Commit Graph
26368 Commits
Author SHA1 Message Date
Jacob Schatz f2b7cd4435 Revert "Merge branch 'new-navigation-prototype' into 'master'"
This reverts merge request !3494
2016-04-07 21:20:16 +00:00
Jacob Schatz 4361cc395c Merge branch 'revert-5e8740ee' into 'master'
Revert "Merge branch 'fix-sidebar-exapnd' into 'master'"

This reverts merge request !3520

See merge request !3606
2016-04-07 21:03:28 +00:00
Jacob Schatz dc3de6e132 Revert "Merge branch 'fix-sidebar-exapnd' into 'master'"
This reverts merge request !3520
2016-04-07 20:33:01 +00:00
Jacob Schatz 1060467bb8 Merge branch 'indentation-bug' into 'master'
Preserve white space



See merge request !3602
2016-04-07 18:28:48 +00:00
Jacob Schatz f79d3cda35 Merge branch 'fix-number-of-todos-sidebar-is-not-updated' into 'master'
Update number of Todos in the sidebar when it's marked as "Done"

Closes #15002 

See merge request !3600
2016-04-07 17:44:41 +00:00
Douglas Barbosa Alexandre ee62ce65a1 Update CHANGELOG 2016-04-07 14:07:13 -03:00
Annabel Dunstone a81fcf8bd6 Indentation update 2016-04-07 09:06:46 -07:00
Annabel Dunstone f84d9e5389 Preserve white space 2016-04-07 08:55:16 -07:00
Douglas Barbosa Alexandre bb5bc90ab0 Update number of Todos in the sidebar when it's marked as "Done" 2016-04-07 12:35:25 -03:00
Rémy Coutable 074c239390 Merge branch 'issue_14012' into 'master'
Fix problem when creating milestones in groups without projects

Fixes #14012 

See merge request !3481
2016-04-07 15:19:56 +00:00
Douwe Maan 9cae14037a Merge branch 'regex-for-colons' into 'master'
Add optional colon.



See merge request !3591
2016-04-07 14:40:18 +00:00
Yorick Peterse 45e0565f98 Merge branch 'no-gc-auto' into 'master'
Disable git gc --auto

See merge request !3572
2016-04-07 14:29:42 +00:00
Rémy Coutable e8e9471c61 Merge branch 'dont-assign-me-if-you-arent-allow' into 'master'
Hide "assign to me" link if not allowed

Fixes #14996

See merge request !3590
2016-04-07 14:02:30 +00:00
Felipe Artur 0bef4b9764 Implement review suggestions 2016-04-07 10:59:24 -03:00
Jacob Schatz 2caaabf10a CHANGELOG 2016-04-07 09:14:20 -04:00
Jacob Schatz 0bbeebc8f9 Remove dumb debug statement and add many tests. 2016-04-07 08:47:29 -04:00
Jacob Schatz d76a769d24 Remove duplication. Remove JS data attributes 2016-04-07 08:32:37 -04:00
Jacob Schatz 8172d2c1f2 Add optional colon. 2016-04-07 08:17:05 -04:00
Grzegorz Bizon b30ebdaa1a Merge branch 'master' of dev.gitlab.org:gitlab/gitlabhq
* 'master' of dev.gitlab.org:gitlab/gitlabhq:
  Make sessions controller specs more explicit
  Fix 2FA authentication spoofing vulnerability
  Add specs for sessions controller  including 2FA
2016-04-07 14:10:28 +02:00
Rémy Coutable 237324cc17 Merge branch 'fix/2fa-authentication-spoofing' into 'master'
Fix 2FA authentication spoofing

## Summary

This is security fix for vulnerability described at 
https://gitlab.com/gitlab-org/gitlab-ce/issues/14900.

Attacker was able to bypass password authentication of users that have 2FA enabled, and consequently sign is as a different user, without knowing his password, if he managed to guess 2FA One Time Password for that user.

It was also possible to enumerate users and check if they have 2FA enabled, because GitLab responded with different error for each case.

## Fix

This MR attempts to change default user search scope if `otp_user_id` session variable has been set. If it is present, it means that user has 2FA enabled, and has already been verified with login and password. In this case we should look for user with `otp_user_id` first, before picking it up by `login`.

