Commit graph

20167 commits

Author SHA1 Message Date
KMY
2927cbd153 Bump version to 12.3 2024-07-05 07:11:24 +09:00
Claire
ff8058642c Bump version to v4.3.0-alpha.5 (#30920) 2024-07-05 07:10:57 +09:00
Claire
e4784b4f69 Merge pull request from GHSA-xjvf-fm67-4qc3 2024-07-05 07:10:48 +09:00
Claire
21b716db12 Merge pull request from GHSA-58x8-3qxw-6hm7
* Fix insufficient permission checking for public timeline endpoints

Note that this changes unauthenticated access failure code from 401 to 422

* Add more tests for public timelines

* Require user token in `/api/v1/statuses/:id/translate` and `/api/v1/scheduled_statuses`
2024-07-05 07:10:33 +09:00
Claire
ca1e2e6131 Merge pull request from GHSA-vp5r-5pgw-jwqx
* Fix streaming sessions not being closed when revoking access to an app

* Add tests for GHSA-7w3c-p9j8-mq3x
2024-07-05 07:07:56 +09:00
Daniel M Brasil
e29c435011 fix: Return HTTP 422 when scheduled status time is less than 5 minutes (#30584) 2024-07-05 07:05:03 +09:00
David Roetzel
650875a820 Improve encoding detection for link cards (#30780) 2024-07-05 07:04:42 +09:00
Eugen Rochko
f60b7fe905 Change search modifiers to be case-insensitive (#30865) 2024-07-05 07:04:20 +09:00
KMY
0370a72dbd Add size limit for link preview URLs (#30854) 2024-07-05 07:03:49 +09:00
Tim Rogers
e53f6a50d2 Added check for STATSD_ADDR setting to emit a warning and proceed rather than crashing if the address is unreachable (#30691) 2024-07-05 07:02:11 +09:00
renovate[bot]
98f36f7fd7 chore(deps): update dependency charlock_holmes to v0.7.8 (#30870)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2024-07-05 07:01:34 +09:00
KMY
f3ac508cf7 Fix /admin/accounts/:account_id/statuses/:id for edited posts with media attachments (#30819) 2024-07-05 06:56:14 +09:00
Claire
ae7ec2bbd9 Update dependency rails 2024-07-05 06:52:16 +09:00
Claire
1e2f401c98 Fix duplicate @context attribute in user export (#30653) 2024-07-05 06:44:41 +09:00
KMY(雪あすか)
3c08e48a70
Merge pull request #754 from kmycode/kbtopic-fix-emoji-reaction-rack-attack-for-12
Release: 12.2
2024-06-03 07:46:13 +09:00
KMY
58040c5aa7 Bump version to 12.2 2024-06-02 11:21:08 +09:00
KMY
0bd26af2dd Fix: 絵文字リアクションに厳しいレートリミットが適用される問題 2024-06-02 11:19:00 +09:00
KMY(雪あすか)
652d037440
Merge pull request #750 from kmycode/kb-draft-12.1
Release: 12.1
2024-05-31 08:39:15 +09:00
KMY
7615e12e88 Fix test 2024-05-31 08:11:57 +09:00
KMY
35bd3ea5b7 Fix dicker-compose 2024-05-31 08:08:12 +09:00
KMY
28b74eabac Bump version to 12.1 2024-05-30 23:36:44 +09:00
Claire
d65f8a1196 Bump version to v4.3.0-alpha.4 (#30482) 2024-05-30 23:36:33 +09:00
Claire
2a05566c5c Fix rate-limiting incorrectly triggering a session cookie on most endpoints (#30483) 2024-05-30 23:35:24 +09:00
Claire
b75b26bab4 Merge pull request from GHSA-c2r5-cfqr-c553
* Add hardening monkey-patch to prevent IP spoofing on misconfigured installations

