Commit graph

  • fa3cf6c299
    Fix type error in security fixes Julia Johannesen 2024-11-20 20:06:46 -0500
  • 4b556efdaa merge: (re-merge) Prevent DoS from spammed media proxy requests (!763) Julia 2024-11-21 00:40:52 +0000
  • 5d49488298 merge: (re-merge) Prevent DoS from spammed media proxy requests (!763) Hazelnoot 2024-11-21 00:39:23 +0000
  • b0834ebf55 prevent DoS from spammed media proxy requests Hazelnoot 2024-11-19 22:59:07 -0500
  • 2234fbcb11 merge: Bump version (!762) Julia 2024-11-21 00:23:26 +0000
  • 581d922348 merge: Bump version (!762) Julia 2024-11-21 00:23:15 +0000
  • 8e90484b3e
    Bump version Julia Johannesen 2024-11-20 19:21:57 -0500
  • 0fcb23c4c1 merge: Coordinated Security Release (!761) Julia 2024-11-21 00:20:48 +0000
  • ac88ac3c95 merge: Coordinated Security Release (!761) Julia 2024-11-21 00:20:19 +0000
  • 776f6fd1f5
    fix(backend): allow fetchSummaryFromProxy, trueMail to access local addresses rectcoordsystem 2024-11-13 15:27:17 +0900
  • 7b3e3f8e25
    fix(backend): add isLocalAddressAllowed option to getAgentByUrl and send (HttpRequestService) rectcoordsystem 2024-11-13 13:30:01 +0900
  • 360d71278a
    fix(backend): lint and typecheck rectcoordsystem 2024-11-13 03:27:52 +0900
  • 663c06be00
    Apply suggestions from code review rectcoordsystem 2024-11-13 03:06:22 +0900
  • 7ccccf5545
    fix(backend): allow accessing private IP when testing rectcoordsystem 2024-11-06 06:33:44 +0900
  • f36f4b5398
    fix(backend): check target IP before sending HTTP request rectcoordsystem 2024-11-06 05:31:11 +0900
  • cc4e99fdde
    fix: Try using CacheService to avoid excess db lookups Julia Johannesen 2024-11-14 23:43:19 -0500
  • 5764fa55cb
    fix: primitives 25-33: proper local instance checks Julia Johannesen 2024-11-14 22:01:22 -0500
  • 74565f67f7
    fix: primitives 21, 22, and 23: reuse resolver Julia Johannesen 2024-11-14 21:53:16 -0500
  • 408e782507
    fix: primitive 19 & 20: respect blocks and hide more Julia Johannesen 2024-11-14 21:38:17 -0500
  • cbf8cc376e
    fix: primitive 18: ap/get bypasses access checks Julia Johannesen 2024-11-14 21:23:27 -0500
  • c04f344049
    fix: primitive 13: check attribution against actor in notes Julia Johannesen 2024-11-14 21:17:30 -0500
  • b9080da75d
    fix: code style for primitive 17 Julia Johannesen 2024-11-14 20:28:50 -0500
  • 4d925fc086
    fix: primitive 17: note same-origin identifier validation can be bypassed by wrapping the id in an array Laura Hausmann 2024-10-24 04:18:49 +0200
  • b74e2e9167
    fix: primitive 16: improper same-origin validation for user uri and url Laura Hausmann 2024-10-24 05:11:16 +0200
  • ebea1a2962
    fix: primitive 15: improper same-origin validation for note uri and url Laura Hausmann 2024-10-24 05:07:58 +0200
  • 4c432c07cb
    fix: code style for primitive 14 Julia Johannesen 2024-11-14 20:21:17 -0500
  • 322b3b677f
    fix: primitive 14: improper validation of outbox, followers, following & shared inbox collections Laura Hausmann 2024-10-26 19:51:11 +0200
  • 1c7e05ce9e
    fix: primitive 7 & 12: prevent poll spoofing Julia Johannesen 2024-11-14 19:57:29 -0500
  • 9ab25ede28
    fix: primitives 9, 10 & 11: http signature validation doesn't enforce required headers or specify auth header name Laura Hausmann 2024-10-24 04:40:33 +0200
  • 174dfb83d0
    fix: primitive 6: reject anonymous objects that were fetched by their id Laura Hausmann 2024-10-24 04:28:43 +0200
  • ad8e8793c7
    fix: primitives 5 & 8: reject activities with non-string identifiers Laura Hausmann 2024-10-24 04:37:47 +0200
  • 1e14612f0e
    fix: primitive 4: missing same-origin identifier validation of collection-wrapped activities Laura Hausmann 2024-10-24 04:11:35 +0200
