ljacqu
8e4288f911
Minor code householding
2018-05-20 13:10:26 +02:00
ljacqu
c96e28f726
Add debug logging for teleports (relates to #1521 )
2018-05-13 22:52:41 +02:00
ljacqu
b5c028301b
Merge master into '1141-optional-additional-2fa-auth'
2018-05-13 18:54:19 +02:00
ljacqu
729c567dd5
#1141 Check that user is logged in before changing TOTP key
...
- Use PlayerCache to check that user is logged in where appropriate
- Add log statements
2018-05-13 18:49:40 +02:00
ljacqu
6f2f7a73af
Merge branch 'master' of https://github.com/AuthMe/AuthMeReloaded into 1141-optional-additional-2fa-auth
2018-05-01 22:49:23 +02:00
ljacqu
1e3ed795c1
#1141 2FA implementation fixes
...
- Merge TotpService into TotpAuthenticator
- Add missing tests
- Migrate old 2fa enabled key to new one
2018-05-01 22:49:07 +02:00
ljacqu and Gabriele C
d55b4bb3b5
#1561 Fix timing attacks by comparing hashes in constant time ( #1563 )
...
* #1561 Fix timing attacks by comparing hashes in constant time
* #1561 Fix timing attacks in phpBB fallback hashes
- As noted by @games647
2018-04-22 21:27:38 +02:00
ljacqu
ecdcaf2479
Fix failing tests
2018-04-22 13:26:51 +02:00
ljacqu
cff456c285
Help message updater: specify the name of the updated file
2018-04-22 12:51:41 +02:00
ljacqu
ecaffbabfc
Small cleanups / changes amassed over time
...
- Small javadoc fixes
- Simplifications
- Move logException method from StringUtils to ExceptionUtils
2018-04-22 12:45:34 +02:00
ljacqu
29ac3a7022
#1141 Fixes to TOTP implementation
...
- Revert back to SHA1 as HMAC hash function so that it works with Google authenticator
- Add message to user to tell him to run /2fa confirm to add a TOTP code
2018-04-22 11:13:27 +02:00
ljacqu
de0e588cf3
Merge branch 'master' of https://github.com/AuthMe/AuthMeReloaded into 1141-optional-additional-2fa-auth
2018-04-22 07:14:05 +02:00
ljacqu
9326094d9c
#1141 Fix review remarks by @games647
...
- Use SHA512 to generate keys instead of default SHA1
- Declare google authenticator dependency as optional and add relocation rule
2018-04-03 00:13:53 +02:00
ljacqu
2bf78dd186
Merge branch 'master' of https://github.com/AuthMe/AuthMeReloaded into 1141-optional-additional-2fa-auth
2018-04-02 23:44:19 +02:00
ljacqu
106dea1611
Minor: fix JavaDoc warnings
2018-04-02 23:43:52 +02:00
ljacqu
fc54c0311b
#1539 Columns handler: finishing touches
...
- Add relocation rule for shading of the library
- Fix SQLite connection not being refreshed on reload
2018-04-02 23:19:13 +02:00
ljacqu
ad9e6dbb6d
Merge branch 'master' of https://github.com/AuthMe/AuthMeReloaded into 1539-datasource-columns-integration
2018-04-02 22:33:26 +02:00
ljacqu
26472b6be3
#1539 Create common parent for SQLite and MySQL
2018-03-25 22:27:44 +02:00
ljacqu
4595a14191
#1539 Add support for columns that are not on player auth (is_logged, has_session)
2018-03-25 11:52:40 +02:00
ljacqu
137fc3d505
#1539 Use columns handler in more datasource methods; fix case-insensitivity for SQLite
2018-03-24 22:53:30 +01:00
ljacqu
881ef6a640
#1539 DataSource columns: close MySQL connections, add missing columns, use newly built-in types, improve column initialization
2018-03-24 21:16:43 +01:00
ljacqu
5a58f2c44f
#1539 Integrate data source columns library
...
