1
0
Fork 0
mirror of https://we.phorge.it/source/phorge.git synced 2024-11-24 07:42:40 +01:00
phorge-phorge/src/applications
epriestley 40fb0f98df Mostly defuse DNS rebinding attack for outbound requests
Summary: Ref T6755. I'll add some notes there about specifics.

Test Plan:
  - Made connections to HTTP and HTTPS URIs.
  - Added some debugging code to verify that HTTP URIs were pre-resolved.

Reviewers: btrahan

Reviewed By: btrahan

Subscribers: epriestley

Maniphest Tasks: T6755

Differential Revision: https://secure.phabricator.com/D12169
2015-03-26 11:12:22 -07:00
..
almanac Move property transaction construction to Almanac 2015-03-23 09:10:42 -07:00
aphlict/management Create the Aphlict PID directory 2015-02-28 21:53:10 +11:00
arcanist/conduit Fix a method call in arcanist.projectinfo 2015-02-02 14:38:40 -08:00
audit Lift inline state transactions into core (in Diffusion) 2015-03-24 05:26:14 -07:00
auth Fixes spelling error in settings log on auth provider pages 2015-03-26 03:49:58 -07:00
base Generalize URI pattern blacklist for Quicksand 2015-03-10 15:32:15 -07:00
cache Fix visiblity of LiskDAO::getConfiguration() 2015-01-14 06:54:13 +11:00
calendar Change setErrorView to setInfoView in PHUIObjectBoxView 2015-03-06 17:03:18 -08:00
celerity Add support for playing sounds 2015-03-10 14:20:00 -07:00
chatlog Remove getIconName from all applications 2015-01-30 12:11:21 -08:00
conduit Modernize Conduit app a bit 2015-03-03 11:09:59 -08:00
config Improve granluarity and defaults of security.allow-outbound-http 2015-03-23 10:44:03 -07:00
conpherence Conpherence - Implement edit rules for rooms 2015-03-25 11:48:22 -07:00
console Move DarkConsole to an application 2014-10-13 11:17:09 -07:00
countdown Policy - filter app engines where the user can't see the application from panel editing 2015-02-04 15:47:48 -08:00
daemon Examine fewer daemons for variant config 2015-03-15 11:31:07 -07:00
dashboard Change setErrorView to setInfoView in PHUIObjectBoxView 2015-03-06 17:03:18 -08:00
differential Move abandoned revisions to "needs review" when updated 2015-03-26 11:11:33 -07:00
diffusion Show only recent open revisions affecting the same files 2015-03-25 10:21:56 -07:00
diviner Move PHUIErrorView to PHUIInfoView 2015-03-01 14:45:56 -08:00
doorkeeper Add "phabricator.silent" for stopping all outbound events from an install 2015-03-18 07:09:43 -07:00
draft/storage Fix visiblity of LiskDAO::getConfiguration() 2015-01-14 06:54:13 +11:00
drydock Policy - filter app engines where the user can't see the application from panel editing 2015-02-04 15:47:48 -08:00
fact Modernize Fact a bit 2015-03-03 13:48:30 -08:00
feed Fix handling of notifications with project members 2015-03-24 12:47:38 -07:00
files Mostly defuse DNS rebinding attack for outbound requests 2015-03-26 11:12:22 -07:00
flag Make pink flags pink 2015-03-17 18:29:07 -07:00
fund Recognize merchant authority in Fund initiatives 2015-03-04 10:35:53 -08:00
harbormaster T7646: Fix buildplan ac on Herald. 2015-03-23 06:19:17 -07:00
help Update Phabricator header to use FontAwesome 2014-12-04 13:01:23 -08:00
herald Move PHUIErrorView to PHUIInfoView 2015-03-01 14:45:56 -08:00
home Move PHUIErrorView to PHUIInfoView 2015-03-01 14:45:56 -08:00
