]>
source.dussan.org Git - gitblit.git/log
James Moger [Sun, 7 Sep 2014 16:53:08 +0000 (12:53 -0400)]
Merge branch 'ticket/164' into develop
James Moger [Sun, 7 Sep 2014 15:52:53 +0000 (11:52 -0400)]
Apply the relaxed XSS filter to Markdown commit messages
James Moger [Sun, 7 Sep 2014 15:21:59 +0000 (11:21 -0400)]
Enforce relaxed XSS filtering on markup documents
James Moger [Sat, 6 Sep 2014 17:14:38 +0000 (13:14 -0400)]
Implement a SafeTextModel and use that for fields vulnerable to XSS
James Moger [Sat, 6 Sep 2014 15:27:04 +0000 (11:27 -0400)]
XSS sanitize standard page url parameters
James Moger [Sat, 6 Sep 2014 15:25:42 +0000 (11:25 -0400)]
Create infrastructure for XSS sanitization
James Moger [Fri, 5 Sep 2014 23:28:24 +0000 (17:28 -0600)]
Merged #167 "Do not let new forks inadvertently disclose repository contents"
James Moger [Fri, 5 Sep 2014 23:20:08 +0000 (19:20 -0400)]
Merge branch 'ticket/167' into develop
James Moger [Fri, 5 Sep 2014 23:19:32 +0000 (19:19 -0400)]
New forks shall respect the source repository access restriction
If the source repository access restriction exceeds the fork default (push)
then the fork shall inherit the source repository access restriction.
James Moger [Fri, 5 Sep 2014 19:41:45 +0000 (13:41 -0600)]
Merged #166 "Fix XRF vulnerability"
James Moger [Fri, 5 Sep 2014 19:33:01 +0000 (15:33 -0400)]
Merge branch 'ticket/166' into develop
James Moger [Fri, 5 Sep 2014 19:32:04 +0000 (15:32 -0400)]
Specify response header X-Frame-Options SAMEORIGIN for generated pages
James Moger [Fri, 5 Sep 2014 19:13:12 +0000 (13:13 -0600)]
Merged #165 "Fix flash security risk"
James Moger [Fri, 5 Sep 2014 19:04:31 +0000 (15:04 -0400)]
Merge branch 'ticket/165' into develop
James Moger [Fri, 5 Sep 2014 19:02:09 +0000 (15:02 -0400)]
Change Clippy's script access attribute
James Moger [Fri, 5 Sep 2014 16:19:00 +0000 (10:19 -0600)]
Merged #163 "Raw servlet fails with long project names"
James Moger [Fri, 5 Sep 2014 16:12:39 +0000 (12:12 -0400)]
Merge branch 'ticket/163' into develop
James Moger [Fri, 5 Sep 2014 16:07:37 +0000 (12:07 -0400)]
Fix NPE in raw servlet for long project names
James Moger [Fri, 5 Sep 2014 00:31:29 +0000 (18:31 -0600)]
Merged #162 "Allow plugins and extensions to be injected"
James Moger [Fri, 5 Sep 2014 00:17:17 +0000 (20:17 -0400)]
Allow Plugins to have injected members and Extensions to be constructed
James Moger [Fri, 5 Sep 2014 00:04:36 +0000 (18:04 -0600)]
Merged #158 "Update Jetty version to 9.2.2"
James Moger [Thu, 4 Sep 2014 23:58:10 +0000 (17:58 -0600)]
Merged #159 "Update lucene version to 4.10"
David Ostrovsky [Thu, 4 Sep 2014 21:58:35 +0000 (23:58 +0200)]
Update jetty version to 9.2.2
James Moger [Thu, 4 Sep 2014 23:49:09 +0000 (19:49 -0400)]
Bump the index version and update the LuceneVersion
David Ostrovsky [Thu, 4 Sep 2014 22:06:48 +0000 (00:06 +0200)]
Update lucene version to 4.10
James Moger [Thu, 4 Sep 2014 21:38:05 +0000 (15:38 -0600)]
Merged #156 "Update stable 1.6.x SSHD to 0.11.1-atlassian-1"
James Moger [Thu, 4 Sep 2014 21:29:20 +0000 (17:29 -0400)]
Update to SSHD 0.11.1-atlassian1
James Moger [Thu, 4 Sep 2014 21:27:20 +0000 (15:27 -0600)]
Merged #155 "Update SSHD version to 0.12"
David Ostrovsky [Thu, 4 Sep 2014 21:07:05 +0000 (23:07 +0200)]
Update SSHD version to 0.12
Also switch back to Maven Central repository.
