Skip to content
Snippets Groups Projects
  1. Nov 15, 2019
  2. Oct 30, 2019
  3. Oct 28, 2019
  4. Oct 25, 2019
  5. Oct 24, 2019
  6. Oct 23, 2019
  7. Oct 16, 2019
    • Luke Duncalfe's avatar
      Pass all wiki markup formats through pipelines · 37a39346
      Luke Duncalfe authored
      Previously, when the wiki page format was anything other than `markdown`
      or `asciidoc` the formatted content would be returned though a Gitaly
      call. Gitaly in turn would delegate formatting to the gitlab-gollum-lib
      gem, which in turn would delegate that to various gems (like RDoc for
      `rdoc`) and then apply some very liberal sanitization.
      
      It was too liberal!
      
      This change brings our wiki content formatting in line with how we
      format other markdown at GitLab, so we have a SSOT for sanitization.
      
      https://gitlab.com/gitlab-org/gitlab/issues/30540
      37a39346
    • Ryan Cobb's avatar
      Mask Sentry auth token · 1b0bead0
      Ryan Cobb authored
      This makes it so we mask Sentry's auth token. This mask only occurs in
      the UI.
      1b0bead0
  8. Oct 14, 2019
  9. Oct 11, 2019
  10. Oct 10, 2019
  11. Oct 09, 2019
    • Kerri Miller's avatar
      Avoid #authenticate_user! in #route_not_found · 15bce7f0
      Kerri Miller authored
      This method, #route_not_found, is executed as the final fallback for
      unrecognized routes (as the name might imply.) We want to avoid
      `#authenticate_user!` when calling `#route_not_found`;
      `#authenticate_user!` can, depending on the request format, return a 401
      instead of redirecting to a login page. This opens a subtle security
      exploit where anonymous users will receive a 401 response when
      attempting to access a private repo, while a recognized user will
      receive a 404, exposing the existence of the private, hidden repo.
      15bce7f0
  12. Oct 08, 2019
Loading