No admin by username, no Swagger in production, no exception text to clients
S14 and the privacy items of P0: - signing up as "admin" no longer grants admin; `PrivaPub admin promote <root>` (and `demote`) does, run on the box against the configured database; - Swagger is served in Development only; - every service and controller answers "Something went wrong." where it used to send ex.Message, and the SMTP warnings no longer log the recipient's address; - sign-up and login no longer log the IP, User-Agent and root id together; - invitation sign-up takes the persona's own AvatarUserName (and optional AvatarName) instead of naming the avatar after the private login, and refuses a persona username equal to the login's. Invitation login uses the named persona, creating it if it is new; - recovery mail comes from "PrivaPub", not collAnon's support address name. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
1 parent
2eb2a63f1e
commit
0f85030744
11 files changed
+144
-76
No files matched your search
@@ -10,5 +10,12 @@ namespace PrivaPub.ClientModels
|
||||
StringLength(Constants.GroupInvitationLength, MinimumLength = Constants.GroupInvitationLength,
|
||||
ErrorMessageResourceName = "StringLengthMinMax", ErrorMessageResourceType = typeof(ErrorsResource))]
|
||||
public string InvitationCode { get; set; }
|
||||
|
||||
[StringLength(32, MinimumLength = 3, ErrorMessageResourceName = "StringLengthMinMax", ErrorMessageResourceType = typeof(ErrorsResource)),
|
||||
RegularExpression("^[a-z0-9_]+$", ErrorMessageResourceName = "EmptySpacesNotAllowed", ErrorMessageResourceType = typeof(ErrorsResource))]
|
||||
public string AvatarUserName { get; set; }
|
||||
|
||||
[StringLength(64, ErrorMessageResourceName = "MaxLengthString", ErrorMessageResourceType = typeof(ErrorsResource))]
|
||||
public string AvatarName { get; set; }
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user