García
f14e19a3d8
Don't compile the regexes each time
4 years ago
Daniel García
668d5c23dc
Removed try_trait and some formatting, particularly around imports
4 years ago
Jeremy Lin
790146bfac
Fix error in PostgreSQL build
4 years ago
Jeremy Lin
a28ebcb401
Use local time in email notifications for new device logins
...
In this implementation, the `TZ` environment variable must be set
in order for the formatted output to use a more user-friendly
time zone abbreviation (e.g., `UTC`). Otherwise, the output uses
the time zone's UTC offset (e.g., `+00:00`).
4 years ago
Daniel García
77e47ddd1f
Merge pull request #1042 from jjlin/hide-passwords
...
Add support for hiding passwords in a collection
4 years ago
Daniel García
596c9b8691
Add option to set name during HELO in email settings
4 years ago
Armaan Tobaccowalla
624791e09a
Allow postgres:// DATABASE_URL
4 years ago
Jeremy Lin
f9a73a9bbe
More cipher optimization/cleanup
4 years ago
Jeremy Lin
35868dd72c
Optimize cipher queries
4 years ago
Jeremy Lin
979d010dc2
Add support for hiding passwords in a collection
...
Ref: https://github.com/bitwarden/server/pull/743
4 years ago
Daniel García
a87646b8cb
Some format changes to main.rs
5 years ago
BlackDex
24c914799d
Fixes #1022 cloning with attachments
...
When a cipher has one or more attachments it wasn't able to be cloned.
This commit fixes that issue.
5 years ago
BlackDex
325691e588
Fixed wrong status if there is an update.
...
- Checking the sha hash first if this is also in the server version.
- Added a badge to show if you are on a branched build.
5 years ago
Robert Kaussow
afbf1db331
add back openssl crate
5 years ago
BlackDex
ac2723f898
Updated Organizations overview
...
- Changed HTML to match users overview
- Added User count
- Added Org cipher amount
- Added Attachment count and size
5 years ago
BlackDex
2fffaec226
Added attachment info per user and some layout fix
...
- Added the amount and size of the attachments per user
- Changed the items count function a bit
- Some small layout changes
5 years ago
BlackDex
5c54dfee3a
Fixed an issue when DNS resolving fails.
...
In the event of a failed DNS Resolving checking for new versions will
cause a huge delay, and in the end a timeout when loading the page.
- Check if DNS resolving failed, if that is the case, do not check for
new versions
- Changed `fn get_github_api` to make use of structs
- Added a timeout of 10 seconds for the version check requests
- Moved the "Unknown" lables to the "Latest" lable
5 years ago
BlackDex
b47cf97409
Updated js/css libraries and fixed smallscreen err
...
- Updated bootstrap js and css to the latest version
- Fixed issue with small-screens where the menu overlaps the token input
- The menu now collapses to a hamburger menu
- Menu's only accessable when logedin are hidden when you are not
- Changed Users Overview to use a table to prevent small-screen issues.
5 years ago
Daniel García
5e802f8aa3
Update lettre to alpha release instead of git commit, and update the rest of dependencies while we are at it
5 years ago
Daniel García
0bdeb02a31
Merge pull request #1009 from jjlin/email-subject
...
Don't HTML-escape email subject lines
5 years ago
Jeremy Lin
39d1a09704
Avoid double-slashes in the admin URL
5 years ago
Jeremy Lin
a447e4e7ef
Don't HTML-escape email subject lines
...
For example, this causes org names like `X&Y` to appear as `X&Y`.
5 years ago
BlackDex
b6fde857a7
Added version check to diagnostics
...
- Added a version check based upon the github api information.
5 years ago
BlackDex
3c66deb5cc
Redesign of the admin interface.
...
Main changes:
- Splitted up settings and users into two separate pages.
- Added verified shield when the e-mail address has been verified.
- Added the amount of personal items in the database to the users overview.
- Added Organizations and Diagnostics pages.
- Shows if DNS resolving works.
- Shows if there is a posible time drift.
- Shows current versions of server and web-vault.
