summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
* Update VERSION to 12.2.7v12.2.7GitLab Release Tools Bot2019-10-011-1/+1
|
* Update CHANGELOG.md for 12.2.7GitLab Release Tools Bot2019-10-012-5/+7
| | | [ci skip]
* Merge branch 'security-29491-12-2-ce' into '12-2-stable'Marin Jankovski2019-10-017-2/+210
|\ | | | | | | | | Fix private feature Elasticsearch leak See merge request gitlab/gitlabhq!3451
| * EE port: Fix private feature Elasticsearch leakMark Chao2019-10-017-2/+210
|/ | | | | | Add spec to test different combinations. Accept string for required_minimum_access_level Allow more flexible project membership query
* Merge branch 'fix_expired_gpg_key_specs' into 'master'Stan Hu2019-09-302-151/+270
| | | | | | | Fix broken specs : Generate new GPG key in place of expired one Closes #32956 See merge request gitlab-org/gitlab!17853
* Update VERSION to 12.2.6v12.2.6GitLab Release Tools Bot2019-09-261-1/+1
|
* Update CHANGELOG.md for 12.2.6GitLab Release Tools Bot2019-09-2611-53/+16
| | | [ci skip]
* Merge branch 'security-gitaly-1-59-3' into '12-2-stable'GitLab Release Tools Bot2019-09-262-1/+6
|\ | | | | | | | | Fix Gitaly SearchBlobs flag RPC injection [Gitaly v1.59.3] See merge request gitlab/gitlabhq!3434
| * Fix Gitaly SearchBlobs flag RPC injectionPaul Okstad2019-09-242-1/+6
| |
* | Merge branch 'security-sarcila-verify-saml-request-origin-12-2' into ↵GitLab Release Tools Bot2019-09-2612-40/+303
|\ \ | | | | | | | | | | | | | | | | | | '12-2-stable' Check that SAML identity linking validates the origin of the request See merge request gitlab/gitlabhq!3377
| * | Validate that SAML requests are originated from gitlabSebastian Arcila Valenzuela2019-09-1612-40/+303
| | | | | | | | | | | | | | | | | | | | | | | | If the request wasn't initiated by gitlab we shouldn't add the new identity to the user, and instead show that we weren't able to link the identity to the user. This should fix: https://gitlab.com/gitlab-org/gitlab-ce/issues/56509
* | | Merge branch ↵GitLab Release Tools Bot2019-09-263-1/+47
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | 'security-12717-fix-confidential-issue-assignee-visible-to-guests-12-2' into '12-2-stable' Display only participants that user has permission to see See merge request gitlab/gitlabhq!3402
| * | | Display only participants that user has permission to seeAlexandru Croitor2019-09-203-1/+47
| |/ /
* | | Merge branch 'security-bypass-email-verification-using-salesforce-12-2' into ↵GitLab Release Tools Bot2019-09-266-24/+78
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | '12-2-stable' Prevent Bypassing Email Verification using Salesforce See merge request gitlab/gitlabhq!3406
| * | | Add checking for email_verified keyMałgorzata Ksionek2019-09-116-24/+78
| |/ / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fix rubocop offences and add changelog Add email_verified key for feature specs Add code review remarks Add code review remarks Fix specs
* | | Merge branch 'security-mermaid-block-12-2' into '12-2-stable'GitLab Release Tools Bot2019-09-263-1/+48
|\ \ \ | | | | | | | | | | | | | | | | Only render fixed number of mermaid blocks See merge request gitlab/gitlabhq!3412
| * | | Only render fixed number of mermaid blocksRajat Jain2019-09-193-1/+48
| |/ /
* | | Merge branch ↵GitLab Release Tools Bot2019-09-264-6/+115
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | 'security-12718-project-milestones-disclosed-via-groups-12-2-ce' into '12-2-stable' Hide disabled project milestones in project settings on group level See merge request gitlab/gitlabhq!3415
