1ee8acf060
* Signup: if entering an existing email, don't admit that the email exists. Instead, send a specialized email to its address. * Search: no longer search for users by email address. * Login: always hash the incoming password on user not found, to take constant time compared to when the user did exist. * Fix a pagination bug when a private (shy account) views a non-friend's photo gallery. |
||
---|---|---|
.. | ||
config | ||
controller | ||
geoip | ||
log | ||
markdown | ||
middleware | ||
models | ||
photo | ||
ratelimit | ||
redis | ||
router | ||
session | ||
templates | ||
utility | ||
worker | ||
version.go | ||
webserver.go |