]> git.proxmox.com Git - pve-access-control.git/blame - debian/changelog
access check: include user/token id in expired exception
[pve-access-control.git] / debian / changelog
CommitLineData
79ae250f
TL
1libpve-access-control (7.1-8) bullseye; urgency=medium
2
3 * fix #3668: realm-sync: replace 'full' & 'purge' with 'remove-
4 vanished'
5
6 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Apr 2022 17:02:46 +0200
7
eed46286
TL
8libpve-access-control (7.1-7) bullseye; urgency=medium
9
10 * userid-group check: distinguish create and update
11
12 * api: get user: declare token schema
13
14 -- Proxmox Support Team <support@proxmox.com> Mon, 21 Mar 2022 16:15:23 +0100
15
cd78b295
FG
16libpve-access-control (7.1-6) bullseye; urgency=medium
17
18 * fix #3768: warn on bad u2f or webauthn settings
19
20 * tfa: when modifying others, verify the current user's password
21
22 * tfa list: account for admin permissions
23
24 * fix realm sync permissions
25
26 * fix token permission display bug
27
28 * include SDN permissions in permission tree
29
30 -- Proxmox Support Team <support@proxmox.com> Fri, 21 Jan 2022 14:20:42 +0100
31
118088d8
TL
32libpve-access-control (7.1-5) bullseye; urgency=medium
33
34 * openid: fix username-claim fallback
35
36 -- Proxmox Support Team <support@proxmox.com> Thu, 25 Nov 2021 07:57:38 +0100
37
ebb14277
WB
38libpve-access-control (7.1-4) bullseye; urgency=medium
39
40 * set current origin in the webauthn config if no fixed origin was
41 configured, to support webauthn via subdomains
42
43 -- Proxmox Support Team <support@proxmox.com> Mon, 22 Nov 2021 14:04:06 +0100
44
44a55ff7
TL
45libpve-access-control (7.1-3) bullseye; urgency=medium
46
47 * openid: allow arbitrary username-claims
48
49 * openid: support configuring the prompt, scopes and ACR values
50
51 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Nov 2021 08:11:52 +0100
52
6f643e79
TL
53libpve-access-control (7.1-2) bullseye; urgency=medium
54
55 * catch incompatible tfa entries with a nice error
56
57 -- Proxmox Support Team <support@proxmox.com> Wed, 17 Nov 2021 13:44:45 +0100
58
92bca71e
TL
59libpve-access-control (7.1-1) bullseye; urgency=medium
60
61 * tfa: map HTTP 404 error in get_tfa_entry correctly
62
63 -- Proxmox Support Team <support@proxmox.com> Mon, 15 Nov 2021 15:33:22 +0100
64
1c9b6501
TL
65libpve-access-control (7.0-7) bullseye; urgency=medium
66
67 * fix #3513: pass configured proxy to OpenID
68
69 * use rust based parser for TFA config
70
71 * use PBS-like auth api call flow,
72
73 * merge old user.cfg keys to tfa config when adding entries
74
75 * implement version checks for new tfa config writer to ensure all
76 cluster nodes are ready to avoid login issues
77
78 * tickets: add tunnel ticket
79
80 -- Proxmox Support Team <support@proxmox.com> Thu, 11 Nov 2021 18:17:49 +0100
81
cd46b379
TL
82libpve-access-control (7.0-6) bullseye; urgency=medium
83
84 * fix regression in user deletion when realm does not enforce TFA
85
86 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Oct 2021 12:28:52 +0200
87
52da88a8
TL
88libpve-access-control (7.0-5) bullseye; urgency=medium
89
90 * acl: check path: add /sdn/vnets/* path
91
92 * fix #2302: allow deletion of users when realm enforces TFA
93
94 * api: delete user: disable user first to avoid surprise on error during the
95 various cleanup action required for user deletion (e.g., TFA, ACL, group)
96
97 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Sep 2021 15:50:47 +0200
98
543d646c
TL
99libpve-access-control (7.0-4) bullseye; urgency=medium
100
101 * realm: add OpenID configuration
102
103 * api: implement OpenID related endpoints
104
105 * implement opt-in OpenID autocreate user feature
106
107 * api: user: add 'realm-type' to user list response
108
109 -- Proxmox Support Team <support@proxmox.com> Fri, 02 Jul 2021 13:45:46 +0200
110
7a4c4fd8
TL
111libpve-access-control (7.0-3) bullseye; urgency=medium
112
113 * api: acl: add missing `/access/realm/<realm>`, `/access/group/<group>` and
114 `/sdn/zones/<zone>` to allowed ACL paths
115
116 -- Proxmox Support Team <support@proxmox.com> Mon, 21 Jun 2021 10:31:19 +0200