James Moger [Thu, 4 Sep 2014 20:13:54 +0000 (14:13 -0600)]
Merged #154 "Raw servlet returns 0-length files instead of 404s"
James Moger [Thu, 4 Sep 2014 20:08:45 +0000 (16:08 -0400)]
Merge branch 'ticket/154' into develop
James Moger [Thu, 4 Sep 2014 20:05:09 +0000 (16:05 -0400)]
Fix raw serving of files/directories that do not exist in a branch/ref
James Moger [Thu, 4 Sep 2014 19:25:43 +0000 (13:25 -0600)]
Merged #153 "Quote all Lucene query args that have non-alphanumeric characters"
James Moger [Thu, 4 Sep 2014 19:17:34 +0000 (15:17 -0400)]
Merge branch 'ticket/153' into develop
James Moger [Thu, 4 Sep 2014 19:16:02 +0000 (15:16 -0400)]
Quote all Lucene query args that have non-alphanumeric characters
James Moger [Thu, 4 Sep 2014 19:08:12 +0000 (13:08 -0600)]
Merged #152 "NPEs when handling tickets with non-existent milestones"
James Moger [Thu, 4 Sep 2014 18:59:32 +0000 (14:59 -0400)]
Merge branch 'ticket/152' into develop
James Moger [Thu, 4 Sep 2014 18:59:05 +0000 (14:59 -0400)]
Fix NPEs when handling referenced milestones that do not exist
James Moger [Thu, 4 Sep 2014 18:28:33 +0000 (12:28 -0600)]
Merged #151 "Treat UTF-9 and UTF-18 (fake) encodings as UTF-8"
James Moger [Thu, 4 Sep 2014 18:20:28 +0000 (14:20 -0400)]
Merge branch 'ticket/151' into develop
James Moger [Thu, 4 Sep 2014 18:19:46 +0000 (14:19 -0400)]
Alias UTF-9 and UTF-18 as UTF-8 in JGit
James Moger [Thu, 4 Sep 2014 17:56:08 +0000 (11:56 -0600)]
Merged #150 "Edit repo drops missing owners from owners list"
James Moger [Thu, 4 Sep 2014 17:48:10 +0000 (13:48 -0400)]
Merge branch 'ticket/150' into develop
James Moger [Thu, 4 Sep 2014 17:46:49 +0000 (13:46 -0400)]
Do not drop missing owners from owners palette
James Moger [Thu, 4 Sep 2014 17:32:44 +0000 (11:32 -0600)]
Merged #149 "Repo creation with initial commit fails if user does not have an email address"
James Moger [Thu, 4 Sep 2014 17:24:46 +0000 (13:24 -0400)]
Merge branch 'ticket/149' into develop
James Moger [Thu, 4 Sep 2014 17:23:54 +0000 (13:23 -0400)]
Create email address for a user if unset for repo creation
James Moger [Thu, 4 Sep 2014 17:13:11 +0000 (11:13 -0600)]
Merged #148 "Do not stamp raw servlet responses with cache-control headers"
James Moger [Thu, 4 Sep 2014 17:12:00 +0000 (13:12 -0400)]
Merge branch 'ticket/148' into develop
James Moger [Thu, 4 Sep 2014 17:04:20 +0000 (13:04 -0400)]
Do not stamp raw servlet responses with cache-control headers
James Moger [Thu, 4 Sep 2014 16:46:13 +0000 (10:46 -0600)]
Merged #147 "NPE in RepositoryNamePanel for anonymous admins"
James Moger [Thu, 4 Sep 2014 16:37:59 +0000 (12:37 -0400)]
Merge branch 'ticket/147' into develop
James Moger [Thu, 4 Sep 2014 16:37:06 +0000 (12:37 -0400)]
Fix NPE when anonymous admins are editing a repository (issue-490)
James Moger [Thu, 4 Sep 2014 16:16:30 +0000 (10:16 -0600)]
Merged #146 "Add install script for Fedora"
James Moger [Thu, 4 Sep 2014 16:08:29 +0000 (12:08 -0400)]
Merge branch 'ticket/146' into develop
James Moger [Thu, 4 Sep 2014 16:08:28 +0000 (10:08 -0600)]
Merged #145 "Pretty print C/C++ headers"
Soeren Grunewald [Tue, 8 Jul 2014 15:35:12 +0000 (17:35 +0200)]
distrib: Add script to install gitblit on fedora
The script will create a environment file keeping all the major settings and
installs a systemd unit file.
