Your Name
8a2649b3ff
feat: add critical path test suite and fix auth/config issues
...
Test Infrastructure:
- Modernize phpunit.xml (bootstrap, source block, Laravel 12 env vars)
- Configure tests/Pest.php with pest()->extend(TestCase::class)->in('Feature')
- Add docker-compose.test.yml (Redis for test suite)
- Add composer test/test:quick scripts
- Rename CACHE_DRIVER to CACHE_STORE across config (backwards compatible)
- Update .env.testing for in-memory SQLite + Docker Redis
Test Coverage (190 tests):
- CriticalRoutes: public routes, auth routes, API endpoints, middleware, schedule
- Auth/LoginTest: login, logout, rate limiting, redirect behavior
- Auth/RegisterTest: registration flow, validation, disabled registration
- Auth/PasswordResetTest: reset request, token validation, password update
- Auth/TwoFactorTest: 2FA checkpoint, setup behind password confirmation
- Auth/PasswordConfirmationTest: sudo mode flow via Laravel password.confirm
- Api/ScopeTest: scope enforcement, public endpoints, admin access
Bugs Fixed:
- Fix unauthenticated API returning 500 instead of 401 (AuthenticationException
not handled in custom exception renderer in bootstrap/app.php)
- Replace custom DangerZone middleware with Laravel password.confirm
- Add HasFactory trait to Profile model for test factories
Bugs Documented (known-bugs group):
- Registration crashes with str_ends_with TypeError (RegisterController:82)
- OAuth routes use legacy array syntax causing ReflectionFunction TypeError
1 month ago
Your Name
1617734907
Revert "Merge pull request #6851 from pixelfed/fix/phpstan-auth-request-scope-2"
...
This reverts commit ce4baf6995 , reversing
changes made to 9235cb979a .
1 month ago
Your Name
0939f495bb
fix: replace Auth facade with $request->user() in request-scoped classes
...
Replace Auth::user() with $request->user() and Auth::check() with
$request->user() !== null (or ! $request->user()) across all
controllers and middleware that have access to the request object.
This resolves 99 larastan.noAuthFacadeInRequestScope errors and
improves Octane compatibility.
For protected helper methods without $request in scope, uses the
request() helper instead.
Methods that previously lacked a Request parameter but used Auth
facade now accept Request $request via Laravel's auto-injection.
1 month ago
Your Name
e7ef58969c
fix: resolve undefined $status variable in GroupsPostController::deletePost
...
Replace all references to non-existent $status with $gp (the GroupPost
instance already in scope). This was a bug where the closure variable
name was changed but references inside the method body were not updated.
1 month ago
Your Name
7c964f3b4f
fix: replace backslash-prefixed facade calls with imported references
...
Replace \Cache::, \Log::, \DB:: calls with their imported facade
equivalents. The backslash-prefix relies on global aliases which
PHPStan cannot resolve, causing class.notFound errors.
1 month ago
Shlee
58a34056ca
Update TimelineController.php
1 month ago
Shlee
b7626891df
Merge pull request #6845 from pixelfed/fix/phpstan-variable-undefined
...
fix: resolve undefined variable bugs (phpstan variable.undefined)
1 month ago
Your Name
e7ba43e2e1
fix: add missing use imports to resolve phpstan class.notFound errors
...
Add missing imports for Log, Cache, DB, FollowerService, StatusService,
LikeService, ReblogService, UserFilterService, AdminProfile, OauthClient,
and fix StatusTimelineTransformer reference (class didn't exist, replaced
with StatusTransformer).
1 month ago
Your Name
ccd75dd903
fix: resolve undefined variable bugs (phpstan variable.undefined)
...
- AdminReportController: fix closure param name and remove reference to
undefined $meta variable
- GroupsPostController: replace $status with $gp (the actual GroupPost
variable in scope)
- PortfolioController: replace undefined $metadata with null
- DeleteWorker: remove Cache::set() call with undefined $key
1 month ago
Your Name
58efefb878
fix: add missing FeedUnfollowPipeline import
...