117
0902a936
FG
118libpve-access-control (7.0-2) bullseye; urgency=medium
119
120 * fix #3402: add Pool.Audit privilege - custom roles containing
121 Pool.Allocate must be updated to include the new privilege.
122
123 -- Proxmox Support Team <support@proxmox.com> Tue, 1 Jun 2021 11:28:38 +0200
124
67febb69
TL
125libpve-access-control (7.0-1) bullseye; urgency=medium
126
127 * re-build for Debian 11 Bullseye based releases
128
129 -- Proxmox Support Team <support@proxmox.com> Sun, 09 May 2021 18:18:23 +0200
130
2942ba41
TL
131libpve-access-control (6.4-1) pve; urgency=medium
132
133 * fix #1670: change PAM service name to project specific name
134
135 * fix #1500: permission path syntax check for access control
136
137 * pveum: add resource pool CLI commands
138
139 -- Proxmox Support Team <support@proxmox.com> Sat, 24 Apr 2021 19:48:21 +0200
140
54d312f3
TL
141libpve-access-control (6.1-3) pve; urgency=medium
142
143 * partially fix #2825: authkey: rotate if it was generated in the
144 future
145
146 * fix #2947: add an option to LDAP or AD realm to switch user lookup to case
147 insensitive
148
149 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Sep 2020 08:54:13 +0200
150
6a9be12f
TL
151libpve-access-control (6.1-2) pve; urgency=medium
152
153 * also check SDN permission path when computing coarse permissions heuristic
154 for UIs
155
156 * add SDN Permissions.Modify
157
158 * add VM.Config.Cloudinit
159
160 -- Proxmox Support Team <support@proxmox.com> Tue, 30 Jun 2020 13:06:56 +0200
161
e6624f50
TL
162libpve-access-control (6.1-1) pve; urgency=medium
163
164 * pveum: add tfa delete subcommand for deleting user-TFA
165
166 * LDAP: don't complain about missing credentials on realm removal
167
168 * LDAP: skip anonymous bind when client certificate and key is configured
169
170 -- Proxmox Support Team <support@proxmox.com> Fri, 08 May 2020 17:47:41 +0200
171
8f4a522f
TL
172libpve-access-control (6.0-7) pve; urgency=medium
173
174 * fix #2575: die when trying to edit built-in roles
175
176 * add realm sub commands to pveum CLI tool
177
178 * api: domains: add user group sync API enpoint
179
180 * allow one to sync and import users and groups from LDAP/AD based realms
181
182 * realm: add default-sync-options to config for more convenient sync configuration
183
184 * api: token create: return also full token id for convenience
185
186 -- Proxmox Support Team <support@proxmox.com> Sat, 25 Apr 2020 19:35:17 +0200
187
23059f35
TL
188libpve-access-control (6.0-6) pve; urgency=medium
189
190 * API: add group members to group index
191
192 * implement API token support and management
193
194 * pveum: add 'pveum user token add/update/remove/list'
195
196 * pveum: add permissions sub-commands
197
198 * API: add 'permissions' API endpoint
199
200 * user.cfg: skip inexisting roles when parsing ACLs
201
202 -- Proxmox Support Team <support@proxmox.com> Wed, 29 Jan 2020 10:17:27 +0100
203
3dd692e9
TL
204libpve-access-control (6.0-5) pve; urgency=medium
205
206 * pveum: add list command for users, groups, ACLs and roles
207
208 * add initial permissions for experimental SDN integration
209
210 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Nov 2019 17:56:37 +0100
211
4ef92d0d
FG
212libpve-access-control (6.0-4) pve; urgency=medium
213
214 * ticket: use clinfo to get cluster name
215
216 * ldaps: add sslversion configuration property to support TLS 1.1 to 1.3 as
217 SSL version
218
219 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2019 11:55:11 +0100
220
6e5bbca4
TL
221libpve-access-control (6.0-3) pve; urgency=medium
222
223 * fix #2433: increase possible TFA secret length
224
225 * parse user configuration: correctly parse group names in ACLs, for users
226 which begin their name with an @
227
228 * sort user.cfg entries alphabetically
229
