Commit graph

17862 commits

Author SHA1 Message Date
Brian Gough
1940e9b061 Merge pull request #1523 from sharelatex/bg-avoid-unwanted-fallback-on-network-errors
avoid fallback to old websocket if initial connection succeeded

GitOrigin-RevId: 1b3f38d0a0f4889b9a15fa071de90a0a9c9a5699
2019-02-14 14:39:19 +00:00
Shane Kilkelly
e78487922e Merge pull request #1513 from sharelatex/sk-migrate-read-and-write-token-prefix-post-deploy
Script to re-activate token access for select projects

GitOrigin-RevId: df379f49ec840948ec1afc0864b35b5b5746ebc1
2019-02-14 11:09:45 +00:00
Shane Kilkelly
349d731745 Merge pull request #1493 from sharelatex/sk-read-write-token-match-on-prefix
Constant-time comparison for read-write tokens

GitOrigin-RevId: ddd83de551c540544fde426d7d5aca9f4c83fcc7
2019-02-14 11:09:40 +00:00
Shane Kilkelly
25a0ea8752 Merge pull request #1495 from sharelatex/sk-migrate-read-and-write-token-prefix
Add migrations for new project property: `tokens.readAndWritePrefix`

GitOrigin-RevId: 276a9e53533ae76e04e20fd94234f65999874662
2019-02-14 10:27:02 +00:00
Brian Gough
00cdc008d5 Merge pull request #1508 from sharelatex/bg-add-websocket-fallback-option
add fallback to siteUrl if websocket fails

GitOrigin-RevId: fd866d17475cb974e4158ac7a89e972c66f0dd97
2019-02-13 09:20:35 +00:00
Brian Gough
038c81f868 use explicit json content-type to avoid security issues with text/html 2019-02-12 16:54:59 +00:00
Brian Gough
8c5d74faef use explicit json content-type to avoid security issues with text/html 2019-02-12 16:45:11 +00:00
Timothée Alby
c4dd8b5da8 Merge pull request #1502 from sharelatex/jel-social-metatags
Update `og` metatags and add protocol to image URL

GitOrigin-RevId: 9548ca5f378cb770e454bc75062e80bd1c3da9ac
2019-02-12 15:48:00 +00:00
Timothée Alby
fb5caf7b63 Merge pull request #1504 from sharelatex/jel-portal-sign-in-redirect
Add redircts when signing in/up via portal

GitOrigin-RevId: b84105f35b5f1c14fa57ca91e766b8b6de00ccd7
2019-02-12 15:47:53 +00:00
Timothée Alby
f01f80c2bb Merge pull request #1505 from sharelatex/ns-fix-regex
remove unecessary $ from regex

GitOrigin-RevId: 5998536f71298daeab2845d070150451bbb4a858
2019-02-12 15:47:47 +00:00
Timothée Alby
b39626751a Merge pull request #1499 from sharelatex/ta-open-redirect-fix
Prevent Open Redirects

GitOrigin-RevId: 8cd2ead74de60f47b728ac227c21440281b111a5
2019-02-12 15:47:41 +00:00
Henry Oswald
6fb6086ba1 remove console.log 2019-02-12 14:28:42 +00:00
Henry Oswald
8bc3ff69e1 Merge pull request #30 from sharelatex/ho-docker
Dockerised
2019-02-12 14:15:18 +00:00
Chrystal Griffiths
26acdfd072 Add comment explaining why not sending anon data up 2019-02-12 14:06:59 +00:00
Chrystal Griffiths
bb06f82e04 Still send cursorData for logged in users 2019-02-12 14:00:47 +00:00
Henry Oswald
fa40e2c95f Merge pull request #44 from sharelatex/ho-docker-no-keychange
docker build script minimal
2019-02-12 13:45:49 +00:00
Henry Oswald
0a0fc91f28 Update app.coffee 2019-02-12 13:27:13 +00:00
Alasdair Smith
9b97af8977 Merge pull request #1403 from sharelatex/as-swap-brand-prefix
Swap brand prefix so OL is the default

GitOrigin-RevId: 60f4f03598fb6befc1ce790d39f546490612a1db
2019-02-12 11:32:28 +00:00
Chrystal Griffiths
2ec760403f Revert to method not sending cursorData because of duplication 2019-02-11 11:52:14 +00:00
Simon Detheridge
255981bdc2 Merge pull request #1486 from sharelatex/ta-subscription-dash-fix
Fix Subscirption Dashboard Messaging

GitOrigin-RevId: 601b0df74c6f9f6bcc1c3ba6ecbf64721bc6fb99
2019-02-11 11:42:34 +00:00
Simon Detheridge
7dcc807caf Merge pull request #1479 from sharelatex/sk-check-read-token-against-v1
Check generated read-tokens against v1