Add missing use statement for FeedUnfollowPipeline in PrivacySettings
and FollowerObserver. These caused PHPStan internal errors blocking
full analysis.
1 month ago
Your Name
c807a8524c
refactor: replace short facade aliases with fully-qualified imports
...
Convert all 273 short facade alias imports (e.g. 'use Cache;') to their
fully-qualified class names (e.g. 'use Illuminate\Support\Facades\Cache;')
across 193 files.
This resolves 643 PHPStan 'class.notFound' errors caused by the static
analyzer being unable to resolve global aliases, and aligns with modern
Laravel conventions. It also unblocks removing the aliases array from
config/app.php in a future change.
All 107 tests pass.
1 month ago
Thomas Jacumin
a113bf071e
Merge branch 'staging' into dev
1 month ago
Your Name
98267eb26f
refactor: replace deprecated str_random() with Str::random()
...
str_random() is a deprecated helper from laravel/helpers that was
missed in the initial helpers removal. Replace all 18 call sites
with the modern Str::random() equivalent.
1 month ago
Your Name
edb4368b08
refactor: replace deprecated laravel/helpers with native alternatives
...
Replace all deprecated helper function calls:
- str_slug() → Str::slug()
- starts_with() → str_starts_with()
- ends_with() → str_ends_with()
- array_first() → Arr::first()
- array_last() → Arr::last()
- array_flatten() → Arr::flatten()
Remove laravel/helpers package from composer.json as it is no longer
needed and will not be maintained for Laravel 13.
1 month ago
Daniel Supernault
8f1e475407
Fix typo
1 month ago
Daniel Supernault
7937d91c37
Update ApiV1Controller, add is_suggestable to update_credentials endpoint
1 month ago
Daniel Supernault
4e2e49f843
Update ApiV1Controller, add show_atom support to update_credentials endpoint
1 month ago
Your Name
79541afaa0
Merge origin/staging, resolve conflicts keeping matomo/device-detector over jenssegers/agent
1 month ago
Shlee
80738385ba
Merge pull request #6777 from pixelfed/fix/pat-creation-500-6630
...
Fix: Bounce error on PAT when OAUTH_PAT_ENABLED is false
1 month ago
Shlee
06e3351e92
Merge pull request #6778 from pixelfed/fix/prevent-pat-client-deletion-6630
...
Fix: Improve the web UX for deleting the OAuth Client and PAT
1 month ago
Shlee
fb655f1308
Merge pull request #6782 from ashleyhull-versent/shift-179490
...
Laravel Shift Preshift
1 month ago
Ashley Hull
ab07a705e6
Merge branch 'dev' into shift-179490
1 month ago
Shlee
68dca50973
Merge pull request #6774 from pixelfed/fix/oauth-scope-bypass-remove-follower-6643
...
Fix: OAuth accountRemoveFollowById to check token.
1 month ago
Shlee
20123ff5ba
Merge pull request #6773 from pixelfed/fix/first-follower-pagination-6695
...
Fix: Show first follower/following record excluded from previous API responses
1 month ago
Your Name
552a55c2d2
Upgrade images to v4
1 month ago
Daniel Supernault
91645faeee
Lint
1 month ago
Daniel Supernault
e1235dfd75
Fix ApiV1Controller, ensure follow notifications have an account
1 month ago
Thomas Jacumin
9d0b5949e9
Use Mastodon username convention for OIDC
1 month ago
Your Name
53759e3ad6
Prevent deletion of personal access OAuth client
...
Fixes #6630 (partial — deletion causing broken PAT)
If a user deletes the OAuth client that serves as the personal access
client, all PAT creation breaks for the entire instance with a 500 error.
Changes:
- Add custom OAuthClientController@destroy that checks if the client
has the personal_access grant type before allowing deletion
- Returns 403 with a clear error message if deletion is blocked
- Add confirmation dialog before client deletion in the frontend
- Add error handling to show server error messages to the user
This prevents accidental destruction of the PAT infrastructure.
1 month ago
Your Name
1ab677a526
Handle PAT creation gracefully when not configured
...