230 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Oct 2019 08:52:23 +0100
231
e073493c
TL
232libpve-access-control (6.0-2) pve; urgency=medium
233
234 * improve CSRF verification compatibility with newer PVE
235
236 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Jun 2019 20:24:35 +0200
237
a237dc2e
TL
238libpve-access-control (6.0-1) pve; urgency=medium
239
240 * ticket: properly verify exactly 5 minute old tickets
241
242 * use hmac_sha256 instead of sha1 for CSRF token generation
243
244 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 18:14:45 +0200
245
f1531f22
TL
246libpve-access-control (6.0-0+1) pve; urgency=medium
247
248 * bump for Debian buster
249
250 * fix #2079: add periodic auth key rotation
251
252 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 21:31:15 +0200
253
ef761f51
TL
254libpve-access-control (5.1-10) unstable; urgency=medium
255
256 * add /access/user/{id}/tfa api call to get tfa types
257
258 -- Proxmox Support Team <support@proxmox.com> Wed, 15 May 2019 16:21:10 +0200
259
860ddcba
TL
260libpve-access-control (5.1-9) unstable; urgency=medium
261
262 * store the tfa type in user.cfg allowing to get it without proxying the call
263 to a higher priviledged daemon.
264
265 * tfa: realm required TFA should lock out users without TFA configured, as it
266 was done before Proxmox VE 5.4
267
268 -- Proxmox Support Team <support@proxmox.com> Tue, 30 Apr 2019 14:01:00 +0000
269
9fbad012
TL
270libpve-access-control (5.1-8) unstable; urgency=medium
271
272 * U2F: ensure we save correct public key on registration
273
274 -- Proxmox Support Team <support@proxmox.com> Tue, 09 Apr 2019 12:47:12 +0200
275
4473c96c
TL
276libpve-access-control (5.1-7) unstable; urgency=medium
277
278 * verify_ticket: allow general non-challenge tfa to be run as two step
279 call
280
281 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Apr 2019 16:56:14 +0200
282
a270d4e1
TL
283libpve-access-control (5.1-6) unstable; urgency=medium
284
285 * more general 2FA configuration via priv/tfa.cfg
286
287 * add u2f api endpoints
288
289 * delete TFA entries when deleting a user
290
291 * allow users to change their TOTP settings
292
293 -- Proxmox Support Team <support@proxmox.com> Wed, 03 Apr 2019 13:40:26 +0200
294
374647e8
TL
295libpve-access-control (5.1-5) unstable; urgency=medium
296
297 * fix vnc ticket verification without authkey lifetime
298
299 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Mar 2019 10:43:17 +0100
300
7fb70c94
TL
301libpve-access-control (5.1-4) unstable; urgency=medium
302
303 * fix #1891: Add zsh command completion for pveum
304
305 * ground work to fix #2079: add periodic auth key rotation. Not yet enabled
306 to avoid issues on upgrade, will be enabled with 6.0
307
308 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Mar 2019 09:12:05 +0100
309
6e010cde
TL
310libpve-access-control (5.1-3) unstable; urgency=medium
311
312 * api/ticket: move getting cluster name into an eval
313
314 -- Proxmox Support Team <support@proxmox.com> Thu, 29 Nov 2018 12:59:36 +0100
315
f5a9380a
TL
316libpve-access-control (5.1-2) unstable; urgency=medium
317
318 * fix #1998: correct return properties for read_role
319
320 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:22:40 +0100
321
b54b7474
TL
322libpve-access-control (5.1-1) unstable; urgency=medium
323
324 * pveum: introduce sub-commands
325
326 * register userid with completion
327
328 * fix #233: return cluster name on successful login
329
330 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Nov 2018 09:34:47 +0100
331
52192dd4
WB
332libpve-access-control (5.0-8) unstable; urgency=medium
333
334 * fix #1612: ldap: make 2nd server work with bind domains again
335
336 * fix an error message where passing a bad pool id to an API function would
337 make it complain about a wrong group name instead
