Commit graph

  • 5181836dc3 Merge pull request 'update-to-2024.9.3' (#16) from update-to-2024.9.3 into dev dev zima 2024-11-21 05:32:22 +0000
  • 4098a0ced6 Merge tag '2024.9.3' into update-to-2024.9.3 zima 2024-11-20 21:52:15 -0700
  • a38d8a91a1 merge: Fix .punyHost misuse (!765) Julia 2024-11-21 02:26:43 +0000
  • 6027b516e1
    Fix .punyHost misuse Julia Johannesen 2024-11-20 21:24:35 -0500
  • 757d9aa5ee merge: Fix type error(s) in security fixes (!764) Julia 2024-11-21 01:44:15 +0000
  • 36af07abe2
    Fix another style error Julia Johannesen 2024-11-20 20:31:22 -0500
  • 23c4aa2571
    Fix style error Julia Johannesen 2024-11-20 20:24:59 -0500
  • 1758f29364
    Fix error in test function calls Julia Johannesen 2024-11-20 20:16:43 -0500
  • fa3cf6c299
    Fix type error in security fixes Julia Johannesen 2024-11-20 20:06:46 -0500
  • 4b556efdaa merge: (re-merge) Prevent DoS from spammed media proxy requests (!763) Julia 2024-11-21 00:40:52 +0000
  • b0834ebf55 prevent DoS from spammed media proxy requests Hazelnoot 2024-11-19 22:59:07 -0500
  • 2234fbcb11 merge: Bump version (!762) Julia 2024-11-21 00:23:26 +0000
  • 8e90484b3e
    Bump version Julia Johannesen 2024-11-20 19:21:57 -0500
  • 0fcb23c4c1 merge: Coordinated Security Release (!761) Julia 2024-11-21 00:20:48 +0000
  • 776f6fd1f5
    fix(backend): allow fetchSummaryFromProxy, trueMail to access local addresses rectcoordsystem 2024-11-13 15:27:17 +0900
  • 7b3e3f8e25
    fix(backend): add isLocalAddressAllowed option to getAgentByUrl and send (HttpRequestService) rectcoordsystem 2024-11-13 13:30:01 +0900
  • 360d71278a
    fix(backend): lint and typecheck rectcoordsystem 2024-11-13 03:27:52 +0900
  • 663c06be00
    Apply suggestions from code review rectcoordsystem 2024-11-13 03:06:22 +0900
  • 7ccccf5545
    fix(backend): allow accessing private IP when testing rectcoordsystem 2024-11-06 06:33:44 +0900
  • f36f4b5398
    fix(backend): check target IP before sending HTTP request rectcoordsystem 2024-11-06 05:31:11 +0900
  • cc4e99fdde
    fix: Try using CacheService to avoid excess db lookups Julia Johannesen 2024-11-14 23:43:19 -0500
  • 5764fa55cb
    fix: primitives 25-33: proper local instance checks Julia Johannesen 2024-11-14 22:01:22 -0500
  • 74565f67f7
    fix: primitives 21, 22, and 23: reuse resolver Julia Johannesen 2024-11-14 21:53:16 -0500
  • 408e782507
    fix: primitive 19 & 20: respect blocks and hide more Julia Johannesen 2024-11-14 21:38:17 -0500
  • cbf8cc376e
    fix: primitive 18: ap/get bypasses access checks Julia Johannesen 2024-11-14 21:23:27 -0500
  • c04f344049
    fix: primitive 13: check attribution against actor in notes Julia Johannesen 2024-11-14 21:17:30 -0500
  • b9080da75d
    fix: code style for primitive 17 Julia Johannesen 2024-11-14 20:28:50 -0500
  • 4d925fc086
    fix: primitive 17: note same-origin identifier validation can be bypassed by wrapping the id in an array Laura Hausmann 2024-10-24 04:18:49 +0200
  • b74e2e9167
    fix: primitive 16: improper same-origin validation for user uri and url Laura Hausmann 2024-10-24 05:11:16 +0200
  • ebea1a2962
    fix: primitive 15: improper same-origin validation for note uri and url Laura Hausmann 2024-10-24 05:07:58 +0200
  • 4c432c07cb
    fix: code style for primitive 14 Julia Johannesen 2024-11-14 20:21:17 -0500
  • 322b3b677f
    fix: primitive 14: improper validation of outbox, followers, following & shared inbox collections Laura Hausmann 2024-10-26 19:51:11 +0200