  • 9090b745e6
    fix: primitive 3: validation of non-final url Laura Hausmann 2024-10-24 04:04:56 +0200
  • d883934826
    fix: primitive 2: acceptance of cross-origin alternate links Laura Hausmann 2024-10-24 05:13:35 +0200
  • 3b25811f1b merge: Coordinated Security Release (!760) Julia 2024-11-20 23:31:25 +0000
  • 2e34537f0a
    fix(backend): allow fetchSummaryFromProxy, trueMail to access local addresses rectcoordsystem 2024-11-13 15:27:17 +0900
  • fb141fb0ef
    fix(backend): add isLocalAddressAllowed option to getAgentByUrl and send (HttpRequestService) rectcoordsystem 2024-11-13 13:30:01 +0900
  • f8a40dd72f
    fix(backend): lint and typecheck rectcoordsystem 2024-11-13 03:27:52 +0900
  • 9842dafdbc
    Apply suggestions from code review rectcoordsystem 2024-11-13 03:06:22 +0900
  • e0af19f8e9
    fix(backend): allow accessing private IP when testing rectcoordsystem 2024-11-06 06:33:44 +0900
  • 55f2e42c7d
    fix(backend): check target IP before sending HTTP request rectcoordsystem 2024-11-06 05:31:11 +0900
  • f0673f6a82
    fix: Try using CacheService to avoid excess db lookups Julia Johannesen 2024-11-14 23:43:19 -0500
  • b83c9bfd91
    fix: primitives 25-33: proper local instance checks Julia Johannesen 2024-11-14 22:01:22 -0500
  • bb6e4210c9
    fix: primitives 21, 22, and 23: reuse resolver Julia Johannesen 2024-11-14 21:53:16 -0500
  • 0a39bfb458
    fix: primitive 19 & 20: respect blocks and hide more Julia Johannesen 2024-11-14 21:38:17 -0500
  • 48787ed99d
    fix: primitive 18: ap/get bypasses access checks Julia Johannesen 2024-11-14 21:23:27 -0500
  • cc710b3a66
    fix: primitive 13: check attribution against actor in notes Julia Johannesen 2024-11-14 21:17:30 -0500
  • aff90aa3c2
    fix: code style for primitive 17 Julia Johannesen 2024-11-14 20:28:50 -0500
  • 1e7afa06e5
    fix: primitive 17: note same-origin identifier validation can be bypassed by wrapping the id in an array Laura Hausmann 2024-10-24 04:18:49 +0200
  • 82e608402a
    fix: primitive 16: improper same-origin validation for user uri and url Laura Hausmann 2024-10-24 05:11:16 +0200
  • 8c25b4cc45
    fix: primitive 15: improper same-origin validation for note uri and url Laura Hausmann 2024-10-24 05:07:58 +0200
  • 644338b049
    fix: code style for primitive 14 Julia Johannesen 2024-11-14 20:21:17 -0500
  • ea6d3d6c74
    fix: primitive 14: improper validation of outbox, followers, following & shared inbox collections Laura Hausmann 2024-10-26 19:51:11 +0200
  • 64a70183ee
    fix: primitive 7 & 12: prevent poll spoofing Julia Johannesen 2024-11-14 19:57:29 -0500
  • 456c79b77a
    fix: primitives 9, 10 & 11: http signature validation doesn't enforce required headers or specify auth header name Laura Hausmann 2024-10-24 04:40:33 +0200
  • 799870e360
    fix: primitive 6: reject anonymous objects that were fetched by their id Laura Hausmann 2024-10-24 04:28:43 +0200
  • aca57e66e2
    fix: primitives 5 & 8: reject activities with non-string identifiers Laura Hausmann 2024-10-24 04:37:47 +0200
  • 46ffdfd57f
    fix: primitive 4: missing same-origin identifier validation of collection-wrapped activities Laura Hausmann 2024-10-24 04:11:35 +0200
  • 91aabe3c0a
    fix: primitive 3: validation of non-final url Laura Hausmann 2024-10-24 04:04:56 +0200
  • bc1087cc57
    fix: primitive 2: acceptance of cross-origin alternate links Laura Hausmann 2024-10-24 05:13:35 +0200
  • 6a4b4a505a merge: upstream changes for 2024.10 (!742) dakkar 2024-11-20 16:45:30 +0000
  • 878e2f46fa
    unescape MOTD html piuvas 2024-11-20 13:42:23 -0300
  • e0bb796aff merge: Fix linter error in emojis endpoint (!758) Julia 2024-11-20 06:29:48 +0000