The script (mainly the unit file part) should also work for other systemd
based distributions like ArchLinux. But /etc/sysconfig may not exist there.
Signed-off-by: Soeren Grunewald <soeren.grunewald@desy.de>
James Moger [Thu, 4 Sep 2014 16:01:32 +0000 (10:01 -0600)]
Merged #144 "Pretty print perl modules"
James Moger [Thu, 4 Sep 2014 16:00:18 +0000 (12:00 -0400)]
Merge branch 'ticket/145' into develop
Soeren Grunewald [Tue, 8 Jul 2014 15:17:16 +0000 (17:17 +0200)]
distrib: Highlight C/C++ header files by default
We already highlight C/C++ source files with the default configuration,
so we should do this also for header files.
Signed-off-by: Soeren Grunewald <soeren.grunewald@desy.de>
James Moger [Thu, 4 Sep 2014 15:56:17 +0000 (09:56 -0600)]
Merged #143 "Fix url-based password keaing in Redmine auth provider"
James Moger [Thu, 4 Sep 2014 15:53:34 +0000 (11:53 -0400)]
Merge branch 'ticket/144' into develop
James Moger [Thu, 4 Sep 2014 15:48:22 +0000 (11:48 -0400)]
Merge branch 'ticket/143' into develop
James Moger [Thu, 4 Sep 2014 15:19:33 +0000 (09:19 -0600)]
Merged #142 "Update setup_authentication.mkd"
James Moger [Thu, 4 Sep 2014 15:11:20 +0000 (11:11 -0400)]
Merge branch 'ticket/142' into develop
James Moger [Thu, 4 Sep 2014 15:06:17 +0000 (09:06 -0600)]
Merged #141 "Allow gitblit baseFolder to be defined by a system property"
James Moger [Thu, 4 Sep 2014 15:03:36 +0000 (11:03 -0400)]
Merge branch 'ticket/141' into develop
James Moger [Thu, 4 Sep 2014 14:53:08 +0000 (08:53 -0600)]
Merged #140 "Update French translation"
James Moger [Thu, 4 Sep 2014 14:45:50 +0000 (10:45 -0400)]
Merge branch 'ticket/140' into develop
Michael Legart [Thu, 4 Sep 2014 10:32:41 +0000 (12:32 +0200)]
Pretty print perl modules
Since perl scripts (.pl) was already supported, add .pm for perl modules
mereth [Mon, 18 Aug 2014 23:13:37 +0000 (01:13 +0200)]
fix misstyped passwords leaked in log files with redmine auth provider
Anthony O. [Fri, 8 Aug 2014 08:47:05 +0000 (10:47 +0200)]
Update setup_authentication.mkd
In AuthenticationManager:385, only `provider instanceof UsernamePasswordAuthenticationProvider` will be called
Koen Serry [Sun, 3 Aug 2014 08:50:14 +0000 (10:50 +0200)]
Allow gitblit baseFolder to be defined by a system property
Romain GAGNAIRE [Fri, 25 Jul 2014 08:12:46 +0000 (10:12 +0200)]
Updated french translations
James Moger [Sat, 5 Jul 2014 17:26:48 +0000 (13:26 -0400)]
Merge branch 'ticket/139' into develop
Conflicts:
src/main/java/com/gitblit/servlet/RawServlet.java
James Moger [Sat, 5 Jul 2014 17:25:26 +0000 (13:25 -0400)]