| * | | Hide disabled project milestones in project settings on group levelAlexandru Croitor2019-09-264-6/+115
| | |/ | |/|
* | | Merge branch 'security-64938-dont-disclose-path-12-2-ce' into '12-2-stable'GitLab Release Tools Bot2019-09-263-1/+40
|\ \ \ | | | | | | | | | | | | | | | | Redirect user to root path after unsubscribing from private resource See merge request gitlab/gitlabhq!3417
| * | | Redirect user to root path after unsubscribing from private resourceAlexandru Croitor2019-09-203-1/+40
| | |/ | |/| | | | | | | | | | | | | | | | | | | If user unsubsrcribes from a resource that they no longer have access to they should not be revealed the resource path, but be redirected to app root instead. https://gitlab.com/gitlab-org/gitlab-ce/issues/64938
* | | Merge branch ↵GitLab Release Tools Bot2019-09-265-0/+178
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | 'security-12630-private-system-note-disclosed-in-graphql-12-2-ce' into '12-2-stable' Add policy check if cross reference system notes are accessible See merge request gitlab/gitlabhq!3427
| * | | Add policy check if cross reference system notes are accessibleAlexandru Croitor2019-09-255-0/+178
| | |/ | |/|
* | | Merge branch 'security-fp-stop-jobs-when-blocking-user-12-2' into '12-2-stable'GitLab Release Tools Bot2019-09-265-1/+68
|\ \ \ | | | | | | | | | | | | | | | | Cancel all running CI jobs when user is blocked See merge request gitlab/gitlabhq!3437
| * | | Cancel all running CI jobs when user is blockedFabio Pitino2019-09-245-1/+68
| | |/ | |/| | | | | | | | | | | | | This prevents a MITM attack where attacker could still access Git repository if any jobs were running long enough.
* | | Merge branch 'security-cross-reference-fix-ce-12-2' into '12-2-stable'GitLab Release Tools Bot2019-09-269-33/+283
|\ \ \ | |_|/ |/| | | | | | | | Filter not accessible label events See merge request gitlab/gitlabhq!3441
| * | Filter not accessible label eventsJan Provaznik2019-09-249-33/+283
| |/ | | | | | | | | | | Label events may use cross-project or cross-group references, if the projects are not accessible by user, we don't show these label events.
* | Merge branch 'ss/fix-sast-failure-on-master-ee' into 'master'Kushal Pandya2019-09-241-1/+1
|/ | | | | Add argument to catch See merge request gitlab-org/gitlab-ee!15911
* Merge remote-tracking branch 'dev/12-2-stable' into 12-2-stableGitLab Release Tools Bot2019-09-113-2/+9
|\
| * Update VERSION to 12.2.5v12.2.5GitLab Release Tools Bot2019-09-101-1/+1
| |
| * Update CHANGELOG.md for 12.2.5GitLab Release Tools Bot2019-09-102-5/+7
| | | | | | [ci skip]
| * Merge branch 'security-12-2-bump-pages' into '12-2-stable'GitLab Release Tools Bot2019-09-102-1/+6
| |\ |/ / | | | | | | Set max-age and secure flag for pages auth cookies See merge request gitlab/gitlabhq!3379
| * Upgrade pages to 1.7.2Vladimir Shushlin2019-09-092-1/+6
|/
* Update VERSION to 12.2.4v12.2.4GitLab Release Tools Bot2019-09-021-1/+1
|
* Update CHANGELOG.md for 12.2.4GitLab Release Tools Bot2019-09-029-40/+17
| | | [ci skip]
* Merge branch '12-2-stable-patch-4' into '12-2-stable'John Jarvis2019-09-0245-227/+422
|\ | | | | | | | | Prepare 12.2.4 release See merge request gitlab-org/gitlab-ce!32455
| * Merge branch '66803-fix-uploads-relative-link-filter' into 'master'12-2-stable-patch-4Grzegorz Bizon2019-09-024-101/+44
| | | | | | | | | | Fix permissions check in `RelativeLinkFilter` See merge request gitlab-org/gitlab-ce!32448
| * Merge branch 'ashmckenzie/12-2-stable-patch-4-add-stub-config' into ↵John Jarvis2019-09-021-0/+4
| |\ | | | | | | | | | | | | | | | | | | '12-2-stable-patch-4' Add StubConfiguration.stub_config method See merge request gitlab-org/gitlab-ce!32530
