28524 Commits
Author SHA1 Message Date
Robert Speicher cec10c85df Update VERSION to 8.8.7 v8.8.7 2016-06-30 17:12:27 -04:00
Douwe MaanandRobert Speicher 2d1166d803 Merge branch '18033-private-repo-mentions' into 'master'
Ensure logged-out users can't see private refs

https://gitlab.com/gitlab-org/gitlab-ce/issues/18033

I'm still not sure what to do about the CHANGELOG on security issues - should I add to a patch release? This issue was assigned to 8.10.

See merge request !1974
(cherry picked from commit 3a6ebb1fd6)
2016-06-30 14:47:17 -04:00
Douwe MaanandRobert Speicher 96b6fb1a3d Merge branch '19312-confidential-issue' into 'master'
Fix privilege escalation issue with OAuth external users

Related to https://gitlab.com/gitlab-org/gitlab-ce/issues/19312

This MR fixes a privilege escalation issue, where manually set external users would be reverted back to internal users if they logged in via OAuth and that provider was not in the `external_providers` list.

/cc @douwe

See merge request !1975
(cherry picked from commit 5e6342b7ac)
2016-06-30 14:39:20 -04:00
Robert Speicher 9c43e624bc Update VERSION to 8.8.6 v8.8.6 2016-06-27 18:26:35 -04:00
Robert SpeicherandRobert Speicher 2dafc49e2a Merge branch 'fix-18997' into 'master'
Fix visibility of snippets when searching

Fixes https://gitlab.com/gitlab-org/gitlab-ce/issues/18997

See merge request !1972
(cherry picked from commit 8a197c15d4)
2016-06-27 16:43:13 -04:00
Stan HuandRobert Speicher 4c80039c48 Merge branch 'update-omniauth-saml' into 'master'
Update omniauth-saml to 1.6.0 to address a security vulnerability in ruby-saml

Updates `omniauth-saml` to bring in the new `ruby-saml` dependency that addresses [CVE-2016-5697](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5697)

Fixes #19206

See merge request !4951
(cherry picked from commit c3a8b252cd)
2016-06-27 16:31:56 -04:00
Tomasz Maczukin 68cd1382e5 Update VERSION to 8.8.5 v8.8.5 2016-06-15 03:41:18 +02:00
Robert SpeicherandTomasz Maczukin ea13df6dd9 Merge branch '18535-confidential-issue-notes' into 'master'
Only show notes through JSON on confidential issues that the user has access to

Fixes https://gitlab.com/gitlab-org/gitlab-ce/issues/18535

See merge request !1970
2016-06-15 00:03:17 +02:00
Tomasz Maczukin 778185a81a Update CHANGELOG for 8.8.5 2016-06-14 22:33:41 +02:00
Robert SpeicherandTomasz Maczukin 2da3f39258 Merge branch '17298-wiki-xss' into 'master'
Forbid scripting for wiki files

Wiki files (not pages - files in the repo) are just sent to the browser
with whatever content-type the mime_types gem assigns to them based on
their extension. As this is from the same domain as the GitLab
application, this is an XSS vulnerability.

Set a CSP forbidding all sources for scripting, CSS, XHR, etc. on these
files.

Fixes https://gitlab.com/gitlab-org/gitlab-ce/issues/17298.

See merge request !1969
2016-06-14 22:26:03 +02:00
Douwe MaanandTomasz Maczukin 6a51392763 Merge branch 'fix/unauthorized-access-to-build-data' into 'master'
Remove 'unscoped' from project builds selection

This is a fix for this security bug: https://gitlab.com/gitlab-org/gitlab-ce/issues/18188

/cc @kamil @grzegorz @stanhu

See merge request !1968
2016-06-14 22:25:10 +02:00
Rémy CoutableandTomasz Maczukin 767d3223fc Merge branch 'fix/incremental-trace-update-api' into 'master'
Fix UTF-8 handling in incremental trace update API

## What does this MR do?

This MR fixes invalid UTF-8 handling in incremental trace update API (used by GitLab Runner).

