summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* bump versionv2.0.9.32-0-stableAaron Patterson2023-03-022-1/+5
* Limit all multipart parts, not just filesJohn Hawthorn2023-03-025-12/+77
* bumping versionv2.0.9.2Aaron Patterson2023-01-171-1/+1
* Update changelogAaron Patterson2023-01-171-0/+6
* Fix ReDoS vulnerability in multipart parserAaron Patterson2023-01-171-1/+1
* Fix ReDoS in Rack::Utils.get_byte_rangesAaron Patterson2023-01-171-5/+6
* Forbid control characters in attributesJohn Hawthorn2023-01-171-1/+1
* update changelog2.0.9.1Aaron Patterson2022-05-271-0/+5
* bump versionAaron Patterson2022-05-261-1/+1
* Escape untrusted text when loggingAaron Patterson2022-05-264-1/+21
* Restrict broken mime parsingAaron Patterson2022-05-264-18/+5
* bump version2.0.9Aaron Patterson2020-02-081-1/+1
* Handle case where session id key is requested but it is missingJeremy Evans2020-01-132-1/+74
* Merge pull request #1455 from trainline-eu/2-0-stableRafael França2020-01-102-0/+20
|\
| * Added support for SameSite=None cookie value, added in revision 3 of rfc6265bisHenning Kulander2020-01-072-0/+20
* | Merge pull request #1462 from jeremyevans/sessionid-to_sAaron Patterson2020-01-101-1/+1
|/
* Bumping version2.0.8Aaron Patterson2019-12-181-1/+1
* Introduce a new base class to avoid breaking when upgradingRafael Mendonça França2019-12-175-22/+54
* Add a version prefix to the private id to make easier to migrate old valuesRafael Mendonça França2019-12-172-3/+3
* Fallback to the public id when reading the session in the pool adapterRafael Mendonça França2019-12-173-4/+49
* Also drop the session with the public id when destroying sessionsRafael Mendonça França2019-12-172-0/+22
* Fallback to the legacy id when the new id is not foundRafael Mendonça França2019-12-172-1/+24
* Add the private idAaron Patterson2019-12-171-1/+1
* revert conditionals to masterAaron Patterson2019-12-173-3/+3
* remove NullSessionAaron Patterson2019-12-173-18/+5
* remove || raise and get closer to masterAaron Patterson2019-12-172-7/+4
* store hashed id, send public idAaron Patterson2019-12-174-12/+22
* use session id objectsAaron Patterson2019-12-175-15/+44
* remove more nilsAaron Patterson2019-12-173-7/+16
* try to ensure we always have some kind of objectAaron Patterson2019-12-172-4/+11
* Bumping to 2.0.7 for release2.0.7eileencodes2019-04-021-1/+1
* Merge pull request #1343 from larsxschneider/ls/forward-fixEileen M. Uchitelle2019-02-192-2/+11
|\
| * Preserve forwarded IP address for trusted proxy chainsSam2019-02-192-2/+11
|/
* Merge pull request #1201 from janko-m/make-multipart-parsing-work-for-chunked...Rafael França2018-12-201-9/+6
* Bumping version for release2.0.6Aaron Patterson2018-11-051-1/+1
* Whitelist http/https schemesPatrick Tulskie2018-11-052-4/+22
* Reduce buffer size to avoid pathological parsingAaron Patterson2018-11-051-1/+1
* Merge tag '2.0.5' into 2-0-stableAaron Patterson2018-11-051-1/+1
|\
| * Bump version for release2.0.5eileencodes2018-04-231-1/+1
* | Merge pull request #1296 from tomelm/fix-prefers-plaintextRafael França2018-09-122-1/+14
|/
* Merge pull request #1268 from eileencodes/forwardport-pr-1249-to-2-0-stableEileen M. Uchitelle2018-04-232-1/+19
|\
| * Merge pull request #1249 from mclark/handle-invalid-method-parametersEileen M. Uchitelle2018-04-232-1/+19
|/
* Stick with a passing version of Rubygems and bundlerRafael Mendonça França2018-04-231-1/+1
* LeahizeLeah Neukirchen2018-04-112-5/+3
* Bumping version2.0.4Aaron Patterson2018-01-311-1/+1
* webrick: remove concurrent-ruby dev dependencyEric Wong2018-01-312-9/+5
* Merge pull request #1190 from hugoabonizio/masterRafael França2018-01-312-3/+3
* Merge pull request #1193 from tompng/multipart_less_memoryRafael França2018-01-311-6/+6
* Merge pull request #1192 from jkowens/masterJeremy Daer2018-01-311-1/+1
* Merge pull request #1179 from tompng/masterJeremy Daer2018-01-311-5/+7