mirror of
1
Fork 0
forgejo/routers/web/user/setting
Gusted a9c97110f9 feat: add configurable cooldown to claim usernames (#6422)
Add a new option that allows instances to set a cooldown period to claim
old usernames. In the context of public instances this can be used to
prevent old usernames to be claimed after they are free and allow
graceful migration (by making use of the redirect feature) to a new
username. The granularity of this cooldown is a day. By default this
feature is disabled and thus no cooldown period.

The `CreatedUnix` column is added the `user_redirect` table, for
existing redirects the timestamp is simply zero as we simply do not know
when they were created and are likely already over the cooldown period
if the instance configures one.

Users can always reclaim their 'old' user name again within the cooldown
period. Users can also always reclaim 'old' names of organization they
currently own within the cooldown period.

Creating and renaming users as an admin user are not affected by the
cooldown period for moderation and user support reasons.

To avoid abuse of the cooldown feature, such that a user holds a lot of
usernames, a new option is added `MAX_USER_REDIRECTS` which sets a limit
to the amount of user redirects a user may have, by default this is
disabled. If a cooldown period is set then the default is 5. This
feature operates independently of the cooldown period feature.

Added integration and unit testing.

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/6422
Reviewed-by: Earl Warren <earl-warren@noreply.codeberg.org>
Reviewed-by: 0ko <0ko@noreply.codeberg.org>
Reviewed-by: Otto <otto@codeberg.org>
Co-authored-by: Gusted <postmaster@gusted.xyz>
Co-committed-by: Gusted <postmaster@gusted.xyz>
2025-01-24 04:16:56 +00:00
..
security feat: migrate TOTP secrets to `keying` 2024-11-27 00:34:16 +01:00
account.go fix: extend `forgejo_auth_token` table 2024-11-15 10:59:36 +01:00
account_test.go Move context from modules to services (#29440) 2024-03-06 12:10:43 +08:00
adopt.go Move context from modules to services (#29440) 2024-03-06 12:10:43 +08:00
applications.go OAuth2 provider: support for granular scopes 2024-08-09 14:58:15 +02:00
blocked_users.go Move context from modules to services (#29440) 2024-03-06 12:10:43 +08:00
keys.go Add setting to disable user features when user login type is not plain (#29615) 2024-04-07 11:09:21 +02:00
main_test.go make writing main test easier (#27270) 2023-09-28 01:38:53 +00:00
oauth2.go Move context from modules to services (#29440) 2024-03-06 12:10:43 +08:00
oauth2_common.go Validate OAuth Redirect URIs (#32643) 2024-12-03 10:19:22 +01:00
packages.go Move context from modules to services (#29440) 2024-03-06 12:10:43 +08:00
profile.go feat: add configurable cooldown to claim usernames (#6422) 2025-01-24 04:16:56 +00:00
runner.go Move context from modules to services (#29440) 2024-03-06 12:10:43 +08:00
webhooks.go [REFACTOR] use Icon from interface in webhook list 2024-03-30 16:00:06 +01:00