Your Name
5a364be58b
fix: remove deprecated Passport::personalAccessClientId() and enableImplicitGrant()
...
- Remove Passport::personalAccessClientId() (removed in Passport v13, auto-discovers now)
- Remove Passport::enableImplicitGrant() (legacy grant, no clients use it)
- Flatten config instance.oauth.pat to pat_enabled (remove dead pat.id key)
- Add OAUTH_PAT_ENABLED=false to .env.example and .env.docker.example
- Show swal alert when PATs disabled instead of hidden API error
- Improve store() error handling to surface 403 messages in the UI
- Remove OAUTH_PAT_ID row from admin diagnostics blade
1 month ago
Your Name
8a2649b3ff
feat: add critical path test suite and fix auth/config issues
...
Test Infrastructure:
- Modernize phpunit.xml (bootstrap, source block, Laravel 12 env vars)
- Configure tests/Pest.php with pest()->extend(TestCase::class)->in('Feature')
- Add docker-compose.test.yml (Redis for test suite)
- Add composer test/test:quick scripts
- Rename CACHE_DRIVER to CACHE_STORE across config (backwards compatible)
- Update .env.testing for in-memory SQLite + Docker Redis
Test Coverage (190 tests):
- CriticalRoutes: public routes, auth routes, API endpoints, middleware, schedule
- Auth/LoginTest: login, logout, rate limiting, redirect behavior
- Auth/RegisterTest: registration flow, validation, disabled registration
- Auth/PasswordResetTest: reset request, token validation, password update
- Auth/TwoFactorTest: 2FA checkpoint, setup behind password confirmation
- Auth/PasswordConfirmationTest: sudo mode flow via Laravel password.confirm
- Api/ScopeTest: scope enforcement, public endpoints, admin access
Bugs Fixed:
- Fix unauthenticated API returning 500 instead of 401 (AuthenticationException
not handled in custom exception renderer in bootstrap/app.php)
- Replace custom DangerZone middleware with Laravel password.confirm
- Add HasFactory trait to Profile model for test factories
Bugs Documented (known-bugs group):
- Registration crashes with str_ends_with TypeError (RegisterController:82)
- OAuth routes use legacy array syntax causing ReflectionFunction TypeError
1 month ago
Your Name
30db57448f
fix: replace str_random/str_limit/str_slug in Blade templates and tests
...
These deprecated helpers will throw 'undefined function' errors at
runtime since laravel/helpers was removed. Replace with Str::random(),
Str::limit(), and Str::slug() respectively.
1 month ago
dansup
4c0c6bdec0
Merge pull request #6577 from shleeable/remove-exp-lc
...
Remove deprecated EXP_LC (hidden like counts) config
1 month ago
dansup
ec38262338
Merge pull request #6576 from shleeable/covidremove
...
Clean up Covid/WHO
1 month ago
dansup
24697b77fc
Merge pull request #6579 from shleeable/remove-exp-loops
...
Remove deprecated legacy loops feature entirely
1 month ago
dansup
dcb3ffa04b
Merge pull request #6684 from pixelfed/shleeable-patch-18
...
missing parentheses
1 month ago
dansup
5cccd4937a
Merge pull request #6679 from pixelfed/shleeable-patch-14
...
OAuth: Cancel/Deny on authorization screen fails with 403 due to missing auth_token
1 month ago
Shlee
a600981820
Update show.blade.php
2 months ago
Shlee
5913b031c8
Update authorize.blade.php
2 months ago
Shlee
28c8772186
Update index.blade.php
2 months ago
Daniel Supernault
ef3fdeeca3
Update profile view
4 months ago
Daniel Supernault
3a71cda51f
Prevent og:image on sensitive posts
5 months ago
Your Name
715c671712
Remove deprecated Loops feature entirely
...
- Remove 'loops' from config/exp.php and instance.discover.loops from config/instance.php
- Remove loops API routes (loopsApi, loopWatch) from web-api.php
- Delete LoopComponent.vue, loops.js entry point, and loops blade view
- Remove EXP_LOOPS diagnostic row from admin diagnostics page
The Loops feature was deprecated and hardcoded to disabled.
5 months ago
Your Name
1f01a15e64
Remove deprecated EXP_LC (hidden like counts) config
...
Remove the EXP_LC env var from config/exp.php and its diagnostic
row from the admin diagnostics page. This feature was already
marked as deprecated and unused.
5 months ago
Your Name
41089fcccd
Remove COVID label feature flag and related code
...
