Commit Graph

18582 Commits (d13351afe8253c950038b2a28d8390f6f3bcc6db)

Author SHA1 Message Date
Claire d13351afe8
Merge pull request from GHSA-55j9-c3mp-6fcq
ci/woodpecker/push/woodpecker Pipeline was successful Details
2023-07-07 13:42:05 +10:00
Claire 5f1d9ad0c6
Merge pull request from GHSA-9pxv-6qvf-pjwc
* Fix timeout handling of outbound HTTP requests

* Use CLOCK_MONOTONIC instead of Time.now
2023-07-07 13:42:05 +10:00
Claire 912582b198
Merge pull request from GHSA-9928-3cp5-93fm
* Fix attachments getting processed despite failing content-type validation

* Add a restrictive ImageMagick security policy tailored for Mastodon

* Fix misdetection of MP3 files with large cover art

* Reject unprocessable audio/video files instead of keeping them unchanged
2023-07-07 13:42:05 +10:00
Claire 56d7c5badc
Merge pull request from GHSA-ccm4-vgcc-73hp
* Tighten allowed HTML in oEmbed-based preview cards

* Sanitize preview cards at render time

* Add `sandbox` attribute to preview card iframes
2023-07-07 13:42:05 +10:00
Claire ff0a267d03
Add hardened headers to user-uploaded files (#25756) 2023-07-07 13:42:05 +10:00
Eugen Rochko b21fe63102
Add canonical link tags in web UI (#25715) 2023-07-07 13:42:05 +10:00
Eugen Rochko e749599432
Add button to see results for polls in web UI (#25726) 2023-07-07 13:42:04 +10:00
Claire 648aeb7c97
Fix OAuth apps page crashing when listing apps with certain admin API scopes (#25713) 2023-07-07 13:42:04 +10:00
Claire 994c2c9402
Fix re-activated accounts being deleted by AccountDeletionWorker (#25711) 2023-07-07 13:42:04 +10:00
Trevor Wolf a95a453711
fix read more button overlapping thread line bug (#25706) 2023-07-07 13:42:04 +10:00
Claire 4373c942bb
Fix forgotten unconfirmed_email migration file (#25702) 2023-07-07 13:42:04 +10:00
mogaminsk 1ce3cfb159
Fix local live feeds does not expand (#25694) 2023-07-07 13:42:04 +10:00
forsamori 93c83b4ac2
Add at-symbol prepended to mention span title (#25684)
Co-authored-by: Sam BC <samuel.balbirnie-cumming@xdesign.com>
2023-07-07 13:42:04 +10:00
Eugen Rochko 60c102a22f
Change labels of live feeds tabs in web UI (#25683) 2023-07-07 13:42:04 +10:00
Daniel M Brasil 68b2abacda
Fix `/api/v2/search` not working with following query param (#25681) 2023-07-07 13:42:04 +10:00
Eugen Rochko 16665a92bd
Fix regression of icon button colors in web UI (#25679) 2023-07-07 13:42:03 +10:00
Trevor Wolf b197297e39
Change button colors to increase hover/focus contrast and consistency (#25677) 2023-07-07 13:42:03 +10:00
Claire 3beaa991ab
Add users index on unconfirmed_email (#25672) 2023-07-07 13:42:03 +10:00
Claire 2f677133ad
Add superapp index on `oauth_applications` (#25670) 2023-07-07 13:42:03 +10:00
Claire 4c78a5d649
Fix inefficient query when requesting a new confirmation email from a logged-in account (#25669) 2023-07-07 13:42:03 +10:00
kouhai dev 814c1f7a71 th: reduce ci clone depth
ci/woodpecker/push/woodpecker Pipeline was successful Details
2023-07-06 02:47:21 -07:00
kouhai dev 4ff0116cf6 th: quieter yarn please
yarn cache logs make woodpecker webui lag. this is not ideal.
2023-07-06 02:47:21 -07:00
kouhai dev 361dc97e40 th: run haml-lint on quote haml
ci/woodpecker/push/woodpecker Pipeline was successful Details
2023-07-05 01:50:54 -07:00
kouhai dev 4801cfbf78 th: invite limit nonfixited bugs 2023-07-05 01:50:54 -07:00
kouhai dev e5fdf9ab86 th: update haml-lint for autocorrect 2023-07-05 01:49:42 -07:00
kouhai dev ea47ea1479 th: oops, foreman's back 2023-07-05 01:49:42 -07:00
kouhai dev 961ac9e493 th: merge glitch again (lol)
ci/woodpecker/push/woodpecker Pipeline was successful Details
2023-07-05 01:14:10 -07:00
kouhai dev 1857350c10 th: update ruby
ci/woodpecker/push/woodpecker Pipeline was successful Details
2023-07-05 00:27:37 -07:00
kouhai dev 763bcbbc19 th: update node base docker
ci/woodpecker/push/woodpecker Pipeline failed Details
2023-07-05 00:24:27 -07:00
kouhai dev 0c68cb08f5 th: add invite limits behind TH_USE_INVITE_QUOTA
ci/woodpecker/push/woodpecker Pipeline was successful Details
TH_USE_INVITE_QUOTA: feature flag
TH_INVITE_MAX_USES: max uses per invite for non-moderators
TH_ACTIVE_INVITE_SLOT_QUOTA: max slots in active invites, including consumed slots
2023-07-05 00:20:28 -07:00
Cyra W c4f112ff01 th: add slowest dot network to readme 2023-07-05 00:14:12 -07:00
kouhai dev aeaeed71f3 th: 12-factor ~~authentication~~ apps were a mistake 2023-07-05 00:14:12 -07:00
Plastikmensch ed15893eed
Add regex filter back to firehose (#2266)
* Add regex filter back to firehose

