Pleroma/lib/pleroma
rinpatch 6ca709816f Fix object spoofing vulnerability in attachments
Validate the content-type of the response when fetching an object,
according to https://www.w3.org/TR/activitypub/#x3-2-retrieving-objects.

content-type headers had to be added to many mocks in order to support
this, some of this was done with a regex. While I did go over the
resulting files to check I didn't modify anything unrelated, there is a
 possibility I missed something.

Closes pleroma#1948
2020-11-12 15:25:33 +03:00
..
activity Remote Timeline: add Streaming support 2020-10-08 20:07:03 -05:00
bbs alias alphabetically order 2020-10-13 16:43:59 +03:00
captcha Use Pleroma.HTTP instead of Tesla 2020-11-01 12:05:39 +03:00
chat
config migration and warning for RemoteIp plug rename 2020-10-13 16:44:04 +03:00
conversation Merge branch 'issue/2069' into 'develop' 2020-10-29 23:39:15 +00:00
docs config descriptions for custom MRF policies 2020-11-10 19:20:14 +03:00
ecto_type
emails AdminEmail: Use AP id as user url. 2020-11-04 17:12:47 +01:00
emoji Use Pleroma.HTTP instead of Tesla 2020-11-01 12:05:39 +03:00
gopher
gun other files consistency 2020-10-13 16:38:19 +03:00
helpers [#1668] Restricted access to app metrics endpoint by default. Added ability to configure IP whitelist for this endpoint. 2020-10-18 21:22:21 +03:00
http changes after rebase 2020-10-13 16:44:03 +03:00
instances federation_status: New endpoint showing unreachable instances 2020-10-16 01:14:04 +02:00
mfa
migration_helper added notification constraints 2020-09-14 14:08:12 +03:00
object Fix object spoofing vulnerability in attachments 2020-11-12 15:25:33 +03:00
reverse_proxy other files consistency 2020-10-13 16:38:19 +03:00
telemetry Add missing Copyright headers 2020-10-12 12:00:50 -05:00
tesla/middleware changes after rebase 2020-10-13 16:44:03 +03:00
tests alias alphabetically order 2020-10-13 16:43:59 +03:00
upload
uploaders UploadedMedia module name 2020-10-13 16:42:51 +03:00
user Merge remote-tracking branch 'origin/develop' into feature/account-export 2020-10-30 19:34:02 +04:00
web Merge branch 'title-injection-change' into 'develop' 2020-11-12 08:50:26 +00:00
workers Merge branch 'develop' of git.pleroma.social:pleroma/pleroma into feature/expire-mutes 2020-11-04 16:51:42 +01:00
activity.ex Permit fetching individual reports with notes preloaded 2020-11-02 13:06:59 -06:00
application.ex Add idempotency_key to the chat_message entity. 2020-10-31 05:50:59 +03:00
application_requirements.ex [#3031] Refactoring: moved system commands checks to ApplicationRequirements. 2020-09-29 16:28:06 +03:00
bookmark.ex
captcha.ex other files consistency 2020-10-13 16:38:19 +03:00
chat.ex Merge branch 'develop' of git.pleroma.social:pleroma/pleroma into issue/2115 2020-09-22 17:13:46 +02:00
clippy.ex
config.ex
config_db.ex other files consistency 2020-10-13 16:38:19 +03:00
constants.ex
conversation.ex
counter_cache.ex
delivery.ex
earmark_renderer.ex
ecto_enums.ex
emoji-data.txt
emoji.ex
filter.ex
following_relationship.ex
formatter.ex
gun.ex other files consistency 2020-10-13 16:38:19 +03:00
healthcheck.ex
html.ex
http.ex other files consistency 2020-10-13 16:38:19 +03:00
instances.ex federation_status: New endpoint showing unreachable instances 2020-10-16 01:14:04 +02:00
job_queue_monitor.ex
jwt.ex Add missing Copyright headers 2020-10-12 12:00:50 -05:00
keys.ex
list.ex
maintenance.ex
maps.ex
marker.ex
mfa.ex
moderation_log.ex Merge branch 'develop' into feature/account-export 2020-10-14 15:27:15 -05:00
notification.ex
object.ex
object_tombstone.ex
otp_version.ex
pagination.ex
password_reset_token.ex
registration.ex
release_tasks.ex
repo.ex RepoStreamer.chunk_stream -> Repo.chunk_stream 2020-09-16 09:47:18 +03:00
report_note.ex
reverse_proxy.ex other files consistency 2020-10-13 16:38:19 +03:00
scheduled_activity.ex
signature.ex Federate data through persistent websocket connections 2020-09-18 11:58:22 +00:00
stats.ex
thread_mute.ex
upload.ex
user.ex Merge branch 'develop' of git.pleroma.social:pleroma/pleroma into feature/expire-mutes 2020-11-04 16:51:42 +01:00
user_invite_token.ex
user_relationship.ex
utils.ex
web.ex Merge branch 'develop' into chore/elixir-1.11 2020-10-13 09:54:53 -05:00
xml_builder.ex more files renamings 2020-10-13 16:38:19 +03:00