- Create wrapper around SqlColumnsHandler for AuthMe-specific behavior
- Integrate columns handler into first SQLite and MySQL method implementations
2018-03-24 12:24:43 +01:00
ljacqu
e9ab82db6b
#1141 Make 2fa messages translatable, various cleanups (null safety, ...)
2018-03-21 23:56:13 +01:00
ljacqu
584a0bebbf
Minor: Fix failing test after command change
2018-03-20 23:13:48 +01:00
ljacqu
f66a8a5b06
Merge branch 'master' of https://github.com/AuthMe/AuthMeReloaded into 1141-optional-additional-2fa-auth
...
# Conflicts:
# src/main/java/fr/xephi/authme/permission/PlayerPermission.java
# src/main/java/fr/xephi/authme/service/BukkitService.java
2018-03-20 23:07:25 +01:00
ljacqu
495cfc69a9
#1141 Move TOTP code during login as separate step: /2fa code
...
Rough version.
- Introduces a limbo player state on the LimboPlayer, allowing us to add further mandatory actions between successful (password) authentication and the ability to play on the server
2018-03-20 23:06:08 +01:00
ljacqu and HexelDev
a1a909c01d
#1531 Move spigot detection to BukkitService ( #1534 )
2018-03-19 23:08:48 +01:00
ljacqu and GitHub
250bd0d148
Merge pull request #1517 from AuthMe/642-kick-on-fast-commands
...
#642 - Quick Command Protection
2018-03-19 22:35:49 +01:00
ljacqu
af6bee59bd
Merge branch 'master' of https://github.com/AuthMe/AuthMeReloaded into 1141-optional-additional-2fa-auth
...
# Conflicts:
# src/main/java/fr/xephi/authme/datasource/MySQL.java
2018-03-19 22:32:16 +01:00
ljacqu
fddb3bf265
Fix minor Checkstyle violations
...
- Mostly missing JavaDoc, some line lengths
2018-03-11 19:08:21 +01:00
ljacqu
ff0a7e1f89
Fix failing test
2018-03-11 16:34:25 +01:00
ljacqu
15f49dcbb3
Merge branch 'global-replacements'
2018-03-10 16:59:56 +01:00
ljacqu
1a53cd11b2
#829 Move CommandSender / name to first argument to avoid confusion with varargs
...
- Overloaded method with (String, String...) as args was problematic as it could be confusing on its own and also confusing with the (CommandSender, String...) flavor
2018-03-10 16:58:30 +01:00
ljacqu
eb9cd31a65
#1141 Split TOTP permissions for add/remove, refactor TOTP services
...
- Split TotpService further into GenerateTotpService and TotpAuthenticator, which wraps the GoogleAuthenticator impl
- Add missing tests for the services
- Change GenerateTotpService's interface to behave like a collection for more intuitive method behavior
2018-03-10 16:21:53 +01:00
ljacqu
e72d5d5e81
#1141 Require TOTP code to be passed with /login (temporary)
...
- Temporarily require the TOTP code to be provided with /login
- Future implementation should require it as a second step
2018-03-09 18:37:01 +01:00
ljacqu
c3cf9e3ee0
#1141 Rough version of TOTP commands to add and remove a code for a player
2018-03-07 20:11:53 +01:00
ljacqu
9954c82cb6
#1141 Add TOTP key field to database and PlayerAuth
...
- Add new field for storing TOTP key
- Implement data source methods for manipulation of its value
2018-03-05 19:50:58 +01:00
ljacqu
8d5afa7fbc
Minor: Use CommonService for permission lookup
...
- Some changes found in a very old patch :) - drop injection of PermissionsManager in favor of CommonService
- Rename IsEqualByReflectionMatcher's method to something more specific to differentiate it better from Hamcrest's equalTo() matcher
2018-02-23 23:37:24 +01:00
ljacqu and GitHub
329657bd5f
#1497 Show specific message for invalid YAML files ( #1506 )
...
