Jasmin
0728a6a709
Merge upstream security fixes of v4.0.5 ( #1316 )
...
It's already running on our instance (queer.group) and working fine.
Manually reviewed the changes, hadn't found anything that could break
hometown-specific code.
And to update our instance, I also just followed the [steps on the
release](https://github.com/mastodon/mastodon/releases/tag/v4.0.5 ) aka
`bundle install && yarn install` followed by a restart of all processes.
---------
Co-authored-by: Claire <claire.github-309c@sitedethib.com>
Co-authored-by: Daniel M Brasil <danielmbrasil@protonmail.com>
Co-authored-by: Emelia Smith <ThisIsMissEm@users.noreply.github.com>
Co-authored-by: Vyr Cossont <VyrCossont@users.noreply.github.com>
Co-authored-by: Renaud Chaput <renchap@gmail.com>
2023-07-06 12:30:13 -07:00
Darius Kazemi
9fe562c31c
Merge tag 'v4.0.4' into hometown-4.0.4
2023-05-19 11:25:13 +01:00
Claire
214c367095
Bump version to v4.0.4
2023-04-04 12:39:56 +02:00
Claire
05c45e9eeb
Fix unescaped user input in LDAP query ( #24379 )
...
Fix CVE-2023-28853
2023-04-04 12:39:56 +02:00
Claire
448986438e
Change root Chewy strategy to emit a warning instead of erroring out in production mode ( #24327 )
2023-04-04 12:39:56 +02:00
Claire
274bb193b2
Fix invalid/expired invites being processed on sign-up ( #24337 )
2023-04-04 12:39:56 +02:00
Sai
46b91cd817
Update Ruby to 3.0.6 ( #24333 )
2023-04-04 12:39:56 +02:00
mhkhung
acc277a152
3.0.5 version of cimg/ruby:3.0-node upgraded to node 18 ( #21873 )
...
Node 18 caused build to fail
2023-04-04 12:39:56 +02:00
Robert R George
971e8b8f5f
Wrap db:setup with Chewy.strategy(:mastodon) ( #24302 )
2023-04-04 12:39:56 +02:00
Claire
aa37eeadf3
Fix user archive takeout when using OpenStack Swift or S3 providers with no ACL support ( #24200 )
2023-04-04 12:39:56 +02:00
Claire
f75fba0531
Fix crash in `tootctl` commands making use of parallelization when Elasticsearch is enabled ( #24182 )
2023-04-04 12:39:56 +02:00
Claire
2125dbf610
Bump version to v4.0.3
2023-03-16 22:49:35 +01:00
Claire
9715a211c7
Add warning for object storage misconfiguration ( #24137 )
2023-03-16 22:49:35 +01:00
Eugen Rochko
a6217bd035
Change user backups to use expiring URLs for download when possible ( #24136 )
2023-03-16 22:49:35 +01:00
Claire
3e9978071b
Update changelog
2023-03-16 22:05:00 +01:00
Claire
8236c3affc
Update changelog
2023-03-16 12:04:15 +01:00
Nick Schonning
43a16e43ba
Skip pushing containers on forks ( #24106 )
2023-03-16 12:02:31 +01:00
Renaud Chaput
520377a609
Use Github Container Registry as the official container image source ( #24113 )
2023-03-16 12:01:41 +01:00
Nick Schonning
0941230e22
Skip Docker CI Login/Push on forks ( #23564 )
2023-03-16 12:01:41 +01:00
Renaud Chaput
98c59c1d58
Push Docker images to Github Container Registry as well ( #24101 )
2023-03-16 12:01:39 +01:00
Claire
2c3cb903ad
Fix misleading error code when receiving invalid WebAuthn credentials ( #23568 )
2023-03-16 11:58:46 +01:00
Claire
86924c344d
Fix incorrect post links in strikes when the account is remote ( #23611 )
2023-03-16 11:58:34 +01:00
Claire
f834fdaf6a
Fix dashboard crash on ElasticSearch server error ( #23751 )
2023-03-16 11:57:23 +01:00
Claire
1da72b41c7
Update changelog
2023-03-14 10:05:48 +01:00
Claire
97e19e8802
Add mail headers to avoid auto-replies ( #23597 )
