-
- Downloads
Always require users to re-authenticate for dangerous operations. (#10184)
Dangerous actions means deactivating an account, modifying an account password, or adding a 3PID. Other actions (deleting devices, uploading keys) can re-use the same UI auth session if ui_auth.session_timeout is configured.
Showing
- changelog.d/10184.bugfix 1 addition, 0 deletionschangelog.d/10184.bugfix
- docs/sample_config.yaml 4 additions, 0 deletionsdocs/sample_config.yaml
- synapse/config/auth.py 4 additions, 0 deletionssynapse/config/auth.py
- synapse/handlers/auth.py 6 additions, 1 deletionsynapse/handlers/auth.py
- synapse/rest/client/v2_alpha/devices.py 6 additions, 0 deletionssynapse/rest/client/v2_alpha/devices.py
- synapse/rest/client/v2_alpha/keys.py 3 additions, 0 deletionssynapse/rest/client/v2_alpha/keys.py
Loading
Please register or sign in to comment