zulip/zerver
Anders Kaseorg 87f7874a79 CVE-2020-12759: Fix reflected XSS vulnerability in Dropbox webhook.
Also check the challenge argument’s presence before using it.

Signed-off-by: Anders Kaseorg <anders@zulip.com>
2020-06-16 22:46:16 -07:00
..
data_import python: Convert more percent formatting to Python 3.6 f-strings. 2020-06-14 23:27:22 -07:00
lib realm: Remove Google Hangouts integration. 2020-06-16 17:02:27 -07:00
management python: Manually convert more percent-formatting to f-strings. 2020-06-14 23:27:22 -07:00
migrations realm: Remove Google Hangouts integration. 2020-06-16 17:02:27 -07:00
openapi api: Remove is_old_stream property from the stream objects. 2020-06-16 10:26:33 -07:00
templatetags python: Convert more percent formatting to Python 3.6 f-strings. 2020-06-14 23:27:22 -07:00
tests realm: Remove Google Hangouts integration. 2020-06-16 17:02:27 -07:00
tornado python: Convert percent formatting to .format for translated strings. 2020-06-15 16:24:46 -07:00
views realm: Remove Google Hangouts integration. 2020-06-16 17:02:27 -07:00
webhooks CVE-2020-12759: Fix reflected XSS vulnerability in Dropbox webhook. 2020-06-16 22:46:16 -07:00
worker python: Manually convert more percent-formatting to f-strings. 2020-06-14 23:27:22 -07:00
__init__.py
apps.py python: Sort imports with isort. 2020-06-11 16:45:32 -07:00
context_processors.py python: Sort imports with isort. 2020-06-11 16:45:32 -07:00
decorator.py python: Fix misuse of Optional types for optional parameters. 2020-06-13 15:31:27 -07:00
filters.py python: Sort imports with isort. 2020-06-11 16:45:32 -07:00
forms.py python: Sort imports with isort. 2020-06-11 16:45:32 -07:00
logging_handlers.py python: Sort imports with isort. 2020-06-11 16:45:32 -07:00
middleware.py python: Manually convert more percent-formatting to f-strings. 2020-06-14 23:27:22 -07:00
models.py realm: Remove Google Hangouts integration. 2020-06-16 17:02:27 -07:00
signals.py python: Sort imports with isort. 2020-06-11 16:45:32 -07:00