summaryrefslogtreecommitdiff
path: root/app
Commit message (Expand)AuthorAgeFilesLines
* Merge branch 'if-53347_fix_impersonation_tokens' into 'master'Stan Hu2018-11-305-17/+23
* Merge branch 'security-fix-uri-xss-applications-11-4' into 'security-11-4'Steve Azzopardi2018-11-261-1/+1
|\
| * Resolve reflected XSS in Ouath authorize windowJames Lopez2018-11-261-1/+1
* | Merge branch 'security-email-change-notification-11-4' into 'security-11-4'Steve Azzopardi2018-11-262-0/+22
|\ \ | |/ |/|
| * Provide email notification on email updatesJames Lopez2018-11-122-0/+22
* | [11.4] Fixed ability to comment on and edit/delete comments on locked or conf...Chantal Rollison2018-11-267-2/+23
* | Merge branch 'security-fix-pat-web-access-11-4' into 'security-11-4'Steve Azzopardi2018-11-2611-26/+52
|\ \
| * | Update code to use API scope on PAT authJames Lopez2018-11-2311-26/+52
* | | Merge branch 'security-11-4-xss-in-markdown-following-unrecognized-html-eleme...Steve Azzopardi2018-11-231-1/+1
|\ \ \
| * | | Sanitize output of SpacedLinkFilterBrett Walker2018-11-161-1/+1
* | | | Merge branch 'security-mermaid-xss-11-4' into 'security-11-4'Steve Azzopardi2018-11-231-0/+3
|\ \ \ \
| * | | | Configure mermaid to not render HTML content in diagramsWinnie Hellmann2018-11-141-0/+3
| |/ / /
* | | | Merge branch 'security-bvl-exposure-in-commits-list-11-4' into 'security-11-4'Steve Azzopardi2018-11-231-53/+41
|\ \ \ \
| * | | | Don't use fragment cache on commit pageBob Van Landuyt2018-11-191-53/+41
| | |/ / | |/| |
* | | | Merge branch 'security-issue_51301-11-4' into 'security-11-4'Steve Azzopardi2018-11-233-6/+32
|\ \ \ \
| * | | | Fix milestone promotion authorizationFelipe Artur2018-11-143-6/+32
| | |_|/ | |/| |
* | | | Merge branch 'security-2736-prometheus-ssrf-11-4' into 'security-11-4'Steve Azzopardi2018-11-231-1/+1
|\ \ \ \
| * | | | No redirects in prometheus servicerpereira22018-11-141-1/+1
| | |_|/ | |/| |
* | | | Merge branch 'security-private-group-11-4' into 'security-11-4'Steve Azzopardi2018-11-231-0/+10
|\ \ \ \ | |_|_|/ |/| | |
| * | | Fixed read name of private groupsChantal Rollison2018-11-071-0/+10
| | |/ | |/|
* | | Merge branch 'security-11-4-2717-xss-username-autocomplete' into 'security-11-4'Steve Azzopardi2018-11-181-4/+11
|\ \ \ | |_|/ |/| |
| * | Fix user name autocomplete XSS when name contains HTMLKushal Pandya2018-11-121-4/+11
| |/
| * Fix token lookup for Git over HTTP operations and registryImre Farkas2018-10-262-2/+2
| * Merge branch 'security-11-4-2717-fix-issue-title-xss' into 'security-11-4'Jan Provaznik2018-10-241-5/+6
| |\
| | * Escape issue title while template rendering to prevent XSSKushal Pandya2018-10-241-5/+6
| * | Merge branch 'security-redact-links-11-4' into 'security-11-4'Jan Provaznik2018-10-244-0/+42
| |\ \
| | * | Redact unsubscribe links in issuable textsJan Provaznik2018-10-234-0/+42
| | |/
| * | Fix content caching for non auth usersJames Lopez2018-10-231-0/+9
| |/
| * [11.4] Persist only SHA digest of PersonalAccessToken#tokenImre Farkas2018-10-236-46/+178
| * Fix XSS in MR source branch namePaul Slaughter2018-10-121-9/+3
* | Fix stage dropdown rendering only in EnglishFilipa Lacerda2018-11-024-6/+4
* | Remove duplicate escape in job sidebarFilipa Lacerda2018-11-021-2/+1
* | Merge branch '53070-fix-usage-ping-link' into 'master'Stan Hu2018-10-311-1/+1
* | Merge branch 'mr-file-tree-inline-fluid-width-fix' into 'master'Filipa Lacerda2018-10-311-1/+1
* | Merge branch 'fix_pat_auth-11-4' into 'security-11-4'Robert Speicher2018-10-262-2/+2
* | Merge branch 'security-11-4-2717-fix-issue-title-xss' into 'security-11-4'Jan Provaznik2018-10-241-5/+6
* | Merge branch 'security-redact-links-11-4' into 'security-11-4'Jan Provaznik2018-10-244-0/+42
* | Merge branch 'security-fix/control-headers-11-4' into 'security-11-4'Jan Provaznik2018-10-241-0/+9
* | Merge branch 'security-if-51113-hash_tokens-11-4' into 'security-11-4'Jan Provaznik2018-10-246-46/+178
* | Merge branch 'security-11-4-51527-xss-in-mr-source-branch' into 'security-11-4'Thiago Presa2018-10-221-9/+3
* | Merge branch 'ml-qa-code-owners' into 'master'Rémy Coutable2018-10-181-1/+1
* | Merge branch '52532-unable-to-toggle-issuable-sidebar-out-of-collapsed-state'...Clement Ho2018-10-162-3/+0
* | Merge branch '52669-fixes-quick-actions-preview' into 'master'Douglas Barbosa Alexandre2018-10-162-2/+2
* | Merge branch '52564-personal-projects-pagination-in-profile-overview-tab-is-b...Phil Hughes2018-10-164-13/+38
* | Merge branch '52614-bugs-on-deployment-status-in-job-log-page' into 'master'Grzegorz Bizon2018-10-161-1/+1
* | Fixed syntax issues in specs11-4-stable-prepare-rc6Jan Provaznik2018-10-151-2/+0
* | Fixes conflicts for app/assets/javascripts/jobs/components/stages_dropdown.vueFilipa Lacerda2018-10-151-39/+5
* | Fixes conflicts for app/assets/javascripts/jobs/components/sidebar.vueFilipa Lacerda2018-10-151-33/+1
* | Merge branch '52608-sidebar' into 'master'Tim Zallmann2018-10-153-4/+6
* | Merge branch '52618-incorrect-stage-being-shown-in-side-bar-of-job-view-api' ...Tim Zallmann2018-10-156-5/+78