Commit Graph

543 Commits (22c1b6f3eec14062c6e0950fdb2d436c34430543)

Author SHA1 Message Date
Claire 73a78cc19d
Fix rate-limiting incorrectly triggering a session cookie on most endpoints (#30483) 8 months ago
Claire 3fa0dd0b88
Merge pull request from GHSA-c2r5-cfqr-c553
* Add hardening monkey-patch to prevent IP spoofing on misconfigured installations

* Remove rack-attack safelist
8 months ago
Claire 16249946ae
Merge pull request from GHSA-q3rg-xx5v-4mxh 8 months ago
Emelia Smith d20a5c3ec9
Fix: remove broken OAuth Application vacuuming & throttle OAuth Application registrations (#30316)
Co-authored-by: Claire <claire.github-309c@sitedethib.com>
8 months ago
Nick Schonning 87156f57b5
Enable Style/StringConcatenation (#30428) 8 months ago
Renaud Chaput acc77c3836
Add instrumentation to the search services (#30350) 8 months ago
Renaud Chaput 9658d3e580
Use the job class as span name for Sidekiq root spans (#30353) 8 months ago
Claire 12472e7f40
Add emphasis on ActiveRecord Encryption configuration values being secret (#30340) 8 months ago
Matt Jankowski 1b6eb2c7f0
Enable YJIT when available (#30310) 8 months ago
Renaud Chaput 283a891e92
Allow to customise the OTEL service name prefix (#30322) 8 months ago
Matt Jankowski 6beead3867
Move `simplecov` config into `rails_helper` (#30302) 8 months ago
Nick Schonning 13fb54920b
Enable Style/IfUnlessModifier RuboCop (#30260) 8 months ago
Renaud Chaput 68b9fe824d
Add OpenTelemetry instrumentation (#30130)
Co-authored-by: Juliano Costa <juliano.costa@datadoghq.com>
Co-authored-by: Robb Kidd <robbkidd@honeycomb.io>
8 months ago
Matt Jankowski 040aaf3a48
Use `default: ...` assignment for Devise config, fixes `Style/ClassVars` cop (#30214) 8 months ago
Claire 33368e3e79
Change ActiveRecordEncryption variable to be more explicit (#30151) 8 months ago
Matt Jankowski 32ead51e5a
Add material design icons to admin/settings views (#27780)
Co-authored-by: Claire <claire.github-309c@sitedethib.com>
9 months ago
Emelia Smith 049b159beb
Add read:me OAuth 2.0 scope, allowing more limited access to user data (#29087) 9 months ago
Tim Rogers 1ca6ff8ca5
Fixed crash when supplying FFMPEG_BINARY environment variable (#30022) 9 months ago
Matt Jankowski c7384adc00
Fix `Style/TrailingCommaInArguments` cop (#30003) 9 months ago
Matt Jankowski 933189887b
Fix `Style/StringLiterals` cop (#30005) 9 months ago
Matt Jankowski 8d47ba893a
Fix `Style/PercentLiteralDelimiters` cop (#30006) 9 months ago
Matt Jankowski 828299e71c
Enable AR Encryption (#29831) 9 months ago
Matt Jankowski 0d9ad96d3f
Rename `PremailerWebpackStrategy` -> `PremailerBundledAssetStrategy` (#29934) 9 months ago
Matt Jankowski edde54e991
Update stoplight to version 4.1.0 (#28366) 10 months ago
Matt Jankowski a59f5694fe
Add empty line after magic frozen string comment (#29696) 10 months ago
Matt Jankowski 6c68c3c0ce
Introduce `inline_svg` gem, minimal usage, prep for material design icons (#29612) 10 months ago
Matt Jankowski a38e424185
Use unchanging github links in docs/comments (#29545) 10 months ago
Dave MacLeod b6b94c971f
Add Interlingue to available_locales (#28630) 11 months ago
Emelia Smith 46142cdbdd
Disable administrative doorkeeper routes (#29187) 11 months ago
Claire 8125dae5a8
Rename `ES_CA_CERT` to `ES_CA_FILE` for consistency (#29147) 11 months ago
Claire 2912829411
Add support for specifying custom CA cert for Elasticsearch (#29122) 11 months ago
Claire 64300e0fe3
Fix self-destruct schedule not actually replacing initial schedule (#29049) 11 months ago
Matt Jankowski c523a9601b
Rename local webpack* var in development env CSP config (#28766) 1 year ago
Matt Jankowski 0ce081fe49
Remove monkey patch in favor of supported Devise config value (#28760) 1 year ago
HTeuMeuLeu 7f471e70c0
Update new email templates (#28416)
Co-authored-by: Matt Jankowski <matt@jankowski.online>
1 year ago
Matt Jankowski 4e02838832
Enable "low risk" Rails 7.1 setting defaults (#28626) 1 year ago
gunchleoc 173953c23e
Fix ISO code for Canadian French (#26015)
Co-authored-by: Claire <claire.github-309c@sitedethib.com>
1 year ago
Matt Jankowski e09419f22a
Move old framework defaults file to regular config value (#28623) 1 year ago
Matt Jankowski a27a82939d
Remove the 7.1 marshalling format "todo" from new_framework_defaults (#28625) 1 year ago
Claire bd415af9a1
Change streaming API host to not be overridden to localhost in development mode (#28557) 1 year ago
Matt Jankowski e56fb9e489
Fix `Style/SymbolProc` cop (#28386) 1 year ago
Matt Jankowski e5717c9bc6
Fix `Style/Lambda` cop (#28378) 1 year ago
