Commit Graph

1619 Commits (528b387563d05cb28bbde2fe0ce4599c62b0f02e)

Author SHA1 Message Date
Andrew Dolgov 528b387563 update individual feed in a separate process to prevent PHP fatal errors
(for example, OOM) from stopping the entire batch
this should also slightly increase memory budget for update processes
5 years ago
Andrew Dolgov e993d4feb2 Merge branch 'master' of git.fakecake.org:tt-rss 5 years ago
Andrew Dolgov 71e9f70b8a search_to_sql: use per-user default language instead of hardcoded english if isn't specified explicitly 5 years ago
Andrew Dolgov d0ed7890df prev: add missing class 5 years ago
Andrew Dolgov 215f388992 move timestamp-related stuff to a separate class 5 years ago
Andrew Dolgov 05744bb474 fix updater never scheduling feeds for update if they never been updated before while having default update interval set 5 years ago
Andrew Dolgov 8fb2baecdc another hack for validation of URLs with invalid characters 5 years ago
Andrew Dolgov a897c4165b validate URLs: convert IDN to punycode before passing URL to filter_var() 5 years ago
Andrew Dolgov 6811d0bde2 use self:: in some places to invoke static methods from the same class 5 years ago
Andrew Dolgov b5710baf34 - don't fail on non-ascii characters when validating URLs
- fix IDN hostnames not being converted properly
5 years ago
Andrew Dolgov ab6aa0ad3e fix previous re: resolve_redirects 5 years ago
Andrew Dolgov 74568df4ff remove a lot of stuff from global context (functions.php), add a few helper classes instead 5 years ago
Andrew Dolgov 3dd4169b5f clarify some URL validation-related error messages 5 years ago
Andrew Dolgov 4785f21316 update_rss_feed: log effective URL after fetching
validate_url: treat scheme as case-insensitive
5 years ago
Andrew Dolgov 05ef9aac2f update URL pointing to version.json 5 years ago
Andrew Dolgov 03a337a660 add basic safe mode which doesn't load any user plugins 5 years ago
Andrew Dolgov a4525d31b2 replace FALSE with false so that static analyzer shuts up about it 5 years ago
Andrew Dolgov afa0023c51 don't try to update manually disabled feeds even if they haven't been updated before or are marked for a manual update 5 years ago
Andrew Dolgov 37f41a5246 forgotpass: use type strict comparison for reset token 5 years ago
Andrew Dolgov e3adacc588 fix several cases of Db class being invoked as wrong name (as DB) 5 years ago
Andrew Dolgov 89d53a7f49 fix typo in previous 5 years ago
Andrew Dolgov 1f79d614c4 fix OTP QR code not displayed because of CSRF token passed as a query
parameter
use type-strict comparison when validating CSRF token on the backend
5 years ago
Andrew Dolgov 9d3c794983 subscribe: allow pre-filling feed URL if passed via query string 5 years ago
Andrew Dolgov 33fdde249e pass CSRF token to opml import and feed icon replace dialogs 5 years ago
Andrew Dolgov 42b5564d1e editarticletags: load dialog via XHR 5 years ago
Andrew Dolgov 0706a328a4 handler: default base csrf_ignore() to false 5 years ago
Andrew Dolgov 0a142912d3 backend handler: require CSRF, remove obsolete code 5 years ago
Andrew Dolgov 154417d80b public/logout: require valid CSRF token 5 years ago
Andrew Dolgov cbcb10a272 Feeds: load quickaddfeed and search dialogs via XHR w/ CSRF protection 5 years ago
Andrew Dolgov 8080c525fd - backend: require CSRF token to be passed via POST
- do not leak CSRF token via GET request in feed debugger
- rework Article/redirect to use POST
5 years ago
Andrew Dolgov e670ac2ee5 require CSRF token for Article/redirect 5 years ago
Andrew Dolgov 7e50c6c4b5 - enable CSRF support earlier
- remove rpc/sanityCheck from CSRF-excluded calls
5 years ago
Andrew Dolgov 79f102c25d af_proxy_http: never print received data directly, always redirect to cached_url
cache/getUrl: basename() passed filename just in case
5 years ago
Andrew Dolgov 4a074111b5 user preferences: forbid < and > characters when changing passwords (were silently stripped on save because of clean()) 5 years ago
Andrew Dolgov da98ba662e public/subscribe: require valid CSRF token when validating the form 5 years ago
Andrew Dolgov c3d14e1fa5 - fix multiple vulnerabilities in af_proxy_http
- fix vulnerability in rewrite_relative_url() which prevented some URLs from being properly absolutized
- fetch_file_contents: validate all URLs before requesting them
- validate URLs: explicitly whitelist http and https scheme, forbid everything else
- DiskCache/cached_url: only serve whitelisted content types (images, video)
- simplify filename/URL handling code, remove and consolidate some less-used functions
5 years ago
Andrew Dolgov a922b3cc6d order_to_override_query: allow HOOK_HEADLINES_CUSTOM_SORT_OVERRIDE plugins to override built-in sorting 5 years ago
Andrew Dolgov 67f02e2aa7 properly return counters for labels with zero assigned articles
refs https://community.tt-rss.org/t/label-counter-doesnt-update-when-count-goes-down-to-zero/3766
5 years ago
Rodney Stromlund 88ced02622 Silence php 7.2 error message generated in `session_set_cookie_params`. 5 years ago
Andrew Dolgov ddf9227dc4 pluginhost: allow overriding default sort modes via HOOK_HEADLINES_CUSTOM_SORT_MAP etc 5 years ago
Andrew Dolgov dfa65e9374 move order_by to SQL override logic into a separate function 5 years ago
Andrew Dolgov 48be005774 instead of taking batch timestamp and score (?) into account, make oldest first sorting work consistently with newest first - i.e. rely on feed-provided timestamp 5 years ago
Andrew Dolgov 05a47e5cf4 OPML: export/import per-feed purge interval 5 years ago
Paco Esteban c4ee0e25a1 more int/string type mismatches on getCategories 6 years ago
Paco Esteban 3da618e0ea make sure all ints are casted (to int) on getCategories 6 years ago
fox 68b78ecd3d Merge branch 'bugfix/invalid-opml' of wn/tt-rss into master 6 years ago
Andrew Dolgov b6372a846d when exporting OPML via web UI, add user login to the filename 6 years ago
Andrew Dolgov fa653f5a43 prefs: show disabled filters properly on mysql 6 years ago
Andrew Dolgov 2996a3942f prefs: show root of filter tree as enabled so it's not grayed out 6 years ago
wn_ 614d3ac1bf Properly check if OPML file was loaded during import. 6 years ago