Commit Graph

14630 Commits (5d8c09194b38e4f237a668a095716906e7d2ad92)
 

Author SHA1 Message Date
Claire 943792c187
Merge pull request from GHSA-5fq7-3p3j-9vrf 9 months ago
Emelia Smith 186f916192 Fix: remove broken OAuth Application vacuuming & throttle OAuth Application registrations (#30316)
Co-authored-by: Claire <claire.github-309c@sitedethib.com>
9 months ago
Claire f9c41ae43b Normalize language code of incoming posts (#30403) 9 months ago
Claire b8edc95e8a Fix leaking Elasticsearch connections in Sidekiq processes (#30450) 9 months ago
Claire 16213a678d Update dependency rexml to 3.2.8 9 months ago
Claire a8dd32102f Update dependency nokogiri to 1.16.5 10 months ago
Claire 6fc07ff31f Update dependency fastimage to 2.3.1 10 months ago
Claire 997b021b69 Update dependency rotp to 6.3.0 10 months ago
Claire 2865bfadaf Update dependency json-jwt to 1.15.3.1 10 months ago
Claire 8c72e80019 Update dependency rack-cors to 2.0.2 10 months ago
Claire 8cf78825a2 Fix off-by-one in `tootctl media` commands (#30306) 10 months ago
Emelia Smith 67b2e62331 Fix missing destory audit logs for Domain Allows (#30125) 10 months ago
Claire 56b7d1a7b6 Fix not being able to block a subdomain of an already-blocked domain through the API (#30119) 10 months ago
Claire 51ef619140 Fix Idempotency-Key ignored when scheduling a post (#30084) 10 months ago
Tim Rogers e69780ec59 Fixed crash when supplying FFMPEG_BINARY environment variable (#30022) 10 months ago
Claire c3be5a3d2e Remove caching in `cache_collection` (#29862) 10 months ago
Claire 86807e4799 Improve email address validation (#29838) 10 months ago
Matt Jankowski 0143c9d3e1 Fix results/query in `api/v1/featured_tags/suggestions` (#29597) 10 months ago
Jeong Arm ab3f9852f2 Normalize idna domain before account unblock domain (#29530) 10 months ago
Claire 7af69f5cf5 Fix admin account created by `mastodon:setup` not being auto-approved (#29379) 10 months ago
Emelia Smith f784213c64 Return domain block digests from admin domain blocks API (#29092) 10 months ago
Claire 6536d96d1b Add fallback redirection when getting a webfinger query `WEB_DOMAIN@WEB_DOMAIN` (#28592) 10 months ago
Matt Jankowski ed8e4bab4c Fix reference to non-existent var in CLI maintenance command (#28363) 10 months ago
Claire bdb6650ebc
Bump version to v4.2.8 (#29370) 1 year ago
Claire f3ad918950
Fix processing of `Link` objects in `Image` objects (#29363) 1 year ago
Claire 9a7802655f
Fix link verifications when page size exceeds 1MB (#29361) 1 year ago
Claire 328a9b8157
Change registrations to be disabled by default for new servers (#29353) 1 year ago
Claire 4fd22acb4a
Fix auto-close email being sent to users with devops permissions instead of settings permissions (#29356) 1 year ago
Claire 28b666b0d5
Automatically switch from open to approved registrations in absence of moderators (#29337) 1 year ago
Claire fbb07893b8
Update dependencies (#29346) 1 year ago
Claire c5d56de98d Fix linting failure 1 year ago
Claire 0e4e98fad1 Bump version to v4.2.7 1 year ago
Claire 15de520201
Merge pull request from GHSA-jhrq-qvrm-qr36
* Fix insufficient Content-Type checking of fetched ActivityStreams objects

* Allow JSON-LD documents with multiple profiles
1 year ago
Claire 684f99908f Update dependency pg to 1.5.5 1 year ago
Claire e4ec4ce217
Update `nsa` gem to version 0.3.0 (#29065) (#29206)
Co-authored-by: Matt Jankowski <matt@jankowski.online>
1 year ago
Claire 870ee80fd3 Fix user creation failure handling in OAuth paths (#29207) 1 year ago
Claire 76a37bd040 Fix OmniAuth tests (#29201) 1 year ago
Claire 7c8ca0c6d6 Bump version to v4.2.6 1 year ago
Claire f1700523f1
Merge pull request from GHSA-vm39-j3vx-pch3
* Prevent different identities from a same SSO provider from accessing a same account

* Lock auth provider changes behind `ALLOW_UNSAFE_AUTH_PROVIDER_REATTACH=true`

* Rename methods to avoid confusion between OAuth and OmniAuth
1 year ago
Claire 0b0c7af2c1
Merge pull request from GHSA-7w3c-p9j8-mq3x
* Ensure destruction of OAuth Applications notifies streaming

Due to doorkeeper using a dependent: delete_all relationship, the destroy of an OAuth Application bypassed the existing AccessTokenExtension callbacks for announcing destructing of access tokens.

* Ensure password resets revoke access to Streaming API

* Improve performance of deleting OAuth tokens

---------

Co-authored-by: Emelia Smith <ThisIsMissEm@users.noreply.github.com>
1 year ago
Claire 1a33d348d0 Add `sidekiq_unique_jobs:delete_all_locks` task and disable `sidekiq-unique-jobs` UI by default (#29199) 1 year ago
Emelia Smith 6d43b63275 Disable administrative doorkeeper routes (#29187) 1 year ago
Claire ae2dce813a Update dependency sidekiq-unique-jobs to 7.1.33 1 year ago
Claire b7230cd759 Update dependency nokogiri to 1.16.2 1 year ago
Claire a6641f828b
Merge pull request from GHSA-3fjr-858r-92rw
* Fix insufficient origin validation

* Bump version to v4.2.5
1 year ago
Claire 4633bb8ce0 Bump version to v4.2.4 1 year ago
Claire 1ab050eb52 Change PostgreSQL version check to check for PostgreSQL 10+ 1 year ago
Claire 4eb98ef755 Ignore the devise-two-factor advisory as we have rate limits in place (#28733) 1 year ago
Claire 7a22999f92 Bump ruby version to 3.2.3 1 year ago
Claire c5c464804d Update dependency puma to v6.4.2 1 year ago