Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								7c8ca0c6d6 
								
							 
						 
						
							
							
								
								Bump version to v4.2.6  
							
							
							
						 
						
							2024-02-14 15:16:34 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								f1700523f1 
								
							 
						 
						
							
							
								
								Merge pull request from GHSA-vm39-j3vx-pch3  
							
							... 
							
							
							
							* Prevent different identities from a same SSO provider from accessing a same account
* Lock auth provider changes behind `ALLOW_UNSAFE_AUTH_PROVIDER_REATTACH=true`
* Rename methods to avoid confusion between OAuth and OmniAuth 
							
						 
						
							2024-02-14 15:16:07 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								0b0c7af2c1 
								
							 
						 
						
							
							
								
								Merge pull request from GHSA-7w3c-p9j8-mq3x  
							
							... 
							
							
							
							* Ensure destruction of OAuth Applications notifies streaming
Due to doorkeeper using a dependent: delete_all relationship, the destroy of an OAuth Application bypassed the existing AccessTokenExtension callbacks for announcing destructing of access tokens.
* Ensure password resets revoke access to Streaming API
* Improve performance of deleting OAuth tokens
---------
Co-authored-by: Emelia Smith <ThisIsMissEm@users.noreply.github.com> 
							
						 
						
							2024-02-14 15:15:34 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								1a33d348d0 
								
							 
						 
						
							
							
								
								Add sidekiq_unique_jobs:delete_all_locks task and disable sidekiq-unique-jobs UI by default ( #29199 )  
							
							
							
						 
						
							2024-02-14 13:17:45 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Emelia Smith 
								
							 
						 
						
							
							
							
							
								
							
							
								6d43b63275 
								
							 
						 
						
							
							
								
								Disable administrative doorkeeper routes ( #29187 )  
							
							
							
						 
						
							2024-02-14 11:03:21 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								ae2dce813a 
								
							 
						 
						
							
							
								
								Update dependency sidekiq-unique-jobs to 7.1.33  
							
							
							
						 
						
							2024-02-14 11:02:55 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								b7230cd759 
								
							 
						 
						
							
							
								
								Update dependency nokogiri to 1.16.2  
							
							
							
						 
						
							2024-02-14 11:02:11 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								a6641f828b 
								
							 
						 
						
							
							
								
								Merge pull request from GHSA-3fjr-858r-92rw  
							
							... 
							
							
							
							* Fix insufficient origin validation
* Bump version to v4.2.5 
							
						 
						
							2024-02-01 15:56:46 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								4633bb8ce0 
								
							 
						 
						
							
							
								
								Bump version to v4.2.4  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								1ab050eb52 
								
							 
						 
						
							
							
								
								Change PostgreSQL version check to check for PostgreSQL 10+  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								4eb98ef755 
								
							 
						 
						
							
							
								
								Ignore the devise-two-factor advisory as we have rate limits in place ( #28733 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								7a22999f92 
								
							 
						 
						
							
							
								
								Bump ruby version to 3.2.3  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								c5c464804d 
								
							 
						 
						
							
							
								
								Update dependency puma to v6.4.2  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								779237f054 
								
							 
						 
						
							
							
								
								Fix error when processing remote files with unusually long names ( #28823 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								b377f82b1d 
								
							 
						 
						
							
							
								
								Fix processing of compacted single-item JSON-LD collections ( #28816 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								6fe2a47357 
								
							 
						 
						
							
							
								
								Add rate-limit of TOTP authentication attempts at controller level ( #28801 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Jonathan de Jong 
								
							 
						 
						
							
							
							
							
								
							
							
								2dbf176d23 
								
							 
						 
						
							
							
								
								Retry 401 errors on replies fetching ( #28788 )  
							
							... 
							
							
							
							Co-authored-by: Claire <claire.github-309c@sitedethib.com> 
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Jeong Arm 
								
							 
						 
						
							
							
							
							
								
							
							
								499bc716a5 
								
							 
						 
						
							
							
								
								Ignore RecordNotUnique errors in LinkCrawlWorker ( #28748 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								3837ec2227 
								
							 
						 
						
							
							
								
								Fix Mastodon not correctly processing HTTP Signatures with query strings ( #28476 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								1998c561b2 
								
							 
						 
						
							
							
								
								Convert signature verification specs to request specs ( #28443 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								c0a9db3611 
								
							 
						 
						
							
							
								
								Fix potential redirection loop of streaming endpoint ( #28665 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								01caa18e5b 
								
							 
						 
						
							
							
								
								Fix streaming API redirection ignoring the port of streaming_api_base_url ( #28558 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								c609b726cb 
								
							 
						 
						
							
							
								
								Fix error when processing link preview with an array as inLanguage ( #28252 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Eugen Rochko 
								
							 
						 
						
							
							
							
							
								
							
							
								4d96d716c4 
								
							 
						 
						
							
							
								
								Fix unsupported time zone or locale preventing sign-up ( #28035 )  
							
							... 
							