338
339 * fix the API-returned permission list so that the GUI knows to show the
340 'Permissions' tab for a storage to an administrator apart from root@pam
341
342 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Jan 2018 13:34:50 +0100
343
3dadf8cf
FG
344libpve-access-control (5.0-7) unstable; urgency=medium
345
346 * VM.Snapshot.Rollback privilege added
347
348 * api: check for special roles before locking the usercfg
349
350 * fix #1501: pveum: die when deleting special role
351
352 * API/ticket: rework coarse grained permission computation
353
354 -- Proxmox Support Team <support@proxmox.com> Thu, 5 Oct 2017 11:27:48 +0200
355
ec4141f4
WB
356libpve-access-control (5.0-6) unstable; urgency=medium
357
358 * Close #1470: Add server ceritifcate verification for AD and LDAP via the
359 'verify' option. For compatibility reasons this defaults to off for now,
360 but that might change with future updates.
361
362 * AD, LDAP: Add ability to specify a CA path or file, and a client
363 certificate via the 'capath', 'cert' and 'certkey' options.
364
365 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Aug 2017 11:56:38 +0200
366
63134bd4
DM
367libpve-access-control (5.0-5) unstable; urgency=medium
368
369 * change from dpkg-deb to dpkg-buildpackage
370
371 -- Proxmox Support Team <support@proxmox.com> Thu, 22 Jun 2017 09:12:37 +0200
372
868fb1ea
DM
373libpve-access-control (5.0-4) unstable; urgency=medium
374
375 * PVE/CLI/pveum.pm: call setup_default_cli_env()
376
377 * PVE/Auth/PVE.pm: encode uft8 password before calling crypt
378
379 * check_api2_permissions: avoid warning about uninitialized value
380
381 -- Proxmox Support Team <support@proxmox.com> Tue, 02 May 2017 11:58:15 +0200
382
63358f40
DM
383libpve-access-control (5.0-3) unstable; urgency=medium
384
385 * use new PVE::OTP class from pve-common
386
387 * use new PVE::Tools::encrypt_pw from pve-common
388
389 -- Proxmox Support Team <support@proxmox.com> Thu, 30 Mar 2017 17:45:55 +0200
390
05fd50af
DM
391libpve-access-control (5.0-2) unstable; urgency=medium
392
393 * encrypt_pw: avoid '+' for crypt salt
394
395 -- Proxmox Support Team <support@proxmox.com> Thu, 30 Mar 2017 08:54:10 +0200
396
0835385b
FG
397libpve-access-control (5.0-1) unstable; urgency=medium
398
399 * rebuild for PVE 5.0
400
401 -- Proxmox Support Team <support@proxmox.com> Mon, 6 Mar 2017 13:42:01 +0100
402
730f8863
DM
403libpve-access-control (4.0-23) unstable; urgency=medium
404
405 * use new PVE::Ticket class
406
407 -- Proxmox Support Team <support@proxmox.com> Thu, 19 Jan 2017 13:42:06 +0100
408
1f1c4593
DM
409libpve-access-control (4.0-22) unstable; urgency=medium
410
411 * RPCEnvironment: removed check_volume_access() to avoid cyclic dependency
412 (moved to PVE::Storage)
413
414 * PVE::PCEnvironment: use new PVE::RESTEnvironment as base class
415
416 -- Proxmox Support Team <support@proxmox.com> Thu, 19 Jan 2017 09:12:04 +0100
417
f9105063
DM
418libpve-access-control (4.0-21) unstable; urgency=medium
419
420 * setup_default_cli_env: expect $class as first parameter
421
422 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jan 2017 13:54:27 +0100
423
9595066e
DM
424libpve-access-control (4.0-20) unstable; urgency=medium
425
426 * PVE/RPCEnvironment.pm: new function setup_default_cli_env
427
428 * PVE/API2/Domains.pm: fix property description
429
430 * use new repoman for upload target
431
432 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Jan 2017 12:13:26 +0100
433
2af5a793
DM
434libpve-access-control (4.0-19) unstable; urgency=medium
435
436 * Close #833: ldap: non-anonymous bind support
437
438 * don't import 'RFC' from MIME::Base32
439
440 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Aug 2016 13:09:08 +0200
441
5d87bb77
WB
442libpve-access-control (4.0-18) unstable; urgency=medium
