0
Fork 0
mirror of https://github.com/TryGhost/Ghost.git synced 2025-01-06 22:40:14 -05:00
Independent technology for modern publishing, memberships, subscriptions and newsletters.
Find a file
Fabien O'Carroll a701ee7023
Added support for token session to /ghost (#11709)
no-issue

* Added default for getting origin of request

This function is used to attach the origin of the request to the
session, and later check that requests using the session are coming from
the same origin. This protects us against CSRF attacks as requests in
the browser MUST originate from the same origin on which the user
logged in.

Previously, when we could not determine the origin we would return
null, as a "safety" net.

This updates the function to use a secure and sensible default - which
is the origin of the Ghost-Admin application, and if that's not set -
the origin of the Ghost application.

This will make dealing with magic links simpler as you can not always
guaruntee the existence of these headers when visiting via a hyperlink

* Removed init fns and getters from session service

This simplifies the code here, making it easier to read and maintain

* Moved express-session initialisation to own file

This is complex enough that it deserves its own module

* Added createSessionFromToken to session service

* Wired up the createSessionFromToken middleware
2020-04-06 11:49:14 +02:00
.github Switched to custom GitHub Action for a release 2020-04-03 13:37:33 +01:00
content Updated Casper to 3.0.11 2020-03-26 14:29:11 +00:00
core Added support for token session to /ghost (#11709) 2020-04-06 11:49:14 +02:00
test Added support for token session to /ghost (#11709) 2020-04-06 11:49:14 +02:00
.editorconfig Removed Makefile settings from .editorconfig 2019-07-31 17:21:16 +08:00
.eslintignore Moved grunt-eslint to npm script executing eslint (#10474) 2019-02-11 13:26:06 +01:00
.eslintrc.json
.gitattributes
.gitignore Move tests from core to root (#11700) 2020-03-30 16:26:47 +01:00
.gitmodules Switched to using relative urls for submodules 2018-12-10 16:56:35 +00:00
.npmignore Added renovate.json to npmignore 2020-04-03 13:10:12 +01:00
config.development.json Removed local setting fron config.dev.json 2019-07-22 13:21:02 +08:00
Gruntfile.js Switched to custom GitHub Action for a release 2020-04-03 13:37:33 +01:00
index.js Integrated Sentry error tracking 2020-02-03 13:43:43 +00:00
LICENSE 2020 2020-01-06 10:51:18 +01:00
MigratorConfig.js
package.json Added support for token session to /ghost (#11709) 2020-04-06 11:49:14 +02:00
PRIVACY.md Updated links to docs (#10941) 2019-07-22 18:17:50 +08:00
README.md Updated README with GitHub Actions badge 2020-03-05 10:03:13 +00:00
renovate.json Move tests from core to root (#11700) 2020-03-30 16:26:47 +01:00
SECURITY.md Updated links to docs (#10941) 2019-07-22 18:17:50 +08:00
yarn.lock Added support for token session to /ghost (#11709) 2020-04-06 11:49:14 +02:00

Ghost

Ghost.org | Features | Showcase | Forum | Documentation | Contributing | Twitter

Downloads Latest release Build status Contributors OpenCollective

 

Fiercely independent, professional publishing. Ghost is the most popular open source, headless Node.js CMS which already works with all the tools you know and love.

Ghost(Pro)

The easiest way to deploy Ghost is with our official Ghost(Pro) managed service. You can have a fresh instance up and running in a couple of clicks with a worldwide CDN, backups, security and maintenance all done for you.

Not only will it save you hours of maintenance per month, but all revenue goes to the Ghost Foundation, which funds the maintenance and further development of Ghost itself. So youll be supporting open source software and getting a great service! Alternatively if you'd like to support us, we're very grateful to all our backers on Open Collective ❤️

If you prefer to run on your own infrastructure, we also provide 1-off installs and managed support and maintenance plans via Ghost(Valet) - which can save a substantial amount of developer time and resources.

 

Quickstart Install

If you want to run your own instance of Ghost, in most cases the best way is to use our CLI tool

$ npm install ghost-cli -g

 

Then, if installing locally add the local flag to get up and running in under a minute - Local install docs

$ ghost install local

 

or on a server run the full install, including automatic SSL setup using LetsEncrypt - Production install docs

$ ghost install

 

Check out our official documentation for more information about our recommended hosting stack & properly upgrading Ghost, plus everything you need to develop your own Ghost themes or work with our API.

 

Getting Help

You can find answers to a huge variety of questions, along with a large community of helpful developers over on the Ghost forum - replies are generally very quick. Ghost(Pro) customers also have access to 24/7 email support.

To stay up to date with all the latest news and product updates, make sure you subscribe to our blog — or you can always follow us on Twitter, if you prefer your updates bite-sized and facetious. 🎷🐢

 

Contributors & Advanced Developers

For anyone wishing to contribute to Ghost or to hack/customise core files we recommend following our full development setup guides: General Contributor Guide | Developer Setup Instructions | Admin Client development guide

 

Copyright & License

Copyright (c) 2013-2020 Ghost Foundation - Released under the MIT license. Ghost and the Ghost Logo are trademarks of Ghost Foundation Ltd. Please see our trademark policy for info on acceptable usage.