discourse/app
Robin Ward d1c12539dd SECURITY: XSS with title selector on preferences page
Note this is very low severity as the group needs to be created with a
default title that contains HTML, and group creation is restricted to
staff members right now.
2019-07-09 17:35:26 -04:00
..
assets SECURITY: XSS with title selector on preferences page 2019-07-09 17:35:26 -04:00
controllers DEV: Respond with error 400 to uploads requested via XHR 2019-06-27 11:30:05 +02:00
helpers replace subfolder on cdn url conversion between general cdn and s3 (#7764) 2019-06-17 11:51:17 -07:00
jobs FIX: Don't send notification email when user isn't allowed to see topic 2019-07-02 09:05:36 +10:00
mailers SECURITY: Strip HTML from invite emails 2019-07-05 14:58:46 -04:00
models FIX: Don't send notification email when user isn't allowed to see topic 2019-07-02 09:05:36 +10:00
serializers FIX: In reply to would sometimes have a broken link 2019-06-10 11:33:10 -04:00
services FIX: iterate when clearing watched words cache 2019-07-04 08:59:01 -07:00
views SECURITY: Add confirmation screen when logging in via email link 2019-06-17 18:20:48 +01:00