The regex filter will apply to all tabs and not be automatically applied when pinned.

Signed-off-by: Plastikmensch <plastikmensch@users.noreply.github.com>

* Keep regex when pinned

Signed-off-by: Plastikmensch <plastikmensch@users.noreply.github.com>

---------

Signed-off-by: Plastikmensch <plastikmensch@users.noreply.github.com>
2023-07-03 15:41:50 +02:00
Plastikmensch b422b5eebd
Fix showing local only toots in "All" (#2265)
* Fix warnings about missing dependency in hooks

Signed-off-by: Plastikmensch <plastikmensch@users.noreply.github.com>

* Add `allowLocalOnly` to timelineId

Without this local-only toots will never be loaded.

feedType is checked to be public to not show local-only toots in the "Remote" tab.

Signed-off-by: Plastikmensch <plastikmensch@users.noreply.github.com>

---------

Signed-off-by: Plastikmensch <plastikmensch@users.noreply.github.com>
2023-07-03 07:00:38 +02:00
Claire ed567c9de6
Merge pull request #2263 from ClearlyClaire/glitch-soc/merge-upstream
Merge upstream changes
2023-07-02 22:14:45 +02:00
Claire 9f3c3f5209 Show local-only posts in “All” by default, and add back option to toggle it 2023-07-02 20:28:02 +02:00
mogaminsk 587ddc2c7f [Glitch] Prevent duplicate concurrent calls of `/api/*/instance` in web UI
Port 5b46345459 to glitch-soc

Signed-off-by: Claire <claire.github-309c@sitedethib.com>
2023-07-02 12:00:03 +02:00
Eugen Rochko c49e339c89 [Glitch] Change dropdown icon above compose form from ellipsis to bars in web UI
Port 0512537eb6 to glitch-soc

Signed-off-by: Claire <claire.github-309c@sitedethib.com>
2023-07-02 11:59:31 +02:00
Claire 7cc2c1be29 [Glitch] Change local and federated timelines to be in a single firehose column
Port cea9db5a0b to glitch-soc

Signed-off-by: Claire <claire.github-309c@sitedethib.com>
2023-07-02 11:58:51 +02:00
Renaud Chaput eb1cb8224a [Glitch] Use an Immutable Record as the root state
Port 78ba12f0bf to glitch-soc

Signed-off-by: Claire <claire.github-309c@sitedethib.com>
2023-07-02 11:55:34 +02:00
Claire 2ba4773ebe [Glitch] Fix onboarding prompt being displayed because of disconnection gaps
Port 9934949fc4 to glitch-soc

Signed-off-by: Claire <claire.github-309c@sitedethib.com>
2023-07-02 11:55:08 +02:00
Claire b75aa6b819 [Glitch] Remove the search button from UI header when logged out
Port 285a691936 to glitch-soc

Signed-off-by: Claire <claire.github-309c@sitedethib.com>
2023-07-02 11:54:47 +02:00
Claire 44e98a2740 Merge branch 'main' into glitch-soc/merge-upstream 2023-07-02 11:49:08 +02:00
Eugen Rochko ba06a2f104
Revert "Rails 7 update" (#25667) 2023-07-02 11:14:22 +02:00
mogaminsk 5b46345459
Prevent duplicate concurrent calls of `/api/*/instance` in web UI (#25663) 2023-07-02 11:12:16 +02:00
Eugen Rochko 0512537eb6
Change dropdown icon above compose form from ellipsis to bars in web UI (#25661) 2023-07-02 10:39:55 +02:00
Matt Jankowski 50c2a03695
Rails 7 update (#24241) 2023-07-02 10:38:53 +02:00
Daniel M Brasil 4fe2d7cb59
Fix HTTP 500 in `/api/v1/emails/check_confirmation` (#25595) 2023-07-02 00:05:44 +02:00
Claire cea9db5a0b
Change local and federated timelines to be in a single firehose column (#25641) 2023-07-02 00:05:10 +02:00
Matt Jankowski 0139b1c8e1
Update uri to version 0.12.2 (CVE fix) (#25657) 2023-07-02 00:04:21 +02:00