Both, 2FA authentication spoofing and 2FA discovery have been covered by specs.

## Further work

Current 2FA code is a bit tricky, so it probably needs some refactoring.



See merge request !1947
2016-04-07 11:56:44 +00:00
Grzegorz Bizon 33a8dfd04f Make sessions controller specs more explicit 2016-04-07 13:16:48 +02:00
Jacob Schatz 92649ca97a Hide "assign to me" link if not allowed 2016-04-07 07:09:31 -04:00
Jacob Vosmaer 3e26f6b00f Merge branch 'master' of https://gitlab.com/gitlab-org/gitlab-ce into no-gc-auto 2016-04-07 12:43:35 +02:00
Yorick Peterse a918e8bf27 Merge branch 'fix-project-404-cache-issue' into 'master'
Expire caches after project creation to ensure a consistent state

See merge request !3586
2016-04-07 10:31:04 +00:00
Rémy Coutable 144912851c Merge branch 'update_main_lang_if_unset' into 'master'
Only update main language if it is not already set

Related to gitlab-org/gitlab-ce#14937 (but does not fully fix) This is a temporary fix so performance isn't affected so much. 

cc @yorickpeterse @ayufan how does this look?

See merge request !3556
2016-04-07 09:41:51 +00:00
Grzegorz Bizon 00da609cfd Fix 2FA authentication spoofing vulnerability
This commit attempts to change default user search scope if otp_user_id
session variable has been set. If it is present, it means that user has
2FA enabled, and has already been verified with login and password. In
this case we should look for user with otp_user_id first, before picking
it up by login.
2016-04-07 11:19:29 +02:00
Rémy Coutable 92897d7683 Merge branch 'api-filter-milestone' into 'master'
API: Ability to filter milestones by state

Ability to filter milestones by `active` and `closed` state.

* Closes https://gitlab.com/gitlab-org/gitlab-ce/issues/14931

See merge request !3566
2016-04-07 08:45:35 +00:00
Rémy Coutable 8eae7b1088 Merge branch 'feature/expose-builds-badge' into 'master'
Expose badges

This MR exposes badge somewhere in visible place.

![expose_badges](/uploads/d2e290d3013d1ef2b1bdeebbbe2c5d8b/expose_badges.png)

Closes #13801

See merge request !3326
2016-04-07 08:40:15 +00:00
Rémy Coutable d62a3decf9 Merge branch 'fix_14638' into 'master'
Fixes #14638.

The SQL query was ambiguous and in this case we want to filter projects.

See merge request !3462
2016-04-07 08:35:38 +00:00
Rémy Coutable 2817c54137 Merge branch 'return-303-for-branch-deletion' into 'master'
Return status code 303 after a branch DELETE operation to avoid project deletion

Closes #14994

See merge request !3583
2016-04-07 08:27:37 +00:00
Stan Hu 27b9f64efb Expire caches after project creation to ensure a consistent state
Closes #14961
2016-04-07 00:29:01 -07:00
Jeroen van Baarsen 7266972b52 Merge branch 'update-coveralls' into 'master'
Update coveralls from 0.8.9 to 0.8.13 and simplecov from 0.10.0 to 0.11.2

This removes a few dependencies! It was also rude to be using coveralls
0.8.9, considering 0.8.12 introduced support for GitLab CI :) Also
paves the way for updating mime-types to 3.0.

Coveralls Changelog:
https://github.com/lemurheavy/coveralls-ruby/releases

Simplecov Changelog:
https://github.com/colszowka/simplecov/blob/master/CHANGELOG.md

See merge request !3584
2016-04-07 06:42:29 +00:00
Robert Schilling f5fdf20d76 Merge branch 'master' of github.com:gitlabhq/gitlabhq 2016-04-07 08:21:04 +02:00
Robert Schilling e684063b21 Merge branch 'patch-1' into 'master'
Fix typo in .gitlab-ci.yml doc. [ci skip]



See merge request !3581
2016-04-07 06:19:33 +00:00
connorshea 50ef9fcafb Update coveralls from 0.8.9 to 0.8.13 and simplecov from 0.10.0 to 0.11.2
This removes a few dependencies! It was also rude to be using coveralls
0.8.9, considering 0.8.12 introduced support for GitLab CI :) Also
paves the way for updating mime-types to 3.0.