Fixes #6630 (partial — PAT 500 error)
Previously, POST /oauth/personal-access-tokens would throw an unhandled
RuntimeException (HTTP 500) when:
- OAUTH_PAT_ENABLED is false (the default), or
- No personal access client exists in the database
Now the endpoint:
1. Returns 403 with a clear message if PAT is disabled in config
2. Catches RuntimeException from the token factory and returns 500
with an actionable error message instead of a stack trace
1 month ago
Your Name
822e9c98cb
Fix OAuth scope bypass on remove_from_followers endpoint
...
Fixes #6643
The POST /api/v1/accounts/{id}/remove_from_followers endpoint was missing
the token existence check (! $request->user()->token()). While the
tokenCan('follow') scope check was already present, the missing token
guard meant unauthenticated token-less requests could potentially bypass
the scope enforcement.
Added the standard guard pattern consistent with accountFollowById and
accountUnfollowById endpoints.
Also adds tests verifying:
- Read-only tokens are denied (403)
- Follow-scoped tokens succeed (200)
- Unauthenticated requests are denied (403)
1 month ago
Your Name
396cf2d861
Fix first follower/following record excluded from API responses
...
Fixes #6695
When no pagination params are provided, the default min_id was set to 1
and the query used 'id > 1', which excluded the very first follower row
(id=1) on fresh instances.
Changed default min_id from 1 to 0 and switched the direction check from
truthy evaluation to !== null, so the query becomes 'id > 0' which
correctly includes all records.
1 month ago
Shift
19880c2ffb
Convert string references to `::class`
...
PHP 5.5.9 adds the new static `class` property which provides the fully qualified class name. This is preferred over using strings for class names since the `class` property references are checked by PHP.
1 month ago
Your Name
651f0de74f
Replace jenssegers/agent with matomo/device-detector
...
- Remove unmaintained jenssegers/agent package (no releases since 2021)
- Add matomo/device-detector v6.5 as actively maintained replacement
- Create App\Services\UserAgentService wrapper for drop-in compatibility
- Update UserDevice model and ApiV1Dot1Controller to use new service
1 month ago
dansup
268ab6dba0
Merge branch 'staging' into remove-exp-pue
1 month ago
dansup
7354f63563
Merge branch 'staging' into remove-exp-rec
1 month ago
Daniel Supernault
26ee049d07
Update AppRegisterController
1 month ago
Daniel Supernault
fbff6ed307
Update trustedproxy config
1 month ago
Daniel Supernault
a2be0cb47d
Update CommentController
1 month ago
Daniel Supernault
40aef7a212
Update GroupsFeedController
1 month ago
Daniel Supernault
5f397f9135
Update StoryController
1 month ago
dansup
f568804426
Merge pull request #6680 from pixelfed/shleeable-patch-15
...
Update FollowerObserver.php
1 month ago
dansup
d6cd65463d
Merge pull request #6676 from pixelfed/shleeable-patch-10
...
Stories API: PostgreSQL story carousel endpoints crash due to calling collection methods on query builder
1 month ago
dansup
668653039f
Merge pull request #6663 from vinzgreg/fix/api-status-edit-auth-guard
...
Fix API status editing: use auth:api guard
1 month ago
dansup
ca5f83d2d1
Merge pull request #6655 from TowyTowy/fix/timeline-home-nullable-max-id
...
Fix home timeline rejecting empty max_id/min_id pagination params
1 month ago
dansup
5aae3f46c7
Merge pull request #6691 from pixelfed/shleeable-patch-26
...
Improve validation
1 month ago
dansup
219297d0e3
Merge pull request #6690 from pixelfed/shleeable-patch-25
...
Typo: change pid to id for FollowerService::remove
1 month ago
dansup
6910115166
Merge pull request #6686 from pixelfed/shleeable-patch-20
...
Update type on abort.
1 month ago
dansup
77831e7640
Merge pull request #6688 from pixelfed/shleeable-patch-22
...
Clear oauth material on permanent delete
1 month ago
dansup
5115e5c960
Merge pull request #6677 from pixelfed/shleeable-patch-12
...
Typo in abort
1 month ago
dansup
179dfffafe
Merge pull request #6672 from pixelfed/shleeable-patch-5
...