* #1497 Throw dedicated exception for invalid YAML files and handle it on startup
- Wrap SnakeYAML exceptions when loading config.yml and commands.yml on startup into own exception type
- Handle exception type on startup with specific error message
* #1497 Fix inaccurate JavaDoc comment
2018-02-23 23:31:22 +01:00
ljacqu
7864bb06ac
Minor cleanups
...
- Fix line length violations
- Add JavaDoc to some longer methods
- Remove unused imports
2018-02-23 23:23:24 +01:00
ljacqu
83e247afe9
Minor: Simplify check for Spigot
2018-02-17 23:23:44 +01:00
ljacqu
90400650c3
Merge branch 'master' of https://github.com/AuthMe/AuthMeReloaded into 1467-message-keys-hierarchy
2018-02-17 23:08:39 +01:00
ljacqu
9dd4039fdd
#1467 Create backup before migrating; output newly added message keys
...
- Extract logic for creating a backup timestamp into FileUtils
2018-02-13 22:15:03 +01:00
ljacqu
ffeb04c0a2
Merge branch 'master' of https://github.com/AuthMe/AuthMeReloaded into 1467-message-keys-hierarchy
...
Conflicts:
src/main/resources/messages/messages_ko.yml
2018-02-11 09:47:07 +01:00
ljacqu
189647d9f2
#1467 Fix character issues by always using UTF-8 when reading and writing
...
- Change usages of Bukkit's FileResource to a ConfigMe PropertyReader
- Specify UTF-8 for reading and writing
2018-02-11 09:22:42 +01:00
ljacqu
cd61febd76
#1467 Change /authme messages to only update help text file now
2018-02-02 20:12:42 +01:00
ljacqu
1d6d9eb764
#1467 Rearrange old keys migration so no entries get lost
...
- 'error' was an old entry but now we have multiple entries under 'error' (which is now a section), so we need to ensure that we migrate the old 'error' entry before the migration sets anything under that path
2018-02-02 19:40:28 +01:00
ljacqu
f44353ed4c
#1467 Fix messages verification tool task + remove empty messages in YML files
2018-02-01 23:09:08 +01:00
ljacqu
f67ddb0c77
#1467 Migrate all message files, make sure migrater keeps predefined order
2018-02-01 20:23:06 +01:00
ljacqu
b72fe1b1a9
Merge branch 'master' of https://github.com/AuthMe/AuthMeReloaded into 1467-message-keys-hierarchy
2018-01-31 22:09:59 +01:00
ljacqu and GitHub
e50a1e26e4
Update ISSUE_TEMPLATE.MD
2018-01-30 22:15:07 +01:00
ljacqu
abd19cdb86
#1467 Fix error in placeholder migration, create and fix tests
2018-01-29 22:15:39 +01:00
ljacqu
760a2a909c
#1467 Fix export issues (style, encoding)
...
- Override yaml file resource to ensure that lines aren't wrapped
- Override yaml file reader to ensure the file is always read as UTF-8
2018-01-29 21:46:58 +01:00
ljacqu
f714e9d564
#1467 Change message keys and messages_en to new structure
2018-01-29 20:56:30 +01:00
ljacqu
dfe47066cd
Merge branch 'master' of https://github.com/AuthMe/AuthMeReloaded into 1467-message-keys-hierarchy
2018-01-29 20:04:38 +01:00
ljacqu
1eaf321575
#1467 Try to clean up abstract message file handler hierarchy
...
- Move some handling with the default file configuration down to the help message file handler since it is the only one with such a behavior now
2018-01-25 21:48:48 +01:00
ljacqu
820e443b81
#1467 Implement messages file migration
...
- Create messages updater called when a messages YML file is loaded
- Work in progress
- Does not yet include changes to any message keys
2018-01-24 22:19:25 +01:00
ljacqu
b3a191d7e2
Minor: simplify CheckMessageKeyUsages task and make check more strict
2018-01-22 19:56:51 +01:00
ljacqu
6f2c586441
Test initialization of permission handlers in PermissionManager
2018-01-21 22:11:47 +01:00
ljacqu
acaaf6fe41
Minor dependency updates
...