## Why was this MR needed?

Current version is using `.length` method to determine current trace size where Runner is using the trace size in bytes. Also this byte size is used in headers and file operations to agree the trace part to send. This is a problem when build trace contains any multi-byte UTF-8 characters. This MR is fixing this situation so all parts are using the same size in bytes.

### Runner -> API communication before fix:
```
Checking for builds... received                     runner=_token_
gitlab-ci-multi-runner 1.3.0~beta.26.gcfd63b9 (cfd63b9)  build=25 runner=_token_
Using Docker executor with image debian:jessie ...  build=25 runner=_token_
Pulling docker image debian:jessie ...              build=25 runner=_token_
25 Submitting build to coordinator... ok            runner=_token_
25 Appending trace to coordinator... ok             RemoteRange=0-158 RemoteState=running ResponseMessage=202 Accepted ResponseStatusCode=202 SentRange=0-158 runner=_token_
25 Appending trace to coordinator... ok             RemoteRange=0-491 RemoteState=running ResponseMessage=202 Accepted ResponseStatusCode=202 SentRange=158-505 runner=_token_
WARNING: 25 Appending trace to coordinator... range missmatch  RemoteRange=0-491 RemoteState= ResponseMessage=416 Requested Range Not Satisfiable ResponseStatusCode=416 SentRange=505-584 runner=_token_
WARNING: 25 Resending trace patch due to range missmatch  runner=_token_
25 Appending trace to coordinator... ok             RemoteRange=0-556 RemoteState=running ResponseMessage=202 Accepted ResponseStatusCode=202 SentRange=491-584 runner=_token_
WARNING: 25 Appending trace to coordinator... range missmatch  RemoteRange=0-556 RemoteState= ResponseMessage=416 Requested Range Not Satisfiable ResponseStatusCode=416 SentRange=584-663 runner=_token_
WARNING: 25 Resending trace patch due to range missmatch  runner=_token_
25 Appending trace to coordinator... ok             RemoteRange=0-621 RemoteState=running ResponseMessage=202 Accepted ResponseStatusCode=202 SentRange=556-663 runner=_token_
Build succeeded                                     build=25 runner=_token_
WARNING: 25 Appending trace to coordinator... range missmatch  RemoteRange=0-621 RemoteState= ResponseMessage=416 Requested Range Not Satisfiable ResponseStatusCode=416 SentRange=663-797 runner=_token_
WARNING: 25 Resending trace patch due to range missmatch  runner=_token_
25 Appending trace to coordinator... ok             RemoteRange=0-741 RemoteState=running ResponseMessage=202 Accepted ResponseStatusCode=202 SentRange=621-797 runner=_token_
25 Submitting build to coordinator... ok            runner=_token_
```

### Runner -> API communication after fix:
```
Checking for builds... received                     runner=_token_
gitlab-ci-multi-runner 1.3.0~beta.26.gcfd63b9 (cfd63b9)  build=26 runner=_token_
Using Docker executor with image debian:jessie ...  build=26 runner=_token_
Pulling docker image debian:jessie ...              build=26 runner=_token_
26 Submitting build to coordinator... ok            runner=_token_
26 Appending trace to coordinator... ok             RemoteRange=0-158 RemoteState=running ResponseMessage=202 Accepted ResponseStatusCode=202 SentRange=0-158 runner=_token_
26 Appending trace to coordinator... ok             RemoteRange=0-505 RemoteState=running ResponseMessage=202 Accepted ResponseStatusCode=202 SentRange=158-505 runner=_token_
26 Appending trace to coordinator... ok             RemoteRange=0-584 RemoteState=running ResponseMessage=202 Accepted ResponseStatusCode=202 SentRange=505-584 runner=_token_
26 Appending trace to coordinator... ok             RemoteRange=0-663 RemoteState=running ResponseMessage=202 Accepted ResponseStatusCode=202 SentRange=584-663 runner=_token_
Build succeeded                                     build=26 runner=_token_
26 Submitting build to coordinator... ok            runner=_token_
```

See merge request !4541
2016-06-14 22:20:57 +02:00
Douwe MaanandTomasz Maczukin b6f28a177e Merge branch 'gh-disable-webhooks' into 'master'
Check if GitHub rate limite API was reached before update Webhooks

## What does this MR do?

Checks if the job needs to sleep, and wait for the rate limit to be reseted before update each Webhook.

