41 Commits (55c6aba9727b0243045cf056b0137e55beeefaed)

Author SHA1 Message Date
pgajdos 1c3dbcc6bf do not use nose for testing
5 years ago
Sai Rahul Poruri 9dd2af27de CLN : Remove utf8 coding cookies
5 years ago
Remi Rampin 617f7468fe
Implement password hashing with bcrypt (#3793)
6 years ago
Bibo Hao 9775af7bba
Update security.py
6 years ago
Bibo Hao 8d43f50f04
Ensure jupyter config dir exist
6 years ago
Kerwin.Sun b5f5c9500e remove py2 dependence
6 years ago
Min RK 08c4c89818 protect against chrome mishandling backslash as slash in URLs
7 years ago
Min RK b9d9e659e9 parse urls when validating redirect targets
7 years ago
Thomas Kluyver 56d7a2d3a6 Remove one-time token code
7 years ago
Denis Ledoux 3729dd02ac [FIX] notebookapp, auth: `get_secure_cookie` kwargs
8 years ago
Thomas Kluyver 61972480b9 Don't clear login cookie on requests without cookie
8 years ago
maartenbreddels 772544e60f renamed manager.py to config_manager.py and added more docstrings
8 years ago
maartenbreddels 89b32e4412 allow default json files in a .d directory, original PR: ipython/traitlets#452
8 years ago
Matthias Bussonnier eca4c71056 Extra self
8 years ago
Matthias Bussonnier a8971410c1 Add option disabled changing password at login.
8 years ago
Matthias Bussonnier 709fdd637a When login-in via token, let a chance for user to set the password
8 years ago
Min RK fea2ef258f set cookie on base_url
8 years ago
Min RK 68a514a29d Merge pull request #2033 from vlimant/master
9 years ago
Kyle Kelley f5f97d1f93 Merge pull request #2007 from minrk/password
9 years ago
jean-roch 6ab3a5c098 correcting function definition
9 years ago
vlimant ab019aae74 allows to overload the method to check unix-type password using crypt
9 years ago
Min RK 53f809d407 use a warning for failure to set file permissions
9 years ago
Min RK cd7e0a939c add `jupyter notebook password` entrypoint
9 years ago
Min RK 86c6268f64 prose review
9 years ago
Min RK 70e79a0ad6 add token_authenticated property
9 years ago
Srinivas Reddy Thatiparthy 161c174a98
rename log.warn to log.warning as log.warn is deprecated
9 years ago
Min RK 1e070a50f5 don't check origin on token-authenticated requests
9 years ago
Min RK 5d5d063746 Look for token in Authorization header
9 years ago
Min RK bf249669e1 call it token
9 years ago
Min RK 5a6d7556af allow entering login token at password prompt
9 years ago
Min RK cd3c6c1b8a use one-time token for opening browser
9 years ago
Min RK 3ba68d8cb7 enable token-authentication by default
9 years ago
Min RK 6c5cca1328 Make login_available method LoginHandler.get_login_available
9 years ago
Min RK 37349b9953 include cross-origin check when allowing login URL redirects
10 years ago
Min RK 07c4d23cad make cookies httponly by default
10 years ago
Min RK 417b17450e Add `cookie_options` to make cookie args configurable
10 years ago
Maarten A. Breddels 5a3272f771 fixed a typo, and corrected the help text
10 years ago
Maarten A. Breddels b9d106a808 implemented changes as discussed at PR 775, password generation moved to module
10 years ago
Chris Seymour 6880715826 Use a 401 status code for invalid login attempts. Fixes #384
11 years ago
Min RK acbe5cc442 restrict login redirect to notebook app
11 years ago
Min RK d71a59cc9f s/jupyter_notebook/notebook
11 years ago