Remove ENABLE_COVID_LABEL, COVID_LABEL_URL, and COVID_LABEL_ORG env
vars and all associated backend/frontend code:
- config/instance.php: remove label.covid config block
- StatusLabelService: remove keyword matching, return static false
- Site/Config.php: remove label.covid from API response
- StatusCard.vue: remove COVID banner and labelRedirect method
- GroupStatus.vue: remove COVID banner and labelRedirect method
- diagnostics blade: remove COVID diagnostic rows
5 months ago
Daniel Supernault
0a41c9e387
Fix typo
6 months ago
Daniel Supernault
14b325641f
Update Password Change with new Revoke Sessions option
...
As requested in https://lgbtqia.space/@serigala_tropis/116412473982617371
6 months ago
dansup
06521c38df
Merge pull request #6398 from nove-b/feat/embed-color-schemes
...
feat(embed): add color theme support
6 months ago
dansup
edcda57e7a
Merge pull request #6387 from rm-yakovenko/issues/6376
...
[Server Bug]: app.logo is not used in code
6 months ago
Daniel Supernault
86de07e146
Fix oauth authorize form
7 months ago
Daniel Supernault
695e851026
Fix oauth
7 months ago
dansup
3959257a53
Merge pull request #6439 from pixelfed/shleeable-patch-24
...
Update redirect.blade.php - Use HTML-escaped URL
8 months ago
dansup
90d2fba597
Merge pull request #6411 from pixelfed/shleeable-patch-10
...
typo
8 months ago
dansup
2da38b1150
Merge pull request #6409 from pixelfed/shleeable-patch-8
...
Bugfix: lint confirm_email.blade.php
8 months ago
Shlee
d1f8fff739
Update redirect.blade.php
8 months ago
Shlee
eb0bb9e81f
Update step-1.blade.php
9 months ago
Shlee
1d01820f57
Update confirm_email.blade.php
9 months ago
Shlee
677f8e49a9
Update permanent.blade.php
9 months ago
Rm Yakovenko
a63dbd8436
[Server Bug]: app.logo is not used in code
9 months ago
nove-b
5596d84055
feat(embed): add color theme support
9 months ago
Daniel Supernault
babaca478b
Add two-factor view
9 months ago
dansup
95b9caac8d
Merge pull request #6374 from joergi/issue_6373_maxlength
...
uses max length of 30 instead of 15
9 months ago
joergi
76c5b4b888
uses max length of 30 instead of 15
...
I have fixed this also for the admin invite.
Closes issue #6373
10 months ago
Rm Yakovenko
9e5c3d9ef5
Web Bug: open graph preview image for videos is missing
10 months ago
Daniel Supernault
cc90df9d8c
Add user admin toggles for email and ip
11 months ago
Ross Bearman
db03733415
Add admin invite interface and email support
...
This commit does two things:
* Add invite email support to AdminInviteCommand
- Moves `invite_code` generation to AdminInvite model `creating` event
* Add admin invite management section under admin users dashboard
- Adds `Admin/AdminUserInviteController` and associated `home` and
`create` Blade templates.
- Adds "Invites" button to admin user dashboard
1 year ago
Matthias Pfefferle
0e2685ceff
Merge pull request #6170 from pfefferle/add/atom-icon
...
Add avatar as icon and logo in Atom user feed
1 year ago
Daniel Supernault
ab378b8fcb
Update curated onboarding username max length
1 year ago
Shlee
c95a65cd41
Update disabled-panel.blade.php
1 year ago
Daniel Supernault
b6bc1e50e2
Update Admin Users dashboard
1 year ago
Daniel Supernault
ece23d751b
Update Places, improve cache invalidation/ttl
1 year ago
Daniel Supernault
f81a4acdc6
Update PlaceController, fix show method
1 year ago
Daniel Supernault
5a3a1cf76c
Update remove_from_followers api endpoint
1 year ago
daniel
92482c24cd
Merge pull request #5895 from eufelipemateus/feat-remove-follow
...
[Improvement] Add button remove follow
1 year ago
daniel
7561026965
Merge pull request #5891 from eufelipemateus/translate-auth
...
[Translation] translate auth
1 year ago
daniel
b3c2781578
Merge pull request #5608 from halkeye/add-generic-oidc
...
[Improvement] Generic OIDC Support
1 year ago
Daniel Supernault
0e59098da2
Update footer to use legalNotice i18n
1 year ago
daniel
69e00d742d
Merge branch 'staging' into dev
1 year ago
Gavin Mogan
441c8e0d4c
Generic OIDC Support
...
* Everything should be configurable by env variables
* Basic request tests
1 year ago