  • 1c7e05ce9e
    fix: primitive 7 & 12: prevent poll spoofing Julia Johannesen 2024-11-14 19:57:29 -0500
  • 9ab25ede28
    fix: primitives 9, 10 & 11: http signature validation doesn't enforce required headers or specify auth header name Laura Hausmann 2024-10-24 04:40:33 +0200
  • 174dfb83d0
    fix: primitive 6: reject anonymous objects that were fetched by their id Laura Hausmann 2024-10-24 04:28:43 +0200
  • ad8e8793c7
    fix: primitives 5 & 8: reject activities with non-string identifiers Laura Hausmann 2024-10-24 04:37:47 +0200
  • 1e14612f0e
    fix: primitive 4: missing same-origin identifier validation of collection-wrapped activities Laura Hausmann 2024-10-24 04:11:35 +0200
  • 9090b745e6
    fix: primitive 3: validation of non-final url Laura Hausmann 2024-10-24 04:04:56 +0200
  • d883934826
    fix: primitive 2: acceptance of cross-origin alternate links Laura Hausmann 2024-10-24 05:13:35 +0200
  • a9a82bed48 Update Sharkey to 2024.9.2 stable zima 2024-11-20 23:39:52 +0000
  • 3d8c3aa081 Merge 2024.9.2 zima 2024-11-20 23:38:42 +0000
  • b47ebf162f Merge remote-tracking branch 'origin/update-to-2024.9.2' into update-to-2024.9.2 zima 2024-11-20 15:08:13 -0700
  • 8ac6e62184 migration must happen after fixorm HellhoundSoftware 2024-11-10 02:55:02 -0500
  • 0670359c4f improve search mfm HellhoundSoftware 2024-11-09 23:21:48 -0500
  • 73ae0cf039 non-fucked migration script HellhoundSoftware 2024-11-09 20:27:41 -0500
  • 3054cd4936 she migrate on my TypeORM till i (GUNSHOTS) HellhoundSoftware 2024-11-08 20:38:37 -0500
  • 783cf3ed4a Change default settings ~keith 2024-11-08 19:31:02 -0500
  • bccd6b2dd8 Remove like button ~keith 2024-11-08 19:30:38 -0500
  • f9dbe135e9 oops :) HellhoundSoftware 2024-11-10 02:29:33 -0500
  • 390d99e531 Fix ORM models to match intended database schema HellhoundSoftware 2024-11-09 19:34:25 -0500
  • da42cd8a4d Set NewRodin to swap display zima 2024-11-08 16:54:29 -0700
  • 196cb6bb8b Replaced NewRodin OTF with fixed TTF/WOFF2 version ~keith 2024-11-08 16:31:43 -0500
  • 9e809aa3b6 Add font NewRodin Pro zima 2024-11-06 22:59:24 -0700
  • 27339e03c2 merge: Bump version (!756) Julia 2024-11-20 05:22:39 +0000
  • 680c2a0718
    Bump version Julia Johannesen 2024-11-20 00:09:56 -0500
  • f258888408 merge: Prevent DoS from spammed media proxy requests (!754) Julia 2024-11-20 04:59:00 +0000
  • d150e92f41 prevent DoS from spammed media proxy requests Hazelnoot 2024-11-19 22:59:07 -0500
  • 4e475f029c Merge pull request 'stable v1' (#6) from dev into stable v0.0.0 zima 2024-11-14 23:55:54 +0000
  • 0954b098a4 change default account and experience settings, and disable like button zima 2024-11-13 03:33:56 +0000
  • 6c92c9c3b3
    migration must happen after fixorm HellhoundSoftware 2024-11-10 02:55:02 -0500
  • b016d28662
    improve search mfm HellhoundSoftware 2024-11-09 23:21:48 -0500
  • 7e064399f8
    non-fucked migration script HellhoundSoftware 2024-11-09 20:27:41 -0500
  • 2716753267
    she migrate on my TypeORM till i (GUNSHOTS) HellhoundSoftware 2024-11-08 20:38:37 -0500
  • f69d75014d
    Change default settings ~keith 2024-11-08 19:31:02 -0500
  • 5bdffb913f
    Remove like button ~keith 2024-11-08 19:30:38 -0500
  • 2b7abfb8d7 Merge pull request 'fix fix orm' (#4) from fix-fix-orm into dev zima 2024-11-10 07:31:03 +0000
  • b62621a44d
    oops :) fix-fix-orm HellhoundSoftware 2024-11-10 02:29:33 -0500
