Skip to content
Extraits de code Groupes Projets
  1. avr. 24, 2015
  2. avr. 22, 2015
    • Jonne Haß's avatar
      Merge branch 'release/0.5.0.0-RC' into develop · 0bad6dba
      Jonne Haß a rédigé
      0bad6dba
    • Jonne Haß's avatar
      Trigger exports through a POST request · 6e546ff2
      Jonne Haß a rédigé
      GET requests don't get any CSRF protection by Rails,
      thus these sensitive actions should be better protected.
      
      Thanks to @tomekr for the report.
      6e546ff2
    • Jonne Haß's avatar
      Add a token the filename for exported user data · 0a70e51f
      Jonne Haß a rédigé
      Also redirect to it for download, for Amazon S3
      compatibility.
      
      Prior to this patch an attacker could obtain an
      users export by guessing the filename with a high
      chance of success. Fully authenticating the
      download request is a lot harder due to our diverse
      deployment scenarios.
      
      This brings the used method in line with the photo
      export feature.
      
      Thanks to @tomekr for the report.
      0a70e51f
  3. avr. 21, 2015
  4. avr. 20, 2015
  5. avr. 19, 2015
  6. avr. 18, 2015
  7. avr. 15, 2015
  8. avr. 14, 2015
  9. avr. 11, 2015
Chargement en cours