- Optimized logo-gray.png using optipng
Items which can be added later:
- Amount of cipher items accessible for a user, not only his personal items.
- Amount of users per Org
- Version update check in the diagnostics overview.
- Copy/Pasteable runtime config which has sensitive data changed or removed for support questions either on the forum or github issues.
- Option to delete Orgs and all its passwords (when there are no members anymore).
- Etc....
5 years ago
Jeremy Lin
a314933557
Allow email changes for existing accounts even when signups are disabled
5 years ago
Daniel García
c5d7e3f2bc
Merge pull request #1003 from frdescam/fix_arm_displaysize
...
Use format! for rounding to fix arm issue
5 years ago
Daniel García
c95a2881b5
Merge pull request #998 from frdescam/fix_email_templates
...
Fixing bad width in 2FA email template
5 years ago
fdeĉ
4c3727b4a3
use format! for rounding to fix arm issue
5 years ago
Daniel García
a8870eef0d
Convert to f32 before rounding to fix arm issue
5 years ago
François
afaebc6cf3
fixing hard coded width email templates
5 years ago
François
8f4a1f4fc2
fixing bad width in 2FA email template
5 years ago
Daniel García
0807783388
Add ip on totp miss
5 years ago
Daniel García
dc2f8e5c85
Merge pull request #994 from jjlin/help-text
...
Update startup banner to direct usage/config questions to the forum
5 years ago
Daniel García
aee1ea032b
Merge pull request #989 from theycallmesteve/update_responses
...
Update responses
5 years ago
Jeremy Lin
322a08edfb
Update startup banner to direct usage/config questions to the forum
5 years ago
theycallmesteve
08afc312c3
Add missing items to profileOrganization response model
5 years ago
theycallmesteve
5571a5d8ed
Update post_keys to return a keys response model
5 years ago
theycallmesteve
6a8c65493f
Rename collection_user_details to collection_read_only to reflect the response model
5 years ago
theycallmesteve
dfdf4473ea
Rename to_json_list to to_json_provder to reflect the response model
5 years ago
theycallmesteve
42e37ebea1
Apply upstream global domain values and whitespace fixes
5 years ago
theycallmesteve
632f4d5453
Whitespace fixes
5 years ago
Daniel García
6c5e35ce5c
Change the mails content types to more closely match what we sent before
5 years ago
Daniel García
4ff15f6dc2
Merge pull request #978 from AltiUP/patch-1
...
Delete the call to the map file
5 years ago
Daniel García
ec8028aef2
Merge pull request #979 from jjlin/admin-redirect
...
Use absolute URIs for admin page redirects
5 years ago
Daniel García
63cbd9ef9c
Update lettre to latest master
5 years ago
Daniel García
9cca64003a
Remove unused dependency and simple feature, update dependencies and fix some clippy lints
5 years ago
Jeremy Lin
819d5e2dc8
Use absolute URIs for admin page redirects
...
This is technically required per RFC 2616 (HTTP/1.1); some proxies will
rewrite a plain `/admin` path to an unexpected URL otherwise.
5 years ago
Christophe Gherardi
3b06ab296b
Delete the call to the map file
...
The file bootstrap.css.map is missing, the reference can be deleted.
5 years ago
Daniel García
0de52c6c99
Merge pull request #957 from jjlin/domain-whitelist
...
Domain whitelist cleanup and fixes
5 years ago
Daniel García
e3b00b59a7
Initial support for soft deletes
5 years ago
BlackDex
1ee8e44912
Fixed issue #965
...
PostgreSQL updates/inserts ignored None/null values.
This is nice for new entries, but not for updates.
Added derive option to allways add these none/null values for Option<>
variables.
This solves issue #965
5 years ago
Jeremy Lin
86685c1cd2
Ensure email domain comparison is case-insensitive
5 years ago
Jeremy Lin
0a68de6c24
Warn on empty `ADMIN_TOKEN` instead of bailing out
...
The admin page will still be disabled.
Fixes #849 .
5 years ago
Jeremy Lin
e4d08836e2
Make org owner invitations respect the email domain whitelist
...
