Commit graph

2580 commits

Author SHA1 Message Date
kaniini
8cc08b94ec Merge branch 'security/add-security-directives-to-systemd-example' into 'develop'
Add some security directives to the systemd example file

See merge request pleroma/pleroma!386
2018-10-25 00:15:29 +00:00
shibayashi
043cb7138e
Add a little bit more detail in the comments. 2018-10-25 00:57:47 +02:00
shibayashi
0a58428de6
Add some security related directives to the systemd service example 2018-10-25 00:37:31 +02:00
scarlett
7cb227dc62 update pleroma-fe 2018-10-23 12:16:49 +01:00
scarlett
f6dda65dda update pleroma-fe 2018-10-23 12:15:48 +01:00
kaniini
945ce9910d Merge branch 'bugfix/html-scrub-comments' into 'develop'
html: ensure comments are correctly scrubbed

See merge request pleroma/pleroma!384
2018-10-23 00:56:09 +00:00
kaniini
bcae57afd2 Merge branch 'new-frontend-options' into 'develop'
New frontend options

See merge request pleroma/pleroma!383
2018-10-23 00:50:28 +00:00
William Pitcock
8613db0e3b html: ensure comments are correctly scrubbed 2018-10-23 00:48:49 +00:00
scarlett
3e79d941c8 Defaults for new frontend options in config.exs 2018-10-21 12:54:37 +01:00
scarlett
a253c1466e New frontend options 2018-10-21 12:52:52 +01:00
eal
aaf3fc1575 Merge branch 'pleroma-list-belongs' into 'develop'
Pleroma list belongs

Closes #333

See merge request pleroma/pleroma!382
2018-10-20 10:14:08 +00:00
eal
5e9a0e2460 Fix some typos in the list test. 2018-10-20 13:03:45 +03:00
AkiraFukushima
a249cbf187 Add a test for List.get_lists_account_belongs 2018-10-19 21:24:15 +09:00
AkiraFukushima
e8c698af41 Add an endpoint /api/v1/accounts/:id/lists to get lists to which account belongs 2018-10-19 01:46:26 +09:00
kaniini
ad3181895c Merge branch 'bugfix/html-scrub-schemes' into 'develop'
lib/pleroma/html.ex: Fix scheme lists

See merge request pleroma/pleroma!377
2018-10-18 14:36:40 +00:00
William Pitcock
595d855f0e html scrubbing policies: restrict img tags to http/https only for mediaproxy compatibility 2018-10-18 14:29:31 +00:00
Haelwenn (lanodan) Monnier
2154c5dcd8
lib/pleroma/html.ex: Use macros for valid_schemes, change config for schemes 2018-10-18 07:58:15 +02:00
kaniini
6098070234 Merge branch 'bugfix/osada-mention' into 'develop'
fix osada mentions

Closes #324

See merge request pleroma/pleroma!380
2018-10-17 19:33:15 +00:00
William Pitcock
958c5e02e8 tests: add a testcase for matching osada users in the formatter 2018-10-17 19:27:05 +00:00
William Pitcock
582dbe5c8d formatter: fix matching osada users 2018-10-17 19:15:20 +00:00
Haelwenn
c7140c67c7 Merge branch 'import-maybe-direct-follow' into 'develop'
Use maybe_direct_follow for follow imports

See merge request pleroma/pleroma!378
2018-10-17 04:24:13 +00:00
scarlett
7562912f6a Use maybe_direct_follow for follow imports 2018-10-17 04:16:11 +01:00
Haelwenn (lanodan) Monnier
d7654c77de
lib/pleroma/html.ex: Use a function as a variable (broken for some reason) 2018-10-16 03:34:33 +02:00
Haelwenn (lanodan) Monnier
50e0a9ae56
lib/pleroma/html.ex: Fix scheme lists
Gosh please don’t break ourselves…

Also this is copy-paste of the list in lib/pleroma/formatter.ex,
I think this should be put in a common variable, but where?
2018-10-16 03:00:37 +02:00
kaniini
c93571b87e Merge branch 'feature/markdown-enable-tags' into 'develop'
common api: enable tag linking in markdown mode