legalpad Change setErrorView to setInfoView in PHUIObjectBoxView 2015-03-06 17:03:18 -08:00
lipsum Minor tidying of lipsum generate workflow 2015-03-01 09:41:52 +11:00
macro Rate limit outbound requests in Macros 2015-03-26 11:11:52 -07:00
mailinglists Improve granluarity and defaults of security.allow-outbound-http 2015-03-23 10:44:03 -07:00
maniphest Improve task subpriority movement algorithm for homogenous blocks 2015-03-26 11:11:23 -07:00
meta Remove redundant administrator requirement from application edit policy page 2015-03-23 09:10:10 -07:00
metamta Fix handling of notifications with project members 2015-03-24 12:47:38 -07:00
notification Move PHUIErrorView to PHUIInfoView 2015-03-01 14:45:56 -08:00
nuance Remove getIconName from all applications 2015-01-30 12:11:21 -08:00
oauthserver Improve granluarity and defaults of security.allow-outbound-http 2015-03-23 10:44:03 -07:00
owners Fix bad button construction in Owners 2015-03-18 07:08:50 -07:00
passphrase Move PHUIErrorView to PHUIInfoView 2015-03-01 14:45:56 -08:00
paste Minor touchup to Paste Embed UI 2015-02-26 11:09:10 -08:00
people Change setErrorView to setInfoView in PHUIObjectBoxView 2015-03-06 17:03:18 -08:00
phame Move PHUIErrorView to PHUIInfoView 2015-03-01 14:45:56 -08:00
phid MetaMTA - add (basic) application emails and deploy to Maniphest 2015-01-19 16:07:26 -08:00
phlux Remove getIconName from all applications 2015-01-30 12:11:21 -08:00
pholio Fix lispum generation of Pholio mocks 2015-03-02 08:15:32 -08:00
phortune Don't workflow the "add payment method" button from carts 2015-03-15 13:52:46 -07:00
phpast Use PhutilXHPASTBinary methods 2015-02-03 06:59:16 +11:00
phragment Move PHUIErrorView to PHUIInfoView 2015-03-01 14:45:56 -08:00
phrequent Add getGroup to ConfigOptions 2015-02-09 13:10:56 -08:00
phriction Use ChangesetListView in Phriction 2015-03-09 10:26:48 -07:00
policy Move PHUIErrorView to PHUIInfoView 2015-03-01 14:45:56 -08:00
ponder Move PHUIErrorView to PHUIInfoView 2015-03-01 14:45:56 -08:00
project Fix matching of very short project hashtags ending in a digit 2015-03-23 09:10:26 -07:00
releeph Move PHUIErrorView to PHUIInfoView 2015-03-01 14:45:56 -08:00
remarkup/conduit Rename Conduit classes 2014-07-25 10:54:15 +10:00
repository Allow repositories to be ordered by commit count 2015-03-23 09:10:34 -07:00
search Convert search results to use PHUIObjectItemView 2015-03-03 07:18:40 -08:00
settings Make durable column sticky across requests 2015-03-10 18:46:16 -07:00
slowvote Policy - filter app engines where the user can't see the application from panel editing 2015-02-04 15:47:48 -08:00
subscriptions Allow public on list of subscribers 2015-02-18 11:11:12 -08:00
support/application Implement the getName method in PhabricatorApplication subclasses 2014-07-23 23:52:50 +10:00
system Fix visibility of PhutilArgumentWorkflow::didConstruct methods 2015-01-16 07:42:07 +11:00
tokens Remove getIconName from all applications 2015-01-30 12:11:21 -08:00
transactions Conpherence - implement join / view rules for rooms 2015-03-24 18:38:16 -07:00
typeahead Projects - tokenize [ProjectX] so "projectX" is a match 2015-01-09 14:09:13 -08:00
uiexample Add ability to have tooltips on buttons 2015-03-26 11:09:20 -07:00
xhprof Set device true on all XHProf pages 2015-03-05 08:45:51 -08:00