| | * Add StubConfiguration.stub_config methodAsh McKenzie2019-09-021-0/+4
| |/
| * Merge branch 'sh-mermaid-8.2.6' into 'master'Filipa Lacerda2019-09-023-5/+10
| | | | | | | | | | Update Mermaid to v8.2.6 See merge request gitlab-org/gitlab-ce!32502
| * Merge branch 'revert-79fa2cd9' into 'master'Evan Read2019-08-301-5/+5
| | | | | | | | | | | | | | | | | | | | | | Revert "Merge branch 'nik-api-snippets-fix' into 'master'" Closes #66673 See merge request gitlab-org/gitlab-ce!32295 (cherry picked from commit 98f2ab296a9b53b7e6fe467b50a9bcf9b75c6957) 5e0378b3 Revert "Merge branch 'nik-api-snippets-fix' into 'master'"
| * Merge branch 'sh-fix-snippet-visibility-api' into 'master'Rémy Coutable2019-08-309-25/+108
| | | | | | | | | | | | | | | | | | | | | | Fix snippets API not working with visibility level Closes #66050 See merge request gitlab-org/gitlab-ce!32286 (cherry picked from commit 1843502ff4d9841f9abf635ffb57d72068ec90c9) 680f4377 Fix snippets API not working with visibility level
| * Merge branch 'sh-fix-piwik-template' into 'master'Ash McKenzie2019-08-303-2/+27
| | | | | | | | | | | | | | | | | | | | | | Fix Piwik not working Closes #66627 See merge request gitlab-org/gitlab-ce!32234 (cherry picked from commit 0c639b2463a4d70bb275e4f139a88594e674a240) f6058981 Fix Piwik not working
| * Merge branch 'sh-upgrade-mermaid-8.2.4' into 'master'Filipa Lacerda2019-08-304-63/+12
| | | | | | | | | | | | | | | | | | Upgrade Mermaid to v8.2.4 See merge request gitlab-org/gitlab-ce!32186 (cherry picked from commit f90759bbf31853e0e69db98588f2416cdef6e2f6) c2541b64 Upgrade Mermaid to v8.2.4
| * Merge branch 'fix-migration-helper' into 'master'Stan Hu2019-08-304-3/+148
| | | | | | | | | | | | | | | | | | | | | | Add helpers to exactly undo cleanup_concurrent_column_rename See merge request gitlab-org/gitlab-ce!32183 (cherry picked from commit fc08d48cf0a596dc151cb7bc7ab0f7d2721f3333) 9b592a59 Add helper to exactly undo cleanup_concurrent_column_rename 61777843 Add spec for undo_rename_column_concurrently d28ad870 Add spec for when default is false
| * Merge branch 'patch-74' into 'master'Mike Greiling2019-08-302-2/+2
| | | | | | | | | | | | | | | | | | fix: remove double % See merge request gitlab-org/gitlab-ce!32178 (cherry picked from commit bf2b4c526955829e8eb99fe8557563b2cb8f775f) 22e2a601 fix: remove double % from layout width description
| * Merge branch 'sh-fix-nplusone-issues' into 'master'Mayra Cabrera2019-08-304-2/+15
| | | | | | | | | | | | | | | | | | Fix N+1 Gitaly calls in /api/v4/projects/:id/issues See merge request gitlab-org/gitlab-ce!32171 (cherry picked from commit bbd39021c39b66ecb954a7fb8276320556b65a3b) 44063501 Fix N+1 Gitaly calls in /api/v4/projects/:id/issues
| * Merge branch 'fe-fix-issuable-sidebar-icon-of-notification-disabled' into ↵Mike Greiling2019-08-303-3/+10
| | | | | | | | | | | | | | | | | | | | | | 'master' Fix issuable sidebar icon of notification disabled See merge request gitlab-org/gitlab-ce!32134 (cherry picked from commit a93612aa5fab7d70f0b6165856402ac53ab18faf) 9ad0a8ad Fix issuable sidebar icon of notification disabled
| * Merge branch '66066-dark-theme-style-for-expansion-on-mr-diffs' into 'master'Mike Greiling2019-08-309-21/+42
|/ | | | | | | | | | | Match syntax highlighting theme for line expansion rows Closes #66066 See merge request gitlab-org/gitlab-ce!31821 (cherry picked from commit 1349a3d5b3b6d6bc151429a969b4cc78fd91c355) 9013ab1f Add syntax highlighting for line expansion
* Update VERSION to 12.2.3v12.2.312-2-stable-patch-2GitLab Release Tools Bot2019-08-281-1/+1
|