Skip to content

Fix/head request journal views - #121

Closed
alphatownsman wants to merge 1864 commits into
doubaniux:masterfrom
neodb-social:fix/head-request-journal-views
Closed

alphatownsman wants to merge 1864 commits into
doubaniux:masterfrom
neodb-social:fix/head-request-journal-views

Conversation

@alphatownsman

Copy link
Copy Markdown
Contributor

No description provided.

Your Name and others added 28 commits February 1, 2026 13:31
Bumps the uv group with 1 update in the / directory: [cryptography](https://github.com/pyca/cryptography).


Updates `cryptography` from 46.0.4 to 46.0.5
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@46.0.4...46.0.5)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.5
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Address review feedback: the input element is used purely for JavaScript
navigation and is not inside a form, so type="button" is more semantically
correct than type="submit".
Bumps the uv group with 1 update in the / directory: [pillow](https://github.com/python-pillow/Pillow).


Updates `pillow` from 12.1.0 to 12.1.1
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](python-pillow/Pillow@12.1.0...12.1.1)

---
updated-dependencies:
- dependency-name: pillow
  dependency-version: 12.1.1
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Add HTTP/HTTPS scheme checks before making outbound requests in
get_redirected_url and _scrape_with_custom to prevent server-side
request forgery via non-HTTP schemes (e.g. file://, gopher://).
The ReviewDB entry incorrectly pointed to neodb.social instead of reviewdb.app.

Fixes #1316
- Add is_valid_url() in common/validators.py that validates URL format
  and resolves hostname to reject private/reserved IPs (DNS rebinding)
- Apply is_valid_url() to search_by_ap_url() and SiteManager.get_site_by_url()
- Fix open redirect in search view: r= parameter now requires same-site URL
- Escape text before building HTML in highlight template filter to
  prevent stored XSS via malicious item titles in search results
- Add is_valid_url() check in RSS.parse_feed_from_url() to block
  non-HTTP schemes and private IP targets via urllib.request.urlopen()
- Escape title in review_translate HTTP response to prevent XSS
- Add OAuth state parameter to Mastodon and Threads login flows to
  prevent CSRF attacks during authentication
- Validate URL scheme in FediverseHtmlParser.create_link() to block
  javascript:, data:, and vbscript: URIs from federated posts
Escape item title and URL in ReviewFeed.item_description() to prevent
XSS when RSS readers render the feed content as HTML.
Replace random.randint (Mersenne Twister) with secrets.randbelow
(CSPRNG) for generating email login/verification codes.
Add codecov.yml to make coverage status checks informational on main
branch while keeping them enforced on PRs. Update .dockerignore to
exclude additional files not needed in Docker build context.
* Add quote post support (FEP-044f)

- Add quote_url field to shadow Post model with migration
- Add quote_url param to Takahe.post() helper
- Add quoted_post/quoted_post_ cached property for template rendering
- Display quoted post in web UI template
- Update neodb-takahe submodule with full AP quote implementation
@alphatownsman
alphatownsman deleted the fix/head-request-journal-views branch April 3, 2026 06:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants