Commit Graph

12695 Commits (e7ba43e2e1ea56243ecf2d4dfffce2d64f2b2317)
 

Author SHA1 Message Date
Shlee 2e97341e0d
Merge branch 'staging' into fix/exif-orientation-portrait-photos 1 month ago
Shlee 5cd94de92f
Merge pull request #6795 from pixelfed/feature/intervention-image-v4-upgrade
Migrate to Intervention Image v4
1 month ago
Shlee 6798175a80
Update .gitignore 1 month ago
Your Name 552a55c2d2 Upgrade images to v4 1 month ago
dansup 21d2f2f9c6
Merge pull request #6794 from pixelfed/staging
Staging (Ready for Dansup)
1 month ago
Shlee 24e22b7cad
Merge pull request #6567 from arnaud-jacquemin/feature/french-translation
French translation of the site pages
1 month ago
Shlee adee14a3a0
Merge pull request #6575 from pixelfed/l10n_staging
New Crowdin updates
1 month ago
Shlee 8b64e857a7
Merge pull request #6624 from raymundovr/feat/es-translation
Spanish translations
1 month ago
Shlee 3bb77bae53
Merge pull request #6793 from pixelfed/shleeable-patch-8
Cleanup Old Container Images
1 month ago
Shlee 7bf4e64d95
Rename workflow for GHCR container image cleanup 1 month ago
Shlee d4d74a96f3
Create docker-ghcr-cleanup.yml 1 month ago
Shlee ae116a76f5
Merge pull request #6765 from pixelfed/pint/tests
Apply Pint formatting to tests/
1 month ago
Shlee 448ec5b475
Merge pull request #6769 from pixelfed/pint/bootstrap
Apply Pint formatting to bootstrap/
1 month ago
Shlee 1051b7c5ff
Merge pull request #6771 from pixelfed/pint/public
Apply Pint formatting to public/ - 1 file
1 month ago
Shlee 0fa1ed65d3
Merge pull request #6792 from pixelfed/shleeable-patch-7
Update Docker workflow to include unstable branch
1 month ago
Shlee 8e3a375534
Enhance Docker workflow with concurrency and platforms 1 month ago
Shlee e53917f047
Update Docker workflow to include unstable branch 1 month ago
Daniel Supernault 8a728fc0dd
Update changelog 1 month ago
Daniel Supernault 91645faeee
Lint 1 month ago
dansup 06d3a19573
Merge pull request #6791 from pixelfed/staging
Staging
1 month ago
Daniel Supernault e1235dfd75
Fix ApiV1Controller, ensure follow notifications have an account 1 month ago
Shlee 8ef7807397
Merge pull request #6790 from pixelfed/shleeable-patch-6
Add GitHub Actions workflow for PHP Pint linting
1 month ago
Shlee 699b8af2d5
Add 'unstable' branch to workflow and update PHP version 1 month ago
Shlee e8b18f6690
Add GitHub Actions workflow for PHP Pint linting 1 month ago
Shlee 4f1bf6a5e6
Merge pull request #6772 from pixelfed/shleeable-patch-6
Create pint.json
1 month ago
Shlee 833c34e3a7
Merge branch 'staging' into shleeable-patch-6 1 month ago
Shlee f97434a266
Merge pull request #6764 from pixelfed/fix/psr4-webfinger-filename
Fix error: rename Webfinger.php to WebFinger.php
1 month ago
Shlee e25b745b6a
Merge pull request #6779 from pixelfed/tooling/install-larastan
Fix: Install Larastan for static analysis - Level 0 (Lowest)
1 month ago
Shlee 382fece953
Merge pull request #6788 from pixelfed/shleeable-patch-7
Add GitHub Actions workflow for Docker image build got GHCR
1 month ago
Shlee aa72592ac0
Update docker-push.yml 1 month ago
Shlee 8cecf38cfe
Add GitHub Actions workflow for Docker tagged release 1 month ago
Shlee f6baba9b13
Add GitHub Actions workflow for Docker image build 1 month ago
dansup f9d7898b02
Merge pull request #6786 from pixelfed/staging
Staging
1 month ago
Daniel Supernault 30085e8708
Fix validateUrl() 1 month ago
Daniel Supernault ce64d0961d
Update Inbox, fixes #6784 1 month ago
Shlee f1ca0340e7
Delete app/Comment.php 1 month ago
Your Name 0ce89e9f95 polish 1 month ago
Shlee c840d6bd71
Create php-larastan.yml 1 month ago
Your Name 9a9726af7c Install Larastan for static analysis
- Add larastan/larastan v3.10 (dev dependency)
- Configure phpstan.neon at level 0 with Laravel extension
- Generate baseline for existing errors (711 items)
- Exclude files with missing class references
- Fix one non-ignorable return type error in BearerTokenResponse
- Add composer analyse script

Usage: composer analyse
1 month ago
Your Name 53759e3ad6 Prevent deletion of personal access OAuth client
Fixes #6630 (partial — deletion causing broken PAT)

If a user deletes the OAuth client that serves as the personal access
client, all PAT creation breaks for the entire instance with a 500 error.

Changes:
- Add custom OAuthClientController@destroy that checks if the client
  has the personal_access grant type before allowing deletion
- Returns 403 with a clear error message if deletion is blocked
- Add confirmation dialog before client deletion in the frontend
- Add error handling to show server error messages to the user

This prevents accidental destruction of the PAT infrastructure.
1 month ago
Your Name 1ab677a526 Handle PAT creation gracefully when not configured
Fixes #6630 (partial — PAT 500 error)

Previously, POST /oauth/personal-access-tokens would throw an unhandled
RuntimeException (HTTP 500) when:
- OAUTH_PAT_ENABLED is false (the default), or
- No personal access client exists in the database

Now the endpoint:
1. Returns 403 with a clear message if PAT is disabled in config
2. Catches RuntimeException from the token factory and returns 500
   with an actionable error message instead of a stack trace
1 month ago
Your Name 655d71ba5c Fix OAuth client secret not displayed after creation
Fixes #6630 (partial — client secret issue)

In Passport v13, client secrets are hashed at the model level and only
available as plain_secret on the response from the creation endpoint.
The previous code immediately re-fetched the client list after creation,
losing the plain secret since it's not stored or returned on GET.

Changes:
- Capture plain_secret from the POST response
- Show a dedicated modal with the client ID and secret after creation
- Warn users to copy the secret immediately (it won't be shown again)
- Add a Copy button for convenience
- Show 'Hidden (only shown at creation)' in the table for existing clients
1 month ago
Shlee 906e3514c6
Delete tests/Feature/Api/RemoveFollowerScopeTest.php 1 month ago
Your Name 822e9c98cb Fix OAuth scope bypass on remove_from_followers endpoint
Fixes #6643

The POST /api/v1/accounts/{id}/remove_from_followers endpoint was missing
the token existence check (! $request->user()->token()). While the
tokenCan('follow') scope check was already present, the missing token
guard meant unauthenticated token-less requests could potentially bypass
the scope enforcement.

Added the standard guard pattern consistent with accountFollowById and
accountUnfollowById endpoints.

Also adds tests verifying:
- Read-only tokens are denied (403)
- Follow-scoped tokens succeed (200)
- Unauthenticated requests are denied (403)
1 month ago
Your Name 5eda130817 Show detailed upload error messages instead of generic error
Fixes #6657

When media uploads fail with a 422 validation error (e.g. file too large),
the error dialog now shows the actual validation message including the
filename, instead of the generic 'An unexpected error occurred.'

Example: 'DSCF0273.JPG: The file may not be greater than 15000 kilobytes'

Also improved the default error case to surface server-provided messages
when available. Applied to both ComposeModal and ComposeClassic components.
1 month ago
Your Name 396cf2d861 Fix first follower/following record excluded from API responses
Fixes #6695

When no pagination params are provided, the default min_id was set to 1
and the query used 'id > 1', which excluded the very first follower row
(id=1) on fresh instances.

Changed default min_id from 1 to 0 and switched the direction check from
truthy evaluation to !== null, so the query becomes 'id > 0' which
correctly includes all records.
1 month ago
Shlee 64eb52596b
Add linting scripts to composer.json 1 month ago
Shlee 3950ace9ac
Create pint.json 1 month ago
Shift 19880c2ffb
Convert string references to `::class`
PHP 5.5.9 adds the new static `class` property which provides the fully qualified class name. This is preferred over using strings for class names since the `class` property references are checked by PHP.
1 month ago
Shift 4c77809444
Adopt short array syntax
Since PHP 5.4 the short array syntax `[]` may be used instead of `array()`.
1 month ago