## Are there points in the code the reviewer needs to double check?

No.

## Why was this MR needed?

The import process can fail if the API rate limit was reached during the import process.

## What are the relevant issue numbers?

https://gitlab.com/gitlab-org/gitlab-ce/issues/17498

## Screenshots (if relevant)

Not relevant.

See merge request !4509
2016-06-14 22:20:15 +02:00
Douwe MaanandTomasz Maczukin 520a57a105 Merge branch 'saml-ldap-link-flow' into 'master'
Adjust the SAML control flow to allow LDAP identities to be added to an existing SAML user.

It correctly lets an existing SAML user to add their LDAP identity automatically at login.

A customer had issues with the `auto_link_ldap_user` feature. The flow was not working if there was an account with a SAML identity, but no LDAP identity. GitLab would pick up the correct LDAP person, but due to the order of the flow, that LDAP person was never associated with the user.

Fixes #17346

/cc @dblessing @balameb @stanhu

See merge request !4498
2016-06-14 22:19:41 +02:00
Douwe MaanandTomasz Maczukin 6e23d642dd Merge branch 'gh-fix-comments-on-diff' 2016-06-14 22:15:52 +02:00
Douwe MaanandTomasz Maczukin 212ebdfb41 Merge branch 'gh-disable-webhooks' 2016-06-14 22:14:20 +02:00
Douwe MaanandTomasz Maczukin a834be61eb Merge branch 'todos-filter-project-delete' into 'master'
Ensure we don't show TODOS for projects pending delete

Joins the todos on the projects table in order to run the default scope. Also includes a where clause because the default scope is being removed soon.

An alternative approach, more like the Issues page, would be to filter down the list by passing user.authorized_projects into the where clause.

Or we could just be more defensive in the view when iterating.

Todos page throws 500 error for users with todos in a project pending deletion.

Fixes https://gitlab.com/gitlab-org/gitlab-ce/issues/17813

cc\ @stanhu

See merge request !4300
2016-06-14 22:14:16 +02:00
Douwe MaanandTomasz Maczukin b240450845 Merge branch 'gh-rate-limit' 2016-06-14 22:13:29 +02:00
Robert Speicher 9c5b68a8de Update CHANGELOG for 8.8.4
[ci skip]
2016-06-09 18:41:56 -04:00
Robert Speicher d4c3f1735d Update VERSION to 8.8.4 v8.8.4 2016-06-09 16:46:53 -04:00
Robert SpeicherandRobert Speicher 00cae51eda Merge branch 'rs-fix-ldap-2fa-login' into 'master'
Fix 2FA-based login for LDAP users

The OTP input form is shared by both LDAP and standard logins, but when
coming from an LDAP-based form, the form parameters aren't nested in a
Hash based on the `resource_name` value.

Now we check for a nested `remember_me` parameter and use that if it
exists, or fall back to the non-nested parameters if it doesn't.

Somewhat confusingly, the OTP input form _does_ nest parameters under
the `resource_name`, regardless of what type of login we're coming from,
so that allows everything else to work as normal.

