zulip/zerver
Anders Kaseorg 4a61e36def CVE-2022-36048: Rewrite only specific local links to relative.
Due to mismatches between the URL parsers in Python and browsers, it
was possible to hoodwink rewrite_local_links_to_relative into
generating links that browsers would interpret as absolute.

Signed-off-by: Anders Kaseorg <anders@zulip.com>
2022-08-24 16:29:09 -07:00
..
actions message_edit: Return a bool in maybe_send_resolve_topic_notifications. 2022-08-18 15:39:23 -07:00
data_import rocketchat: Handle PMs with only one recipient. 2022-08-09 10:58:58 -07:00
integration_fixtures/nagios
lib CVE-2022-36048: Rewrite only specific local links to relative. 2022-08-24 16:29:09 -07:00
management logout_all_users: Add --rotate-api-keys option to the command. 2022-08-15 17:58:05 -07:00
migrations message_edit: Make zero invalid value for message_content_edit_time_limit_seconds. 2022-08-12 18:09:53 -07:00
openapi typing: Remove FuncT. 2022-08-22 15:46:16 -07:00
tests CVE-2022-36048: Rewrite only specific local links to relative. 2022-08-24 16:29:09 -07:00
tornado user_topic: Add user_topic event. 2022-08-04 17:44:00 -07:00
views portico: Move to corporate folder. 2022-08-22 15:53:43 -07:00
webhooks slack_incoming: Handle optional attachment fields aptly. 2022-08-22 16:40:13 -07:00
worker queue_processor: Fix type annotation for connection. 2022-07-26 18:00:24 -07:00
__init__.py
apps.py caching: Make sender type optional for flush_cache. 2021-07-26 14:48:07 -07:00
context_processors.py footer: Reduce links for self-hosted installations on signup pages. 2022-07-22 15:46:42 -07:00
decorator.py decorator: Rename profile to user_profile. 2022-08-17 12:05:38 -07:00
filters.py typing: Fix function signatures. 2021-08-20 05:54:19 -07:00
forms.py billing: Fix licenses amount check during user signup/invitation. 2022-08-18 11:56:54 -07:00
logging_handlers.py python: Use Python 3.8 typing.{Protocol,TypedDict}. 2022-04-27 12:57:49 -07:00
middleware.py typing: Remove ViewFuncT. 2022-08-22 15:46:16 -07:00
models.py message_edit: Make zero invalid value for message_content_edit_time_limit_seconds. 2022-08-12 18:09:53 -07:00
signals.py requirements: Upgrade to Django 4.0. 2022-07-13 16:07:17 -07:00