Sign in
apache
/
allura
/
HEAD
93857a0
[#8613] Add encrypted field for user preferences email address
by Carlos Cruz
· 2 weeks ago
master
4b3b05d
make test more reliable (not reliant on fetching "url":"https://httpbin.org/image/png"
by Dave Brondsema
· 24 hours ago
81208e1
enable webp screenshots & attachments
by Dave Brondsema
· 7 days ago
db/webp
1a5e508
bumping Pillow 12.2.0 -> 12.3.
by Guillermo Cruz
· 11 days ago
ad248b0
bumping soupsieve 2.8.3 -> 2.8.4
by Guillermo Cruz
· 2 weeks ago
c7a0209
[#8610] Implement field level encryption for Users email addresses
by Carlos Cruz
· 5 weeks ago
79f1f64
[#8610] Add support for list fields to field conversion script
by Carlos Cruz
· 5 weeks ago
4a81f02
[#8610] Add encrypted field for Users email addresses
by Carlos Cruz
· 5 weeks ago
0ec1fd9
bump joserfc 1.6.4 -> 1.7.2
by Guillermo Cruz
· 4 weeks ago
7538a9e
config pip in rebuild-all.sh to install in a more compatible way for LSPs
by Dillon Walls
· 4 weeks ago
8e10408
stringify some ids
by Dave Brondsema
· 4 weeks ago
db/solr_nones
d1ccfec
don't pass sort=None etc to solr
by Dave Brondsema
· 4 weeks ago
2b55895
get chained exception details into errormiddleware output
by Dave Brondsema
· 4 weeks ago
1f290c6
add docker/compose health checks and use --wait to check them
by Dave Brondsema
· 4 weeks ago
e65e720
CHANGES updated for ASF release 1.19.1
by Dave Brondsema
· 4 weeks ago
rel/1.19.1
da948e3
provide merged config to ming, so debug key is there
by Dave Brondsema
· 4 weeks ago
a98de00
add timeouts to ApacheAccessHandler.py network requests
by Dave Brondsema
· 4 weeks ago
4569770
CHANGES updated for ASF release 1.19.0
by Dave Brondsema
· 5 weeks ago
08e62a6
Update copyright year
by Dave Brondsema
· 5 weeks ago
35289fd
[#8611] documentation and migration scripts
by Dave Brondsema
· 5 weeks ago
ba9733e
[#8611] put encryption settings into development.ini with a default that triggers a warning
by Dave Brondsema
· 5 weeks ago
e95355a
better escape_html that does quotes too
by Dave Brondsema
· 5 weeks ago
66e3ca1
bumping bleach 6.3.0 -> 6.4.0
by Guillermo Cruz
· 5 weeks ago
2eccab5
[#8607] limit prefs able to set via form
by Dave Brondsema
· 6 weeks ago
0cfffd9
[#8607] use |tojson within JS
by Dave Brondsema
· 6 weeks ago
f5ad949
[#8607] perm checks on ticket bulk edit & move
by Dave Brondsema
· 6 weeks ago
35130ea
[#8607] require post for phone verification endpoints
by Dave Brondsema
· 6 weeks ago
b696630
[#8607] validate links via rest
by Dave Brondsema
· 6 weeks ago
d4dfbf5
[#8607] check domain when adding github auth token
by Dave Brondsema
· 6 weeks ago
a5ecc79
[#8607] lock down a bit of the incomplete commit_status endpoint
by Dave Brondsema
· 6 weeks ago
c73b0a3
bumping cryptography 46.0.7 -> 49.0.0
by Guillermo Cruz
· 5 weeks ago
7c34ea3
[#8604] Update transient anonymous user property to not use encrypted field
by Carlos Cruz
· 2 months ago
cc/11102-part2b
e075d27
Remove dead ProjectUserSelect code
by Carlos Cruz
· 3 months ago
4d22657
[#8604] Implement field level encryption for User's display_name_field
by Carlos Cruz
· 3 months ago
daceb4c
[#8604] Add the display_name_encrypted field to the User class
by Carlos Cruz
· 3 months ago
1fc0675
enforce text limits for all markdown rendering paths
by Dave Brondsema
· 6 weeks ago
f84206a
[#8606] Implement field level encryption for EmailAddress email field
by Carlos Cruz
· 2 months ago
77dc646
update httpbin testing domain again
by Dave Brondsema
· 7 weeks ago
9635e2f
bump webob 1.8.9 -> 1.8.10
by Guillermo Cruz
· 7 weeks ago
c6f48a4
[#8607] lock down get_markdown content type and only to those who could use it to update anyway
by Dave Brondsema
· 7 weeks ago
2a81793
[#8607] another perm check for MRs
by Dave Brondsema
· 7 weeks ago
b8de78d
[#8606] Add encrypted field for email from the EmailAddress model
by Carlos Cruz
· 2 months ago
f2d93d1
autopep8
by Dave Brondsema
· 7 weeks ago
481b202
[#8607] scoping checks for ForgeChat
by Dave Brondsema
· 7 weeks ago
3e63f3b
[#8607] add explicit perm check on project rest controller
by Dave Brondsema
· 7 weeks ago
2c8e26f
[#8607] harden git operations
by Dave Brondsema
· 8 weeks ago
160216b
[#11645] Fix email subject text for authentication link test
by Carlos Cruz
· 7 weeks ago
1a0e24b
[#11645] Use jQuery cookie plugin to get CSRF token
by Carlos Cruz
· 7 weeks ago
5009819
[#11645] Restore Authentication Link text in email subject
by Carlos Cruz
· 7 weeks ago
3c97522
[#11645] Force /auth/logout to go through a POST request
by Carlos Cruz
· 8 weeks ago
0640949
[#8607] solr: syntax problems deserve an escaped retry; don't expose underlying error messages
by Dave Brondsema
