Neil Lalonde
760d51cab1
Version bump to v2.2.2
2019-03-01 12:27:02 -05:00
Sam
3ac5f526be
SECURITY: bypass long GET requests
...
In some rare cases we would check URLs with very large payloads
this ensures we always bypass and do not read entire payloads
2019-02-27 21:52:40 +11:00
David Taylor
c10941bbde
REFACTOR: Proxy letter avatars in rails instead of nginx
...
Co-authored-by: Sam Saffron <sam.saffron@gmail.com>
Co-authored-by: David Taylor <david@taylorhq.com>
This gives more control over the request. In particular we can easily
lookup DNS dynamically, instead of only upon NGINX startup.
Previously, NGINX was looking up IP for the letter avatar service and
caching the CDN IP address, this caused issues if CDN changed IP, in
which letter avatars would be broken till a container restarted.
NGINX config has been updated to add caching. This change will require
a container rebuild.
The proxy will now function in development environments, so the patch
for `letter_avatar_proxy` has been removed.
2019-02-18 08:51:58 +11:00
Kris
4325d0ffc3
UX: Reduce font size on about pages
...
(cherry picked from commit 3d11064a33
)
2019-02-14 20:12:55 -05:00
Sam
904e5ac09c
FIX: unable to create new categories
...
Previous attempt at 70adb940
missed the critical "everyone" group from
staff, leading to a case where staff was no longer able to create categories
2019-02-15 10:28:13 +11:00
Bianca Nenciu
8e1efe6899
DEV: Improve test.
2019-02-14 23:04:38 +02:00
Bianca Nenciu
426810fcaf
FIX: Fix failing test.
2019-02-14 23:04:34 +02:00
Bianca Nenciu
37214bc3eb
SECURITY: Do not leak private group names. ( #7008 )
2019-02-14 23:04:32 +02:00
Vinoth Kannan
2fb5271069
FIX: Bump onebox version to include imgur security fix
...
(cherry picked from commit 36ff971c9c
)
2019-02-13 11:51:15 +05:30
Vinoth Kannan
e11ae2a5ab
FIX: Bump onebox version to include imgur security fix
...
(cherry picked from commit fb911766ee
)
2019-02-13 11:50:35 +05:30
Arpit Jalan
e1094724fb
FIX: some posters were not getting added to topic_allowed_users when moving posts to a new PM
...
If a user posted twice in a topic then subsequent posters were not getting added as topic_allowed_users.
2019-02-11 18:25:06 +05:30
Neil Lalonde
e9d1597f81
Version bump to v2.2.1
2019-02-07 10:56:03 -05:00
Kris
3ad5f6ea4b
UX: checkboxes were too close to other inputs
2019-02-07 10:09:19 -05:00
Bianca Nenciu
589187b732
FIX: Fix delete button for Tag Groups. ( #6965 )
2019-02-07 10:09:16 -05:00
Kris
dc43fb69d1
UX: Minor button icon color fixes
2019-02-07 10:09:13 -05:00
Bianca Nenciu
beb6e154ef
FIX: in:title should work irrespective of the order. ( #6968 )
2019-02-07 10:09:08 -05:00
Dan Ungureanu
cc983e3b11
UX: Use translatedLabel for aria-label in buttons.
2019-02-07 10:09:05 -05:00
Maja Komel
7426c427a1
fix typo
2019-02-07 10:09:02 -05:00
David Taylor
9f49007b7b
FIX: Rescue and display import errors when updating theme via git
2019-02-07 10:08:59 -05:00
Sam
bfceb29db8
DEV: update logster to stable release
...
This update logster to the stable 2.0.1 release instead of running a pre
release
2019-02-07 10:08:56 -05:00
Gerhard Schlager
d576a3fa57
FIX: S3 endpoint broke bucket creation in non-default region
2019-02-07 10:08:53 -05:00
Kris
12cf3320c2
UX: Turn off autocomplete on composer title
2019-02-07 10:08:50 -05:00
Régis Hanol
1e9a884244
UX: disable browser's autocomplete in search menu
2019-02-07 10:08:47 -05:00
David Taylor
f01ca1f22d
FIX: Correctly process {{each}} in raw handlebars templates for themes
2019-02-07 10:08:43 -05:00
Jeff Wong
9564eac72a
FIX: Register pan events for touch only
...