							
							
							Co-authored-by: Claire <claire.github-309c@sitedethib.com> 
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Brian Holley 
								
							 
						 
						
							
							
							
							
								
							
							
								3ecc991f63 
								
							 
						 
						
							
							
								
								Fix "Hide these posts from home" list setting not refreshing when switching lists ( #27763 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Eugen Rochko 
								
							 
						 
						
							
							
							
							
								
							
							
								8f2dac0567 
								
							 
						 
						
							
							
								
								Fix missing background behind dismissable banner in web UI ( #27479 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								dfc8fcc6f0 
								
							 
						 
						
							
							
								
								Fix width of large text icon buttons ( #27127 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									gunchleoc 
								
							 
						 
						
							
							
							
							
								
							
							
								e8c5754142 
								
							 
						 
						
							
							
								
								Fix line wrapping of language selection button with long locale codes ( #27100 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									MitarashiDango 
								
							 
						 
						
							
							
							
							
								
							
							
								0a01bc01d2 
								
							 
						 
						
							
							
								
								Fix Undo Announce activity is not sent, when not followed by the reblogged post author ( #18482 )  
							
							... 
							
							
							
							Co-authored-by: Claire <claire.github-309c@sitedethib.com> 
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								a12b7551cf 
								
							 
						 
						
							
							
								
								Fix N+1s because of association preloaders not actually getting called ( #28339 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								7abc61887f 
								
							 
						 
						
							
							
								
								Fix empty column explainer getting cropped under certain conditions ( #28337 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								279be07679 
								
							 
						 
						
							
							
								
								Fix LinkCrawlWorker error when encountering empty OEmbed response ( #28268 )  
							
							
							
						 
						
							2024-01-24 15:31:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								d7875adad2 
								
							 
						 
						
							
							
								
								Fix call to inefficient delete_matched cache method in domain blocks ( #28367 )  
							
							
							
						 
						
							2023-12-19 11:27:37 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								90371a4fc4 
								
							 
						 
						
							
							
								
								Bump version to v4.2.3  
							
							
							
						 
						
							2023-12-05 15:35:05 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								71b60b09f4 
								
							 
						 
						
							
							
								
								Update dependency json-ld to v3.3.1  
							
							
							
						 
						
							2023-12-05 15:35:05 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								4b8fe9df73 
								
							 
						 
						
							
							
								
								Bump version to v4.2.2  
							
							
							
						 
						
							2023-12-04 15:28:15 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								7b9496322f 
								
							 
						 
						
							
							
								
								Change dismissed banners to be stored server-side ( #27055 )  
							
							
							
						 
						
							2023-12-04 15:28:15 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								09115731d6 
								
							 
						 
						
							
							
								
								Change GIF max matrix size error to explicitly mention GIF files ( #27927 )  
							
							
							
						 
						
							2023-12-04 15:28:15 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								e11100d782 
								
							 
						 
						
							
							
								
								Clamp dates when serializing to Elasticsearch API ( #28081 )  
							
							
							
						 
						
							2023-12-04 15:28:15 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Jonathan de Jong 
								
							 
						 
						
							
							
							
							
								
							
							
								252ea2fc67 
								
							 
						 
						
							
							
								
								Have Follow activities bypass availability ( #27586 )  
							
							... 
							
							
							
							Co-authored-by: Claire <claire.github-309c@sitedethib.com> 
							
						 
						
							2023-12-04 15:28:15 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								8d02e58ff4 
								
							 
						 
						
							
							
								
								Fix upper border radius of onboarding columns ( #27890 )  
							
							
							
						 
						
							2023-12-04 15:28:15 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								1076a6cd62 
								
							 
						 
						
							
							
								
								Fix incoming status creation date not being restricted to standard ISO8601 ( #27655 )  
							
							
							
						 
						
							2023-12-04 15:28:15 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								54a07731d1 
								
							 
						 
						
							
							
								
								Fix posts from threads received out-of-order sometimes not being inserted into timelines ( #27653 )  
							
							
							
						 
						
							2023-12-04 15:28:15 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								81d7cfd544 
								
							 
						 
						
							
							
								
								Fix posts from force-sensitized accounts being able to trend ( #27620 )  
							
							
							
						 
						
							2023-12-04 15:28:15 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								e6f4c91c5c 
								
							 
						 
						
							
							
								
								Fix hashtag matching pattern matching some URLs ( #27584 )  
							
							
							
						 
						
							2023-12-04 15:28:15 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								de86e822f4 
								
							 
						 
						
							
							
								
								Fix error when trying to delete already-deleted file with OpenStack Swift ( #27569 )  
							
							
							
						 
						
							2023-12-04 15:28:15 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								4c38706474 
								
							 
						 
						
							
							
								
								Fix batch attachment deletion when using OpenStack Swift ( #27554 )  
							
							
							
						 
						
							2023-12-04 15:28:15 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Renaud Chaput 
								
							 
						 
						
							
							
							
							
								
							
							
								4fc2523546 
								
							 
						 
						
							
							
								
								Do not display the navigation banner in the logo container ( #27476 )  
							
							
							
						 
						
							2023-12-04 15:28:15 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Renaud Chaput 
								
							 
						 
						
							
							
							
							
								
							
							
								d5bc10b711 
								
							 
						 
						
							
							
								
								The class props should be className ( #27462 )  
							
							
							
						 
						
							2023-12-04 15:28:15 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								c66ade7de8 
								
							 
						 
						
							
							
								
								Fix processing LDSigned activities from actors with unknown public keys ( #27474 )  
							
							
							
						 
						
							2023-12-04 15:28:15 +01:00