  • 3e40be0a81 merge: Fix linter error in emojis endpoint (!758) Julia 2024-11-20 06:20:18 +0000
  • fb54546573
    Fix linter error in emojis endpoint Julia Johannesen 2024-11-20 01:17:24 -0500
  • 9e0b759197 merge: Bump develop version (!757) Julia 2024-11-20 05:56:55 +0000
  • 49e3769f9c merge: Bump develop version (!757) Julia 2024-11-20 05:56:32 +0000
  • 41c500851b
    Bump develop version Julia Johannesen 2024-11-20 00:54:30 -0500
  • 27339e03c2 merge: Bump version (!756) 2024.9.2 Julia 2024-11-20 05:22:39 +0000
  • 5530617197 merge: Bump version (!756) Julia 2024-11-20 05:11:58 +0000
  • 680c2a0718
    Bump version Julia Johannesen 2024-11-20 00:09:56 -0500
  • 19b618d301 merge: Stable (!755) Julia 2024-11-20 05:05:42 +0000
  • f258888408 merge: Prevent DoS from spammed media proxy requests (!754) Julia 2024-11-20 04:59:00 +0000
  • 56ddbedb59 merge: Prevent DoS from spammed media proxy requests (!754) Hazelnoot 2024-11-20 04:33:25 +0000
  • a393878d4f merge: Prevent DoS from spammed media proxy requests (!753) Hazelnoot 2024-11-20 04:32:17 +0000
  • d150e92f41 prevent DoS from spammed media proxy requests Hazelnoot 2024-11-19 22:59:07 -0500
  • 472307ff23 prevent DoS from spammed media proxy requests Hazelnoot 2024-11-19 22:59:07 -0500
  • 8afa4ca5f3 merge: Fix "make emoji categories and names case insensitive." (!752) Natsuki Kaede 2024-11-19 16:48:46 +0000
  • d52f68962c Fix "make emoji categories and names case insensitive." fly_mc 2024-11-20 00:47:22 +0800
  • c8a062cd0f merge: Draft: Draft Add option to use Elasticsearch (!708) James Moy 2024-11-17 17:50:32 +0000
  • 24447e636f merge: Merge inactive moderators spam protection from upstream (!732) Marie 2024-11-17 13:22:52 +0000
  • 482538c7f8 merge: make emoji categories and names case insensitive. (!746) dakkar 2024-11-17 13:22:39 +0000
  • d7e97104e8 merge: make emoji categories and names case insensitive. (!746) piuvas silly 2024-11-17 00:50:20 +0000
  • d579687156 merge: Dockerfile mkdir files (!740) Hazelnoot 2024-11-17 00:48:37 +0000
  • 1e22c8fe91 merge: Dockerfile mkdir files (!740) Rachel Y 2024-11-17 00:41:22 +0000
  • de970ff54e merge: Change example config - db name and user consistent with docs (!739) Hazelnoot 2024-11-17 00:41:14 +0000
  • 620c1e2f0c merge: Change example config - db name and user consistent with docs (!739) Maciej 2024-11-17 00:40:59 +0000
  • 1bfb0dc395 merge: check harder for connectibility (!737) Hazelnoot 2024-11-17 00:40:52 +0000
  • b7fc7dc80c merge: check harder for connectibility (!737) dakkar 2024-11-17 00:40:25 +0000
  • da2dfee0a8 merge: Remove check to prevent admin reporting (Fixes #757) (!727) Hazelnoot 2024-11-17 00:39:08 +0000
  • eaad96aae3
    edit query piuvas 2024-11-15 13:40:53 -0300
  • a16d7e1e75 fix SCSS warning feature/2024.10 dakkar 2024-11-14 12:12:25 +0000
  • 1092bb3166 merge: Remove check to prevent admin reporting (Fixes #757) (!727) Kio! 2024-11-14 00:40:35 +0000
  • fdad036912 Merge branch 'develop' into feature/2024.10 dakkar 2024-11-13 11:45:10 +0000
  • 0a05841f33 merge: Add "pinned" section to notes tab on user profiles (!689) dakkar 2024-11-13 11:14:59 +0000
  • 68e5b5a84a Set horizontal margin for even better consistency tess 2024-11-12 22:09:37 +0100
  • 6d6b03dfe2 tweak popup left margin for consistency tess 2024-11-12 21:30:19 +0100
  • 19be113cb4 Keep MkUserPopup from extending past left side of screen tess 2024-11-12 21:29:22 +0100
  • 101ca9e0f7 make sure popup position is never off screen to the left tess 2024-11-12 21:16:59 +0100
  • 906c2863db
    fix: move cypress to optionalDependencies in packages/frontent/package.json fix/cypress-optional Luna Nova 2024-11-12 14:33:05 -0500