TinyTinyRSS for BananaNetwork - to apply required patches before release or release in async to the official version https://git.tt-rss.org/fox/tt-rss
You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 
 
Go to file
Andrew Dolgov c3d14e1fa5 - fix multiple vulnerabilities in af_proxy_http
- fix vulnerability in rewrite_relative_url() which prevented some URLs from being properly absolutized
- fetch_file_contents: validate all URLs before requesting them
- validate URLs: explicitly whitelist http and https scheme, forbid everything else
- DiskCache/cached_url: only serve whitelisted content types (images, video)
- simplify filename/URL handling code, remove and consolidate some less-used functions
4 years ago
api
cache
classes - fix multiple vulnerabilities in af_proxy_http 4 years ago
feed-icons
images center and rework some utility screens 6 years ago
include - fix multiple vulnerabilities in af_proxy_http 4 years ago
install Merge branch 'escape-install-part-two' of JustAMacUser/tt-rss into master 5 years ago
js Store FeedTree data in localStorage 4 years ago
lib minitemplator->writeString: print always returns 1 in PHP 5 years ago
locale Translated using Weblate (Czech) 4 years ago
lock
plugins - fix multiple vulnerabilities in af_proxy_http 4 years ago
plugins.local
schema
templates remove atom-to-html XSLT 5 years ago
templates.local allow overriding built-in templates via templates.local 5 years ago
themes hide #toolbar-frame_splitter back again 5 years ago
themes.local
utils
vendor
.editorconfig
.eslintrc.js eslint-related fixes; move a few things from global context to App 5 years ago
.gitignore
CONTRIBUTING.md
COPYING
README.md
backend.php
config.php-dist More fixes when installer generates config file. 5 years ago
errors.php
index.php pluginhost: allow overriding default sort modes via HOOK_HEADLINES_CUSTOM_SORT_MAP etc 4 years ago
jsconfig.json unify prefs/main App objects, remove fake classes, use single static App object instead 5 years ago
messages.pot rebase translations 5 years ago
opml.php
prefs.php add URL parameter to ignore user theme on startup 5 years ago
public.php
register.php don't generate default.css, replace with themes/light.css as a default root CSS file 5 years ago
update.php add --opml-export to update.php 5 years ago
update_daemon2.php

README.md

Tiny Tiny RSS

Web-based news feed aggregator, designed to allow you to read news from any location, while feeling as close to a real desktop application as possible.

http://tt-rss.org

This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.

This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

You should have received a copy of the GNU General Public License along with this program. If not, see http://www.gnu.org/licenses/.

Copyright (c) 2005 Andrew Dolgov (unless explicitly stated otherwise).

Uses Silk icons by Mark James: http://www.famfamfam.com/lab/icons/silk/