443
444 * fix #1062: recognize base32 otp keys again
445
446 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Jul 2016 08:43:18 +0200
447
28ddf48b
WB
448libpve-access-control (4.0-17) unstable; urgency=medium
449
450 * drop oathtool and libdigest-hmac-perl dependencies
451
452 -- Proxmox Support Team <support@proxmox.com> Mon, 11 Jul 2016 12:03:22 +0200
453
15cebb28
DM
454libpve-access-control (4.0-16) unstable; urgency=medium
455
456 * use pve-doc-generator to generate man pages
457
458 -- Proxmox Support Team <support@proxmox.com> Fri, 08 Apr 2016 07:06:05 +0200
459
678df887
DM
460libpve-access-control (4.0-15) unstable; urgency=medium
461
462 * Fix uninitialized warning when shadow.cfg does not exist
463
464 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:10:57 +0200
465
cca9761a
DM
466libpve-access-control (4.0-14) unstable; urgency=medium
467
468 * Add is_worker to RPCEnvironment
469
470 -- Proxmox Support Team <support@proxmox.com> Tue, 15 Mar 2016 16:47:34 +0100
471
8643c99d
DM
472libpve-access-control (4.0-13) unstable; urgency=medium
473
474 * fix #916: allow HTTPS to access custom yubico url
475
476 -- Proxmox Support Team <support@proxmox.com> Mon, 14 Mar 2016 11:39:23 +0100
477
ae2a6bf9
DM
478libpve-access-control (4.0-12) unstable; urgency=medium
479
480 * Catch certificate errors instead of segfaulting
481
482 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Mar 2016 14:41:01 +0100
483
4836db5f
DM
484libpve-access-control (4.0-11) unstable; urgency=medium
485
486 * Fix #861: use safer sprintf formatting
487
488 -- Proxmox Support Team <support@proxmox.com> Fri, 08 Jan 2016 12:52:39 +0100
489
ccbe23dc
DM
490libpve-access-control (4.0-10) unstable; urgency=medium
491
492 * Auth::LDAP, Auth::AD: ipv6 support
493
494 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Dec 2015 12:09:32 +0100
495
90399ca4
DM
496libpve-access-control (4.0-9) unstable; urgency=medium
497
498 * pveum: implement bash completion
499
500 -- Proxmox Support Team <support@proxmox.com> Thu, 01 Oct 2015 17:22:52 +0200
501
364ffc13
DM
502libpve-access-control (4.0-8) unstable; urgency=medium
503
504 * remove_storage_access: cleanup of access permissions for removed storage
505
506 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:39:15 +0200
507
7c26cb4a
DM
508libpve-access-control (4.0-7) unstable; urgency=medium
509
510 * new helper to remove access permissions for removed VMs
511
512 -- Proxmox Support Team <support@proxmox.com> Fri, 14 Aug 2015 07:57:02 +0200
513
296afbd1
DM
514libpve-access-control (4.0-6) unstable; urgency=medium
515
516 * improve parse_user_config, parse_shadow_config
517
518 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:14:33 +0200
519
7d2df2ef
DM
520libpve-access-control (4.0-5) unstable; urgency=medium
521
522 * pveum: check for $cmd being defined
523
524 -- Proxmox Support Team <support@proxmox.com> Wed, 10 Jun 2015 10:40:15 +0200
525
98a34e3f
DM
526libpve-access-control (4.0-4) unstable; urgency=medium
527
528 * use activate-noawait triggers
529
530 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:25:31 +0200
531
15462727
DM
532libpve-access-control (4.0-3) unstable; urgency=medium
533
534 * IPv6 fixes
535
536 * non-root buildfix
537
538 -- Proxmox Support Team <support@proxmox.com> Wed, 27 May 2015 11:15:44 +0200
539
bbf4cc9a
DM
540libpve-access-control (4.0-2) unstable; urgency=medium
541
542 * trigger pve-api-updates event
543
544 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:06:38 +0200
545
dfbcf6d3
DM
546libpve-access-control (4.0-1) unstable; urgency=medium
547
548 * bump version for Debian Jessie
549
550 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Feb 2015 11:22:01 +0100
551
94971b3a
DM
552libpve-access-control (3.0-16) unstable; urgency=low
553
554 * root@pam can now be disabled in GUI.
