Ivan Tashkinov
60b025b782
[ #2074 ] OAuth scope checking in Streaming API.
4 years ago
lain
ea2b5c07e3
Merge branch 'stable' of git.pleroma.social:pleroma/pleroma into pleroma-2.1-rc0
4 years ago
lain
6a25f72a75
FrontendStatic: Work correctly for other frontend types.
4 years ago
lain
ad5c42628a
FrontendStatic: Add plug to serve frontends based on configuration.
4 years ago
lain
14c28dcbd1
InstanceStatic: Refactor.
4 years ago
feld
3f65f2ea79
Merge branch 'feature/1922-media-proxy-whitelist' into 'develop'
...
Support for hosts with scheme in MediaProxy whitelist setting
Closes #1922
See merge request pleroma/pleroma!2754
4 years ago
Ivan Tashkinov
9b225db7d8
[ #1940 ] Applied rate limit for requests with bad `admin_token`. Added doc warnings on `admin_token` setting.
4 years ago
Ivan Tashkinov
cf3f8cb72a
[ #1940 ] Reinstated OAuth-less `admin_token` authentication. Refactored UserIsAdminPlug (freed from checking admin scopes presence).
4 years ago
Alexander Strizhakov
b376442325
MediaProxy whitelist setting now supports hosts with scheme
...
added deprecation warning about using bare domains
4 years ago
Mark Felder
d23804f191
Use the Pleroma.Config alias
4 years ago
Mark Felder
49c4e24953
Merge branch 'develop' into fix/csp-for-captcha
4 years ago
Mark Felder
da4029391d
IO list, not concatenation
4 years ago
Mark Felder
65843d92c4
Simplify the logic
4 years ago
lain
158c26d7dd
StaticFE Plug: Use phoenix helper to get the requested format.
4 years ago
Mark Felder
af612bd006
Ensure all CSP parameters for remote hosts have a scheme
4 years ago
Mark Felder
e9a28078ad
Rename function and clarify that CSP is only strict with MediaProxy enabled
4 years ago
Mark Felder
eaa59daa4c
Add Captcha endpoint to CSP headers when MediaProxy is enabled.
...
Our CSP rules are lax when MediaProxy enabled, but lenient otherwise.
This fixes broken captcha on instances not using MediaProxy.
4 years ago
lain
a5bbfa21a1
StaticFE: Prioritize json in requests.
4 years ago
Mark Felder
2731ea1334
Change references from "deleted_urls" to "banned_urls" as nothing is handled via media deletions anymore; all actions are manual operations by an admin to ban the url
4 years ago
Maksim Pechnikov
2e8a236cef
fix invalidates media url's
4 years ago
feld
90676bdfe3
Merge branch 'fix/csp-mediaproxy-base-url' into 'develop'
...
HTTP security plug: add media proxy base url host to csp
See merge request pleroma/pleroma!2638
4 years ago
rinpatch
cd2df734dd
Merge branch 'bugfix/csp-unproxied' into 'develop'
...
http_security_plug.ex: Fix non-proxied media
See merge request pleroma/pleroma!2610
4 years ago
Haelwenn (lanodan) Monnier
e313aa0977
static-fe.css: Restore and move to /priv/static/static-fe
4 years ago
Mark Felder
7f7a1a4676
Check for media proxy base_url, not Upload base_url
4 years ago
rinpatch
99afc7f4e4
HTTP security plug: add media proxy base url host to csp
4 years ago
rinpatch
a51284b60a
Merge branch 'fix/mediaproxy-bypass-emoji' into 'develop'
...
Fix profile emojis bypassing mediaproxy and harden CSP
Closes #1810
See merge request pleroma/pleroma!2596
4 years ago
rinpatch
d23b3701d8
Merge branch 'bugfix/csp-unproxied' into 'develop'
...
http_security_plug.ex: Fix non-proxied media
See merge request pleroma/pleroma!2610
4 years ago
rinpatch
109af93227
Apply suggestion to lib/pleroma/plugs/http_security_plug.ex
4 years ago
Alex Gleason
d38f28870e
Add blob: to connect-src CSP
4 years ago
Haelwenn (lanodan) Monnier
da1e31fae3
http_security_plug.ex: Fix non-proxied media
4 years ago
rinpatch
27180611df
HTTP Security plug: make starting csp string generation more readable
4 years ago
rinpatch
29ff6d414b
HTTP security plug: Harden img-src and media-src when MediaProxy is enabled
4 years ago
rinpatch
455a402c8a
HTTP Security plug: rewrite &csp_string/0
...
- Directives are now separated with ";" instead of " ;",
according to https://www.w3.org/TR/CSP2/#policy-parsing
the space is optional
- Use an IO list, which at the end gets converted to a binary as
opposed to ++ing a bunch of arrays with binaries together and joining
them to a string. I doubt it gives any significant real world advantage,
but the code is cleaner and now I can sleep at night.
- The static part of csp is pre-joined to a single binary at compile time.
Same reasoning as the last point.
4 years ago
lain
bfdd90f6d7
AuthenticationPlug: Also update crypt passwords.
4 years ago
lain
baef35bcc8
Authentication Plug: Update bcrypt password on login.
4 years ago
Alex Gleason
5b0f27d23d
Pbkdf2.verify_pass --> AuthenticationPlug.checkpw
4 years ago
Alex Gleason
9cbf17d59f
Handle bcrypt passwords for Mastodon migration
4 years ago
Alex Gleason
b46811a074
Upgrade Comeonin to v5
...
https://github.com/riverrun/comeonin/blob/master/UPGRADE_v5.md
4 years ago
Maksim
3d0c567fbc
Pleroma.Web.TwitterAPI.TwoFactorAuthenticationController -> Pleroma.Web.PleromaAPI.TwoFactorAuthenticationController
4 years ago
lain
07e7c80bc9
Merge branch 'plug-if-unless-func-options-refactoring' into 'develop'
...
Refactoring of :if_func / :unless_func plug options
See merge request pleroma/pleroma!2446
4 years ago
Haelwenn (lanodan) Monnier
c6ddfa8f95
static-fe.css: Restore and move to /priv/static/static-fe
4 years ago
rinpatch
b6ca8cc539
Merge branch 'bugfix/1727-fix-signature-decoding' into 'develop'
...
Bugfix/1727 fix signature decoding
Closes #1727
See merge request pleroma/pleroma!2454
4 years ago
lain
3453e54e6b
MappedSignatureToIdentityPlug: Fix.
4 years ago
lain
a4afeed426
Uploads: Sandbox them in the CSP.
4 years ago
Ivan Tashkinov
862d4886c9
[ #1682 ] Fixed Basic Auth permissions issue by disabling OAuth scopes checks when password is provided. Refactored plugs skipping functionality.
4 years ago
rinpatch
da4923f2e5
Merge branch 'authenticated-api-oauth-check-enforcement' into 'develop'
...
Enforcement of OAuth scopes check for authenticated API endpoints
See merge request pleroma/pleroma!2349
4 years ago
Alex Gleason
6e0b046771
Let blob: pass CSP
4 years ago
Ivan Tashkinov
2c4844237f
Refactoring of :if_func / :unless_func plug options (general availability). Added tests for Pleroma.Web.Plug.
4 years ago
Ivan Tashkinov
908cf22a6c
Merge remote-tracking branch 'remotes/origin/develop' into automatic-authentication-and-instance-publicity-checks
...
# Conflicts:
# lib/pleroma/web/mastodon_api/controllers/account_controller.ex
4 years ago
Alex Gleason
1bd9749a8f
Let blob: pass CSP
4 years ago