2023-03-14 10:00:38 +01:00
Claire
bd43f7d4cc
Add `lang` tag to native language names in language picker ( #23749 )
2023-03-14 10:00:28 +01:00
Thijs Kinkhorst
c44ddbdb3e
Fix paths with url-encoded @ to redirect to the correct path ( #23593 )
2023-03-14 10:00:19 +01:00
Christian Schmidt
4ea4c3f49c
Unescape HTML entities ( #24019 )
2023-03-14 10:00:13 +01:00
Christian Schmidt
419bd9281d
Do not strip tags from `Setting.site_short_description` ( #23975 )
2023-03-14 10:00:07 +01:00
Claire
d6f1bd2e08
Fix sidekiq jobs not triggering Elasticsearch index updates ( #24046 )
2023-03-14 09:59:56 +01:00
Rodion Borisov
c2d38ef0f1
Center the text itself in upload area ( #24029 )
2023-03-14 09:59:46 +01:00
Claire
ad77e8a2fb
Fix `/api/v1/streaming` sub-paths not being redirected ( #23988 )
2023-03-14 09:59:38 +01:00
Eugen Rochko
0f2e8476e0
Fix pgBouncer resetting application name on every transaction ( #23958 )
2023-03-14 09:59:30 +01:00
Claire
290d02e936
Fix original account being unfollowed on migration before the follow request could be sent ( #21957 )
2023-03-14 09:59:00 +01:00
Claire
11f04e3b97
Fix unconfirmed accounts being registered as active users ( #23803 )
2023-03-14 09:58:47 +01:00
Claire
76c96cdd72
Fix error when displaying post history of a trendable post in the admin interface ( #23574 )
2023-03-14 09:58:34 +01:00
Claire
c22c4247d9
Fix server error when failing to follow back followers from `/relationships` ( #23787 )
2023-03-14 09:58:26 +01:00
Claire
348599a543
Fix inefficiency when searching accounts per username in admin interface ( #23801 )
2023-03-14 09:58:13 +01:00
Botao Wang
0e3f06da99
Fix sidebar cut-off on small screens in admin UI ( #23764 )
2023-03-14 09:58:05 +01:00
Dean Bassett
cc80f4ed9b
Fix case-sensitive check for previously used hashtags ( #23526 )
2023-03-14 09:57:10 +01:00
Claire
e2103c9175
Fix “Remove all followers from the selected domains” being more destructive than it claims ( #23805 )
2023-03-14 09:50:57 +01:00
Darius Kazemi
7aa6f41c61
Bump version
2023-01-13 17:35:16 -08:00
Darius Kazemi
4c577a769a
Fix leak where edited, local-only statuses federated
...
More info to come in release notes, coming very very soon.
2023-01-13 16:43:16 -08:00
Darius Kazemi
15e78b9a0a
One more fixup per @gargron suggestion
2023-01-05 13:43:04 -08:00
Darius Kazemi
d6171de99f
Fix ranking order to correct direction
2023-01-05 13:12:00 -08:00
Darius Kazemi
7d12ca1fa5
Make autosuggest for mentions return followed accounts first
...
This makes it so that (when elasticsearch is disabled) when a user types '@foo' in the compose box, they are first going to get accounts they follow ordered by the ranking algorithm, and then second they will get accounts they do not follow, also ordered by the ranking algorithm.
This makes behavior more consistent with user expectation and also with results when elasticsearch is enabled.
Fixes #1272
2023-01-05 12:51:57 -08:00
Darius Kazemi
b761fbac34
Linter fix
2023-01-03 09:44:29 -08:00
Darius Kazemi
c88d2835fb
Add sign-in button to mobile view when logged out
2023-01-03 09:39:31 -08:00
Darius Kazemi
ae4ec996a4
Add `local_only` to FEDERATION.md
2023-01-02 19:33:38 -08:00
Darius Kazemi
84d86aa0bd
Removing ellipsis which render pooly on Safari
2023-01-02 18:29:39 -08:00