zulip/zerver
Tim Abbott 3da06fecd5 invite: Fix validation of referred_by field.
Previously, we could 500 if an organization administrator scanned
possible PreregistrationUser IDs looking for a valid invitation they
can interact with.

They couldn't do anything, so no security issue, but this fixes that
case to just be a 400 error as it should be.
2019-03-21 16:31:18 -07:00
..
data_import import: Move SubscriberHandler to import_util. 2019-03-20 11:29:51 -07:00
lib invite: Fix validation of referred_by field. 2019-03-21 16:31:18 -07:00
management email_mirror: Move some helper functions out of actions.py. 2019-03-21 15:25:57 -07:00
migrations email_mirror: Make email_token a unique column of Stream. 2019-03-17 12:55:35 -07:00
openapi api/streams: Support including bot owner's subscriptions. 2019-02-28 22:32:05 -08:00
templatetags zerver core: Remove unused imports. 2019-02-02 17:41:24 -08:00
tests email_mirror: Raise ZulipEmailForwardError if email pattern not recognised. 2019-03-21 15:25:57 -07:00
tornado tornado: Remove unused imports. 2019-02-02 17:33:13 -08:00
views invite: Fix validation of referred_by field. 2019-03-21 16:31:18 -07:00
webhooks webhooks/bitbucket: Support empty push payloads with no user info. 2019-03-21 17:43:35 -02:30
worker email_mirror: Add realm-based rate limiting. 2019-03-18 11:16:58 -07:00
__init__.py
apps.py python: Mark intentionally unused imports with noop statements. 2019-02-22 16:54:47 -08:00
context_processors.py context_processors: Cache the realm description in default context. 2019-03-18 22:19:18 -07:00
decorator.py rate_limit tests: Cover RateLimiterLockingException case in rate_limit_user. 2019-03-18 11:16:58 -07:00
filters.py error reports: Ensure we filter API keys from query strings. 2018-10-19 15:03:14 -07:00
forms.py zerver core: Remove unused imports. 2019-02-02 17:41:24 -08:00
logging_handlers.py try_git_describe: Set cwd, not --git-dir. 2019-02-28 14:59:33 -08:00
middleware.py auth: Use HTTP status 404 for invalid realms. 2019-03-14 13:50:09 -07:00
models.py onboarding: Change default notifications stream to #general. 2019-03-21 12:29:51 -07:00
signals.py zerver core: Remove unused imports. 2019-02-02 17:41:24 -08:00
static_header.txt