458 Commits (hometown-dev)

Author SHA1 Message Date
Misty De Méo a0c53bc040
Bringing Hometown up to date with mastodon/mastodon (#1371) 3 weeks ago
Claire 34936ca889
Merge commit from fork 1 year ago
Claire a5641a9244 Fix incorrect rate limit on PUT requests (#31356) 2 years ago
Tim Rogers 17f69c0002 Added check for STATSD_ADDR setting to emit a warning and proceed rather than crashing if the address is unreachable (#30691) 2 years ago
Claire 9740c7eaea Fix rate-limiting incorrectly triggering a session cookie on most endpoints (#30483) 2 years ago
Claire 8ab0ca7d64
Merge pull request from GHSA-c2r5-cfqr-c553 2 years ago
Claire 7920aa59e8
Merge pull request from GHSA-q3rg-xx5v-4mxh 2 years ago
Emelia Smith 186f916192 Fix: remove broken OAuth Application vacuuming & throttle OAuth Application registrations (#30316) 2 years ago
Tim Rogers e69780ec59 Fixed crash when supplying FFMPEG_BINARY environment variable (#30022) 2 years ago
Misty De Méo 3c9599f19a
Upstream backports (#1343) 2 years ago
Emelia Smith 6d43b63275 Disable administrative doorkeeper routes (#29187) 2 years ago
nachtjasmin 4c01f78480
Automatic rubocop fixing 2 years ago
Claire ef149674f0 Change Content-Security-Policy to be tighter on media paths (#26889) 2 years ago
Claire 8acc75435b
Change S3 checksum mode to be disabled by default (#27007) 3 years ago
Jasmin 3b69a29703
Merge changes of 4.0.7..4.0.10 (#1324) 3 years ago
Claire a04ae16201
Fix CSP when using `ONE_CLICK_SSO_LOGIN` (#26901) 3 years ago
CSDUMMI 9a70cac9de
Fix #26849 by adding the domain of the current SSO provider to the form-action CSP (#26857) 3 years ago
Christian Schmidt ea31929776
Fix invalid Content-Type header for WebP images (#26773) 3 years ago
Claire 9e26cd5503
Add `authorized_fetch` server setting in addition to env var (#25798) 3 years ago
Christian Schmidt 286a21afdc
Support webpacker live-reloading on Docker (#26419) 3 years ago
Renaud Chaput b95867ad1f
Allow setting a custom HTTP method in CacheBuster (#26528) 3 years ago
Claire dd049fc37a
Fix ES_PRESET not being applied to Chewy's internal index (#26489) 3 years ago
Claire f5778caa3a
Add `ES_PRESET` option to customize numbers of shards and replicas (#26483) 3 years ago
Claire 4bc0dd751c
Add `S3_DISABLE_CHECKSUM_MODE` environment variable for compatibility with some S3-compatible providers (#26435) 3 years ago
Claire 12c43e4ab5
Re-add StatsD support through the `nsa` gem (#26310) 3 years ago
Emelia Smith e258b4cb64
Refactor: replace whitelist_mode mentions with limited_federation_mode (#26252) 3 years ago
Matt Jankowski ad81be6c8e
Update rubocop rules for linelength (#26190) 3 years ago
Matt Jankowski bada7a65aa
Ignore long line in regex initializer (#26182) 3 years ago
Claire 889102013f Fix CSP headers being unintendedly wide (#26105) 3 years ago
Claire c46aa2348e Add check preventing Sidekiq workers from running with Makara configured (#25850) 3 years ago
Claire fc4a93b937 Fix CSP headers being unintendedly wide (#26105) 3 years ago
Claire 69c8f26946
Add check preventing Sidekiq workers from running with Makara configured (#25850) 3 years ago
Claire e5f1000ad1
Fix CSP headers being unintendedly wide (#26105) 3 years ago
Claire 934c7b33d1
Change default KeyGenerator digest to SHA1 to fix cookies in rolling upgrades (#26023) 3 years ago
Misty De Méo b848ba3867
Paperclip: add support for Azure blob storage (#23607) 3 years ago
Matt Jankowski ce43ed144c
Rails 7.0 update (#25668) 3 years ago
Matt Jankowski 2e1391fdd2
Fix `Naming/MemoizedInstanceVariableName` cop (#25928) 3 years ago
Nick Schonning 1d557305d2
Enable Rubocop Style/FrozenStringLiteralComment (#23793) 3 years ago
Kurtis Rainbolt-Greene e4cfe4b3db
First pass at multi-database for read replica using Rails native adapter (#25693) 3 years ago
Jasmin 0728a6a709
Merge upstream security fixes of v4.0.5 (#1316) 3 years ago
Claire 2119aadf0a
Merge pull request from GHSA-9928-3cp5-93fm 3 years ago
Claire 0aa0b71f2c
Merge pull request from GHSA-9928-3cp5-93fm 3 years ago
Claire dc8f1fbd97
Merge pull request from GHSA-9928-3cp5-93fm 3 years ago
Renaud Chaput 94c67e8bfd Allow carets in URL search params (#25216) 3 years ago
Claire 41a0a3c87f Fix CSP headers when S3_ALIAS_HOST includes a path component (#25273) 3 years ago
Renaud Chaput 8eb1bb8ba6 Allow carets in URL search params (#25216) 3 years ago
Claire a197fc094f Fix CSP headers when S3_ALIAS_HOST includes a path component (#25273) 3 years ago
Eugen Rochko ba06a2f104
Revert "Rails 7 update" (#25667) 3 years ago
Matt Jankowski 50c2a03695
Rails 7 update (#24241) 3 years ago
Claire f378f10404
Fix compatibility of recent migration with PostgreSQL 10 (#25324) 3 years ago