67 Commits (514cd874a7f2db1637c218a463754d900688c6d5)

Author SHA1 Message Date
  Eugen Rochko 339ce1c4e9
Add specific rate limits for posting and following (#13172) 4 years ago
  Eugen Rochko 5265df0a8a
Change signature verification to ignore signatures with invalid host (#13033) 4 years ago
  Eugen Rochko 49b2f7c0a2
Fix base64-encoded file uploads not being possible (#12748) 4 years ago
  Eugen Rochko 3ed94dcc1a
Add account migration UI (#11846) 4 years ago
  Eugen Rochko e1066cd431
Add password challenge to 2FA settings, e-mail notifications (#11878) 4 years ago
  Eugen Rochko 1bc077dc74
Add HTTP signature keyId to request log (#11591) 4 years ago
  Eugen Rochko 24552b5160
Add whitelist mode (#11291) 4 years ago
  Eugen Rochko c669bb42ba
Add (back) rails-level JSON caching (#11333) 4 years ago
  Eugen Rochko bd1545de5e
Change locale detection to run once per session (#8657) 4 years ago
  Eugen Rochko 5bf67ca913
Add ActivityPub secure mode (#11269) 4 years ago
  Eugen Rochko 4e92183227
Refactor domain block checks (#11268) 4 years ago
  Eugen Rochko 63c7fe8e48
Refactor controllers for statuses, accounts, and more (#11249) 4 years ago
  ThibG cac9110533 Cleanup various controllers (#10972) 5 years ago
  ThibG 89d600bedb Move signature verification stoplight to the requests themselves (#10813) 5 years ago
  ThibG 2361917944 Mark the 410 gone response for suspended accounts as cachable (#10339) 5 years ago
  Eugen Rochko 51e154f5e8
Admission-based registrations mode (#10250) 5 years ago
  ThibG 28b482874a Improvements to signature verification (#9667) 5 years ago
  Eugen Rochko 17cd91c777
Fix signature verification stoplight triggering on non-timeout errors (#9617) 5 years ago
  ysksn 189a6b17fb Remove RemoteAccountControllerConcern never used (#9482) 5 years ago
  Eugen Rochko 4615512285
Reduce connect timeout limit and limit signature failures by source IP (#9236) 5 years ago
  Eugen Rochko 21ad21cb50
Improve signature verification safeguards (#8959) 5 years ago
  Eugen Rochko a00ce8c92c
Remove dead code (#8919) 5 years ago
  Eugen Rochko bb71538bb5
Redesign public profiles and toots (#8068) 5 years ago
  Marty McGuire 8fea9cc311 Typo in signature verification failure logging (#7916) 5 years ago
  Eugen Rochko dfb6907e08
HTTP signatures spec no longer requires algorithms field (#7525) 6 years ago
  ThibG 352bae8c3e Update session activation time (fixes #5605) (#7408) 6 years ago
  Yamagishi Kazutoshi 87e3f0a41d Fix spec for sr-Latn (#7203) 6 years ago
  ThibG 1364e9e4ae Fix follow/unfollow buttons on public profile (fixes #7036) (#7040) 6 years ago
  Eugen Rochko 39f27b6cf3
If DEFAULT_LOCALE is set, enforce it instead of HTTP request locale (#6817) 6 years ago
  Akihiko Odaki 51d760960c Set the default locale in config (#6580) 6 years ago
  puckipedia 8e4cf6282b Allow retrieval of private statuses (single or in outbox) using HTTP signatures (#6225) 6 years ago
  Eugen Rochko 1cc44cba81
Fix #6331 (#6341) 6 years ago
  Akihiko Odaki 613e7c7521 Rename ResolveRemoteAccountService to ResolveAccountService (#6327) 6 years ago
  Eugen Rochko 9b3b40df66
Fix regeneration marker not expiring (#6290) 6 years ago
  Eugen Rochko 38fc1b498d
Add more instance stats APIs (#6125) 6 years ago
  Eugen Rochko feed07227b
Apply a 25x rate limit by IP even to authenticated requests (#5948) 6 years ago
  Eugen Rochko a865b62efc
Rate limit by user instead of IP when API user is authenticated (#5923) 6 years ago
  Eugen Rochko e84fecb7e9
Add logging of admin actions (#5757) 6 years ago
  Eugen Rochko 7bb8b0b2fc
Add moderator role and add pundit policies for admin actions (#5635) 6 years ago
  Eugen Rochko b8db386e05 Fix UserTrackingConcern firing on every request, optimize some queries (#5368) 6 years ago
  Akihiko Odaki 63f0979799 Validate id of ActivityPub representations (#5114) 6 years ago
  ThibG dfaa219f88 Fix HTTP responses for salmon and ActivityPub inbox processing (#5200) 6 years ago
  Eugen Rochko 76f360c625 If HTTP signature is wrong and webfinger cache is stale, retry with resolve (#5129) 6 years ago
  Eugen Rochko 72bb3e03fd Support more variations of ActivityPub keyId in signature (#4630) 6 years ago
  Eugen Rochko a2aeacbfee Add alternate links to ActivityPub resources from HTML/HEAD variants (#4586) 6 years ago
  Eugen Rochko fdea173237 Add Digest header to requests with body, handle acct and URI keyId (#4565) 6 years ago
  Eugen Rochko 1618b68bfa HTTP signatures (#4146) 6 years ago
  Eugen Rochko dc8a6244fc Fix #2619 - When redis feed is empty, fall back to database (#3721) 7 years ago
  Akihiko Odaki (@fn_aki@pawoo.net) 4919b89ab8 Improve default language decision and spec (#3351) 7 years ago
  Matt Jankowski f0634ba876 Coverage improvement and concern extraction for rate limit headers in API controller (#3625) 7 years ago