Grant Limberg
|
c1384422c3
|
just sleep 1 second
|
4 years ago |
Grant Limberg
|
ccc0ebd0f9
|
don't spam the logs quite as much on first startup
sleep the thread 1 second every round until we're actually updating
members
|
4 years ago |
Grant Limberg
|
9d4336d296
|
redis connection tuning
|
4 years ago |
Grant Limberg
|
17bc9d3085
|
redis thread now uses this_thread::yield()
|
4 years ago |
Grant Limberg
|
436f481a34
|
fix log line
|
4 years ago |
Grant Limberg
|
9e8215b213
|
adjust sleep between onlineNotification runs. Added timer to output
|
4 years ago |
TossPig
|
bc7f18064f
|
fix sql
bind message supplies 17 parameters, but prepared statement "" requires 16
|
4 years ago |
Grant Limberg
|
355d3f44fb
|
logging & redis standalone fix
|
4 years ago |
Grant Limberg
|
9de863e68b
|
update controller db record
|
4 years ago |
Grant Limberg
|
64b7f8e445
|
quiet down logs more
|
4 years ago |
Grant Limberg
|
626f488cb4
|
quiet down the controller logs a smidge
|
4 years ago |
Grant Limberg
|
10212e376a
|
more redis in the controller
|
4 years ago |
Grant Limberg
|
0ed339f19d
|
make sure value here is true, not just that the env var is set
|
4 years ago |
Grant Limberg
|
b65c1ed3a0
|
Add inja
Requries update to C++17 standard
|
4 years ago |
Grant Limberg
|
9ddc0327d4
|
enable redis member status again
|
4 years ago |
Grant Limberg
|
59151fbf86
|
remove max count for xread
|
4 years ago |
Grant Limberg
|
1c700b7b41
|
Fix redis cluster usage
|
4 years ago |
Grant Limberg
|
ff18bacd94
|
fix XREAD commands for redis message queue
|
4 years ago |
Adam Ierymenko
|
ef08346a74
|
Fix a possible excessive memory use issue in controller and clean up a bunch of COM handling and other code in the normal node.
|
4 years ago |
Adam Ierymenko
|
912036b260
|
Push credentials always if updated (client-side) and some controller-side cleanup that should be logically irrelevant but will prevent unnecessary DB lookups.
|
4 years ago |
Adam Ierymenko
|
a4e8847664
|
Restore sending of rejections but move it exclusively to a thread, widen netconf window to 30 minutes.
|
4 years ago |
Adam Ierymenko
|
c492bf7eea
|
Forgot to send error on v0 auth expiry.
|
4 years ago |
Adam Ierymenko
|
cb086ff97f
|
Simplify SSO logic. SSO should just normally expire when it expires. No full deauth needed. Deauth is for really giving someone the boot.
|
4 years ago |
Adam Ierymenko
|
55a99f34d0
|
Tighten certificate window and deprecate sending of revocations for ordinary SSO timeouts. Revocations should only be for deliberate deauth to kick people off networks. Cert window should now stay within refresh window for SSO so normal cert expiration should handle it just fine.
|
4 years ago |
Adam Ierymenko
|
58119598ae
|
comment out some new deauth code
|
4 years ago |
Adam Ierymenko
|
42a2afaef9
|
This may improve controller behavior with SSO and mixed SSO, needs testing!
|
4 years ago |
Grant Limberg
|
f8e24f4629
|
Fix issue where restarting a controller causes a DB write for each network member
|
4 years ago |
Grant Limberg
|
c09010c25a
|
handle nonce rotation in controller better
Won't generate new nonces until there are no active ones.
|
4 years ago |
Grant Limberg
|
b3fbbd3124
|
refresh tokens now working
Still investigating the best way to do a couple things, but we have something working
|
4 years ago |
Grant Limberg
|
730482e62f
|
encode network ID into sso state param
|
4 years ago |
Grant Limberg
|
663a09b38d
|
oidc stuff coming across the wire properly and generating a working login URL
|
4 years ago |
Grant Limberg
|
7cce23ae79
|
wip
|
4 years ago |
Grant Limberg
|
dfdac7adbd
|
iomanip
|
4 years ago |
Grant Limberg
|
a33d7c64fe
|
more fixin
|
4 years ago |
Grant Limberg
|
d15516f0ef
|
query fix & controller build fix
|
4 years ago |
Grant Limberg
|
fa21fdc1cc
|
rename stuff for clarity
authenticationURL will still be used by the client for v1 and v2 of sso
|
4 years ago |
Grant Limberg
|
43433cdb5a
|
integrate rust build of zeroidc to linux
|
4 years ago |
Grant Limberg
|
8d39c9a861
|
plumbing full flow from controller -> client network
|
4 years ago |
Grant Limberg
|
3818351287
|
use pqxx::pipeline for online update thread
|
5 years ago |
Grant Limberg
|
4d26b5a868
|
no reason for this to be a pointer
|
5 years ago |
Grant Limberg
|
ac0dc7844f
|
rework commit thread & some connection pool borrowing issues
|
5 years ago |
Adam Ierymenko
|
eabe091038
|
Backport only the COM mitigation instead of everything from 1.8
|
5 years ago |
Adam Ierymenko
|
75a45eeb27
|
Revert "Backport guts of 1.8 to 1.6 tree so we can point release without waiting for UI quirks to be fixed."
This reverts commit 48ce7632fa.
|
5 years ago |
Adam Ierymenko
|
48ce7632fa
|
Backport guts of 1.8 to 1.6 tree so we can point release without waiting for UI quirks to be fixed.
|
5 years ago |
Adam Ierymenko
|
134d33c218
|
Add a bit of hardening in the network certificate of membership by incorporating a full hash of the identity to which it is issued. This means the recipient need not depend entirely on the root verifying identities properly to make sure impersonation is not occurring.
|
5 years ago |
Grant Limberg
|
46adc1f059
|
ifdef this out
|
5 years ago |
Grant Limberg
|
9002555596
|
ensure count > 0
|
5 years ago |
Adam Ierymenko
|
7c3166e9be
|
Add a bit of hardening in the network certificate of membership by incorporating a full hash of the identity to which it is issued. This means the recipient need not depend entirely on the root verifying identities properly to make sure impersonation is not occurring.
|
5 years ago |
Grant Limberg
|
a20a290836
|
ifdef this out
|
5 years ago |
Grant Limberg
|
83265768c1
|
ensure count > 0
|
5 years ago |