aboutsummaryrefslogtreecommitdiff
path: root/doc/todo/emailauth.mdwn
Commit message (Collapse)AuthorAge
* introduce portier here as well, while i'm herehttps://id.koumbit.net/anarcat2016-11-01
|
* Do not directly enable emailauth by default, only indirectly via openidSimon McVittie2015-05-27
| | | | | | | This avoids nasty surprises on upgrade if a site is using httpauth, or passwordauth with an account_creation_password, and relying on only a select group of users being able to edit the site. We can revisit this for ikiwiki 4.
* cloak user PII when making commits etc, and let cloaked PII be used in ↵Joey Hess2015-05-14
| | | | | | | | | | | | | | banned_users This was needed due to emailauth, but I've also wrapped all IP address exposure in cloak(), although the function doesn't yet cloak IP addresses. (One IP address I didn't cloak is the one that appears on the password reset email template. That is expected to be the user's own IP address, so ok to show it to them.) Thanks to smcv for the pointer to http://xmlns.com/foaf/spec/#term_mbox_sha1sum
* Merge branch 'master' of ssh://git.ikiwiki.infoJoey Hess2015-05-14
|\
| * please do cloak email addresses, the principle of least astonishment appliessmcv2015-05-14
| |
* | update re passwordauth @Joey Hess2015-05-14
|/
* closeJoey Hess2015-05-13
|
* link to indieauth and mention existing problems with this approachhttps://id.koumbit.net/anarcat2015-05-13
|
* thoughtsJoey Hess2015-05-13
|
* tyoJoey Hess2015-05-13
|
* updateJoey Hess2015-05-13
|
* updateJoey Hess2015-05-13
|
* proposalJoey Hess2015-05-13