Commit Graph

  • b1a6e8d80d test: add sanity tests for federator handling of AP docs William Pitcock 2018-11-17 21:01:19 +0000
  • 0d1375f274 federator: return :ok or :error depending on if an AP doc was accepted or not William Pitcock 2018-11-17 21:00:37 +0000
  • 3d9266a8cb federator: do origin containment when processing inbound messages William Pitcock 2018-11-17 20:43:43 +0000
  • 55640c4804 tests: add a test to verify the general fake direction protection works in all cases William Pitcock 2018-11-17 20:31:20 +0000
  • dc1d8e13b4 tests: add a testcase for user collision William Pitcock 2018-11-17 20:20:45 +0000
  • c88533209c activitypub: user fetching: use fetch_and_contain_remote_object_from_id() William Pitcock 2018-11-17 20:13:38 +0000
  • 1a940cb46e tests: add tests for contain_origin_from_id() William Pitcock 2018-11-17 20:07:49 +0000
  • daa8ec3d62 activitypub: factor out AP object fetching to it's own function and add ID-based containment William Pitcock 2018-11-17 20:02:02 +0000
  • e0b0fde713
    Web.AdminAPI.AdminAPIController: Change right to permission group (except for function names) Haelwenn (lanodan) Monnier 2018-11-10 15:16:19 +0100
  • 1a31d71187
    lib/mix/tasks/relay_{un,}follow.ex: Use a with block Haelwenn (lanodan) Monnier 2018-11-10 15:08:03 +0100
  • ccd6b1956d
    lib/pleroma/web/admin_api/admin_api_controller.ex: Support status reply of Relay.{un,}follow Haelwenn (lanodan) Monnier 2018-11-10 14:55:49 +0100
  • 7fbfd2db96
    lib/mix/tasks/relay_{un,}follow.ex: Support status reply of Relay.{un,}follow Haelwenn (lanodan) Monnier 2018-11-10 14:55:32 +0100
  • 265c8c5209
    Pleroma.Web.ActivityPub.Relay: make {un,}follow return :ok only if it worked, :error if it didn’t Haelwenn (lanodan) Monnier 2018-11-10 14:49:02 +0100
  • 4a79b89dba
    lib/pleroma/plugs/user_is_admin_plug.ex: change 403 string to “User is not admin.” Haelwenn (lanodan) Monnier 2018-11-10 14:43:22 +0100
  • f9d05902fe
    lib/pleroma/web/admin_api/admin_api_controller.ex: An admin cannot un-admin themselves Haelwenn (lanodan) Monnier 2018-11-10 14:42:34 +0100
  • a87ed2fad6
    Pleroma.Web.AdminAPI.AdminAPIController: user_create statement format Haelwenn (lanodan) Monnier 2018-11-02 08:30:52 +0100
  • f48062488e
    Add get endpoints for rights [AdminAPI] Haelwenn (lanodan) Monnier 2018-11-02 08:19:56 +0100
  • 59ce7fedce
    Fix connection returns make generic right endpoint [AdminAPI] Haelwenn (lanodan) Monnier 2018-11-02 08:15:09 +0100
  • c5a2bd6a65
    admin_api_controller.ex: fix remaining params at once Haelwenn (lanodan) Monnier 2018-10-12 06:43:08 +0200
  • 95b107b6cc
    admin_api_controller.ex: Add documentation, fix get_invite_token Haelwenn (lanodan) Monnier 2018-10-12 06:37:37 +0200
  • 578a911737
    admin_api_controller.ex: get_password_reset: fix params and response Haelwenn (lanodan) Monnier 2018-10-12 06:28:20 +0200
  • 5732eef16b
    lib/pleroma/web/admin_api/admin_api_controller.ex: Pleroma.Web.AdminAPI.Controller → Pleroma.Web.AdminAPI.AdminAPIController Haelwenn (lanodan) Monnier 2018-10-12 06:26:58 +0200
  • c8b8f1d32c
    [Pleroma.Plugs.UserIsAdminPlug]: Check if admin is true instead of false, fix error reporting Haelwenn (lanodan) Monnier 2018-10-12 06:25:50 +0200
  • 011a2e36b1
    lib/mix/tasks/make_admin.ex: New task Haelwenn (lanodan) Monnier 2018-10-12 05:12:09 +0200
  • 7076d45cb6
    lib/pleroma/plugs/user_is_admin_plug.ex: Create Haelwenn (lanodan) Monnier 2018-10-02 19:13:21 +0200
  • 77d2fd54dd
    admin_api_controller: Have some basic code Haelwenn (lanodan) Monnier 2018-10-02 19:03:05 +0200