- JaCoCo 0.8.0 brings some interesting exclusions in code coverage, which means we might be able to drop TestHelper#validateHasOnlyPrivateEmptyConstructor soon
2018-01-21 21:01:23 +01:00
ljacqu
610a699c95
Refactor message handlers into injectable components (preparation for #1467 )
2018-01-21 20:47:29 +01:00
ljacqu
847991b658
#1474 Don't log /email changepassword command (exposes password)
2018-01-21 19:06:51 +01:00
ljacqu
761ee2f05b
#1035 Migrate other accounts config from config.yml to commands.yml
2018-01-21 18:58:20 +01:00
ljacqu and GitHub
1e16f251ef
Merge pull request #1477 from AuthMe/1035-handle-alt-accounts-in-commandsYml
...
1035 handle alt accounts in commands yml
2018-01-17 21:49:29 +01:00
ljacqu
fe4ea6d22b
Remove migration of commands from config.yml to commands.yml
...
- Migration was shipped with the 5.2 release and is now becoming harder to maintain; since it's quite old we drop it
2018-01-17 21:42:17 +01:00
ljacqu
7f77f30439
Minor: Fix forgotten param documentation in JavaDoc
2018-01-16 20:40:21 +01:00
ljacqu
f19f8502d8
#1035 Forced commands: add more tests, rename account constraints, update commands.yml comments
2018-01-16 20:32:17 +01:00
ljacqu
3c0236e15e
#1035 Fix handling of new login command constraints
...
- Incorporate ConfigMe fix
- Various fixes in the integration
2018-01-15 22:39:29 +01:00
ljacqu
8dbba1dc93
#1035 Add optional constraints to onLogin and onFirstLogin commands for number of alt accounts
...
- Extend Command to add specific constraints
- Currently doesn't work because of missing ConfigMe support
2018-01-14 12:23:04 +01:00
ljacqu
1cd5a6acce
#1472 Add zhtw translation changes by @haer0248
2018-01-14 11:16:23 +01:00
ljacqu
d9c1af4311
#1454 Run other accounts command in sync mode
2018-01-08 23:08:37 +01:00
ljacqu
a29738e2a8
#1460 Fix null handling in recent players command
...
- Last login might be null
2018-01-06 20:26:07 +01:00
ljacqu
ea87075cd2
#930 Add specific message for register captcha success
2018-01-06 20:01:45 +01:00
ljacqu
9afd8679e9
Merge branch 'master' of https://github.com/AuthMe/AuthMeReloaded into 930-captcha-for-register
2018-01-06 19:04:14 +01:00
ljacqu
23c246748a
#930 Register captcha: avoid circular dependency by handling limbo message in captcha command
...
- Set limbo message in captcha command (as is done for login captcha)
- Add clarifying comments to captcha command
- Remove classes handling circular dependencies
2018-01-06 19:04:03 +01:00
ljacqu
94cf310d5b
Minor: fix code climate config test
2018-01-06 18:06:30 +01:00
ljacqu
99ef874327
Update CodeClimate configuration to new structure
2018-01-06 11:48:27 +01:00
ljacqu
84b376d2a5
#930 Change captcha storage to change code internally upon failure
...
- Within CaptchaStorage#checkCode, a player's captcha code is overridden with a new one on failure or cleared on success
- Fixes inconsistencies in the retrieval / regeneration of codes
2018-01-06 02:31:26 +01:00
ljacqu
180bbbf0be
#930 Refactor captcha managers to have a crude captcha storage class instead of inheritance
...
- Remove abstract captcha manager in favor of a primitive captcha code storage (composition over inheritance)
- Supply player when checking captcha code for further usage (fixes open point from previous commit)
2018-01-05 01:26:25 +01:00
ljacqu
0494886518
Merge branch 'master' of https://github.com/AuthMe/AuthMeReloaded into 930-captcha-for-register
2018-01-05 00:17:39 +01:00
ljacqu
7cf3f6d77b
#930 Registration captcha: update message shown to player on failed captcha
...