Matt Jankowski 1ee8d1e50e
Assign a proc to `Rack::Request.ip_filter` instead of patching method (#28380) 1 year ago
Claire f37c93f3d7
Change cookie rotator to use SHA1 digest for new cookies (#27392) 1 year ago
Matt Jankowski 42afd30324
Replace Sprockets with Propshaft (#28239) 1 year ago
Matt Jankowski a8473f582d
Add zeitwerk inflector for cli->CLI (#27635) 1 year ago
Claire 85662a5a57
Change `img-src` and `media-src` CSP directives to not include `https:` (#28025) 1 year ago
Matt Jankowski 31bef99b9e
Move lib/mastodon/premailer_webpack_strategy to lib/ (#27636) 1 year ago
Matt Jankowski 9429e30d75
Disable sidekiq unique jobs in test env (#27737) 1 year ago
Matt Jankowski c875dfc90b
Fix `Lint/UnusedBlockArgument` cop (#27777) 1 year ago
Matt Jankowski 33cc3ae8fa
Fix `Style/StabbyLambdaParentheses` cop (#27771) 1 year ago
Matt Jankowski 02d27de5ce
Move i18n locale configuration to separate initializer (#27571) 1 year ago
Matt Jankowski d6f50839e1
Fix `RSpec/SpecFilePathFormat` cops (#27730) 1 year ago
Matt Jankowski 7ef56d6e50
Move json_ld context loaders to `config/initializers` (#27590) 1 year ago
Matt Jankowski 3107a9410c
Silence deprecation warning about secrets/credentials with Devise patch (#27578) 1 year ago
Matt Jankowski eae5c7334a
Extract class from CSP configuration/initialization (#26905) 1 year ago
Matt Jankowski 4aa05d45fc
Capture minimum postgres version 12 (#27528) 1 year ago
Matt Jankowski 9a3d047f3e
Run `bin/rails app:update` with Rails 7.1 (#27522) 1 year ago
Claire 379115e601
Add SELF_DESTRUCT env variable to process self-destructions in the background (#26439) 1 year ago
Claire c3e0eb3699
Change Content-Security-Policy to be tighter on media paths (#26889) 1 year ago
Matt Jankowski bcd0171e5e
Fix `Lint/UselessAssignment` cop (#27472) 1 year ago
Wladimir Palant 23f8e93c64
Fixes #23135 - Allow cross origin request for /nodeinfo/2.0 API (#27413) 1 year ago
Renaud Chaput e0da64bb4e
Fix empty ENV variables not using default nil value (#27400) 1 year ago
Nick Schonning 85db392464
Autofix Rubocop cops for config/ (#24145) 1 year ago
Matt Jankowski 56c0babc0b
Fix rubocop `Layout/ArgumentAlignment` cop (#26060) 1 year ago
Claire 8acc75435b
Change S3 checksum mode to be disabled by default (#27007) 1 year ago
Claire a04ae16201
Fix CSP when using `ONE_CLICK_SSO_LOGIN` (#26901) 1 year ago
CSDUMMI 9a70cac9de
Fix #26849 by adding the domain of the current SSO provider to the form-action CSP (#26857) 1 year ago
Christian Schmidt ea31929776
Fix invalid Content-Type header for WebP images (#26773) 1 year ago
Claire 9e26cd5503
Add `authorized_fetch` server setting in addition to env var (#25798) 1 year ago
Christian Schmidt 286a21afdc
Support webpacker live-reloading on Docker (#26419) 1 year ago
Renaud Chaput b95867ad1f
Allow setting a custom HTTP method in CacheBuster (#26528)
Co-authored-by: Jorijn Schrijvershof <jorijn@jorijn.com>
1 year ago
Claire dd049fc37a
Fix ES_PRESET not being applied to Chewy's internal index (#26489) 1 year ago
Claire f5778caa3a
Add `ES_PRESET` option to customize numbers of shards and replicas (#26483)
Co-authored-by: Eugen Rochko <eugen@zeonfederated.com>
1 year ago
Claire 4bc0dd751c
Add `S3_DISABLE_CHECKSUM_MODE` environment variable for compatibility with some S3-compatible providers (#26435) 1 year ago
Claire 12c43e4ab5
Re-add StatsD support through the `nsa` gem (#26310) 1 year ago
Emelia Smith e258b4cb64
Refactor: replace whitelist_mode mentions with limited_federation_mode (#26252) 1 year ago
Matt Jankowski ad81be6c8e
Update rubocop rules for linelength (#26190) 1 year ago
Matt Jankowski bada7a65aa
Ignore long line in regex initializer (#26182) 1 year ago
Claire e5f1000ad1
Fix CSP headers being unintendedly wide (#26105) 2 years ago
Claire 934c7b33d1
Change default KeyGenerator digest to SHA1 to fix cookies in rolling upgrades (#26023) 2 years ago
Misty De Méo b848ba3867
Paperclip: add support for Azure blob storage (#23607) 2 years ago
Matt Jankowski ce43ed144c
Rails 7.0 update (#25668) 2 years ago
Matt Jankowski 2e1391fdd2
Fix `Naming/MemoizedInstanceVariableName` cop (#25928) 2 years ago
Nick Schonning 1d557305d2
Enable Rubocop Style/FrozenStringLiteralComment (#23793) 2 years ago
Kurtis Rainbolt-Greene e4cfe4b3db
First pass at multi-database for read replica using Rails native adapter (#25693)
Co-authored-by: emilweth <7402764+emilweth@users.noreply.github.com>
2 years ago
Claire dc8f1fbd97
Merge pull request from GHSA-9928-3cp5-93fm
* Fix attachments getting processed despite failing content-type validation