  • ee2e1328ad
    admin_api_controller.ex: Create Haelwenn (lanodan) Monnier 2018-10-02 18:38:16 +0200
  • a960983815 Merge branch 'security/actor-containment' into 'develop' lambda 2018-11-17 18:33:09 +0000
  • b483ae0a72 tests: add a second spoofing variant William Pitcock 2018-11-17 18:24:58 +0000
  • 603fccf175 activitypub: fetch_object_from_id(): prefer `actor` over `attributedTo` to avoid spoofing William Pitcock 2018-11-17 18:17:17 +0000
  • 9c8adfb6ef test: fix more test defects William Pitcock 2018-11-17 18:16:55 +0000
  • d9cb081f07 tests: add additional spoofing tests William Pitcock 2018-11-17 18:12:11 +0000
  • 2ab8e28728 transmogrifier tests: fix defective spoofing test William Pitcock 2018-11-17 18:11:31 +0000
  • 010fcb73d7 test: httpoison mock: add second spoofing activity test William Pitcock 2018-11-17 17:42:47 +0000
  • 05967472f2 Merge branch 'feature/uploader-mdii' into 'develop' kaniini 2018-11-17 16:41:09 +0000
  • 59e079f641 fallbacking into local uploader hakabahitoyo 2018-11-17 20:16:25 +0900
  • 8fd0556c78 better config reading hakabahitoyo 2018-11-17 18:14:42 +0900
  • e4f57f89de Merge branch 'bugfix/dm-timeline-scope' into 'develop' kaniini 2018-11-16 23:34:43 +0000
  • f87b315618 TwitterAPI: Fix dm_timeline displaying only half of the conversation. lain 2018-11-16 19:47:36 +0100
  • 2f639ea129 Merge branch 'feature/pleromafe-usersearch' into 'develop' lambda 2018-11-16 18:13:47 +0000
  • 38f76d964f Merge branch 'bugfix/csp-remove-form-action' into 'develop' kaniini 2018-11-16 17:47:22 +0000
  • c07464607d http security: remove form-action from CSP definitions William Pitcock 2018-11-16 17:40:21 +0000
  • e8d8c84f79 Add better test for user search functionlity. lain 2018-11-16 18:31:32 +0100
  • 4ad0432565 Merge branch 'fix/test' into 'develop' lambda 2018-11-16 15:52:38 +0000
  • 62944b47fb Reset http security settings to fix plug test AkiraFukushima 2018-11-17 00:45:21 +0900
  • 55abd8482e better config hakabahitoyo 2018-11-16 20:41:12 +0900
  • 52224de39f better extension detection hakabahitoyo 2018-11-16 20:22:36 +0900
  • 4fbfacf5e1 debug hakabahitoyo 2018-11-15 16:08:55 +0900
  • 8e707aba29 format hakabahitoyo 2018-11-15 15:11:59 +0900
  • ebe658c169 debuf Hakaba Hitoyo 2018-11-15 14:46:43 +0900
  • 698cb3587c omplement mdii uploader Hakaba Hitoyo 2018-11-15 14:38:45 +0900
  • 58af0787be add mdii uploader Hakaba Hitoyo 2018-11-15 14:19:10 +0900
  • 5c8b8f6cb7 Merge remote-tracking branch 'official/develop' into develop Hakaba Hitoyo 2018-11-15 14:04:09 +0900
  • 3484f68795 Revert "update pleroma frontend" Hakaba Hitoyo 2018-11-15 14:03:52 +0900
  • 27aa136aac Format. lain 2018-11-14 20:41:12 +0100
  • 7b170cd616 Add Pleroma user search api for PleromaFE. lain 2018-11-14 20:33:23 +0100
  • cc45797f4e Merge branch 'fix-media-proxy-filename' into 'develop' lambda 2018-11-14 18:17:10 +0000
  • 8456675c45 Merge branch 'update/pleroma-fe-20181114' into 'develop' kaniini 2018-11-14 16:10:27 +0000
  • 2a75de84e1 update pleroma frontend William Pitcock 2018-11-14 16:08:22 +0000
  • 69d557e86d Merge branch 'twitter-api-direct-messages' into 'develop' kaniini 2018-11-14 08:52:08 +0000
  • f52a1d1ec5
    media_proxy: use path only to retrieve filename href 2018-11-13 23:41:33 +0100
  • ea9a776d7b TwitterApi: Add direct message endpoint lain 2018-11-13 20:08:50 +0100
  • 2cf40237ff MastodonAPI: Add pagination to private messages. lain 2018-11-13 19:46:34 +0100
  • a43195bdaa Merge branch 'media-proxy-safety' into 'develop' lambda 2018-11-13 15:15:05 +0000
  • 9b553a1087