- Show message with new captcha code when a captcha has failed
- Requires implementation of circular dependency handler (initial draft)
2018-01-05 00:17:22 +01:00
ljacqu
c8d82a23e0
Merge branch 'master' of https://github.com/AuthMe/AuthMeReloaded into 930-captcha-for-register
2017-12-22 21:54:58 +01:00
ljacqu
8bae71e1bd
#1435 Send password recovery emails in async
2017-12-21 21:54:23 +01:00
ljacqu
1a60036592
#930 Extract common captcha functionality into abstract superclass
...
- Create AbstractCaptchaManager
- Add tests
2017-12-01 23:40:20 +01:00
ljacqu
33904c09e9
#930 Create registration captcha manager
...
- Introduce registration captcha manager, rename login captcha manager accordingly
- Integrate reg. captcha manager into /register command
Open points:
- Refactor common captcha functionality into abstract superclass
- If captcha before /register necessary, show appropriate message to player immediately
- Unit tests
2017-12-01 21:12:35 +01:00
ljacqu
67a6a42dfe
Minor Javadoc fix: one "yet" is enough :)
2017-12-01 20:33:33 +01:00
ljacqu
058ac22462
Update docs
2017-12-01 19:16:49 +01:00
ljacqu
c784fc7f2e
#1423 Fix ignored review remarks
2017-11-29 19:43:35 +01:00
ljacqu
f1c1848985
#1046 Add onFirstLogin to commands.yml
...
- Allow to configure commands run on player's first login (login of player with a previously null lastlogin date)
2017-11-28 21:41:30 +01:00
ljacqu
50dbbb8d87
#1254 Create command to see recently logged in players
...
- Create datasource method to fetch most recent players by last login date
- Add command to view last logged in players
2017-11-28 21:07:10 +01:00
ljacqu
7932c1bf90
Update to injector 1.0
...
- Includes Factory and SingletonStore so our custom implementation is removed
2017-11-25 21:27:18 +01:00
ljacqu
86a07771d7
Open 5.5 development iteration
2017-11-25 14:41:23 +01:00
ljacqu
6365926cf0
Fix test in AntiBotServiceTest
2017-11-23 20:06:21 +01:00
ljacqu
53f7bf155f
Fix wrong check in CodeClimateConfigTest
2017-11-23 18:13:17 +01:00
ljacqu
1053440b15
Refactor util for setting BukkitService mock behavior
...
- Move helper methods for setting BukkitService mock behavior into their own class
- Change methods to use Mockito's answer instead of verification + argument capture -> calling the methods now belongs to the test setup (given clause) and allows the behavior to take effect more than once
2017-11-22 00:24:11 +01:00
ljacqu
4717dc148c
#1413 Don't run onUnregister command in async
2017-11-21 23:48:15 +01:00
ljacqu
c693901330
Merge branch '1400-phpbb-hash' of https://github.com/AuthMe/AuthMeReloaded
2017-11-04 11:32:44 +01:00
ljacqu
5c40cb3b73
Insert null email as DEFAULT so column default may take effect
...
Ugly implementation to fit into AuthMe 5.4. If email on PlayerAuth is null, do not supply NULL as the email value but use DEFAULT instead so that the default value is used if present in the column configuration.
2017-11-04 11:29:21 +01:00
ljacqu
7d6c61258b
Fix #1401 bungeecord message sent even if disabled
2017-11-04 10:17:52 +01:00
ljacqu
80ab41ae5a
#1400 Sync AuthMe's phpBB hash implementation with phpBB3's
...
- phpBB3 seems to favor using BCrypt $2y$ now
- Keep unsalted MD5 and phpass salted MD5 comparisons for backwards compatibility
2017-11-04 09:58:51 +01:00