Places directory crashes on PostgreSQL for multi-word country URLs (case-sensitive mismatch)
1 month ago
Shlee
c2044f77cf
Update AdminUserController.php
2 months ago
Shlee
1d72f1b437
Update ApiV1Controller.php
2 months ago
Shlee
fbe98ea4de
Update AccountController.php
2 months ago
Shlee
9966eb50b8
Update ApiV1Controller.php
2 months ago
Shlee
87d866f58d
Update SettingsController.php
2 months ago
Shlee
baf21797f0
Update RemoteOidcController.php
2 months ago
Shlee
0f79861f1d
Update PrivacySettings.php
2 months ago
Shlee
4e6b341532
Update StoryController.php
2 months ago
Shlee
8ce4b5d409
Update StoryApiV1Controller.php
2 months ago
Shlee
f99ee65676
Update PlaceController.php
2 months ago
Shlee
6f5f6e3368
Update ReportController.php
2 months ago
vinzgreg
d19671a92c
Fix API status editing: use auth:api guard
...
StatusEditController's constructor applies the web `auth` guard, which
Bearer/OAuth clients cannot satisfy. PUT /api/v1/statuses/{id} and
GET /api/v1/statuses/{id}/history therefore fail for every third-party
API client, while status create/delete keep working because
ApiV1Controller has no controller-level web auth.
The controller is routed only from routes/api.php, where the route group
already applies ['auth:api', 'validemail'], so no web/session route
depends on the old guard. Switch the constructor to match.
2 months ago
TowyTowy
795473be55
Fix home timeline rejecting empty max_id/min_id pagination params
...
`GET /api/v1/timelines/home?max_id=` (empty value) fails validation
because `min_id`/`max_id` use the `sometimes|integer` rule. The global
`ConvertEmptyStringsToNull` middleware turns `?max_id=` into `null`, and
since the field is present, `sometimes` does not skip it while `null`
fails the `integer` rule — returning HTTP 422.
Every other timeline/listing endpoint in this controller (timelinePublic,
accountStatusesById, etc.) uses `nullable|integer` for these params, so
`timelineHome` was the lone outlier. Mastodon-API clients such as Pixelfed
for iOS send `max_id=` on first page load and could not paginate the home
timeline.
Switch `min_id`/`max_id` to `nullable|integer` to match the rest of the
controller.
Fixes #6610
Co-Authored-By: Claude <noreply@anthropic.com>
2 months ago
Daniel Supernault
0f781cba34
Update Personal Access Tokens
3 months ago
Daniel Supernault
fb92949a71
Update PersonalAccessTokenController.php
3 months ago
Daniel Supernault
25d5142f12
Fix PAT + oauth routes
3 months ago
Daniel Supernault
9fe9b7eb32
Update AdminInviteController
3 months ago
dansup
096a1bc901
Merge pull request #6553 from pixelfed/w2
...
OAuth: Token endpoint response loses required no-store/no-cache headers
4 months ago
dansup
120b08b758
Merge pull request #6563 from pixelfed/shleeable-patch-1
...
Update to Passport 13 refresh token method in AppRegisterController.php
5 months ago
Your Name
3c9fc9a1fe
Remove EXP_PUE flag, post editing is always enabled
...
Remove the 'pue' entry from config/exp.php and the abort_if guard
in StatusEditController. Post editing is now unconditionally available.
5 months ago
Your Name
10a5eb7228
Remove exp.rec recommendations dead code
...
- Remove userRecommendations controller method and /api/local/exp/rec route
- Remove suggestions UI panel, data properties, and methods from Timeline.vue
- Remove commented-out suggestions card from feed template
The recommendations feature was deprecated and hardcoded to false/empty.
5 months ago
Daniel Supernault
14b325641f
Update Password Change with new Revoke Sessions option
...
As requested in https://lgbtqia.space/@serigala_tropis/116412473982617371
6 months ago
Shlee
bbd09fe50f
Update AppRegisterController.php
6 months ago
Your Name
b329ee9edc
API: Media uploads leak orphaned files when status creation validation fails
6 months ago
Your Name
3d858af1fa
OAuth: Token endpoint response loses required no-store/no-cache headers when adding created_at
6 months ago
dansup
6e9c33fcab
Merge pull request #6496 from pixelfed/shleeable-patch-7
...