GitOrigin-RevId: 15749a41a295c0401b0a39968f2c3657f8abebb8
2019-02-11 11:42:29 +00:00
Simon Detheridge
78b79999e9 Merge pull request #1492 from sharelatex/spd-dropbox-unlink-csrf
Add csrf protection for unlinking Dropbox accounts

GitOrigin-RevId: 00bbf0b8d4dc9f97098a645267bf23a6c3e5eea3
2019-02-11 11:42:24 +00:00
Simon Detheridge
c7f30bdfec Merge pull request #1494 from sharelatex/spd-overleaf-v1-oauth-state
Use 'state' parameter to prefent CSRF attacks when authenticating with v1

GitOrigin-RevId: bf5f8ddffa391d8f3ca84d3588df906b08eb018d
2019-02-11 11:42:20 +00:00
Simon Detheridge
ea807d053e Merge pull request #1489 from sharelatex/spd-mendeley-csrf
Enforce use of csrf token in Mendeley / tpr OAuth

GitOrigin-RevId: b615ee195442123e0cd8ff19a864909ac2e6496d
2019-02-11 11:42:15 +00:00
Simon Detheridge
9e07daba0b Merge pull request #1490 from sharelatex/ns-remove-ip-endpoint
remove /ip endpoint

GitOrigin-RevId: 42ea1ff6db6cba5e74a6e6c133a4d9f2b93d4a2e
2019-02-11 11:42:10 +00:00
Chrystal Griffiths
cb12e1c6f6 Send an empty string for every nameless user 2019-02-08 15:39:51 +00:00
Henry Oswald
3bc4cb492a added log line 2019-02-07 16:30:53 +00:00
Brian Gough
79c1dc5c1a use explicit json content-type to avoid security issues with text/html 2019-02-07 15:54:13 +00:00
Henry Oswald
08723f8972 revert health check redis types 2019-02-07 15:53:26 +00:00
Henry Oswald
ecaef6485b revert the removal of realtime keyspace 2019-02-07 15:27:51 +00:00
Henry Oswald
b5564095f3 add /health_check/redis route back in 2019-02-07 15:10:40 +00:00
Henry Oswald
73bd264401 remove realtime keys in settings, no longer used 2019-02-07 14:55:24 +00:00
Henry Oswald
1fc1b4206e add shutDownInProgress check into sig listening 2019-02-07 13:57:38 +00:00
Henry Oswald
7999b33faa Merge branch 'master' of https://github.com/sharelatex/metrics-sharelatex 2019-02-07 09:47:56 +00:00
Henry Oswald
15d14d8e2b add injectMetricsRoute into statsd so it doens't blow up 2019-02-07 09:47:29 +00:00
Henry Oswald
2998750a33 fix redis version lock 2019-02-06 16:01:44 +00:00
Henry Oswald
4e1a2c787c Revert "turn down logging, use logger.info for less important data"
This reverts commit c5f91428e3c7702fbbd3ffd1ef7a772d513f33f2.
2019-02-06 15:29:22 +00:00
Henry Oswald
d85bf5cedb remove extra logging line 2019-02-06 15:26:12 +00:00
Henry Oswald
54d16bcab9 remove redis from config, it doesn't use redis 2019-02-06 15:20:30 +00:00
Ersun Warncke
81e3db260c Merge pull request #1472 from sharelatex/ew-add-close-site-and-private-disconnect-route
Add close site setting and private disconnect all users route

GitOrigin-RevId: d078c053ba4e5f5c048f30f2a6d509966736b3e0
2019-02-06 14:24:52 +00:00
Henry Oswald
01d3f4bff4 Merge pull request #54 from sharelatex/ho-docker
Update docker build process
2019-02-06 13:42:03 +00:00
Henry Oswald
0151826eaf clear error if s3 keys are not set for tests 2019-02-06 12:23:15 +00:00
Henry Oswald
2adae20368 remove a console.log 2019-02-06 11:43:11 +00:00
Henry Oswald
7caf3d4935 remove debugging 2019-02-06 11:29:31 +00:00
Henry Oswald
cef7e1e17b Merge branch 'master' into ho-docker 2019-02-06 11:28:16 +00:00
Henry Oswald
2a68ddca6e Merge pull request #20 from sharelatex/ho-docker
Move to docker based builds
2019-02-06 10:35:20 +00:00
Brian Gough
c51461da09 Merge pull request #1480 from sharelatex/bg-allow-separate-websocket-url
allow setting separate wsUrl for websockets

GitOrigin-RevId: afd4f441397c6b4b402e342f1dec01c971847a0f
2019-02-06 10:20:36 +00:00
Henry Oswald
f4602d0b38 Merge pull request #47 from sharelatex/ho-docker
Move to docker build process
2019-02-06 10:06:13 +00:00
Henry Oswald
ee9bfcf7e8 Merge pull request #32 from sharelatex/ho-docker
Dockerise builds
2019-02-06 09:47:44 +00:00
Henry Oswald
8d74b9e2ec call app chat not chat-sharelatex 2019-02-05 18:50:57 +00:00