* touch events - only register touch, not pointer events
* immediately request redraw frame, do not wait for after render to fire.
2019-02-07 10:08:40 -05:00
Gerhard Schlager
8573ac0d18
FIX: Unpause Sidekiq before uploading backup to S3
...
No need to pause Sidekiq longer than really needed. Uploads to S3 can take a long time.
2019-02-07 10:08:37 -05:00
Kris
a36527ca77
Minor icon color fix
2019-02-07 10:08:34 -05:00
Sam
894b98685b
FIX: old migration was loading up invalid model schema
...
Generally we should never be touching AR objects in migrations, this is
super risky as we may end up with invalid schema cache.
This code from 2013 did it unconditionally. This change amends it so:
1. We only load up schema if we have no choice
2. We flush the cache before and after
This makes this migration far less risky.
2019-02-07 10:08:29 -05:00
Kris
5ef75197da
UX: Header icon color fix
2019-02-01 17:50:00 +00:00
David Taylor
78eb51f780
SECURITY: Escape HTML in dashboard report tables
2019-02-01 13:11:14 +00:00
David Taylor
94ccedb730
FIX: Login button icons should be white
2019-02-01 11:41:54 +00:00
Kris
34f120c011
Header icon focus color fix
2019-02-01 10:50:40 +00:00
Neil Lalonde
bbb4b6ccef
Version bump to v2.2.0
2019-01-31 17:41:36 -05:00
Neil Lalonde
87f89e92a8
Merge diffs from master
2019-01-31 17:24:35 -05:00
Neil Lalonde
23e2a01572
Merge master
2019-01-31 17:18:47 -05:00
Neil Lalonde
6bfd2b6eaf
Update translations
2019-01-31 16:27:07 -05:00
Kris
95e16ab0a6
UX: Badge checkmarks should be round
2019-01-31 15:27:46 -05:00
Kris
6141290399
FIX: Mobile button colors
2019-01-31 15:13:54 -05:00
Robin Ward
720e896e17
FIX: PostActionCreator
was not checking the guardian properly
...
It also exposed a bug in the EmailReceiver spec, where a test had a user
liking their own post and was not failing.
2019-01-31 14:48:42 -05:00
Gerhard Schlager
ec7f418a22
REFACTOR: Simplify finding the opengraph image
...
* removes deprecation warnings for "logo url"
* adds the "large icon" as fallback before the "apple touch icon"
2019-01-31 20:46:15 +01:00
Penar Musaraj
3500acf2f6
FIX: refresh admin/customize/themes route after import
...
Fixes an issue where the imported color schemes of a theme were not available immediately in the UI.
2019-01-31 14:29:09 -05:00
Kris
0dfcbdeb54
ok/cancel button fix
2019-01-31 14:20:27 -05:00
Kris
3d394a6144
prettier
2019-01-31 14:06:32 -05:00
Kris
3eb000a968
UX: Overflow hidden was causing some icons to be cropped
2019-01-31 14:03:11 -05:00
Kris
94f16ba931
UX: Make button icons use lighter color instead of opacity
2019-01-31 13:59:49 -05:00
David Taylor
886ba9dff9
DEV: Correct spec for theme export change
2019-01-31 17:52:03 +00:00
David Taylor
c0b1a1a914
DEV: Do not add -theme
suffix to theme exports
...
This could be confusing if the theme name already ended in "theme" or "theme-component"
2019-01-31 17:46:39 +00:00
David Taylor
43f3bf71ba
FIX: Imported themes should set their color scheme automatically
2019-01-31 17:45:11 +00:00
David Taylor
b3a41878ec
FIX: Exporting themes when uploads are on S3
2019-01-31 17:34:34 +00:00
Régis Hanol
1021a42b22
FIX: new mailgun webhooks
2019-01-31 17:52:33 +01:00