summaryrefslogtreecommitdiff
path: root/lib/api/wikis.rb
Commit message (Collapse)AuthorAgeFilesLines
* Validate Wiki attachments are valid temporary filesStan Hu2018-10-231-2/+2
| | | | | | | | | | A malicious attacker could craft a request to read arbitrary files on the system. This change adds a Grape validation to ensure that the tempfile parameter delivered by the Rack multipart uploader is a Tempfile type to prevent users from being able to specify arbitrary filenames. Closes https://gitlab.com/gitlab-org/gitlab-ce/issues/53072
* Enable frozen string in lib/api and lib/backupgfyoung2018-09-291-0/+2
| | | | | | | | | | Partially addresses #47424. Had to make changes to spec files because stubbing methods on frozen objects is a mess in RSpec and leads to failures: https://github.com/rspec/rspec-mocks/issues/1190
* Uploads to wiki stored inside the wiki git repositoryFrancisco Javier López2018-09-041-0/+31
|
* Add API support for wiki pagesblackst0ne2017-09-071-0/+89