* Add a restrictive ImageMagick security policy tailored for Mastodon

* Fix misdetection of MP3 files with large cover art

* Reject unprocessable audio/video files instead of keeping them unchanged
2 years ago
Eugen Rochko ba06a2f104
Revert "Rails 7 update" (#25667) 2 years ago
Matt Jankowski 50c2a03695
Rails 7 update (#24241) 2 years ago
Claire f378f10404
Fix compatibility of recent migration with PostgreSQL 10 (#25324) 2 years ago
Nick Schonning c66250abf1
Autofix Rubocop Regex Style rules (#23690)
Co-authored-by: Claire <claire.github-309c@sitedethib.com>
2 years ago
Claire e428670e61
Fix CSP headers when S3_ALIAS_HOST includes a path component (#25273) 2 years ago
Matt Jankowski e49819142f
Remove unmaintained `nsa` gem (#25265) 2 years ago
Claire 94329f28e1
Change wording of “Content cache retention period” setting to highlight destructive implications (#23261) 2 years ago
Renaud Chaput 942d850b0a
Allow carets in URL search params (#25216) 2 years ago
Nick Schonning c0b9664a31
Autofix Rubocop spacing in config (#25022) 2 years ago
Nick Schonning cee4369cf5
Autofix Rubocop Lint/AmbiguousOperatorPrecedence (#25002) 2 years ago
Matt Jankowski d9a958fcf7
Fix Performance/RedundantMerge cop (#24817) 2 years ago
Matt Jankowski d902a707a3
Fix Rails/CompactBlank cop (#24690) 2 years ago
Matt Jankowski 5a2aa06a51
Fix Rails/Present cop (#24688) 2 years ago