0
Fork 0
mirror of https://codeberg.org/forgejo/forgejo.git synced 2025-04-14 06:42:40 -05:00
forgejo/services
Gusted 29a0b0131e fix: Revert "allow synchronizing user status from OAuth2 login providers (#31572)"
This commit has a fundamental flaw, in order to syncronize if external
users are still active the commit checks if the refresh token is
accepted by the OAuth provider, if that is not the case it sees that as
the user is disabled and sets the is active field to `false` to signal
that. Because it might be possible (this commit makes this a highly
likelyhood) that the OAuth provider still recognizes this user the
commit introduces code to allow users to re-active themselves via the
oauth flow if they were disabled because of this. However this code
makes no distinction in why the user was disabled and always re-actives
the user.

Thus the reactivation via the OAuth flow allows users to bypass the
manually activation setting (`[service].REGISTER_MANUAL_CONFIRM`) or if
the admin for other reasons disabled the user.

This reverts commit 21fdd28f08.

(cherry picked from commit 7f8f9b878f)
2024-12-12 05:43:20 +00:00
..
actions fix: clean up log files that no longer exist 2024-12-03 07:08:16 +00:00
agit
asymkey
attachment
auth fix: Revert "allow synchronizing user status from OAuth2 login providers (#31572)" 2024-12-12 05:43:20 +00:00
automerge
context Improve Swagger documentation for user endpoints 2024-11-28 20:44:16 +00:00
contexttest
convert
cron
doctor Merge pull request 'fix: dbconsistency check adding missing quotes' (#6124) from 71rd/forgejo:dbconsistency-forgejo into forgejo 2024-12-03 04:07:18 +00:00
externalaccount fix: Revert "allow synchronizing user status from OAuth2 login providers (#31572)" 2024-12-12 05:43:20 +00:00
f3
federation
feed
forgejo
forms
gitdiff
indexer
issue fix: check read permissions for code owner review requests 2024-11-17 19:19:11 +00:00
lfs
mailer fix: extend forgejo_auth_token table 2024-11-15 11:33:17 +01:00
markup
migrations fix: support www.github.com for migrations 2024-11-03 17:28:30 +00:00
mirror
notify
org
packages fix arch pkg 2024-10-21 05:10:13 +00:00
pull Fix the logic of finding the latest pull review commit ID (#32139) 2024-10-06 11:34:08 +02:00
release
remote
repository Fix: return correct type in GetSubModule 2024-12-03 03:24:54 +00:00
secrets
task
uinotification
user Do not rewrite ssh keys files when deleting a user without one (#6097) 2024-12-05 21:32:48 +00:00
webhook fix: improve discord webhook api conformance 2024-10-09 16:07:34 +00:00
wiki Show page titles in wiki search results (#6048) 2024-11-25 14:18:18 +00:00