Commit message Age Author Refs
r1831:87ca65d7
user-group-api: use simple schema validator to be consistent how we validate user group names during creation between API and WEB.
0
r1830:d786fdd7
security: use safe escaped version of description for repo and repo group to potentially prevent any XSS attacks on returned data.
0
r1829:ff4add41
audit-logs: implemented full audit logs across application. - Fixes #5321 - Api+web actions - To be extended while we develop new features.
0
r1828:20cd932d
security: fix self-xss inside the email add functionality.
0
r1827:9e60361c
security: escape the returned paths of files and directories. Nodes function is used for autocomplete in files view, it prevents from XSS type of attack in file search.
0
r1826:76aa3640
security: use 404 instead of 403 in case missing permissions for comment deletion. - prevents resource discovery
0
r1825:fcaa19d4
security: don't use literal in notifications. - exposes security problems - we don't store any html anyway in the subject
0
r1824:fdf0761c
audit-logs: added *basic* support for NOT query term in audit logs.
0
r1823:e27e4796
audit-logs: updated action data attrbiutes.
0
r1822:4bb2ace4
audit-logs: consistent data between my-account and admin user logs.
0
< 1 .. 350 351 352 353 354 .. 535 >