Matej Bačo
05f2d2b9cf
Fix tests
2026-04-28 19:29:37 +02:00
Matej Bačo
c1f61b22aa
Merge branch '1.9.x' into feat-create-dynamic-keys
2026-04-28 17:18:36 +02:00
Matej Bačo
980762fc3e
Rename from dynamic key to ephemeral key (api keys)
2026-04-28 17:18:06 +02:00
Matej Bačo
c96836b1c0
Improve code quality of folder decoding project ID
2026-04-28 17:10:58 +02:00
Matej Bačo
15917ac7ba
Fix failing tests
2026-04-28 17:05:30 +02:00
Matej Bačo
f5a732d231
Add dynami key integration test
2026-04-28 16:47:39 +02:00
Matej Bačo
72dfd8a7bc
Add E2E tests for dynamic keys
2026-04-28 16:45:00 +02:00
Matej Bačo
11f80fc2ed
Solve key projectId backwards compatibility
2026-04-28 16:35:40 +02:00
Harsh Mahajan and GitHub
547709a1d8
Merge pull request #12167 from appwrite/feat/impersonation-query-params
...
feat: add query param fallback for impersonation headers
2026-04-28 19:51:23 +05:30
Matej Bačo
ccb0ddd578
Bug&test fixing
2026-04-28 16:18:36 +02:00
Matej Bačo
b2ce95a0cd
Dynamic key backwards compatibility
2026-04-28 16:14:10 +02:00
Matej Bačo
ed9b47f6ce
Migrate project jwt to dynamic api key
2026-04-28 15:57:37 +02:00
harsh mahajan
2a357511ea
fix: use unique emails and phone in query param impersonation test
2026-04-28 19:17:25 +05:30
Harsh Mahajan and GitHub
67d24d3ef1
Merge branch '1.9.x' into feat/impersonation-query-params
2026-04-28 19:11:14 +05:30
harsh mahajan
87ed7c3817
feat: add query param fallback for all impersonation params and simplify tests
2026-04-28 19:10:55 +05:30
Matej Bačo
8f176166c9
Re-introduce project JWT endpoint
2026-04-28 15:31:10 +02:00
Matej Bačo and GitHub
3d3f5934c6
Merge pull request #11993 from appwrite/feat-public-oauth2-endpoints
...
Feat: Public project OAuth2 configuration API
2026-04-28 12:41:50 +02:00
harsh mahajan
f0cbfbbbe4
fix: use assertEmpty for impersonatorUserId to match response model
2026-04-28 14:31:49 +05:30
Matej Bačo
cb4cff120b
Add Keycloak oauth support
2026-04-28 10:54:13 +02:00
Matej Bačo
49e6a38e7f
Add fusionauth oauth
2026-04-28 10:43:16 +02:00
Matej Bačo
dfa3ae5274
Fix tests
2026-04-28 10:19:36 +02:00
Matej Bačo
543765a22a
Improve copy
2026-04-28 10:15:45 +02:00
Matej Bačo
e2bb9a9161
Simplify oauth endpoints
2026-04-28 10:08:39 +02:00
harsh mahajan
bda823ac0e
chore: format
2026-04-28 13:38:00 +05:30
harsh mahajan
3dd5a51ba4
style: fix method argument spacing (Pint PSR-12)
2026-04-28 13:34:01 +05:30
harsh mahajan
5afc8f462d
fix: allow same-site in CSRF guard to support Console on subdomains
2026-04-28 13:26:13 +05:30
harsh mahajan
ed0c7b4e12
test: add CSRF attack prevention test for impersonateUserId query param
2026-04-28 13:24:15 +05:30
Matej Bačo
d25707346f
Add console oauth endpoint
2026-04-28 09:47:27 +02:00
harsh mahajan
a3f6cf4645
fix: restrict CSRF guard to same-origin only, drop same-site
2026-04-28 13:00:18 +05:30
harsh mahajan
9a175c5098
test: add E2E tests for impersonateUserId query param and CSRF guards
2026-04-28 12:56:17 +05:30
harsh mahajan
5465be6301
fix: make CSRF guard fail-closed by requiring explicit same-origin Sec-Fetch-Site
2026-04-28 12:27:57 +05:30
harsh mahajan
46a457bfa3
fix: block impersonateUserId query param on cross-site requests to prevent CSRF
2026-04-28 12:10:51 +05:30
harsh mahajan
4c989f99c3
fix: cast impersonateUserId query param to string to prevent array injection
2026-04-28 12:05:02 +05:30
harsh mahajan
8f1d73a6cb
chore: clarify intentional header-only restriction for email/phone impersonation
2026-04-28 12:02:00 +05:30
harsh mahajan
01b5fa8ecb
fix: restrict impersonation query param fallback to userId only
...
Remove query param fallback for impersonateEmail and impersonatePhone
to avoid PII exposure in server logs, browser history, and Referer
headers. Only impersonateUserId (an opaque internal ID) is safe to
pass via URL query param.
2026-04-28 11:58:25 +05:30
harsh mahajan
d73b7a70d8
feat: add query param fallback for impersonation headers
...
Allow impersonation to be specified via URL query params
(?impersonateUserId, ?impersonateEmail, ?impersonatePhone) as a
fallback to the existing headers, enabling Console to embed
impersonation in direct file/image URLs where headers cannot be set.
2026-04-28 11:44:39 +05:30
Damodar Lohani and GitHub
cefd063c55
Merge pull request #12165 from appwrite/fix/CLO-4280-getheader-string-coerce
...
fix: coerce non-string header values in Request::getHeader
2026-04-28 10:43:40 +05:45
Damodar Lohani and GitHub
c924cbcc59
Merge pull request #12166 from appwrite/fix/CLO-4279-favicon-empty-body
...
fix: guard DOMDocument::loadHTML against empty body in favicon endpoint
2026-04-28 10:32:32 +05:45
81321e82d1
Update src/Appwrite/Platform/Modules/Avatars/Http/Favicon/Get.php
...
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-04-28 10:05:01 +05:45
Damodar Lohani
30a511692b
test: add unit coverage for Request::getHeader non-string coercion
...
Refs CLO-4280
2026-04-28 04:15:00 +00:00
Damodar Lohani
9637409831
fix: coerce non-string header values in Request::getHeader
...
Closes CLO-4280
2026-04-28 03:54:35 +00:00
Damodar Lohani
c4f6b11706
fix: guard DOMDocument::loadHTML against empty body in favicon endpoint
...
Closes CLO-4279
2026-04-28 03:54:34 +00:00
Matej Bačo
ad4178aa42
Fix missing lib params for domain
2026-04-27 18:33:30 +02:00
Matej Bačo
1f16b0d9e7
Fix failing startup
2026-04-27 18:21:21 +02:00
Matej Bačo
015aee087a
Fix write only security
2026-04-27 18:04:22 +02:00
Matej Bačo
50d86c5b5d
Update ci.yml
2026-04-27 17:45:52 +02:00
Matej Bačo
3d43530225
Fix failing test
2026-04-27 17:41:13 +02:00
Matej Bačo
d0d536a2dd
Improve test coverage
2026-04-27 17:40:49 +02:00
Matej Bačo
4b620bb31a
Improve test coverage
2026-04-27 17:27:23 +02:00
Matej Bačo
ca7f36a9b8
Fix bugs by improving tests
2026-04-27 17:17:57 +02:00