Closes https://gitlab.com/gitlab-org/gitlab-ce/issues/18185

See merge request !4493
2016-06-09 14:53:12 -04:00
Robert Speicher 374d212b05 Update VERSION to 8.8.3 v8.8.3 2016-06-02 14:43:27 -04:00
Robert Speicher cde5625d72 Update CHANGELOG for 8.8.3 2016-06-02 13:21:59 -04:00
Robert SpeicherandRobert Speicher ca24ea5241 Merge branch 'issue_18102' into 'master'
Fixes missing number on generated ordered list

Closes #18102

See merge request !4437
2016-06-02 13:17:17 -04:00
Stan HuandYorick Peterse e8e4dbc179 Merge branch 'fix-inline-filter-speed' into 'master'
Fix serious performance bug with rendering Markdown with InlineDiffFilter

Nokogiri's `node.replace` was being unnecessarily called for every text node in
the document due to a comparison bug. The code previously was comparing the
HTML representation of the full document against the text node, which would
always fail. Fix the comparison to just compare the modified text.

Closes #18011

See merge request !4392
2016-06-02 16:56:42 +02:00
Robert SpeicherandYorick Peterse 3799edd78c Merge branch 'data_leak' into 'master'
Confidential notes data leak

Fixes part of https://gitlab.com/gitlab-org/gitlab-ee/issues/575

See merge request !1967
2016-06-02 13:49:18 +02:00
Rémy CoutableandYorick Peterse e30c651bbd Merge branch 'chujinjin/gitlab-ce-fix_wiki_project_clone_address_error' into 'master'
Fix wiki project clone address error

_Note: Originally opened at !4407 by @chujinjin._

---

fix wiki project clone address error in Wiki Git Access View, show as below:

![image](/uploads/5e3bf6d1418c42862a885319c31bc3cf/image.png)

Fixes #17643.

See merge request !4429
2016-06-02 13:46:06 +02:00
Stan HuandYorick Peterse e601e683bc Merge branch 'downcase-registry-repository' into 'master'
Use downcased path to container repository as this is expected path by Docker

Docker Engine requires path to be lowercase. This makes all container registry paths to be show and used downcased instead of mixed case.

Fixes https://gitlab.com/gitlab-org/gitlab-ce/issues/17959

See merge request !4420
2016-06-02 13:43:25 +02:00
Rémy CoutableandYorick Peterse eb48969ad5 Merge branch 'fix/error-500-in-pipeline-when-fork' into 'master'
Use project that belongs to pipeline in view

This MR makes project in pipelines view match the one that pipeline has been created for.

Closes #17943

See merge request !4376
2016-06-02 13:42:31 +02:00
Yorick Peterse 0aec06ac67 Added CHANGELOG entry for !4369 2016-06-02 13:41:19 +02:00
Douwe MaanandYorick Peterse d4ae68cdd6 Merge branch 'rs-remember-me-2fa' into 'master'
Pass the "Remember me" value to the 2FA token form

Prior, if a user had 2FA enabled and checked the "Remember me" field,
the setting was ignored because the OTP input was on a new form and the
value was never passed.

Closes #18000

See merge request !4369
2016-06-02 13:41:03 +02:00
Douwe MaanandYorick Peterse 1d94757c1a Merge branch 'container-registry-token-ttl' into 'master'
Add Application Setting to configure Container Registry token expire delay (default 5min)

This adds an option to configure Container Registry token expire delay. The default is set to 5mins (something that is also used by Docker Hub).

What is left:
* [x] Write test to check the expire_delay

Fixes: https://gitlab.com/gitlab-org/gitlab-ce/issues/17890

@stanhu I think that this should land in patch release of 8.8.

See merge request !4364
2016-06-02 13:39:56 +02:00
Yorick Peterse 0df4fa78e7 Fixed CHANGELOG entry for !4363 2016-06-02 13:35:03 +02:00
Stan HuandYorick Peterse b89d3faf55 Merge branch 'make-container-registry-authentication-service-compatible-with-older-docker' into 'master'
Make authentication service for Container Registry to be compatible with < Docker 1.11

This removes the usage of `offline_token` which is only present when using `Docker 1.11.x` instead we relay on `scope`. This should make it compatible with any client starting from 1.6 (I did test only 1.8 and up).

Right now we return 403 if unauthorized user doesn't have access to anything. In all other cases we return token, but with empty `access`, which simply disallow requested action.