555
556 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Jan 2015 06:20:22 +0100
557
7b17c7cb
DM
558libpve-access-control (3.0-15) unstable; urgency=low
559
560 * oath: add 'step' and 'digits' option
561
562 -- Proxmox Support Team <support@proxmox.com> Wed, 23 Jul 2014 06:59:52 +0200
563
1abc2c0a
DM
564libpve-access-control (3.0-14) unstable; urgency=low
565
566 * add oath two factor auth
567
568 * add oathkeygen binary to generate keys for oath
569
570 * add yubico two factor auth
571
572 * dedend on oathtool
573
574 * depend on libmime-base32-perl
30be0de9
DM
575
576 * allow to write builtin auth domains config (comment/tfa/default)
1abc2c0a
DM
577
578 -- Proxmox Support Team <support@proxmox.com> Thu, 17 Jul 2014 13:09:56 +0200
579
298450ab
DM
580libpve-access-control (3.0-13) unstable; urgency=low
581
582 * use correct connection string for AD auth
583
584 -- Proxmox Support Team <support@proxmox.com> Thu, 22 May 2014 07:16:09 +0200
585
396034e4
DM
586libpve-access-control (3.0-12) unstable; urgency=low
587
588 * add dummy API for GET /access/ticket (useful to generate login pages)
589
590 -- Proxmox Support Team <support@proxmox.com> Wed, 30 Apr 2014 14:47:56 +0200
591
26361123
DM
592libpve-access-control (3.0-11) unstable; urgency=low
593
594 * Sets common hot keys for spice client
595
596 -- Proxmox Support Team <support@proxmox.com> Fri, 31 Jan 2014 10:24:28 +0100
597
3643383d
DM
598libpve-access-control (3.0-10) unstable; urgency=low
599
600 * implement helper to generate SPICE remote-viewer configuration
601
602 * depend on libnet-ssleay-perl
603
604 -- Proxmox Support Team <support@proxmox.com> Tue, 10 Dec 2013 10:45:08 +0100
605
0baedcf7
DM
606libpve-access-control (3.0-9) unstable; urgency=low
607
608 * prevent user enumeration attacks
e4f8fc2e
DM
609
610 * allow dots in access paths
0baedcf7
DM
611
612 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2013 09:06:38 +0100
613
d4b63eae
DM
614libpve-access-control (3.0-8) unstable; urgency=low
615
616 * spice: use lowercase hostname in ticktet signature
617
618 -- Proxmox Support Team <support@proxmox.com> Mon, 28 Oct 2013 08:11:57 +0100
619
49594944
DM
620libpve-access-control (3.0-7) unstable; urgency=low
621
622 * check_volume_access : use parse_volname instead of path, and remove
623 path related code.
7c410d63
DM
624
625 * use warnings instead of global -w flag.