Remove sleep from AppRegisterController.php
6 months ago
dansup
bdc203dc5c
Merge pull request #6493 from ShadowJonathan/fix-profile-saving
...
Make sure profile saving has a clear error when email is not verified
6 months ago
Daniel Supernault
ef803ae9b6
Fix oauth/token
7 months ago
Daniel Supernault
f6746aec8b
Update AuthServiceProvider
7 months ago
Daniel Supernault
52f5626530
Fix oauth
7 months ago
Daniel Supernault
695e851026
Fix oauth
7 months ago
Shlee
d9bd6d446f
Update AppRegisterController.php
7 months ago
Jonathan de Jong
8e91918b88
Make sure profile saving has a clear error when email is not verified
7 months ago
Shlee
1b21f83132
Update BaseApiController.php
7 months ago
dansup
f1af72e66d
Merge pull request #6454 from pixelfed/a5
...
Bugfix: Validation was ignored, allows any file type/size
7 months ago
Daniel Supernault
c975ddb13f
Update composer deps
7 months ago
Your Name
1a1dc5e096
fix typo
8 months ago
Daniel Supernault
3140404835
Update ApiV1Controller.php
8 months ago
Daniel Supernault
80a2f4f2b0
Add api/v1/accounts/lookup endpoint
8 months ago
Daniel Supernault
f76567f67b
Improve reblog check
8 months ago
Severin
066f8ee309
Pulls user settings for reblogs
8 months ago
dansup
1f04a190a9
Merge pull request #6438 from pixelfed/shleeable-patch-22
...
UpdatePersonValidator rejects null name/summary due to required|nullable conflict
8 months ago
dansup
fc694dd37a
Merge pull request #6431 from grossermensch/patch-1
...
Fix for portfolio with recent images not showing up on PSQL
8 months ago
dansup
b3fdc41816
Merge pull request #6429 from albattran/dev
...
Added pagination to the followers/followings API endpoints
8 months ago
dansup
ceec5a0eea
Merge pull request #6419 from pixelfed/shleeable-patch-18
...
Bugfix: CommentController : inherit appropriate visibility
8 months ago
dansup
70f3206b51
Merge pull request #6415 from pixelfed/shleeable-patch-14
...
Bugfix: Reversed follower check in PublicApiController::scopeCheck for private accounts.
8 months ago
dansup
ebb119e4df
Merge pull request #6410 from pixelfed/shleeable-patch-9
...
Bugfix: Missing status filter exposes suspended/disabled profiles via ActivityPub in getCachedUser(withTrashed)
8 months ago
dansup
11692c72e9
Merge pull request #6408 from pixelfed/shleeable-patch-3
...
Bugfix: Account deletion proceeds without validation server side.
8 months ago
Shlee
ac19942083
Update RemoteAuthController.php
8 months ago
Severin
b948a31e61
Fix for portfolio with recent images not showing up on PSQL
8 months ago
samir
9c3130a3c7
Added pagination to the followers/followings API endpoints
8 months ago
Shlee
4419054ae5
Update CommentController.php
9 months ago
Shlee
da03ca79d5
Update PublicApiController.php
9 months ago
Shlee
8394b8ac4b
Update ProfileController.php
9 months ago
Shlee
43f6686667
Update SettingsController.php
9 months ago
Shlee
def22b267d
Update BookmarkController.php
9 months ago
Daniel Supernault
ef6187b917
Fix LoginController
9 months ago
Daniel Supernault
0032eaf482
Fix AdminController
9 months ago
Daniel Supernault
34278c77c2
Update LoginController
9 months ago
Daniel Supernault
374344754e
Lint
9 months ago
Rm Yakovenko
7cb54eb7c2
[Bug]: public API endpoint /accounts/{id}/statuses ignores max_id parameter
10 months ago
Daniel Supernault
4bc1e22121
Refactor LikePipeline and improve Undo Announce handling
11 months ago
Daniel Supernault
04bf75fb68
Revert inbox changes
11 months ago
dansup
f783db493a
Merge pull request #6340 from grossermensch/patch-3
...