· 8 weeks ago
e0de4b3
[#8607] solr: strip local-params syntax
by Dave Brondsema
· 8 weeks ago
38b68f9
[#8607] solr: move **kw to specific params for all other tools using common search_app helper
by Dave Brondsema
· 8 weeks ago
27f7a69
[#8607] solr: change ticket searches from **kw passthru to explicit
by Dave Brondsema
· 9 weeks ago
13675be
[#8607] ./run_tests QoL: show final message, allow trailing slash for tab-complete of suites
by Dave Brondsema
· 9 weeks ago
08db853
[#8607] remove useless try/except/raise
by Dave Brondsema
· 9 weeks ago
d4b5031
[#8607] remove potential info disclosure
by Dave Brondsema
· 9 weeks ago
ea0aa7f
[#8607] svn tarball path safety
by Dave Brondsema
· 9 weeks ago
5f8dca2
[#8607] be extra safe with display names
by Dave Brondsema
· 9 weeks ago
4a1ac65
[#8607] various has_access improvements
by Dave Brondsema
· 9 weeks ago
c17f5cb
[#8607] check activity nbhd
by Dave Brondsema
· 9 weeks ago
ca1ac59
[#8607] check subproject parent
by Dave Brondsema
· 9 weeks ago
a23ae35
[#8607] replace last pickle usage with our own bit of compatible code
by Dave Brondsema
· 9 weeks ago
717a0f1
[#8607] remove old pickle-based session support
by Dave Brondsema
· 9 weeks ago
281e56b
[#8607] add X-Content-Type-Options header
by Dave Brondsema
· 9 weeks ago
4f58190
[#8607] harden attachment upload
by Dave Brondsema
· 9 weeks ago
e53e9e3
[#8607] test for save_attachments (export) path handling
by Dave Brondsema
· 9 weeks ago
36c6133
[#8607] check client_id when making bearer token
by Dave Brondsema
· 10 weeks ago
bb89bba
[#8607] perm checks in markdown_to_html and fix wiki tool check
by Dave Brondsema
· 10 weeks ago
2a6733f
[#8607] safer pwd comparison
by Dave Brondsema
· 10 weeks ago
c57d710
[#8607] replace random with secrets in some places
by Dave Brondsema
· 10 weeks ago
b983158
[#8607] check subscribe here too
by Dave Brondsema
· 10 weeks ago
5a99493
[#8607] check before mailbox sub too
by Dave Brondsema
· 10 weeks ago
b763ed7
[#8607] check mailbox owner
by Dave Brondsema
· 10 weeks ago
13d1f75
[#8607] check project when loading role_id inputs
by Dave Brondsema
· 10 weeks ago
da78898
[#8607] move |safe to be directly on the string source
by Dave Brondsema
· 10 weeks ago
a3d4086
[#8607] check app_config_id in update_forums
by Dave Brondsema
· 10 weeks ago
120de2c
[#8607] add comments, add test
by Dave Brondsema
· 10 weeks ago
b8d1b43
[#8607] test for zipdir symlink handling
by Dave Brondsema
· 2 months ago
3d9cc03
[#8607] move webhook send from requests to urlopen so our NoInternal handlers run automatically including on redirects
by Dave Brondsema
· 2 months ago
01d6fe7
[#8607] test for oembed output security
by Dave Brondsema
· 2 months ago
3d53e1e
[#8607] check for email code mode when verifying email link
by Dave Brondsema
· 2 months ago
ff11615
[#8607] escape html in a few places
by Dave Brondsema
· 2 months ago
4bb6a49
[#8605] Use C.UTF-8 locale instead of en_US.UTF-8 for SVN export
by Dillon Walls
· 2 months ago
6f41f01
add & update some mongo indexes
by Dave Brondsema
· 8 weeks ago
25fb538
fixup! [#8608] precommit pin dependencies and updates
by Guillermo Cruz
· 9 weeks ago
4eef6f1
[#8608] precommit pin dependencies and updates
by Guillermo Cruz
· 9 weeks ago
8dd8d20
[#8609] include geo information that could be available for the html template
by Guillermo Cruz
· 9 weeks ago
gc/8609
9efd8e8
bump idna 3.11 -> 3.15
by Guillermo Cruz
· 9 weeks ago
32aa4dc
form-action change from self to base_url to avoid proxied sites
by Daniel Castillo
· 9 weeks ago
1f9e0de
[#11526] form-action from self to base_url
by Daniel Castillo
· 2 months ago
61b040c
make with_trailing_slash and without_trailing_slash apply to HEAD requests too
by Dave Brondsema
· 10 weeks ago
3ba29f3
another fix for clone task validation: move validation down into init_as_clone and do file path and URL validation separately based on which is used
by Dave Brondsema
· 9 weeks ago
82a94e6
fix scheme/protocol checking in clone task
by Dave Brondsema
· 10 weeks ago
006ae25
change httpbin domain we use, so redirect-to tests keep working
by Dave Brondsema
· 10 weeks ago
719ec40
Set up default protection ruleset for default and release branches
by The Apache Software Foundation
· 10 weeks ago
6754e9c
[#8603] check multifactor login mode
by Dave Brondsema
· 2 months ago
68b8d44
[#8603] validate URLs on clone tasks too (e.g. if task delayed from form usage, and DNS changes)
by Dave Brondsema
· 2 months ago
bb66149
[#8603] use Markup in SxsOutputGenerator
by Dave Brondsema
· 3 months ago
8e96d70
[#8603] NonPrivateUrl checks all host=>IP resolutions not just one
by Dave Brondsema
· 3 months ago
Next »