Commit Graph

2124 Commits (0679216fa2adae822bca875e2cd4bd8ee207ad7e)

Author SHA1 Message Date
Shlee fb655f1308
Merge pull request #6782 from ashleyhull-versent/shift-179490
Laravel Shift Preshift
1 month ago
Ashley Hull ab07a705e6
Merge branch 'dev' into shift-179490 1 month ago
Shlee 68dca50973
Merge pull request #6774 from pixelfed/fix/oauth-scope-bypass-remove-follower-6643
Fix: OAuth accountRemoveFollowById to check token.
1 month ago
Shlee 20123ff5ba
Merge pull request #6773 from pixelfed/fix/first-follower-pagination-6695
Fix: Show first follower/following record excluded from previous API responses
1 month ago
Shlee 49d8e02411
Merge pull request #6757 from pixelfed/shleeable-patch-3
Fix RESTRICTED_INSTANCE
1 month ago
Your Name 552a55c2d2 Upgrade images to v4 1 month ago
Daniel Supernault 91645faeee
Lint 1 month ago
Daniel Supernault e1235dfd75
Fix ApiV1Controller, ensure follow notifications have an account 1 month ago
Your Name 53759e3ad6 Prevent deletion of personal access OAuth client
Fixes #6630 (partial — deletion causing broken PAT)

If a user deletes the OAuth client that serves as the personal access
client, all PAT creation breaks for the entire instance with a 500 error.

Changes:
- Add custom OAuthClientController@destroy that checks if the client
  has the personal_access grant type before allowing deletion
- Returns 403 with a clear error message if deletion is blocked
- Add confirmation dialog before client deletion in the frontend
- Add error handling to show server error messages to the user

This prevents accidental destruction of the PAT infrastructure.
1 month ago
Your Name 1ab677a526 Handle PAT creation gracefully when not configured
Fixes #6630 (partial — PAT 500 error)

Previously, POST /oauth/personal-access-tokens would throw an unhandled
RuntimeException (HTTP 500) when:
- OAUTH_PAT_ENABLED is false (the default), or
- No personal access client exists in the database

Now the endpoint:
1. Returns 403 with a clear message if PAT is disabled in config
2. Catches RuntimeException from the token factory and returns 500
   with an actionable error message instead of a stack trace
1 month ago
Your Name 822e9c98cb Fix OAuth scope bypass on remove_from_followers endpoint
Fixes #6643

The POST /api/v1/accounts/{id}/remove_from_followers endpoint was missing
the token existence check (! $request->user()->token()). While the
tokenCan('follow') scope check was already present, the missing token
guard meant unauthenticated token-less requests could potentially bypass
the scope enforcement.

Added the standard guard pattern consistent with accountFollowById and
accountUnfollowById endpoints.

Also adds tests verifying:
- Read-only tokens are denied (403)
- Follow-scoped tokens succeed (200)
- Unauthenticated requests are denied (403)
1 month ago
Your Name 396cf2d861 Fix first follower/following record excluded from API responses
Fixes #6695

When no pagination params are provided, the default min_id was set to 1
and the query used 'id > 1', which excluded the very first follower row
(id=1) on fresh instances.

