This website requires JavaScript.
Explore
Help
Sign In
pi-hole
/
FTL
Watch
1
Star
0
Fork
0
mirror of
https://github.com/pi-hole/FTL.git
synced
2024-10-26 16:52:18 +02:00
Code
Issues
Actions
Packages
Projects
Releases
Wiki
Activity
Files
1161463a60a95d72b9bc2c68df2defdbcc752762
FTL
/
src
/
webserver
T
History
DL6ER
e085728e3e
Merge pull request
#1601
from pi-hole/fix/redirect_slash
...
Slash the slash
2023-07-28 23:07:30 +02:00
..
civetweb
Add mg.request_info.is_authenticated to check if a user is authenticated
2023-07-05 21:11:58 +02:00
cJSON
Move src/cJSON -> src/webserver/cJSON
2023-01-27 20:34:04 +01:00
CMakeLists.txt
Move Lua-related functions into dedicated source file
2023-04-26 21:47:59 +02:00
http-common.c
Use explicitly sized integers (u/int64_t) to ensure consistent operation on both 32 and 64 bit architectures
2023-07-27 04:10:23 +02:00
http-common.h
Use explicitly sized integers (u/int64_t) to ensure consistent operation on both 32 and 64 bit architectures
2023-07-27 04:10:23 +02:00
json_macros.h
Add global object "took" to all API endpoints
2023-05-07 12:20:07 +02:00
lua_web.c
Handle index page (= dashboard) correctly
2023-07-26 19:17:24 +02:00
lua_web.h
Move Lua-related functions into dedicated source file
2023-04-26 21:47:59 +02:00
webserver.c
Simplify code and handle case of missing trailing slashes for index pages properly
2023-07-28 22:36:41 +02:00
webserver.h
Move Lua-related functions into dedicated source file
2023-04-26 21:47:59 +02:00
x509.c
Change generated elliptic curve from secp521r1 to secp384r1 because the former is not supported any longer by current Google Chrome (and, presumably, Chromium-based browsers like Edge). The reason for the removal is that NSA Suite B does not *mention* P-521 in the document, leading to Chrome removing support (even though Firefox keeps support for it). Furthermore, FIPS 140-2 also focuses on P-256 and P-384. There is nothing wrong about this curve but with the removal of it, it doesn't make sense to still keep it for automatic certificate generation in Pi-hole. There are debates on the web if P-256 wouldn't be enough as it is somewhat more efficient, but - at the end of the day - the difference is small and it still worth mentioning that even the largest standardized EC at this point is faster than any standardized and trusted non-EC cryptography used today. If you dislike ECC, Pi-hole offers the generation of a 4096 bit RSA key, instead.
2023-07-07 04:55:23 +02:00
x509.h
!!! BREAKING CHANGE !!! Switch to the proven memory-hard password-hashing alogorithm BALLOON. The stored password hash will be upgraded on the first successdful login. To wave the necessity to implement BALLOON with every client trying to access the API, we remove the existing challenge-response authentication in favor of allowing login straight with the password. This has been avoided in the past, however, seems now acceptable that FTL (even by default) offers secure end-to-end encryption over HTTPS.
2023-05-30 21:22:45 +02:00