  • 62ea386ca4 Merge pull request 'Fix ORM models to match intended database schema' (#3) from fix-orm into dev zima 2024-11-10 04:27:48 +0000
  • ce037e0738
    Fix ORM models to match intended database schema HellhoundSoftware 2024-11-09 19:34:25 -0500
  • 55a827642c Merge pull request 'Set NewRodin to swap display' (#2) from fix-font-display into dev immutable-devcontainer zima 2024-11-09 00:15:53 +0000
  • a976f82c36 Set NewRodin to swap display zima 2024-11-08 16:54:29 -0700
  • 976dead978 Merge pull request 'Replaced NewRodin OTF with fixed TTF/WOFF2 version' (#1) from fix-new-rodin into dev HellhoundSoftware 2024-11-08 21:49:26 +0000
  • 548f5ead3f
    Replaced NewRodin OTF with fixed TTF/WOFF2 version ~keith 2024-11-08 16:31:43 -0500
  • 8928bf24fc Add font NewRodin Pro zima 2024-11-06 22:59:24 -0700
  • 680e3ac7a3 merge: release 2024.9.1 (!733) Julia 2024-11-05 03:59:23 +0000
  • 002d0def42 comment out sharkey-specific crowdin link dakkar 2024-11-04 20:54:48 +0000
  • a769423c15 bump version number for release dakkar 2024-11-04 18:50:26 +0000
  • e783359aca merge: Revert "Experimental: dont mark backfetched notes as silent" (!703) Julia 2024-11-03 19:39:00 +0000
  • fa03c4cebe merge: Respect user privacy settings in federation endpoints (resolves #712) (!652) dakkar 2024-11-02 22:02:54 +0000
  • ddf572c22f fix lint errors in FollowingEntityService.ts Hazelnoot 2024-11-02 17:43:11 -0400
  • 872f987845 hide instance following / followers tabs from logged-out users Hazelnoot 2024-11-02 12:03:14 -0400
  • 37fd454f70 factor out shared code Hazel K 2024-10-07 18:56:48 -0400
  • 2e6726c81f update autogen types Hazel K 2024-10-07 17:02:29 -0400
  • 3a72bf453a respect following privacy settings Hazel K 2024-10-04 22:07:30 -0400
  • 65d81a4ae2 Revert "fix incorrect populated object in followers endpoint" Hazel K 2024-10-04 20:57:30 -0400
  • 8f0df1f01c check for blocks in following / followers endpoints Hazel K 2024-10-04 20:57:24 -0400
  • c566fa1f36 require auth for followers & following endpoints Hazel K 2024-10-04 17:55:02 -0400
  • 1906dbe1dc merge: Fix frontend TS configs (!725) dakkar 2024-11-02 18:00:57 +0000
  • b97db55a94 fix eslint in frontend / frontend-embed Hazelnoot 2024-11-02 13:00:49 -0400
  • 56023140cb merge: add FriendlyCaptcha as a captcha solution (!723) dakkar 2024-11-02 15:46:25 +0000
  • 4ad816e0df fix frontend-embed tsconfig includes Hazelnoot 2024-11-02 11:40:51 -0400
  • 5e054d0218 fix frontend tsconfig includes Hazelnoot 2024-11-02 11:40:40 -0400
  • b8b077cbad chore: replace recaptcha with frc Marie 2024-11-02 11:02:13 +0000
  • d786e96c2b
    upd: add FriendlyCaptcha as a captcha solution Marie 2024-11-02 02:20:35 +0100
  • 8824422cb5 merge: Add a clear filter option to the search widget if set (!722) Hazelnoot 2024-11-01 18:01:19 +0000
  • bcc845cdb1 merge: Allow admins to create users (resolves #764) (!719) Hazelnoot 2024-11-01 18:00:33 +0000
  • c8357a410b upd: append ✔ on set filter Marie 2024-11-01 17:45:04 +0000
  • 8b16b0fce9 merge: Hide Following Feed from guest users/logged out users and also don't show the button for migrated accounts (!721) dakkar 2024-11-01 17:33:39 +0000
  • 4da262d98c merge: fix inconsistent following feed filters on mobile (resolves #776) (!717) Hazelnoot 2024-11-01 15:40:43 +0000
  • ade801ec58 check token permissions in admin/accounts/create.ts Hazelnoot 2024-11-01 10:12:28 -0400