    media_proxy: CSP, content-disposition href 2018-11-13 15:58:02 +0100
  • 22d20c497b Merge branch 'security/cookie-hardening' into 'develop' lambda 2018-11-13 13:23:04 +0000
  • c3f562a611 Merge branch 'add-MIX_ENV-to-systemd-example' into 'develop' lambda 2018-11-13 12:24:29 +0000
  • cf35a9dc3d Merge branch 'whalebird' into 'develop' lambda 2018-11-13 12:22:41 +0000
  • 87c76a9a2f
    Add __Host- prefix when secure flag is enabled shibayashi 2018-11-13 00:32:38 +0100
  • 124a9bb7a5
    Add MIX_ENV=prod shibayashi 2018-11-12 23:01:06 +0100
  • 0ce5623134 Merge branch 'twitter-api-null-display-name' into 'develop' scarlett 2018-11-12 17:08:54 +0000
  • db78c72868 Twitter API: Add tests for nil names. scarlett 2018-11-12 16:40:34 +0000
  • 35895b1c4c Add Whalebird as a client application in README AkiraFukushima 2018-11-13 01:02:49 +0900
  • cb6fd73861 Twitter API: Fall back to user.nickname if user has no name scarlett 2018-11-12 15:38:39 +0000
  • 54923c2e55 Merge branch 'feature/csp-plug' into 'develop' kaniini 2018-11-12 15:30:42 +0000
  • 2829fa4183 sample config: chase http_security change William Pitcock 2018-11-12 15:17:04 +0000
  • ee5932a504 http security: allow referrer-policy to be configured William Pitcock 2018-11-12 15:14:46 +0000
  • fe67665e19 rename CSPPlug to HTTPSecurityPlug. William Pitcock 2018-11-12 15:08:02 +0000
  • e7d6f133eb Merge branch 'update-readme' into 'develop' Haelwenn 2018-11-11 16:44:04 +0000
  • 3e6e4e3be7
    Update README.md shibayashi 2018-11-11 17:31:16 +0100
  • b982ced92c Merge branch 'fix-list-streaming' into 'develop' kaniini 2018-11-11 13:41:48 +0000
  • 1592fa2bea Mastodon API: Fix list streaming KokaKiwi 2018-11-11 04:33:14 +0100
  • 5dda13ee5f config docs: typo fix William Pitcock 2018-11-11 07:27:36 +0000
  • 54fdce9107 tests: add tests for CSPPlug William Pitcock 2018-11-11 07:26:31 +0000
  • e4bd5a6950 example configs: kill STS/CT headers William Pitcock 2018-11-11 06:56:46 +0000
  • df72978dce csp plug: add support for certificate transparency William Pitcock 2018-11-11 06:53:42 +0000
  • 331cf6ada1 csp plug: add sts support William Pitcock 2018-11-11 06:50:28 +0000
  • a2bf5426cb sample config: document how to make CSPPlug send STS headers (off by default to allow for SSL debugging) William Pitcock 2018-11-11 06:42:14 +0000
  • 69f5dfcfb3 config: add default parameters for CSPPlug William Pitcock 2018-11-11 06:37:18 +0000
  • 057a9017b3 example configs: remove obsolete CSP configuration William Pitcock 2018-11-11 06:12:26 +0000
  • f516e317ea plugs: add CSPPlug William Pitcock 2018-11-11 06:10:21 +0000
  • 617aff4f0c Merge branch 'bugfix/corsplug-config' into 'develop' kaniini 2018-11-11 05:49:49 +0000
  • fd918863aa nginx example config: remove CORS headers, now managed by CORSPlug. William Pitcock 2018-11-11 05:42:30 +0000
  • 234e471289 config: properly configure CORSPlug. William Pitcock 2018-11-11 05:40:55 +0000
  • 61d173d37c Merge branch 'bugfix/oauth-padding' into 'develop' kaniini 2018-11-11 05:34:45 +0000
  • 419ed3a0ca oauth: fix token decode regression William Pitcock 2018-11-11 05:11:27 +0000
  • f745e823f0 Merge branch 'bugfix/json-ld-object-sanitization' into 'develop' lambda 2018-11-10 12:37:18 +0000
  • 9cdbac6843 Merge branch 'feature/documentation' into 'develop' kaniini 2018-11-10 12:25:08 +0000
  • 69b8c0e299 tests: add test for internal data stripping William Pitcock 2018-11-10 12:16:10 +0000
  • 97e50f3191 activitypub: transmogrifier: sanitize internal representation details from outgoing objects William Pitcock 2018-11-10 12:08:53 +0000