49594944
DM
626
627 -- Proxmox Support Team <support@proxmox.com> Tue, 01 Oct 2013 12:35:53 +0200
628
fe7de5d0
DM
629libpve-access-control (3.0-6) unstable; urgency=low
630
631 * use shorter spiceproxy tickets
632
633 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Jul 2013 12:39:09 +0200
634
4cdd9507
DM
635libpve-access-control (3.0-5) unstable; urgency=low
636
637 * add code to generate tickets for SPICE
638
639 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Jun 2013 13:08:32 +0200
640
677f9ab0
DM
641libpve-access-control (3.0-4) unstable; urgency=low
642
643 * moved add_vm_to_pool/remove_vm_from_pool from qemu-server
644
645 -- Proxmox Support Team <support@proxmox.com> Tue, 14 May 2013 11:56:54 +0200
646
139a8ecf
DM
647libpve-access-control (3.0-3) unstable; urgency=low
648
7b395f99 649 * Add new role PVETemplateUser (and VM.Clone priviledge)
139a8ecf
DM
650
651 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Apr 2013 11:42:15 +0200
652
b78ce7c2
DM
653libpve-access-control (3.0-2) unstable; urgency=low
654
655 * remove CGI.pm related code (pveproxy does not need that)
656
657 -- Proxmox Support Team <support@proxmox.com> Mon, 15 Apr 2013 12:34:23 +0200
658
786820f9
DM
659libpve-access-control (3.0-1) unstable; urgency=low
660
661 * bump version for wheezy release
662
663 -- Proxmox Support Team <support@proxmox.com> Fri, 15 Mar 2013 08:07:06 +0100
664
e5ae5487
DM
665libpve-access-control (1.0-26) unstable; urgency=low
666
667 * check_volume_access: fix access permissions for backup files
668
669 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Feb 2013 10:00:14 +0100
670
e3e6510c
DM
671libpve-access-control (1.0-25) unstable; urgency=low
672
673 * add VM.Snapshot permission
674
675 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Sep 2012 09:23:32 +0200
676
1e15ebe7
DM
677libpve-access-control (1.0-24) unstable; urgency=low
678
679 * untaint path (allow root to restore arbitrary paths)
680
681 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2012 13:06:34 +0200
682
437be042
DM
683libpve-access-control (1.0-23) unstable; urgency=low
684
685 * correctly compute GUI capabilities (consider pools)
686
687 -- Proxmox Support Team <support@proxmox.com> Wed, 30 May 2012 08:47:23 +0200
688
5bb4e06a
DM
689libpve-access-control (1.0-22) unstable; urgency=low
690
691 * new plugin architecture for Auth modules, minor API change for Auth
692 domains (new 'delete' parameter)
693
694 -- Proxmox Support Team <support@proxmox.com> Wed, 16 May 2012 07:21:44 +0200
695
3030a176
DM
696libpve-access-control (1.0-21) unstable; urgency=low
697
698 * do not allow user names including slash
699
700 -- Proxmox Support Team <support@proxmox.com> Tue, 24 Apr 2012 10:07:47 +0200
701
702libpve-access-control (1.0-20) unstable; urgency=low
703
704 * add ability to fork cli workers in background
705
706 -- Proxmox Support Team <support@proxmox.com> Wed, 18 Apr 2012 08:28:20 +0200
707
dd2cfee0
DM
708libpve-access-control (1.0-19) unstable; urgency=low
709
710 * return set of privileges on login - can be used to adopt GUI
711
712 -- Proxmox Support Team <support@proxmox.com> Tue, 17 Apr 2012 10:25:10 +0200
713
1cf154b7
DM
714libpve-access-control (1.0-18) unstable; urgency=low
715
533219a1
DM
716 * fix bug #151: corretly parse username inside ticket
717
718 * fix bug #152: allow user to change his own password
1cf154b7
DM
719
720 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2012 09:40:15 +0200
721
2de14407
DM
722libpve-access-control (1.0-17) unstable; urgency=low
723
724 * set propagate flag by default
725
726 -- Proxmox Support Team <support@proxmox.com> Thu, 01 Mar 2012 12:40:19 +0100
727
