Commit message Age Author Refs
r2181:0bf8e4db
pull-requests: security, prevent from injecting comments to other pull requests users don't have access to.
0
r2180:d1b66400
repo-settings: ensure deletion on repo settings model validate the settings id against the initialized model repo. - prevents from malicious deletions of settings by forgin IDs
0
r2179:a3d55bf9
select2: always escape .text attributes to prevent XSS via vcs references.
0
r2178:34dda1ab
templates: rename base.mako into summary_base.mako. The previous naming wasn't optimal for search and code discovery.
0
r2177:4abf28f1
pull-requests: security double check permissions on injected forms of source and target repositories.
0
r2176:d21fb0df
db: prevent empty IN queries that generally are performance problem, and triggers sql warnings.
0
r2175:ea878558
repo-groups: moved to pyramid
0
r2174:b234a120
tests: change name of test module of auth-modules to prevent pytest complaining about it.
0
r2173:d100eea4
repo-forks: security, check for access to fork_id parameter to prevent resource discovery.
0
r2172:f94ee74b
repo-forks: security, fix issue when forging fork_repo_id could allow reading other people forks.
0
< 1 .. 315 316 317 318 319 .. 535 >