Allow to set new image types in admin interface
11 months ago
dansup
eae2dafcac
Merge branch 'staging' into intervention-laravel-clean
11 months ago
Severin
df5814d0f8
Allow to set new image types in admin interface
11 months ago
Shlee
fabb93d4a0
Update StoryComposeController.php
11 months ago
Your Name
45a9a3b472
RemoveUnreachableStatementRector
11 months ago
dansup
7881b09c2f
Merge pull request #6304 from pixelfed/classV2
...
Larastan: Fix Missing classes 2 - Medium risk
11 months ago
dansup
14d5fe940e
Merge pull request #6302 from pixelfed/miscClosureUnusedUseV2
...
Larastan: fix Unused Use - Low risk
11 months ago
dansup
f9d430d6e6
Merge pull request #6299 from pixelfed/classNotFoundV1
...
Larastan: Fix Missing classes - Low risk
11 months ago
dansup
99e89814b4
Merge pull request #6295 from pixelfed/shleeable-patch-20
...
Dead Code - Delete app/Http/Controllers/Api/InstanceApiController.php - Low Risk
11 months ago
dansup
6df58e67f2
Merge pull request #6290 from pixelfed/emptyv1
...
Larastan: 'empty() always exists and is not falsy' errors - Low risk
11 months ago
dansup
93217c8c63
Merge pull request #6284 from pixelfed/shleeable-patch-15
...
Larastan: Remove unused arg from Function config_cache - Safe/Mergable
11 months ago
dansup
d2acad9388
Merge pull request #6283 from pixelfed/shleeable-patch-14
...
Larastan: Update GroupsPostController.php - Safe/Mergable
11 months ago
dansup
bc9a974037
Merge pull request #6280 from pixelfed/refactor-RemoveDuplicatedArrayKeyRector
...
Larastan: Removed duplicated Keys in arrays.
11 months ago
dansup
e5c6ac0eca
Merge pull request #6274 from pixelfed/shleeable-patch-9
...
Larastan: Update BaseApiController.php
11 months ago
dansup
59e1e12625
Merge pull request #6273 from pixelfed/shleeable-patch-8
...
Larastan: Update ResetPasswordController.php / ForgotPasswordController.php
11 months ago
Your Name
15cc07e602
Fix all class.notFound PHPStan issues - 31 fixes
11 months ago
Your Name
28ed625f12
Fix PHPStan closure.unusedUse issues - 7 fixes
11 months ago
Your Name
ca6c875bbb
Fix PHPStan class.notFound issues
11 months ago
Shlee
e297cd0e94
Dead Code - Delete app/Http/Controllers/Api/InstanceApiController.php
11 months ago
Your Name
72e840345e
Fix PHPStan 'empty() always exists and is not falsy' errors
...
- Remove redundant empty() checks where variables are guaranteed to exist and be non-falsy
- Replace empty() with simple null/false checks where appropriate
- Maintain original logic while fixing static analysis issues
- Affected files:
- app/Http/Controllers/GroupController.php
- app/Http/Controllers/ProfileAliasController.php
- app/Jobs/ImageOptimizePipeline/ImageUpdate.php
- app/Jobs/InboxPipeline/DeleteWorker.php
- app/Jobs/InboxPipeline/InboxValidator.php
- app/Jobs/InboxPipeline/InboxWorker.php
- app/Jobs/ProfilePipeline/HandleUpdateActivity.php
- app/Rules/ExpoPushTokenRule.php
- app/Services/AutospamService.php
- app/Services/CollectionService.php
- app/Services/NotificationAppGatewayService.php
- app/Services/WebfingerService.php
- app/Util/ActivityPub/Helpers.php
11 months ago
Shlee
133e497879
Larastan: Update ComposeController.php
11 months ago
Shlee
304c3eab3f
Update GroupsPostController.php
11 months ago
Your Name
e43078961c
Fix PHP deprecation warnings for implicit nullable parameters
...
