nextcloud/apps
Peter Ringelmann dfaf200838
fix(frontend): add strict password confirmation for sensitive admin actions
Register axios password confirmation interceptors in the apps
management, admin delegation, admin security, and OAuth2 settings
bundles, and pass PwdConfirmationMode.Strict on requests to endpoints
protected with #[PasswordConfirmationRequired(strict: true)], so that
the user password is verified via Basic auth on the request itself
rather than relying on the session timestamp.

Signed-off-by: Peter Ringelmann <peter.ringelmann@nextcloud.com>
2026-04-21 15:44:02 +02:00
..
admin_audit fix(l10n): Update translations from Transifex 2026-03-31 00:19:24 +00:00
cloud_federation_api Merge pull request #59727 from nextcloud/backport/59721/stable33 2026-04-20 15:04:31 +02:00
comments fix(l10n): Update translations from Transifex 2026-04-08 00:19:17 +00:00
contactsinteraction fix(l10n): Update translations from Transifex 2026-03-27 00:29:17 +00:00
dashboard fix(dashboard): remove status list if there are none 2026-04-07 15:28:00 +00:00
dav chore: fix ESLint issues for rules added in ESLint v10 2026-04-20 23:10:06 +02:00
encryption Merge pull request #59314 from nextcloud/backport/59202/stable33 2026-04-07 23:38:47 +02:00
federatedfilesharing fix(l10n): Update translations from Transifex 2026-03-27 00:29:17 +00:00
federation fix(l10n): Update translations from Transifex 2026-04-18 00:19:07 +00:00
files Merge pull request #59749 from nextcloud/backport/58786/stable33 2026-04-21 15:23:24 +02:00
files_external fix(l10n): Update translations from Transifex 2026-04-21 00:18:44 +00:00
files_reminders fix(l10n): Update translations from Transifex 2026-03-14 00:19:15 +00:00
files_sharing chore: fix ESLint issues for rules added in ESLint v10 2026-04-20 23:10:06 +02:00
files_trashbin test: skip testTrashEntryCreatedWhenSourceNotInCache on object store 2026-04-08 16:04:42 +00:00
files_versions chore: fix ESLint issues for rules added in ESLint v10 2026-04-20 23:10:06 +02:00
lookup_server_connector fix(l10n): Update translations from Transifex 2026-03-28 00:30:34 +00:00
oauth2 fix(frontend): add strict password confirmation for sensitive admin actions 2026-04-21 15:44:02 +02:00
profile fix(l10n): Update translations from Transifex 2026-04-20 00:18:58 +00:00
provisioning_api fix: Add missing PasswordConfirmationRequired attributes 2026-04-21 15:43:56 +02:00
settings fix(frontend): add strict password confirmation for sensitive admin actions 2026-04-21 15:44:02 +02:00
sharebymail fix(l10n): Update translations from Transifex 2026-04-21 00:18:44 +00:00
systemtags chore: fix ESLint issues for rules added in ESLint v10 2026-04-20 23:10:06 +02:00
testing fix(testing): Fix fake provider reverting strings with emojis 2026-04-10 16:37:19 +00:00
theming fix(l10n): Update translations from Transifex 2026-04-18 00:19:07 +00:00
twofactor_backupcodes fix(l10n): Update translations from Transifex 2026-03-30 00:29:26 +00:00
updatenotification fix(l10n): Update translations from Transifex 2026-04-21 00:18:44 +00:00
user_ldap fix: Change the setting name 2026-04-14 22:28:19 +02:00
user_status fix(l10n): Update translations from Transifex 2026-04-08 00:19:17 +00:00
weather_status fix(l10n): Update translations from Transifex 2026-04-06 00:21:35 +00:00
webhook_listeners fix(l10n): Update translations from Transifex 2026-02-24 00:19:33 +00:00
workflowengine fix(l10n): Update translations from Transifex 2026-04-20 00:18:58 +00:00