Merge branch 'ticket/139'
Conflicts:
src/main/java/com/gitblit/servlet/RawServlet.java
James Moger [Sat, 5 Jul 2014 17:06:24 +0000 (13:06 -0400)]
Fix raw servlet blob paths not respecting web.forwardSlashCharacter
James Moger [Sat, 5 Jul 2014 17:10:40 +0000 (11:10 -0600)]
Merged #139 "Raw link blob paths do not respect web.forwardSlashCharacter"
James Moger [Sat, 5 Jul 2014 17:07:04 +0000 (13:07 -0400)]
Merge branch 'ticket/139' into develop
James Moger [Sat, 5 Jul 2014 17:06:24 +0000 (13:06 -0400)]
Fix raw servlet blob paths not respecting web.forwardSlashCharacter
James Moger [Sat, 5 Jul 2014 16:32:39 +0000 (10:32 -0600)]
Merged #137 "NPE in RawServlet#L265"
James Moger [Sat, 5 Jul 2014 16:28:37 +0000 (12:28 -0400)]
Merge branch 'ticket/137' into develop
James Moger [Sat, 5 Jul 2014 16:27:17 +0000 (12:27 -0400)]
Fix possible NPE in RawServlet
James Moger [Thu, 3 Jul 2014 22:07:16 +0000 (16:07 -0600)]
Merged #80 "Replace Dagger with Guice"
James Moger [Thu, 3 Jul 2014 21:52:15 +0000 (17:52 -0400)]
Update to Moxie 0.9.4
James Moger [Thu, 3 Jul 2014 20:19:49 +0000 (16:19 -0400)]
Update to Guava 17
James Moger [Thu, 3 Jul 2014 18:30:22 +0000 (14:30 -0400)]
Support injection of plugin Extensions
James Moger [Wed, 2 Jul 2014 21:51:35 +0000 (17:51 -0400)]
Delay setup of the repositories folder to start()
James Moger [Wed, 2 Jul 2014 20:50:45 +0000 (16:50 -0400)]
Delay pf4j instantiation and setup to start()
James Moger [Wed, 2 Jul 2014 20:45:37 +0000 (16:45 -0400)]
Extract ticket service into an injectable object with a custom provider
James Moger [Wed, 2 Jul 2014 20:39:47 +0000 (16:39 -0400)]
Implement custom IPublicKeyManager provider
James Moger [Wed, 2 Jul 2014 20:30:55 +0000 (16:30 -0400)]
Annotate managers with @Singleton
James Moger [Wed, 2 Jul 2014 20:21:16 +0000 (16:21 -0400)]
Extract services manager into a top-level injectable manager
James Moger [Tue, 1 Jul 2014 03:25:01 +0000 (23:25 -0400)]
Documentation
James Moger [Tue, 1 Jul 2014 02:45:52 +0000 (22:45 -0400)]
Adjust builds for appropriate dependencies
James Moger [Tue, 1 Jul 2014 02:29:48 +0000 (22:29 -0400)]
Removed beans.xml
James Moger [Tue, 1 Jul 2014 01:29:01 +0000 (21:29 -0400)]
Use forked guice-servlet jar rather than stock jar from Google
James Moger [Thu, 12 Jun 2014 23:25:12 +0000 (19:25 -0400)]
Temporarily depend on patched guice-servlet (guice-807)
James Moger [Thu, 12 Jun 2014 23:19:26 +0000 (19:19 -0400)]
Restore all security filters
James Moger [Thu, 12 Jun 2014 22:12:46 +0000 (18:12 -0400)]
Use Guice annotations, not javax.inject annotations