summaryrefslogtreecommitdiff
path: root/app
Commit message (Expand)AuthorAgeFilesLines
* Add latest changes from gitlab-org/gitlab@12-4-stable-eeGitLab Bot2019-11-047-13/+21
* Merge branch 'security-mask-sentry-token-12-4-ce' into '12-4-stable'GitLab Release Tools Bot2019-10-253-4/+13
|\
| * Mask Sentry auth tokenRyan Cobb2019-10-243-4/+13
* | Merge branch 'security-remove-leaky-401-responses-12.4' into '12-4-stable'GitLab Release Tools Bot2019-10-251-2/+4
|\ \
| * | Avoid #authenticate_user! in #route_not_foundKerri Miller2019-10-221-2/+4
| |/
* | Return 404 on LFS request if project doesn't existIgor Drozdov2019-10-251-0/+1
* | Merge branch 'security-bvl-validate-force-remove-branch-on-mrs-12-4-ce' into ...GitLab Release Tools Bot2019-10-247-9/+52
|\ \
| * | Only assign merge params when allowedBob Van Landuyt2019-10-237-9/+52
| |/
* | Merge branch 'security-wiki-rdoc-content-12-4-ce' into '12-4-stable'GitLab Release Tools Bot2019-10-242-9/+7
|\ \
| * | Pass all wiki markup formats through pipelinesLuke Duncalfe2019-10-232-9/+7
| |/
* | Merge branch 'security-developer-transfer-project-12-4' into '12-4-stable'GitLab Release Tools Bot2019-10-243-1/+5
|\ \
| * | Require maintainer permission to transfer projectsmanojmj2019-10-233-1/+5
| |/
* | Merge branch 'security-open-redirect-internalredirect-12-4' into '12-4-stable'GitLab Release Tools Bot2019-10-241-1/+1
|\ \
| * | Use the '\A' and '\z' regex anchors in `InternalRedirect` to mitigate an Open...Joern Schneeweisz2019-10-221-1/+1
| |/
* | Merge branch 'security-2914-labels-visible-despite-no-access-to-issues-reposi...GitLab Release Tools Bot2019-10-242-5/+11
|\ \
| * | Fix labels finder to filter issuablesEugenia Grieff2019-10-222-5/+11
| |/
* | Merge branch 'security-2920-fix-notes-with-label-cross-reference-12-4' into '...GitLab Release Tools Bot2019-10-242-1/+4
|\ \
| * | Add milestone and label note types to cross refsEugenia Grieff2019-10-242-1/+4
| |/
* | Merge branch 'security-64519-circular-graphql-queries-12-4' into '12-4-stable'GitLab Release Tools Bot2019-10-241-5/+5
|\ \
| * | Check for recursion and fail if too recursivecharlieablett2019-10-231-5/+5
| |/
* | Merge branch 'security-33689-post-filter-search-results-ce-12-4' into '12-4-s...GitLab Release Tools Bot2019-10-246-2/+15
|\ \
| * | Add #to_ability_name to Project & MilestoneDylan Griffith2019-10-232-0/+8
| * | Change Note#to_ability_name to 'note'Dylan Griffith2019-10-234-2/+7
| |/
* | Merge branch 'security-65756-ex-admin-attacker-can-comment-in-internalsecurit...GitLab Release Tools Bot2019-10-241-0/+1
|\ \
| * | Users without commit access cannot create notescharlieablett2019-10-231-0/+1
| |/
* | Pick only those groups that the viewing user has access to,Aakriti Gupta2019-10-242-2/+56
|/
* Add latest changes from gitlab-org/gitlab@12-4-stable-eeGitLab Bot2019-10-221005-4473/+12844
* EE port: Fix private feature Elasticsearch leakMark Chao2019-10-012-2/+8
* Merge branch 'security-bypass-email-verification-using-salesforce' into '12-3...GitLab Release Tools Bot2019-09-261-1/+17
|\
| * Add checking for email_verified keyMaƂgorzata Ksionek2019-09-231-1/+17
* | Merge branch 'security-sarcila-verify-saml-request-origin-12-3' into '12-3-st...GitLab Release Tools Bot2019-09-261-2/+7
|\ \
| * | Validate that SAML requests are originated from gitlabSebastian Arcila Valenzuela2019-09-201-2/+7
| |/
* | Merge branch 'security-mermaid-block' into '12-3-stable'GitLab Release Tools Bot2019-09-261-1/+4
|\ \
| * | Only render fixed number of mermaid blocksRajat Jain2019-09-131-1/+4
* | | Merge branch 'security-12717-fix-confidential-issue-assignee-visible-to-guest...GitLab Release Tools Bot2019-09-261-1/+1
|\ \ \
| * | | Display only participants that user has permission to seeAlexandru Croitor2019-09-231-1/+1
| | |/ | |/|
* | | Merge branch 'security-64938-dont-disclose-path-12-3-ce' into '12-3-stable'GitLab Release Tools Bot2019-09-261-1/+5
|\ \ \
| * | | Redirect user to root path after unsubscribing from private resourceAlexandru Croitor2019-09-231-1/+5
| |/ /
* | | Merge branch 'security-12718-project-milestones-disclosed-via-groups-12-3-ce'...GitLab Release Tools Bot2019-09-261-4/+8
|\ \ \
| * | | Hide disabled project milestones in project settings on group levelAlexandru Croitor2019-09-231-4/+8
| |/ /
* | | Merge branch 'security-12630-private-system-note-disclosed-in-graphql-12-3-ce...GitLab Release Tools Bot2019-09-262-0/+10
|\ \ \
| * | | Add policy check if cross reference system notes are accessibleAlexandru Croitor2019-09-232-0/+10
| |/ /
* | | Merge branch 'security-fp-stop-jobs-when-blocking-user-12-3' into '12-3-stable'GitLab Release Tools Bot2019-09-262-0/+23
|\ \ \
| * | | Cancel all running CI jobs when user is blockedFabio Pitino2019-09-242-0/+23
| |/ /
* | | Filter not accessible label eventsJan Provaznik2019-09-243-0/+65
* | | Add latest changes from gitlab-org/gitlab@12-3-stable-eeGitLab Bot2019-09-248-18/+17
|/ /
* | Add latest changes from gitlab-org/gitlab@12-3-stableGitLab Bot2019-09-20102-798/+462
* | Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-09-205-4/+4
* | Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-09-206-56/+73
* | Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-09-201-1/+0