- 03 Jan, 2019 14 commits
-
-
Daniel Gerhardt authored
The following formerly separate commits have been merged in: * Adjust 'Sign in' button for GitLab's CSRF protection GitLab introduced CSRF protection for authentication requests in 571ba5a7. The 'Sign in' button has been adjusted to send a POST request. * Opt out of turbolinks for 'Sign in' button
-
Daniel Gerhardt authored
This restriction does not apply to admins.
-
Daniel Gerhardt authored
This restriction does not apply to admins.
-
Daniel Gerhardt authored
-
Daniel Gerhardt authored
-
Daniel Gerhardt authored
-
Daniel Gerhardt authored
The project variable can hold an object which is not an instance of Project (e.g. ProjectWiki). In this case, visibility_level is not defined.
-
Daniel Gerhardt authored
Additionally, the prompt to set a password is no longer shown for CAS users.
-
Daniel Gerhardt authored
-
Daniel Gerhardt authored
-
Daniel Gerhardt authored
-
Daniel Gerhardt authored
-
Daniel Gerhardt authored
-
Daniel Gerhardt authored
-
- 20 Dec, 2018 3 commits
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[ci skip]
-
John Jarvis authored
-
- 13 Dec, 2018 3 commits
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[ci skip]
-
John Jarvis authored
[11.3] Validate LFS hrefs before downloading them See merge request gitlab/gitlabhq!2700
-
- 06 Dec, 2018 3 commits
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[ci skip]
-
Cindy Pallares authored
[11.3] Prevent a path traversal attack on global file templates See merge request gitlab/gitlabhq!2671
-
- 27 Nov, 2018 2 commits
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[ci skip]
-
- 26 Nov, 2018 11 commits
-
-
Steve Azzopardi authored
[11.3] Reflected XSS in OAuth Authorize window due to redirect_uri allowing arbitrary protocols See merge request gitlab/gitlabhq!2581
-
Steve Azzopardi authored
[11.3] Fix CRLF issue in UrlValidator See merge request gitlab/gitlabhq!2654
-
Francisco Javier López authored
-
Steve Azzopardi authored
[11.3] Redact sensitive information on workhorse log See merge request gitlab/gitlabhq!2586
-
Steve Azzopardi authored
[11.3] Fix SSRF in project integrations See merge request gitlab/gitlabhq!2609
-
Steve Azzopardi authored
[11.3] Resolve: "Provide email notification when a user changes their email address" See merge request gitlab/gitlabhq!2604
-
Steve Azzopardi authored
[11.3] Fixed ability to comment on and edit/delete comments on locked or confidential issues See merge request gitlab/gitlabhq!2648
-
Chantal Rollison authored
-
James Lopez authored
-
Steve Azzopardi authored
[11.3] [pages] Possible symlink time of check to time of use race condition See merge request gitlab/gitlabhq!2651
-
Steve Azzopardi authored
[11.3] Resolve "Personal access token with only `read_user` scope can be used to authenticate any web request" See merge request gitlab/gitlabhq!2657
-
- 23 Nov, 2018 4 commits
-
-
Steve Azzopardi authored
6.1.1 does not include the security fix, but 6.1.2 does.
-
Steve Azzopardi authored
Merge branch 'security-11-3-xss-in-markdown-following-unrecognized-html-element' into 'security-11-3' [11.3] XSS in markdown following unrecognized HTML element See merge request gitlab/gitlabhq!2633
-
Steve Azzopardi authored
[11.3] Fix XSS in mermaid diagrams See merge request gitlab/gitlabhq!2640
-
Steve Azzopardi authored
[11.3] Don't expose confidential information in commit message list See merge request gitlab/gitlabhq!2644
-