Coveralls Changelog:
https://github.com/lemurheavy/coveralls-ruby/releases

Simplecov Changelog:
https://github.com/colszowka/simplecov/blob/master/CHANGELOG.md
2016-04-06 23:54:28 -06:00
Stan Hu 924e4b3700 Return status code 303 after a branch DELETE operation to avoid project deletion
Closes #14994
2016-04-06 21:11:10 -07:00
Robert Speicher 8f0945311b Merge branch 'anti-memoizer-mr-fix' into 'master'
Reset merge request widget options

Fixes #14986 

See merge request !3582
2016-04-07 03:00:51 +00:00
Jacob Schatz b471c76bcb Reset MR opts 2016-04-06 21:46:12 -04:00
Robert Speicher 936be025cd Merge branch 'saml-external-groups' into 'master'
Allow SAML to identify external users and set them as such

Related to #4009

Fixes #14577

This allows SAML to retrieve group information form the `SAML Response`
and match that to a setting that will flag all matching users as external.

See merge request !3530
2016-04-07 00:35:08 +00:00
Robert Speicher 730625f022 Merge branch 'patch/fix-markdown-preview-wikis' into 'master'
Wiki preview URL converting problem [via Markdown]

Current implementation when rendering the preview, thinks relative links are for project repository files.

We are creating a new preview route that will define correct context data to render for wikis instead.

Fixes #2380, #1184

See merge request !3461
2016-04-07 00:17:21 +00:00
Patricio Cano 8110e75309 Implemented suggested fixes 2016-04-06 18:12:25 -05:00
Gabriel Mazetto 1575a95b65 little refactor and improvements on specs 2016-04-06 20:09:15 -03:00
Jacob Schatz 7c6c933c9f Merge branch 'issue_14952' into 'master'
Do not add location badge when creating a group or project

Closes #14952 

![](/uploads/778d0cbccffc717d601a91528ca8eb3c/Screen_Shot_2016-04-05_at_5.34.10_PM.png)

![](/uploads/dbd9eb06b510a6ac091dcf2e3fcb9c88/Screen_Shot_2016-04-05_at_5.34.21_PM.png)

See merge request !3555
2016-04-06 22:55:15 +00:00
frodsan 71b5010a94 [ci skip] Fix typo. 2016-04-06 22:45:56 +00:00
Jacob Schatz d2f7813078 Merge branch '14866-url-overflow' into 'master'
Wrap code blocks to next line

Closes #14866 

![Screen_Shot_2016-04-06_at_9.27.06_AM](/uploads/8bed5c17b17c9d15fe34dc7161d31e09/Screen_Shot_2016-04-06_at_9.27.06_AM.png)

See merge request !3573
2016-04-06 22:25:30 +00:00
Achilleas Pipinellis 3a40e523a2 Merge branch 'doc-missing-ticks' into 'master'
Fix missing entries in permission matrix [ci skip]

Closes https://gitlab.com/gitlab-org/gitlab-ce/issues/14882

See merge request !3580
2016-04-06 21:54:42 +00:00
Robert Speicher 5bdc18c5b3 Merge branch 'patch/fix-ldap-unblock-user-logic' into 'master'
Unblocks user when active_directory is disabled and it can be found

We implemented a specific block state to handle user blocking that originates from LDAP filtering rules / directory state in !2242. 

That introduced a regression in LDAP authentication when Active Directory support was disabled. You could have a scenario where the user would not be temporarily found (like a filtering rule), that would mark the user as `ldap_blocked`, but will never unblock it automatically when that state changed.

Fixes #14253, #13179, #13259, #13959

See merge request !3550
2016-04-06 21:50:40 +00:00
Robert Schilling 43b9217705 Fix missing entries in permission matrix [ci skip] 2016-04-06 23:49:12 +02:00
Annabel Dunstone 86d346b6f4 Change word-break to word-wrap 2016-04-06 14:40:29 -07:00
Alfredo Sumaran bfcee4a51d Merge branch 'master' into issue_14952 2016-04-06 16:35:04 -05:00