1. 27 Nov, 2018 2 commits
  2. 26 Nov, 2018 12 commits
  3. 23 Nov, 2018 10 commits
  4. 21 Nov, 2018 2 commits
  5. 20 Nov, 2018 3 commits
  6. 19 Nov, 2018 1 commit
  7. 18 Nov, 2018 7 commits
  8. 16 Nov, 2018 1 commit
  9. 15 Nov, 2018 1 commit
    • Alessio Caiazza's avatar
      Validate URI scheme also for internal URI · a4ef6934
      Alessio Caiazza authored
      This is a backport for 11.4 stable branch.
      
      Gitlab::UrlBlocker ignores scheme when validating URI matching either
      config.gitlab or config.gitlab_shell
      
      This patch enforces matching config.gitlab.protocol for internal web and
      ssh for internal shell.
      
      A cleanup migration for stored XSS from environments table is included.
      a4ef6934
  10. 14 Nov, 2018 1 commit