- Add explicit nullable type declarations to GroupService::log() method parameters
- Add explicit nullable type declaration to ModLogService::metadata() method parameter
- Add explicit nullable type declaration to HitHighlighter::highlight() method parameter
- Resolves PHP 8.1+ deprecation warnings about implicitly marking parameters as nullable
11 months ago
Daniel Supernault
cc90df9d8c
Add user admin toggles for email and ip
11 months ago
Shlee
8d197107e8
Update BaseApiController.php
11 months ago
Shlee
b826f4fe48
Update ForgotPasswordController.php
11 months ago
Shlee
4adc8947d8
Update ResetPasswordController.php
11 months ago
dansup
ea0fd2e719
Merge pull request #6261 from pixelfed/shleeable-patch-24
...
Larastan: Update FederationController.php
11 months ago
Shlee
d8c9d72f11
Update FederationController.php
11 months ago
Shlee
5a3d841e19
Update AccountController.php
11 months ago
dansup
f2e4715749
Merge pull request #6194 from emlove/migration
...
Account Migration fixes
11 months ago
dansup
1586808b11
Merge pull request #6189 from rossbearman/admin-invites
...
Admin web interface for creating and expiring invites; add invitation emails
11 months ago
Daniel Supernault
76b5601a01
Update IG Import
...
To support non-local fs
12 months ago
Daniel Supernault
03d01d296f
Update StoryComposeController.php
...
Fix non-local storage bug
12 months ago
Daniel Supernault
02455129a5
Update StoryComposeController.php
...
Fix support for non-local fs
12 months ago
Emily Love Watson
7709d5da29
Cleanup
12 months ago
Emily Love Watson
871efff1a8
Remove unused params
12 months ago
Emily Love Watson
453ae4b32e
MVP migration
12 months ago
Ross Bearman
db03733415
Add admin invite interface and email support
...
This commit does two things:
* Add invite email support to AdminInviteCommand
- Moves `invite_code` generation to AdminInvite model `creating` event
* Add admin invite management section under admin users dashboard
- Adds `Admin/AdminUserInviteController` and associated `home` and
`create` Blade templates.
- Adds "Invites" button to admin user dashboard
1 year ago
Daniel Supernault
3686c92122
Update Status storage, add SanitizerService to fix spacing in html stripped content
1 year ago
Daniel Supernault
ec21eec508
Update ApiV1Dot1Controller, fix Story report follower check
1 year ago
Daniel Supernault
f195102b34
Update StoryApiV1Controller, reduce min story size to 10kb
1 year ago
Daniel Supernault
5d4674daa4
Update ApiV1StoryController, fix viewer pagination
...
Fix cursor pagination
1 year ago
(dan)iel (sup)ernault
2e0b3829a3
Merge pull request #6081 from eufelipemateus/adjust-oderby-statuses-profile
...
fix: ordery by statutes profile
1 year ago
Daniel Supernault
32b1f26d69
Update StoryApiV1Controller, update error messsage
1 year ago
Daniel Supernault
8fb44e3162
Update StoryApiV1Controller, improve text overlay validation regex for improved support
1 year ago
Daniel Supernault
76d9ded694
Update StoryApiV1Controller, add missing validation rule
1 year ago
Daniel Supernault
6c701b335d
Update StoryComposeController, add StoryIndexService support
1 year ago
Daniel Supernault
97badbbdd6
Update StoryApiV1Controller, add new v1.2 endpoints
1 year ago
Daniel Supernault
44914a5143
Update StoryController, add StoryIndexService s markSeen support for webUI endpoint
1 year ago
Daniel Supernault
f5dced0f7a
Update ApiV1Dot1Controller, add story report support
1 year ago
Daniel Supernault
35424ccb4d
Update HomeSettings, remove unnecessary relation query
1 year ago
Daniel Supernault
86af73455f
Update DirectMessageController, add mutuals endpoint
1 year ago
Daniel Supernault
d42c25ca64
Update DiscoverController
1 year ago
Daniel Supernault
c319dfbcc4
Update AppRegister controller, add scheduled cleanup task to delete older than 90d