This closes a loophole where org owners can invite new users from any domain.
5 years ago
Jeremy Lin
c2a324e5da
Clean up domain whitelist logic
...
* Make `SIGNUPS_DOMAINS_WHITELIST` override the `SIGNUPS_ALLOWED` setting.
Otherwise, a common pitfall is to set `SIGNUPS_DOMAINS_WHITELIST` without
realizing that `SIGNUPS_ALLOWED=false` must also be set.
* Whitespace is now accepted in `SIGNUPS_DOMAINS_WHITELIST`. That is,
`foo.com, bar.com` is now equivalent to `foo.com,bar.com`.
* Add validation on `SIGNUPS_DOMAINS_WHITELIST`. For example, `foo.com,`
is rejected as containing an empty token.
5 years ago
Jeremy Lin
6cd8512bbd
Fix Duo auth failure with non-lowercased email addresses
5 years ago
Jeremy Lin
7407b8326a
Fix attachment size limit calculation
...
The config values (in KB) need to be converted to bytes when comparing
against total attachment sizes.
5 years ago
Daniel García
adf47827c9
Make sure the data field is always returned, otherwise the mobile apps seem to have issues
5 years ago
Jeremy Lin
862d401077
Fix WebSocket notifications
...
Ignore a missing `id` query param; it's unclear what this ID represents,
but it wasn't being used in the existing bitwarden_rs code, and no longer
seems to be sent in the latest versions of the official clients.
5 years ago
Jeremy Lin
c06162b22f
Handle `devicePushToken`
...
Mobile push isn't currently supported, but this should get rid of spurious
`Detected unexpected parameter during login: devicepushtoken` warnings.
5 years ago
Daniel García
7a6a3e4160
Set the cargo version and allow changing it during build time with BWRS_VERSION.
...
Also renamed GIT_VERSION because that's not the only source anymore.
5 years ago
Daniel García
94341f9f3f
Fix token error while accepting invite
5 years ago
Daniel García
ff19fb3426
Merge pull request #919 from BlackDex/issue-908
...
Fixed issue #908
5 years ago
BlackDex
baac8d9627
Fixed issue #908
...
The organization uuid is most of the time within the uri path as a
parameter. But sometimes it only is there as a query value.
This fix checks both, and returns the uuid when possible.
5 years ago
BlackDex
669b101e6a
Fixing issue #908
...
Sometimes an org-uuid is not within the path but in a query value,
This fixes the check for that.
5 years ago
Daniel García
d2d9fb08cc
Revert "Use opportunistic TLS in SMTP connections"
5 years ago
BlackDex
35f30088b2
Fixing issue #759 by disabling Foreign Key Checks.
...
During migrations some queries are out of order regarding to foreign
keys.
Because of this the migrations fail when the sql database has this
enforced by default.
Turning of this check during the migrations will fix this and this is
only per session.
5 years ago
Daniel García
dce054e632
Merge pull request #912 from ymage/openssl_as_default
...
Fix alpine build with openssl crate as default
5 years ago
Ymage
ba725e1c25
Make openssl crate as default (non feature-flipped)
5 years ago
Daniel García
7d9c7017c9
Merge pull request #911 from BlackDex/upgrade-rocket
...
Upgrade rocket
5 years ago
BlackDex
bd09fe1a3d
Updated code so backtraces are logged also.
5 years ago
BlackDex
bcbe6177b8
Merge branch 'master' of https://github.com/dani-garcia/bitwarden_rs into log-panics
5 years ago
BlackDex
9b1d07365e
Updated ring
...
Some small changes to match the updated ring package.
5 years ago
BlackDex
37b212427c
Updated jsonwebtoken
...
Updated to the latest version of jsonwebtoken.
Some small code changes to match the new versions.
5 years ago
BlackDex
078234d8b3
Small change for rocket compatibilty
5 years ago
Daniel García
2ee07ea1d8
Fix empty data when cloning cipher
5 years ago
Daniel García
40c339db9b
Fix postgres policies, second try
5 years ago
Daniel García
402c1cd06c
Merge pull request #906 from BlackDex/upgrade-reqwest
...