bdc61d7a
DM
728libpve-access-control (1.0-16) unstable; urgency=low
729
730 * add 'pveum passwd' method
731
732 -- Proxmox Support Team <support@proxmox.com> Thu, 23 Feb 2012 12:05:25 +0100
733
cc7bdf33
DM
734libpve-access-control (1.0-15) unstable; urgency=low
735
736 * Add VM.Config.CDROM privilege to PVEVMUser rule
737
738 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 11:44:23 +0100
739
a69bbe2e
DM
740libpve-access-control (1.0-14) unstable; urgency=low
741
742 * fix buf in userid-param permission check
743
744 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 10:52:35 +0100
745
d9483d94
DM
746libpve-access-control (1.0-13) unstable; urgency=low
747
748 * allow more characters in ldap base_dn attribute
749
750 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 06:17:02 +0100
751
84619607
DM
752libpve-access-control (1.0-12) unstable; urgency=low
753
754 * allow more characters with realm IDs
755
756 -- Proxmox Support Team <support@proxmox.com> Mon, 20 Feb 2012 08:50:33 +0100
757
09d27058
DM
758libpve-access-control (1.0-11) unstable; urgency=low
759
760 * fix bug in exec_api2_perm_check
761
762 -- Proxmox Support Team <support@proxmox.com> Wed, 15 Feb 2012 07:06:30 +0100
763
7a4c849e
DM
764libpve-access-control (1.0-10) unstable; urgency=low
765
766 * fix ACL group name parser
767
768 * changed 'pveum aclmod' command line arguments
769
770 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Feb 2012 12:08:02 +0100
771
3eac4e35
DM
772libpve-access-control (1.0-9) unstable; urgency=low
773
774 * fix bug in check_volume_access (fixes vzrestore)
775
776 -- Proxmox Support Team <support@proxmox.com> Mon, 13 Feb 2012 09:56:37 +0100
777
4384e19e
DM
778libpve-access-control (1.0-8) unstable; urgency=low
779
780 * fix return value for empty ACL list.
781
782 -- Proxmox Support Team <support@proxmox.com> Fri, 10 Feb 2012 11:25:04 +0100
783
d8a56966
DM
784libpve-access-control (1.0-7) unstable; urgency=low
785
786 * fix bug #85: allow root@pam to generate tickets for other users
787
788 -- Proxmox Support Team <support@proxmox.com> Tue, 17 Jan 2012 06:40:18 +0100
789
cb6f2f93
DM
790libpve-access-control (1.0-6) unstable; urgency=low
791
792 * API change: allow to filter enabled/disabled users.
793
794 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Jan 2012 12:30:37 +0100
795
272fe9ff
DM
796libpve-access-control (1.0-5) unstable; urgency=low
797
798 * add a way to return file changes (diffs): set_result_changes()
799
800 -- Proxmox Support Team <support@proxmox.com> Tue, 20 Dec 2011 11:18:48 +0100
801
e42eedbc
DM
802libpve-access-control (1.0-4) unstable; urgency=low
803
804 * new environment type for ha agents
805
806 -- Proxmox Support Team <support@proxmox.com> Tue, 13 Dec 2011 10:08:53 +0100
807
1fba27e0
DM
808libpve-access-control (1.0-3) unstable; urgency=low
809
810 * add support for delayed parameter parsing - We need that to disable
811 file upload for normal API request (avoid DOS attacs)
812
813 -- Proxmox Support Team <support@proxmox.com> Fri, 02 Dec 2011 09:56:10 +0100
814
5bf71a96
DM
815libpve-access-control (1.0-2) unstable; urgency=low
816
817 * fix bug in fork_worker
818
819 -- Proxmox Support Team <support@proxmox.com> Tue, 11 Oct 2011 08:37:05 +0200
820
2c3a6c0a
DM
821libpve-access-control (1.0-1) unstable; urgency=low
822
823 * allow '-' in permission paths
824
825 * bump version to 1.0
826
827 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jun 2011 13:51:48 +0200
828
829libpve-access-control (0.1) unstable; urgency=low
830
831 * first dummy package - no functionality
832
833 -- Proxmox Support Team <support@proxmox.com> Thu, 09 Jul 2009 16:03:00 +0200
834