summaryrefslogtreecommitdiff
path: root/lib/gitlab/url_blocker.rb
Commit message (Expand)AuthorAgeFilesLines
* Add latest changes from gitlab-org/gitlab@15-11-stable-ee15-11-stableGitLab Bot2023-05-171-10/+37
* Add latest changes from gitlab-org/gitlab@15-11-stable-eev15.11.0-rc42GitLab Bot2023-04-201-2/+25
* Add latest changes from gitlab-org/gitlab@15-10-stable-eev15.10.0-rc42GitLab Bot2023-03-201-20/+61
* Add latest changes from gitlab-org/gitlab@15-9-stable-eeGitLab Bot2023-03-011-2/+2
* Add latest changes from gitlab-org/gitlab@15-9-stable-eev15.9.0-rc42GitLab Bot2023-02-201-2/+2
* Add latest changes from gitlab-org/gitlab@15-7-stable-eev15.7.0-rc42GitLab Bot2022-12-201-2/+4
* Add latest changes from gitlab-org/gitlab@14-9-stable-eeGitLab Bot2022-04-121-2/+3
* Add latest changes from gitlab-org/gitlab@14-9-stable-eev14.9.0-rc42GitLab Bot2022-03-181-0/+40
* Add latest changes from gitlab-org/security/gitlab@14-7-stable-eeGitLab Bot2022-02-031-0/+8
* Add latest changes from gitlab-org/security/gitlab@14-6-stable-eeGitLab Bot2022-01-101-2/+2
* Add latest changes from gitlab-org/gitlab@14-5-stable-eev14.5.0-rc42GitLab Bot2021-11-181-5/+11
* Add latest changes from gitlab-org/security/gitlab@13-8-stable-eeGitLab Bot2021-02-011-1/+3
* Add latest changes from gitlab-org/gitlab@13-6-stable-eev13.6.0-rc42GitLab Bot2020-11-191-9/+9
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2020-03-311-2/+2
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2020-03-161-4/+4
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-10-031-0/+5
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-09-131-30/+18
* Allow not resolvable urls when rebinding setting is disabledFrancisco Javier López2019-09-051-2/+6
* Fix broken master because of security mergeFrancisco Javier López2019-07-291-5/+2
* Merge branch 'master' of dev.gitlab.org:gitlab/gitlabhqRobert Speicher2019-07-291-2/+14
|\
| * Fix Server Side Request Forgery mitigation bypassFrancisco Javier López2019-07-151-2/+11
* | [ADD] outbound requests whitelistReuben Pereira2019-07-241-6/+30
|/
* Don't use bang method when there is no safe methodReuben Pereira2019-07-121-33/+59
* Add DNS rebinding protection settingsOswaldo Ferreira2019-05-301-10/+24
* Protect Gitlab::HTTP against DNS rebinding attackDouwe Maan2019-05-301-13/+48
* Align UrlValidator to validate_url gem implementation.Thong Kuah2019-04-111-5/+5
* Add table and model for error tracking settingsReuben Pereira2019-01-071-2/+16
* Allow URLs to be validated as ascii_onlyJames Edwards-Jones2018-12-061-1/+8
* Merge branch 'security-11-5-fix-webhook-ssrf-ipv6' into 'security-11-5'Steve Azzopardi2018-11-281-4/+8
* Merge branch 'security-fj-crlf-injection' into 'master'Cindy Pallares2018-11-281-5/+14
* Merge branch 'security-stored-xss-for-environments' into 'master'Cindy Pallares2018-11-281-2/+4
* Merge branch 'sh-block-other-localhost' into 'master'Thiago Presa2018-10-251-0/+7
|\
| * Block loopback addresses in UrlBlockerStan Hu2018-09-051-0/+7
* | Enable frozen string for lib/gitlab/*.rbgfyoung2018-10-221-0/+2
|/
* Block link-local addresses in URLBlockerStan Hu2018-08-121-0/+8
* Avoid checking the user format in every url validationFrancisco Javier López2018-06-111-2/+2
* Add validation to webhook and service URLs to ensure they are not blocked bec...Francisco Javier López2018-06-011-5/+12
* Rename allow_private_networks to allow_local_networkDouwe Maan2018-04-021-2/+2
* Make error messages even more descriptiveDouwe Maan2018-04-021-33/+47
* Raise more descriptive errors when URLs are blockedDouwe Maan2018-04-021-14/+32
* Merge branch 'fj-15329-services-callbacks-ssrf' into 'security-10-6'Douwe Maan2018-03-211-10/+13
* Merge branch 'ssrf-protections-round-2' into 'security-10-1'Douwe Maan2017-11-081-1/+3
* Merge branch 'rs-alphanumeric-ssh-params' into 'security-9-4'jej/security-release-2017-08-10James Edwards-Jones2017-08-101-0/+8
* Merge branch 'ssrf' into 'security' Rubén Dávila2017-03-201-0/+2
* Merge branch 'ssrf' into 'security' Douwe Maan2017-03-201-0/+57