Changed default min_id from 1 to 0 and switched the direction check from
truthy evaluation to !== null, so the query becomes 'id > 0' which
correctly includes all records.
1 month ago
Shift 19880c2ffb
Convert string references to `::class`
PHP 5.5.9 adds the new static `class` property which provides the fully qualified class name. This is preferred over using strings for class names since the `class` property references are checked by PHP.
1 month ago
Your Name 651f0de74f Replace jenssegers/agent with matomo/device-detector
- Remove unmaintained jenssegers/agent package (no releases since 2021)
- Add matomo/device-detector v6.5 as actively maintained replacement
- Create App\Services\UserAgentService wrapper for drop-in compatibility
- Update UserDevice model and ApiV1Dot1Controller to use new service
1 month ago
Shlee f6f9d5368c
Update allowed routes for restricted access middleware 1 month ago
Shlee 3800612fdf
Update Kernel.php 1 month ago
dansup 268ab6dba0
Merge branch 'staging' into remove-exp-pue 1 month ago
dansup 7354f63563
Merge branch 'staging' into remove-exp-rec 1 month ago
Daniel Supernault 26ee049d07
Update AppRegisterController 1 month ago
Daniel Supernault fbff6ed307
Update trustedproxy config 1 month ago
Daniel Supernault a2be0cb47d
Update CommentController 1 month ago
Daniel Supernault 40aef7a212
Update GroupsFeedController 1 month ago
Daniel Supernault 5f397f9135
Update StoryController 1 month ago
dansup f568804426
Merge pull request #6680 from pixelfed/shleeable-patch-15
Update FollowerObserver.php
1 month ago
dansup d6cd65463d
Merge pull request #6676 from pixelfed/shleeable-patch-10
Stories API: PostgreSQL story carousel endpoints crash due to calling collection methods on query builder
1 month ago
dansup 668653039f
Merge pull request #6663 from vinzgreg/fix/api-status-edit-auth-guard
Fix API status editing: use auth:api guard
1 month ago
dansup ca5f83d2d1
Merge pull request #6655 from TowyTowy/fix/timeline-home-nullable-max-id
Fix home timeline rejecting empty max_id/min_id pagination params
1 month ago
dansup 5aae3f46c7
Merge pull request #6691 from pixelfed/shleeable-patch-26
Improve validation
1 month ago
dansup 219297d0e3
Merge pull request #6690 from pixelfed/shleeable-patch-25
Typo: change pid to id for FollowerService::remove
1 month ago
dansup 6910115166
Merge pull request #6686 from pixelfed/shleeable-patch-20
Update type on abort.
1 month ago
dansup 77831e7640
Merge pull request #6688 from pixelfed/shleeable-patch-22
Clear oauth material on permanent delete
1 month ago
dansup 5115e5c960
Merge pull request #6677 from pixelfed/shleeable-patch-12
Typo in abort
1 month ago
dansup 179dfffafe
Merge pull request #6672 from pixelfed/shleeable-patch-5
Places directory crashes on PostgreSQL for multi-word country URLs (case-sensitive mismatch)
1 month ago
dansup f344b40aa9
Merge pull request #6671 from pixelfed/shleeable-patch-4
Account migration fails with 500 when remote ActivityPub profile returns `alsoKnownAs` as a string
1 month ago
Shlee c2044f77cf
Update AdminUserController.php 2 months ago
Shlee 1d72f1b437
Update ApiV1Controller.php 2 months ago
Shlee fbe98ea4de
Update AccountController.php 2 months ago
Shlee 9966eb50b8
Update ApiV1Controller.php 2 months ago
Shlee 87d866f58d
Update SettingsController.php 2 months ago
Shlee baf21797f0
Update RemoteOidcController.php 2 months ago
Shlee 0f79861f1d
Update PrivacySettings.php 2 months ago
Shlee 4e6b341532
Update StoryController.php 2 months ago
Shlee 8ce4b5d409
Update StoryApiV1Controller.php 2 months ago
Shlee f99ee65676
Update PlaceController.php 2 months ago
Shlee 142025db82
Update ProfileMigrationStoreRequest.php 2 months ago
Shlee 6f5f6e3368
Update ReportController.php 2 months ago
vinzgreg d19671a92c Fix API status editing: use auth:api guard
StatusEditController's constructor applies the web `auth` guard, which
Bearer/OAuth clients cannot satisfy. PUT /api/v1/statuses/{id} and
GET /api/v1/statuses/{id}/history therefore fail for every third-party
API client, while status create/delete keep working because
ApiV1Controller has no controller-level web auth.

The controller is routed only from routes/api.php, where the route group
already applies ['auth:api', 'validemail'], so no web/session route
depends on the old guard. Switch the constructor to match.
2 months ago
TowyTowy 795473be55 Fix home timeline rejecting empty max_id/min_id pagination params
`GET /api/v1/timelines/home?max_id=` (empty value) fails validation
because `min_id`/`max_id` use the `sometimes|integer` rule. The global
`ConvertEmptyStringsToNull` middleware turns `?max_id=` into `null`, and
since the field is present, `sometimes` does not skip it while `null`
fails the `integer` rule — returning HTTP 422.

Every other timeline/listing endpoint in this controller (timelinePublic,
accountStatusesById, etc.) uses `nullable|integer` for these params, so
`timelineHome` was the lone outlier. Mastodon-API clients such as Pixelfed
for iOS send `max_id=` on first page load and could not paginate the home
timeline.

Switch `min_id`/`max_id` to `nullable|integer` to match the rest of the
controller.

Fixes #6610

Co-Authored-By: Claude <noreply@anthropic.com>
2 months ago
Daniel Supernault 0f781cba34
Update Personal Access Tokens 3 months ago
Daniel Supernault fb92949a71
Update PersonalAccessTokenController.php 3 months ago
Daniel Supernault 25d5142f12
Fix PAT + oauth routes 3 months ago
Daniel Supernault 9fe9b7eb32
Update AdminInviteController 3 months ago
Daniel Supernault 038a2bbf9f
Lint 3 months ago
dansup 096a1bc901
Merge pull request #6553 from pixelfed/w2
OAuth: Token endpoint response loses required no-store/no-cache headers
4 months ago
dansup 120b08b758
Merge pull request #6563 from pixelfed/shleeable-patch-1
Update to Passport 13 refresh token method in AppRegisterController.php
5 months ago
Your Name 3c9fc9a1fe Remove EXP_PUE flag, post editing is always enabled
Remove the 'pue' entry from config/exp.php and the abort_if guard
in StatusEditController. Post editing is now unconditionally available.
5 months ago
Your Name 10a5eb7228 Remove exp.rec recommendations dead code
- Remove userRecommendations controller method and /api/local/exp/rec route
- Remove suggestions UI panel, data properties, and methods from Timeline.vue
- Remove commented-out suggestions card from feed template

