88 Commits (9b9c19186dbb877483e445bc30fe8ca55760d30d)

Author SHA1 Message Date
Thomas Kluyver 0f0fe84740 Expand description of compatibility code
8 years ago
Thomas Kluyver 6ba7b17181 Only use force_clear_cookie for the extra compatibility piece
8 years ago
Thomas Kluyver 1fdcd375ab Fix clearing two cookies with the same name
8 years ago
Daniel Farrell 605eaa72be Added a flag to allow access of hidden files (#2819)
8 years ago
Thomas Kluyver 74fbc5b578
Merge pull request #3008 from Carreau/autopawd
8 years ago
Matthias Bussonnier a8971410c1 Add option disabled changing password at login.
8 years ago
Min RK 1deb0aec16 tornado 5: PeriodicCallback loop arg will be removed (#3034)
8 years ago
Thomas Kluyver 9a5c2c06ad
Merge pull request #2958 from kevin-bates/fix-2957-add-reason-to-json-errors
8 years ago
Thomas Kluyver e7f69cc2d7 Work on loading UI translations (#2969)
8 years ago
Kevin Bates ed3b0e4594 Set reason on HTTP errors, None otherwise.
8 years ago
Thomas Kluyver 55aa80e10f Merge pull request #2920 from minrk/allow-origin-token
8 years ago
Min RK fea2ef258f set cookie on base_url
8 years ago
Kevin Bates b24aa5e023 Add 'reason' field to JSON error responses
8 years ago
Min RK 08f7189cba only allow CORS exception when auth is enabled
8 years ago
Min RK 9acf6a80f4 allow token-authenticated requests cross-origin by default
8 years ago
Min RK a8c6b8bab6 Fix some errors caused by raising 403 in get_current_user (#2919)
8 years ago
Sam Lau 1c2a256add Add x-xsrftoken to Access-Control-Allow-Headers
8 years ago
Min RK 4467dc9f12 specify version for deprecation
8 years ago
Min RK 962c5ccd80 stop using `@json_handlers`
8 years ago
Min RK ba353e20f7 use .write_error on APIHandler instead of `@json_errors` for JSON error messages
8 years ago
Min RK 92209228f6 raise 403 on APIHandler failed login
8 years ago
Min RK d6a534ec5b use RFC5987 encoding for filenames
9 years ago
Grant Nestor 64ed6e439c Don't url escape filenames on download
9 years ago
Min RK 0308dc78d9 ensure "default-src 'none'" CSP is added to APIHandlers
9 years ago
Thomas Kluyver 227704cda5 Merge pull request #2671 from minrk/dont-modify-headers
9 years ago
Min RK f512880fcb allow overriding csp report uri via tornado settings
9 years ago
Min RK fb7ee6f348 avoid modifying settings['headers'] in add_default_headers
9 years ago
Grant Nestor 5192d72c63 Merge pull request #2656 from agermanidis/master
9 years ago
Anastasis Germanidis 95a53b775e Fixed bug in get_content_type
9 years ago
Anastasis Germanidis 180bbe88f6 Cleaning up AuthenticatedFileHandler.get
9 years ago
Anastasis Germanidis 539c2f7521 Added charset handling on AuthenticatedFileHandler
9 years ago
Anastasis Germanidis a82a510199 Use static file handler when files are local
9 years ago
Thomas Kluyver 724bdd1570 Remove old websocket draft76 protocol.
9 years ago
Krista d3b94fa5f4 added robots.txt
9 years ago
Min RK a49397bf98 expose passthrough for WebSocketHandler.get_compression_options
9 years ago
Thomas Kluyver a051f24e0d Don't call sys_info() at import time
9 years ago
Min RK 32a353378a track REST API activity
9 years ago
Thomas Kluyver 666ecbf35c Merge pull request #2011 from minrk/unwebpack
9 years ago
Thomas Kluyver 4917ba4d44 Merge pull request #1991 from minrk/template-log-message
9 years ago
Min RK 47d4451958 remove webpack shims
9 years ago
Min RK 86c6268f64 prose review
9 years ago
Min RK d6f091c443 allow disabling xsrf check
9 years ago
Min RK 9478a6b82b use tornado xsrf token in API
9 years ago
Min RK 70e79a0ad6 add token_authenticated property
9 years ago
Min RK 4a8af93b5b enable tornado xsrf cookie
9 years ago
Min RK 3f32d7da00 remove debug statement about no custom error page template
9 years ago
Min RK a51efa5acc add Authorization to allowed CORS headers
9 years ago
Min RK 38060d001e Merge pull request #1939 from jupyter/static-file-log
9 years ago
Thomas Kluyver 283042c675 Ensure variable is set if exc_info is falsey
9 years ago
Min RK 1e070a50f5 don't check origin on token-authenticated requests
9 years ago