- Dec 13, 2019
-
-
John Skarbek authored
This reverts commit 0455f2f3.
-
- Dec 12, 2019
-
-
GitLab Release Tools Bot authored
[ci skip]
-
John Skarbek authored
This reverts commit 2404e6c7.
-
- Dec 11, 2019
-
-
GitLab Release Tools Bot authored
[ci skip]
-
- Oct 24, 2019
-
-
David Wilkins authored
- Extend Gitlab::UrlBlocker to allow relative urls (require_absolute setting). The new `require_absolute` setting defaults to true, which is the existing behavior. - Extend AddressableUrlValidator to accept `require_abosolute` and default to the existing behavior - Add validation for ApplicationSetting#grafana_url to validate that the URL does not contain XSS but can be a valid relative or absolute url. - In the case of existing stored URLs, validate the stored URL does not contain XSS. If the stored URL contains stored XSS or is an otherwise invalid URL, return the default database column value. - Add tests for Gitlab::UrlBlocker to test require_absolute setting - Add tests for AddressableUrlValidator - Add tests for ApplicationSetting#grafana_url
-