Closes #322

See merge request pleroma/pleroma!376
2018-10-14 20:42:23 +00:00
William Pitcock
30efa86c05 common api: enable tag linking in markdown mode 2018-10-14 20:36:11 +00:00
kaniini
e0c035589a Merge branch 'security/clear-oauth-with-password' into 'develop'
Delete Tokens and Authorizations on password change

Closes #320

See merge request pleroma/pleroma!375
2018-10-14 19:29:58 +00:00
Haelwenn (lanodan) Monnier
eacab0fb05
Delete Tokens and Authorizations on password change
Closes: https://git.pleroma.social/pleroma/pleroma/issues/320
2018-10-14 02:14:54 +02:00
kaniini
117e005409 Merge branch 'security/fix-local-locked-accounts' into 'develop'
security: fix local locked accounts

Closes #316

See merge request pleroma/pleroma!372
2018-10-11 10:56:12 +00:00
William Pitcock
51eaece3ea user: break out local cases for maybe_direct_follow 2018-10-11 10:49:54 +00:00
William Pitcock
ebc32045f0 test: add regression test for #316 2018-10-11 10:35:32 +00:00
William Pitcock
2c29329d39 user: local users are always AP-enabled (closes #316) 2018-10-11 10:35:11 +00:00
kaniini
3a77336d89 Merge branch 'bugfix/length-enforce-subjects' into 'develop'
common api: take the combination of the subject and content for length limit enforcement

Closes #315

See merge request pleroma/pleroma!371
2018-10-10 08:00:23 +00:00
William Pitcock
111841ad34 common api: take the combination of the subject and content for length limit enforcement
closes #315
2018-10-10 07:53:44 +00:00
Haelwenn
5294b11ef0 Merge branch 'feature/mrf-transparency-opt-out' into 'develop'
nodeinfo: allow opting out of MRF transparency

See merge request pleroma/pleroma!370
2018-10-07 01:34:16 +00:00
William Pitcock
08d5ad71b6 nodeinfo: allow opting out of MRF transparency 2018-10-07 01:23:38 +00:00
kaniini
4a3a46074d Merge branch 'security/follow-always-async' into 'develop'
AP follows must be always async (closes #306)

Closes #306

See merge request pleroma/pleroma!368
2018-10-07 01:16:05 +00:00
kaniini
b638cc50b6 Merge branch 'patch-2' into 'develop'
Relax form-action content security policy in sample nginx config

See merge request pleroma/pleroma!364
2018-10-07 01:10:12 +00:00
kaniini
a15eac05a6 Merge branch 'update-pleroma-frontend' into 'develop'
update-pleroma-frontend

See merge request pleroma/pleroma!369
2018-10-07 01:09:33 +00:00
William Pitcock
7b3fff9af8 {mastodon api, twitter api}: make the follow handshake timeout configurable 2018-10-07 01:05:59 +00:00
hakabahitoyo
be7bb90bef update-pleroma-frontend 2018-10-07 09:58:08 +09:00
William Pitcock
7f530f6f80 mastodon api: relationship view: better handle no pre-existing follow activity 2018-10-05 23:50:13 +00:00
William Pitcock
e69faf550c user: add wait_and_refresh() for async three-way handshake case 2018-10-05 23:40:49 +00:00
William Pitcock
3e751496e3 mastodon api: account view: fetch follow state and use it to populate requested field 2018-10-05 23:31:49 +00:00
William Pitcock
a71b822013 activitypub: always track following state for async reasons 2018-10-05 23:31:00 +00:00
William Pitcock
8ce217776d activitypub transmogrifier: better manage follow state 2018-10-05 23:30:34 +00:00
William Pitcock
4f7a468659 user: only pre-create follow relationships on OStatus
closes #306
2018-10-05 22:58:03 +00:00
kaniini
614e47aa7c Merge branch 'revert-d31bbb1c' into 'develop'
Rich Text Redo Branch

See merge request pleroma/pleroma!314
2018-10-05 21:17:46 +00:00
William Pitcock
497814cbbb test: update test for new html scrub policy 2018-10-05 21:11:22 +00:00
William Pitcock
bd76d9cee6 nodeinfo: add accepted post formats to metadata 2018-10-05 21:05:37 +00:00