Updated reqwest to the latest version.
5 years ago
Daniel García
819f340f39
Fix issue with postgres
5 years ago
BlackDex
1b4b40c95d
Updated reqwest to the latest version.
...
- Use the blocking client (no async).
- Disabled gzip.
- use_sys_proxy is now default.
5 years ago
Daniel García
afd9f4e278
Allow the smtp mechanism to be provided without quotes and all lowercase
5 years ago
Daniel García
47a9461f39
Merge pull request #903 from TheBinaryLoop/patch-1
...
Updated domains with new values vualt
5 years ago
Daniel García
c6f64d8368
Merge pull request #901 from sleweke/feature/opportunistic_tls
...
Use opportunistic TLS in SMTP connections
5 years ago
Daniel García
a30d5f4cf9
Fix cloning issues
5 years ago
Daniel García
3fa78e7bb1
Initial version of policies
5 years ago
Lukas Eßmann
a8a7e4f9a5
Updated domains with new values vualt
...
Added domains from official vault.bitwarden.com
5 years ago
Samuel Leweke
5d3b765a23
Use opportunistic TLS in SMTP connections
...
If SSL is disabled, the SMTP ClientSecurity of the lettre crate
defaults to None, that is, an insecure connection. This is changed to
Opportunistic, which uses TLS if available. If TLS is not available,
the insecure connection is used (i.e., this change is backward
compatible).
5 years ago
Daniel García
70f3ab8ec3
Migrate lazy_static to once_cell, less macro magic and slightly faster
5 years ago
BlackDex
84dc2eda1f
Changed javascript default argument construction
5 years ago
BlackDex
390d10d656
Relocated SMTP test input+button.
...
- Moved smtp test option to within the "SMTP Email" Settings block.
- Added optional option to prevent full page reload.
- SMTP Test and Backup do not reload the admin interface any more.
5 years ago
zethra
cc404b4edc
Added command line flags for help and version
...
Signed-off-by: zethra <benaagoldberg@gmail.com>
5 years ago
BlackDex
97fb7b5b96
Added urlpath to smtpTest function
5 years ago
BlackDex
5a974c7b94
Added SMTP test button in the admin gui
...
- Added a test button for checking the e-mail settings.
- Fixed a bug with the _post JavaScript function:
A function was overwriten with a variable and errors were not handled
correctly like a 500 for example.
5 years ago
BlackDex
7439aeb63e
Make panics logable (as warn)
...
panic!()'s only appear on stderr, this makes tracking down some strange
issues harder with the usage of docker since stderr does not get logged
into the bitwarden.log file. This change logs the message to stdout and
the logfile when activated.
5 years ago
Daniel García
cd8907542a
Make sure the provided domain contains the protocol and show a useful error when it doesn't
5 years ago
Daniel García
ad9f2b2d8e
Removed test urlpath
5 years ago
Daniel García
2f4a9865e1
Use absolute paths in the admin page
5 years ago
Jeremy Lin
29a0795219
Add backend support for alternate base dir (subdir/subpath) hosting
...
To use this, include a path in the `DOMAIN` URL, e.g.:
* `DOMAIN=https://example.com/custom-path `
* `DOMAIN=https://example.com/multiple/levels/are/ok `
5 years ago
Daniel García
325039c316
Attachment size limits, per-user and per-organization
5 years ago
Miro Prasil
03233429f4
Remove check from Invitation:take()
...
I've checked the spots when `Invitation::new()` and `Invitation::take()`
are used and it seems like all spots are already correctly gated. So to
enable invitations via admin API even when invitations are otherwise
disabled, this check can be removed.
5 years ago
Miroslav Prasil
0a72c4b6db
Do not disable invitations via admin API
...
This was brought up today:
https://github.com/dani-garcia/bitwarden_rs/issues/752#issuecomment-586715073
I don't think it makes much sense in checking whether admin has the
right to send invitation as admin can change the setting anyway.
Removing the condition allows users to forbid regular users from
inviting new users to server while still preserving the option to do so
via the admin API.