The recommendations feature was deprecated and hardcoded to false/empty.
5 months ago
Daniel Supernault 14b325641f
Update Password Change with new Revoke Sessions option
As requested in https://lgbtqia.space/@serigala_tropis/116412473982617371
6 months ago
Shlee bbd09fe50f
Update AppRegisterController.php 6 months ago
Your Name b329ee9edc API: Media uploads leak orphaned files when status creation validation fails 6 months ago
Your Name 3d858af1fa OAuth: Token endpoint response loses required no-store/no-cache headers when adding created_at 6 months ago
dansup 6e9c33fcab
Merge pull request #6496 from pixelfed/shleeable-patch-7
Remove sleep from AppRegisterController.php
6 months ago
dansup bdc203dc5c
Merge pull request #6493 from ShadowJonathan/fix-profile-saving
Make sure profile saving has a clear error when email is not verified
6 months ago
Daniel Supernault ef803ae9b6
Fix oauth/token 7 months ago
Daniel Supernault f6746aec8b
Update AuthServiceProvider 7 months ago
Daniel Supernault 52f5626530
Fix oauth 7 months ago
Daniel Supernault 695e851026
Fix oauth 7 months ago
Shlee d9bd6d446f
Update AppRegisterController.php 7 months ago
Jonathan de Jong 8e91918b88
Make sure profile saving has a clear error when email is not verified 7 months ago
Shlee 1b21f83132
Update BaseApiController.php 7 months ago
dansup f1af72e66d
Merge pull request #6454 from pixelfed/a5
Bugfix: Validation was ignored, allows any file type/size
7 months ago
Daniel Supernault c975ddb13f
Update composer deps 7 months ago
Your Name 1a1dc5e096 fix typo 8 months ago
Daniel Supernault 3140404835
Update ApiV1Controller.php 8 months ago
Daniel Supernault 80a2f4f2b0
Add api/v1/accounts/lookup endpoint 8 months ago
Daniel Supernault f76567f67b
Improve reblog check 8 months ago
Severin 066f8ee309
Pulls user settings for reblogs 8 months ago
dansup 1f04a190a9
Merge pull request #6438 from pixelfed/shleeable-patch-22
UpdatePersonValidator rejects null name/summary due to required|nullable conflict
8 months ago
dansup fc694dd37a
Merge pull request #6431 from grossermensch/patch-1
Fix for portfolio with recent images not showing up on PSQL
8 months ago
dansup b3fdc41816
Merge pull request #6429 from albattran/dev
Added pagination to the followers/followings API endpoints
8 months ago
dansup ceec5a0eea
Merge pull request #6419 from pixelfed/shleeable-patch-18
Bugfix: CommentController : inherit appropriate visibility
8 months ago
dansup 70f3206b51
Merge pull request #6415 from pixelfed/shleeable-patch-14
Bugfix: Reversed follower check in PublicApiController::scopeCheck for private accounts.
8 months ago
dansup ebb119e4df
Merge pull request #6410 from pixelfed/shleeable-patch-9
Bugfix: Missing status filter exposes suspended/disabled profiles via ActivityPub in getCachedUser(withTrashed)
8 months ago
dansup 11692c72e9
Merge pull request #6408 from pixelfed/shleeable-patch-3
Bugfix: Account deletion proceeds without validation server side.
8 months ago
Shlee ac19942083
Update RemoteAuthController.php 8 months ago
Severin b948a31e61
Fix for portfolio with recent images not showing up on PSQL 8 months ago
samir 9c3130a3c7 Added pagination to the followers/followings API endpoints 8 months ago
Shlee 4419054ae5
Update CommentController.php 9 months ago
Shlee da03ca79d5
Update PublicApiController.php 9 months ago
Shlee 8394b8ac4b
Update ProfileController.php 9 months ago
Shlee 43f6686667
Update SettingsController.php 9 months ago
Shlee def22b267d
Update BookmarkController.php 9 months ago
Daniel Supernault ef6187b917
Fix LoginController 9 months ago
Daniel Supernault 0032eaf482
Fix AdminController 9 months ago
Daniel Supernault 34278c77c2
Update LoginController 9 months ago
Daniel Supernault 374344754e
Lint 9 months ago
Rm Yakovenko 7cb54eb7c2 [Bug]: public API endpoint /accounts/{id}/statuses ignores max_id parameter 10 months ago
Daniel Supernault 4bc1e22121
Refactor LikePipeline and improve Undo Announce handling 11 months ago
Daniel Supernault 04bf75fb68
Revert inbox changes 11 months ago
dansup f783db493a
Merge pull request #6340 from grossermensch/patch-3
Allow to set new image types in admin interface
11 months ago