| Age | Commit message (Collapse) | Author | |
|---|---|---|---|
| 2026-07-24 | Give all sessions a uniform absolute lifetime of one week | erdgeist | |
| Enforced at restore via a login-time stamp, written only at genuine logins so the limit stays absolute rather than sliding. The cookie name rotation logs everyone out once at deploy. Second-factor users are deliberately not treated worse than password-only ones. | |||
| 2009-02-15 | * initial commit of the stripped restful-authentication | simon | |
| * http basic auth and login from cookie have been removed * no it does not work yet, it's so f*cking secure, it won't even let legitimate users login | |||
