Photo Sharing. For Everyone.
You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
Go to file
Your Name 08a442e661 Rewrite 2FA tests for the pending-login refactor
The 2FA flow moved from a middleware-gated i/auth/checkpoint model to a
pending-login model (auth.pending session, POST /login/2fa, /login?step=2fa
challenge). The old tests referenced the removed route and dead session keys
(2fa.session.active, 2fa.attempts) and failed with 404s.

Rewritten against the new code as source of truth:
- Checkpoint test: throttle assertion retargeted to the login/2fa route;
  failed-verification audit log now driven through a pending 2FA session.
- Logout-session test: asserts auth.pending is cleared and the user stays a
  guest after MAX_2FA_ATTEMPTS failures (replacing the old flag cleanup).
- TwoFactorTest: challenge-redirect and challenge-page cases rewritten around
  the login flow; setup/recovery password-confirmation cases unchanged.
- MiddlewarePipelineTest: 2FA is enforced at login, not per-request, so an
  authenticated 2FA user browses normally.

Full suite: 715 passed.
2 weeks ago
.ddev
.github Update dependabot.yml 3 weeks ago
.vscode
app Backfill storage_used on upgrade via queued job + data migration 2 weeks ago
bootstrap polish 2 weeks ago
config Move account_storage_reconcile flag to config/scheduledtasks.php 2 weeks ago
database Backfill storage_used on upgrade via queued job + data migration 2 weeks ago
lang polish 3 weeks ago
notes Update DeduplicationChanges.md with service reference 4 weeks ago
public Update compiled assets 2 weeks ago
resources Refactor Auth, remove expensive middleware 2 weeks ago
routes Move scheduled tasks file from routes/ to bootstrap/ 2 weeks ago
storage
tests Rewrite 2FA tests for the pending-login refactor 2 weeks ago
.dockerignore chore: add Psalm static analysis (plugin-laravel, baseline, CI) 4 weeks ago
.editorconfig
.env.docker.example fix: remove deprecated Passport::personalAccessClientId() and enableImplicitGrant() 4 weeks ago
.env.example fix: remove deprecated Passport::personalAccessClientId() and enableImplicitGrant() 4 weeks ago
.env.testing Add Sanctum support 3 weeks ago
.gitattributes
.gitignore chore: resolve psalm issues in admin commands and auth 4 weeks ago
.markdownlint.json
.node-version
.shellcheckrc
CHANGELOG.md Update CHANGELOG.md 4 weeks ago
CODEOWNERS
CODE_OF_CONDUCT.md
CONTRIBUTING.md
DOCKER_COMPOSE_SETUP.md Fix duplicate command in Docker Compose setup 4 weeks ago
Dockerfile Update Dockerfile 1 month ago
LICENSE
README.md
SECURITY.md
artisan chore: uplift framework skeleton toward Laravel 12 defaults 3 weeks ago
composer.json Require ext-redis to support phpredis client 3 weeks ago
composer.lock Require ext-redis to support phpredis client 3 weeks ago
crowdin.yml chore: move resources/lang to top-level lang/ per Laravel 9+ convention 3 weeks ago
docker-compose.test.yml ci: refactor GitHub Actions with Redis service and best practices 4 weeks ago
docker-compose.yml fix: remove bootstrap/cache bind mount from docker-compose 4 weeks ago
funding.json
package-lock.json Merge pull request #7046 from pixelfed/dependabot/npm_and_yarn/svgo-2.8.4 3 weeks ago
package.json chore(deps)(deps): bump blurhash from 1.1.5 to 2.0.5 3 weeks ago
phpstan.neon chore: move resources/lang to top-level lang/ per Laravel 9+ convention 3 weeks ago
phpunit.xml Shift `ENV` variables 3 weeks ago
pint.json Create pint.json 4 weeks ago
psalm-baseline.xml chore: add Psalm static analysis (plugin-laravel, baseline, CI) 4 weeks ago
psalm.xml chore: target PHP 8.4 in psalm config 4 weeks ago
server.php
webpack.mix.js

README.md

Pixelfed logo

Latest Stable Version License Total Pixelfed users from FediDB

Introduction

Photo sharing the way it should be. Pixelfed lets your casual shots and creative photography find their audience naturally, without algorithmic barriers. Join millions of people sharing across the fediverse.

Pixelfed web user interface in light mode

Official Documentation

Documentation for Pixelfed can be found on the Pixelfed documentation website.

Run on YunoHost

Install on YunoHost

Pixelfed app for YunoHost. See the package source code

License

Pixelfed is open-sourced software licensed under the AGPL license.

Communication

The ways you can communicate on the project are below. Before interacting, please read through the Code Of Conduct.

Pixelfed Sponsors

We would like to extend our thanks to the following sponsors for funding Pixelfed development. If you are interested in becoming a sponsor, please visit the Pixelfed Patreon Page

This project is supported by: