Commit Graph

4704 Commits (ac9a485ca22f5df3a0f1664415ebed5b1154c469)

Author SHA1 Message Date
Unknwon ba93504804
setting: check mailService.From only if it has value (#4134) 2017-02-17 12:28:23 -05:00
Unknwon 57cb23ac81
Security: fix XSS attack on alert 2017-02-17 08:16:27 -05:00
Unknwon 5155f026b4
Security: fix XSS attack on milestone
Reported by Miguel Ángel Jimeno.
2017-02-17 08:06:48 -05:00
Unknwon d521e716dd
refactoring: SSH and HTTP push procees is now unified
We used to handle SSH and HTTP push separately which produces
duplicated code, but now with post-receive hook, the process
is unified to one single place and much cleaner.
Thus, UpdateTask struct is removed.

Narrow down the range of Git HTTP routes to reduce condufsing
HTTP Basic Authentication window popup on browser.

By detecting <old-commit, new-commit, ref-name> inside post-receive
hook, Git HTTP doesn't need to read the whole content body anymore,
which completely solve the RAM problem reported in #636.
2017-02-16 16:33:49 -05:00
Unknwon 3b49a99b60
wiki: fix crash with blob name contains tab (#3916) 2017-02-16 11:47:54 -05:00
Unknwon f129e0ecb5
repo/editor: fix breadcrumb path cuts parent dirs (#3859) 2017-02-16 08:34:49 -05:00
Unknwon 88143f1934
models/repo: UpdateLocalCopy should always aceept valid branch name 2017-02-16 06:28:37 -05:00
Unknwon 3137665e6e
Simplify description 2017-02-15 22:29:31 -05:00
Unknwon f35bd34002
models/repo: use reset --hard to align with remote branch (#4123)
If user has force pushed to a branch, git pull will fail.
2017-02-15 21:00:46 -05:00
Unknwon b9560ec9cb
vendor: update git-module (#4128) 2017-02-15 18:34:02 -05:00
Unknwon 189924cabf
repo/branch: force delete merged branch (#4128) 2017-02-15 18:24:32 -05:00
Unknwon c2277796e4
wiki: remove redundant string replace (#3754) 2017-02-15 18:18:33 -05:00
Unknwon f97b250509
Security: prevent XSS attach on wiki page
Reported by Miguel Ángel Jimeno.
2017-02-15 18:05:02 -05:00
Mourad Boufarguine 59981b8818 Enable syntax highlighting for CMakeLists.txt files #2199 (#4130) 2017-02-15 12:38:54 -05:00
Unknwon 40bce6310c
Improve error handling 2017-02-15 12:35:24 -05:00
Unknwon a4f9e5031f
migration.v15: don't generate hook file if wiki not exist (#1623) 2017-02-15 05:45:15 -05:00
Unknwon 4da325a45c
user/profile: paging doesn't respect private repository count (#4082) 2017-02-15 05:39:36 -05:00
Unknwon fd5881fb64
migration: minor code fix (#1623) 2017-02-15 05:28:05 -05:00
Unknwon 0f6e464126
migration: should regenerate wiki hook files (#1623) 2017-02-15 05:25:51 -05:00
Unknwon 6132a82287
admin: sync wiki's hook files as well 2017-02-15 05:15:39 -05:00
Unknwon 32a868d431
wiki: handle '#' in edit page (#3767) 2017-02-15 05:10:00 -05:00
Unknwon 94f91543b6
Fix compilation error 2017-02-15 04:09:07 -05:00
Unknwon 3d52ef6e39
Solve conflicts (#3837) 2017-02-15 04:01:59 -05:00
Thibault Meyer a45205b988
Commits fetch concurrency (#3837) 2017-02-15 03:59:53 -05:00
Unknwon ec9c14c09d
vendor: update dependency 2017-02-14 18:47:09 -05:00
Kim "BKC" Carlbäcker b6fc35f637 Implement list/check/delete Repo Collaborator (#3689) 2017-02-14 18:45:08 -05:00
Unknwon e24d62e583
modules/ssh: SSH_KEYGEN_PATH not used for exec ssh-keygen (#4124) 2017-02-14 18:08:26 -05:00
Unknwon 0386b5ae54
cmd/hook: check existence before call custom hook 2017-02-14 18:06:54 -05:00
Unknwon a0253cab62
vendor: update git-module 2017-02-14 17:21:55 -05:00
Unknwon 0f32aeec70
migration: adjust rule to prevent migrate wrong hook file 2017-02-14 16:50:16 -05:00
Unknwon 78145cd166
migration: handle edge case 2017-02-14 16:40:49 -05:00
Unknwon 904f0ebec3
migration: add trace log 2017-02-14 16:30:49 -05:00
Unknwon 039dc33367
git: delegate all server-side Git hooks (#1623) 2017-02-14 16:22:16 -05:00
Christian Höppner 859009259a Typo in LocalCopyPath (#4122)
This won't fix any bugs, but a typo is a typo.
2017-02-14 07:39:55 -05:00
Unknwon 4c5255f5ad
cookie: enhance cookie security (#3525) 2017-02-14 03:52:20 -05:00
Unknwon 279e475b89
webhook: match email with real user in database for test delivery (#3652) 2017-02-14 03:32:13 -05:00
Unknwon f4aedda13a
org/team: make 'new' as reserved for team name (#3789) 2017-02-14 03:16:02 -05:00
Unknwon 1381f0f28e
vendor: check in missing dependency 2017-02-13 20:58:53 -05:00
Unknwon f967e9d021
vendor: add new dependency (#3772) 2017-02-13 20:52:35 -05:00
dlob 5179063e71 Added mssql support. (#3772) 2017-02-13 20:50:00 -05:00
Unknwon ad4bbf5173
Update new logo
[CI SKIP]
2017-02-13 19:11:31 -05:00
Egon Elbre 35f30a306b Icon redesign. (#4121) 2017-02-13 18:20:30 -05:00
Unknwon c37d3f6486
vendor: remove unnecessary sublime files 2017-02-13 14:09:08 -05:00
Unknwon bd786b8ef0
auth: remove MD5 for secure cookie secret (#4117)
Update vendor accordingly
2017-02-13 14:05:49 -05:00
Unknwon d02e7d9e6a
install: no need to check SMTPFrom is not set (#4118) 2017-02-13 04:20:03 -05:00
Unknwon 1c87b082c1
api/issue: minor code refactor (#3688) 2017-02-12 19:46:38 -05:00
Kim "BKC" Carlbäcker 99d86c7175 Implement more issue-endpoints (#3688) 2017-02-12 19:42:28 -05:00
Aaron Wood 68ead67a63 Use very strong ciphers (#4116)
* Use very strong ciphers

* Remove TLS_RSA_WITH_AES_256_GCM_SHA384 to be compatible with Go 1.5
2017-02-12 19:12:07 -05:00
Unknwon 2d38b75400
diff: fix can't show compare page for fork repository (#4110) 2017-02-12 18:43:26 -05:00
Unknwon f59a607361
install: allow sender's username to be non-email (#3717) 2017-02-12 18:35:25 -05:00