5 years ago
Daniel García
8867626de8
Add option to change invitation org name, fixes #825
...
Add option to allow additional iframe ancestors, fixes #843
Sort the rocket routes before printing them
5 years ago
Daniel García
f5916ec396
Fix backwards indices
5 years ago
Daniel García
ebb36235a7
Cache icons in the clients
5 years ago
Daniel García
def174a517
Convert email domains to punycode
5 years ago
Daniel García
480ba933fa
Don't error if admin token is empty but disabled
5 years ago
Miro Prasil
c4101162d6
SIGNUPS_ALLOWED with no whitelist [ fixes #830 ]
...
This reverts back to `SIGNUPS_ALLOWED` when there is no domain whitelist
set. The functionality was broken in 64d6f72
.
5 years ago
Daniel García
632d55265b
Merge pull request #824 from tomuta/fix_change_email
...
Fix change email when no whitelist is configured
5 years ago
tomuta
e277f7d1c1
Fix change email when no whitelist is configured
...
Fixes issue #792
5 years ago
Daniel García
ff7b4a3d38
Update handlebars to 3.0 which included performance improvements.
...
Updated lettre to newer git revision, which should give better error messages now.
5 years ago
Daniel García
d212dfe735
Accept y/n, True/False, 1/0 as booleans in environment vars
5 years ago
Daniel García
84ed185579
Update u2f to 0.2, which requires OpenSSL but also might solve the problems we've had with certificates.
...
The rust image doesn't need installing curl or tar, so removed. Also collapsed ENV lines.
5 years ago
Michael Powers
e196ba6e86
Switch error handling to ? operator instead of explicit handling.
5 years ago
Michael Powers
76743aee48
Fixes #635 - Unique constraint violation when using U2F tokens on PostgreSQL
...
Because of differences in how .on_conflict() works compared to .replace_into() the PostgreSQL backend wasn't correctly ensuring the unique constraint on user_uuid and atype wasn't getting violated.
This change simply issues a DELETE on the unique constraint prior to the insert to ensure uniqueness. PostgreSQL does not support multiple constraints in ON CONFLICT clauses.
5 years ago
Daniel García
96a189deb9
Merge pull request #803 from aeolyus/master
...
Minor typo conect -> connect
5 years ago
Daniel García
8c229920ad
Protect websocket server against panics
5 years ago
Richard Huang
d592323e39
minor typo conect -> connect
5 years ago
Daniel García
36ae946655
Avoid some to_string in the request logging and include message to disable web vault when not found.
5 years ago
Daniel García
cb6f392774
When receiving a comma separated list as IP, pick the first
5 years ago
Daniel García
88c56de97b
Config option for client IP header
5 years ago
Daniel García
e274af6e3d
Print current server time when failing TOTP, and use chrono as the rest of the server
5 years ago
Daniel García
a0ece3754b
Formatting
5 years ago
Daniel García
2545469713
Fix crash when page URL points to huge file
5 years ago
Daniel García
5cabf4d040
Fix IP not shown when failed login ( Fixes #761 )
5 years ago
Daniel García
a03db6d224
Also hide options requests, unless using debug or trace
5 years ago
Daniel García
8d1b72b951
Collapsed log messages from 3 lines per request to 2 and hidden the ones valued as less informative.
...
Use LOG_LEVEL debug or trace to recover them.
Removed LOG_MOUNTS and bundled it with LOG_LEVEL debug and trace.
Removed duplicate error messages
Made websocket not proxied message more prominent, but only print it once.
5 years ago
Daniel García
912e1f93b7
Fix some lints
5 years ago
Daniel García
adc443ea80
Add endpoint to delete specific U2F key
5 years ago
Daniel García
0d32179d07
Logout button in admin page
5 years ago
Daniel García
12928b832c
Fix broken tests
5 years ago
Daniel García
1e224220a8
Updated deps and fixed some lints
5 years ago
Daniel García
924ba153aa
Merge pull request #730 from tomuta/email_verification
...
Implement change-email, email-verification, account-recovery, and welcome notifications
5 years ago