1 year ago
Daniel Supernault
3977137d02
Update AppRegisterController
1 year ago
Felipe Mateus
11a5fa9314
fix: ordery by
1 year ago
Daniel Supernault
e56bcf3853
Update ComposeController, fix postgres operator
1 year ago
Daniel Supernault
2a9c28b81e
Update ComposeController, fix user tagging endpoint
1 year ago
Daniel Supernault
10eb1a8acb
Update ComposeController, prioritize followed users and follower_count first
1 year ago
Daniel Supernault
b6bc1e50e2
Update Admin Users dashboard
1 year ago
Daniel Supernault
56f909a61b
Update ComposeController, add addl compose settings data
1 year ago
Daniel Supernault
1cb01545bc
Update ComposeController, add addl compose settings data
1 year ago
Daniel Supernault
9048ab52c2
Update ComposeController, add addl compose settings data
1 year ago
Daniel Supernault
1c66cf7fef
Update CuratedRegisterController
1 year ago
Daniel Supernault
ece23d751b
Update Places, improve cache invalidation/ttl
1 year ago
Daniel Supernault
f81a4acdc6
Update PlaceController, fix show method
1 year ago
Daniel Supernault
9d89425e62
Update StoryController, fix intervention/image
1 year ago
Daniel Supernault
86fbeeec35
Update StoryComposeController, fix intervention/image v3 support
1 year ago
Daniel Supernault
7f7387ee4d
Update StatusController, fix mimeTypeCheck
1 year ago
Daniel Supernault
4747266b04
Update ApiV1Controller, fix cache invalidation order
1 year ago
Daniel Supernault
ae47ba73d6
Update ComposeController, fix cache invalidation order
1 year ago
Daniel Supernault
4e938a8ffa
Fix heic, avif, webp support and add libvips driver
1 year ago
Daniel Supernault
ab9c13fe0d
New supported formats, Preserve ICC Color Profiles, libvips support
...
Update image pipeline to handle avif, heic and webp and preserve ICC color profiles and added libvips support.
1 year ago
Daniel Supernault
5a3a1cf76c
Update remove_from_followers api endpoint
1 year ago
daniel
92482c24cd
Merge pull request #5895 from eufelipemateus/feat-remove-follow
...
[Improvement] Add button remove follow
1 year ago
Daniel Supernault
26887c7672
Update OIDC config with comments, and disable tests as we dont have db tests configured
1 year ago
Gavin Mogan
70584b47c5
Fixes for items highlighted by review.ai
...
* Consider using `hash_equals()` instead of `==` when comparing the state values to prevent timing attacks:
`abort_unless(hash_equals($request->input('state'), $request->session()->pull('oauth2state')), 400, 'invalid
state');`
* For better data integrity, consider adding a foreign key constraint to the user_id column: `$table-
>foreign('user_id')->references('id')->on('users')->onDelete('cascade');`
* Does the OIDC provider guarantee that the username field exists in the userInfo data? Consider adding a
null check or fallback: `$userInfoData[config('remote-auth.oidc.field_username')] ?? null`
1 year ago
Gavin Mogan
441c8e0d4c
Generic OIDC Support
...
* Everything should be configurable by env variables
* Basic request tests
1 year ago
Mackenzie Morgan
9966260a91
use case insensitive search when tagging accounts
1 year ago
Felipe Mateus
fed800acfb
Merge branch 'dev-contrib-origin' into feat-remove-follow
1 year ago
Daniel Supernault
fc77a98f7b
Update CustomFilterController, remove statuses check as we dont support them yet
1 year ago
Daniel Supernault
5f5ed1e62d
Update ComposeController, fix tag mention bug. Closes #5885
1 year ago
Daniel Supernault
5a32bfe304
Update ApiV1Controller, add Custom Filters to home/public and hashtag feeds
1 year ago
Daniel Supernault
c4a96da019
Update CustomFilterController, improve case-insentive handling, mastoAPI compatibility and custom config limits
1 year ago
Daniel Supernault
b86102823b
Update CustomFilter model and CustomFilterController
1 year ago