* Remove rack-attack safelist
2024-05-30 23:35:17 +09:00
Claire
993bae2850 Merge pull request from GHSA-q3rg-xx5v-4mxh 2024-05-30 23:35:11 +09:00
Claire
4bfcf0d3f0 Merge pull request from GHSA-5fq7-3p3j-9vrf 2024-05-30 23:35:03 +09:00
Emelia Smith
8e788e260e Fix: remove broken OAuth Application vacuuming & throttle OAuth Application registrations (#30316)
Co-authored-by: Claire <claire.github-309c@sitedethib.com>
2024-05-30 23:34:50 +09:00
KMY
5ba5aa5c5c Normalize language code of incoming posts (#30403) 2024-05-30 23:33:59 +09:00
Claire
3807dd2352 Fix leaking Elasticsearch connections in Sidekiq processes (#30450) 2024-05-30 23:31:18 +09:00
Claire
2432d870f5 Update dependency rexml to 3.2.8 2024-05-30 23:29:59 +09:00
KMY(雪あすか)
420316fa1a
Merge pull request #732 from kmycode/kb-draft-12.0
Release: 12.0
2024-05-08 06:53:08 +09:00
KMY
1e25b59ed8 Merge branch 'kb_development' into kb-draft-12.0 2024-04-27 09:01:28 +09:00
KMY(雪あすか)
06917cbe83
Merge pull request #736 from kmycode/upstream-20240427
Upstream 20240427
2024-04-27 09:00:54 +09:00
KMY
ec7b51504b Merge remote-tracking branch 'parent/main' into kb_development 2024-04-27 08:42:37 +09:00
Renaud Chaput
65093c619f
Fix marker thunks to not ignore eslint directives for the whole file (#30089) 2024-04-26 17:11:27 +00:00
Claire
de4a7bf531
Change moderation warning notification icon (#30081) 2024-04-26 15:33:15 +00:00
renovate[bot]
0cf6cf457d
Update dependency selenium-webdriver to v4.20.1 (#30060)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2024-04-26 15:32:48 +00:00
renovate[bot]
17e0a31fe3
Update dependency cssnano to v7 (#30061)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2024-04-26 15:32:38 +00:00
Michael Stanclift
bb8c6346fb
Reword and rearrange Content Retention page (#27733) 2024-04-26 15:17:41 +00:00
Matt Jankowski
b67b61b963
Ignore dotenv *.local files (#29932) 2024-04-26 14:50:39 +00:00
renovate[bot]
ac82f34f7d
Update dependency pino to v9 (#30057)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2024-04-26 14:49:54 +00:00
Claire
91ca90e25b
Fix Idempotency-Key ignored when scheduling a post (#30084) 2024-04-26 13:19:02 +00:00
Claire
e845594878
Fix moderator account being exposed in account moderation notification (#30082) 2024-04-26 12:42:06 +00:00
github-actions[bot]
5201882a23
New Crowdin Translations (automated) (#30077)
Co-authored-by: GitHub Actions <noreply@github.com>
2024-04-26 10:05:18 +00:00
KMY(雪あすか)
801d3bcf3a
Fix: モデレーターが投稿を編集するとき、編集したアカウントを保存する処理においてkmy.blueサーバー向け個別設定を削除 (#735) 2024-04-26 12:43:21 +09:00
KMY(雪あすか)
081a9f5e18
Merge pull request #734 from kmycode/upstream-20240426
Upstream 20240426
2024-04-26 12:39:39 +09:00
KMY
c4017eb993 Merge remote-tracking branch 'parent/main' into upstream-20240426 2024-04-26 09:16:08 +09:00
Claire
4ef0b48b95
Add in-app notifications for moderation actions/warnings (#30065) 2024-04-25 17:26:05 +00:00
Eugen Rochko
0ec061aa8f
Change design of people tab on explore in web UI (#30059) 2024-04-25 16:25:33 +00:00
KMY(雪あすか)
d1d68e85f2
Merge pull request #731 from kmycode/upstream-20240425
Upstream 20240425
2024-04-25 18:47:38 +09:00