- 13.12.2019 13 коммитов
-
-
John T Skarbek создал
-
-
Alessio Caiazza создал
-
-
-
GitLab Bot создал
-
-
Kyle Wiebers создал
-
John T Skarbek создал
-
-
-
John T Skarbek создал
-
-
- 12.12.2019 3 коммита
-
-
John T Skarbek создал
-
-
-
- 11.12.2019 3 коммита
-
-
John T Skarbek создал
-
-
-
- 09.12.2019 2 коммита
-
-
Valery Sizov создал
- 11.09.2019 1 коммит
-
-
GitLab Release Tools Bot создал
-
- 10.09.2019 3 коммита
-
-
GitLab Release Tools Bot создал
-
-
GitLab Release Tools Bot создал
Set max-age and secure flag for pages auth cookies See merge request gitlab/gitlabhq!3381
-
- 09.09.2019 1 коммит
-
-
Vladimir Shushlin создал
-
- 28.08.2019 6 коммитов
-
-
GitLab Release Tools Bot создал
-
-
Jan Provaznik создал
Merge branch '66641-broken-master-real-http-connections-are-disabled-unregistered-request' into 'master' Use `stub_full_request` to fix spec failure Closes #66641 See merge request gitlab-org/gitlab-ce!32259
-
-
GitLab Release Tools Bot создал
Return NO_ACCESS if user is nil See merge request gitlab/gitlabhq!3388
-
Patrick Derichs создал
-
- 27.08.2019 3 коммита
-
-
GitLab Release Tools Bot создал
-
-
GitLab Release Tools Bot создал
Avoid exposing unaccessible repo data upon GFM post processing See merge request gitlab/gitlabhq!3384
-
- 26.08.2019 5 коммитов
-
-
Oswaldo Ferreira создал
When post-processing relative links to absolute links RelativeLinkFilter didn't take into consideration that internal repository data could be exposed for users that do not have repository access to the project. This commit solves that by checking whether the user can `download_code` at this repository, avoiding any processing of this filter if the user can't. Additionally, if we're processing for a group ( no project was given), we check if the user can read it in order to expand the href as an extra. That doesn't seem necessarily a breach now, but an extra check doesn't hurt as after all the user needs to be able to `read_group`.
-
GitLab Release Tools Bot создал
Prevent disclosure of merge request id via email See merge request gitlab/gitlabhq!3352
-
GitLab Release Tools Bot создал
Send TODOs for comments on commits correctly See merge request gitlab/gitlabhq!3367
-
GitLab Release Tools Bot создал
Require a captcha after unique failed logins from the same IP See merge request gitlab/gitlabhq!3296
-
Małgorzata Ksionek создал
Add method to store session ids by ip Add new specs for storing session ids Add cleaning up records after login Add retrieving anonymous sessions Add login recaptcha setting Add new setting to sessions controller Add conditions for showing captcha Add sessions controller specs Add admin settings specs for login protection Add new settings to api Add stub to devise spec Add new translation key Add cr remarks Rename class call Add cr remarks Change if-clause for consistency Add cr remarks Add code review remarks Refactor AnonymousSession class Add changelog entry Move AnonymousSession class to lib Move store unauthenticated sessions to sessions controller Move link to recaptcha info Regenerate text file Improve copy on the spam page Change action filter for storing anonymous sessions Fix rubocop offences Add code review remarks Fix specs Update schema version
-