See merge request !4363
2016-06-02 13:33:56 +02:00
Yorick Peterse ad65b56193 Fixed CHANGELOG entry for !4332 2016-06-02 13:31:30 +02:00
Douwe MaanandYorick Peterse ef205c885b Merge branch 'current-settings-use-request-store-during-request' 2016-06-02 13:30:00 +02:00
Yorick Peterse ac53874330 Fixed CHANGELOG entry for !4321 2016-06-02 13:27:16 +02:00
Robert SpeicherandYorick Peterse 322464ea92 Merge branch 'fix/migration-uri-issue' into 'master'
Fix import URL migration error

Fixes https://gitlab.com/gitlab-org/gitlab-ce/issues/17956

See merge request !4321
2016-06-02 13:26:44 +02:00
Yorick Peterse 0591d06b00 Fixed CHANGELOG entry for !4312 2016-06-02 13:26:03 +02:00
Douwe MaanandYorick Peterse 4cd2d46889 Merge branch 'fix-404-labels-in-todos' into 'master'
Fix 404 page when viewing TODOs that contain milestones or labels in different projects

A user viewing the TODOs page will see a 404 if there are mentioned milestones or labels in multiple different projects. This is likely a caching bug and only occurs
when Markdown rendering occurs across multiple projects, which is why it's so tricky to reproduce. This is what I think is happening:
    
1. LabelReferenceFilter#references_in encounters label ~X for ProjectA and finds the label in the DB as id = 1.
2. LabelReferenceFilter.references_in yields [1, 'X', nil, ...]
3. Since project_ref is nil, AbstractReferenceFilter#project_from_ref_cache caches nil => ProjectA.
4. LabelReferenceFilter#references_in encounters label ~Y for ProjectB and finds the label in the DB as id = 2.
5. LabelReferenceFilter.references_in yields [2, 'Y', nil, ...]
6. AbstractReferenceFilter#project_from_ref_cache lookups nil and returns ProjectA. It was supposed to be ProjectB.
7. A is the wrong project, so the label lookup fails.
   
This MR expands the `project_ref` to the right value as soon as we have it to avoid this caching bug.
    
Closes #17898


See merge request !4312
2016-06-02 13:25:30 +02:00
Jacob SchatzandYorick Peterse 6b6c5db194 Merge branch 'fix-shortcuts-spec' into 'master'
Ensure project name is present on page

## What does this MR do?
Fixes a failing spec




See merge request !4307
2016-06-02 13:25:09 +02:00
Yorick Peterse 4b03f9992b Added CHANGELOG entry for !4303 2016-06-02 13:24:13 +02:00
Jacob SchatzandYorick Peterse 46a83371d5 Merge branch 'discussion-outdated-form' into 'master'
Fixed JS error when trying to remove discussion form

## What does this MR do?

Fixes a JS error which was caused by an ID of the form not matching what was returned by the JSON. Instead of checking that, it gets the current form from the ajax success event.

This would only happen on outdated discussions because the ID of the discussion form ends with `-false` because it isn't active. However, the note is added to an active discussion so the ID returned actually ends in `-true` & therefore the JS couldn't find the correct form.

## What are the relevant issue numbers?

Closes #17778

See merge request !4303
2016-06-02 13:23:47 +02:00
Yorick Peterse 42b9a51581 Fixed CHANGELOG for !4301 2016-06-02 13:23:24 +02:00
Robert SpeicherandYorick Peterse ac98845e7a Merge branch 'fix/gitlab-importer-issue' into 'master'
Fix gitlab importer issue

Fixed credentials not being called correctly - probably some bad refactoring or search & replace... 

Fixes https://gitlab.com/gitlab-org/gitlab-ee/issues/565

See merge request !4301
2016-06-02 13:23:06 +02:00
Yorick Peterse 88bb7b51c9 Added CHANGELOG entry for !4287 2016-06-02 13:22:31 +02:00
Jacob SchatzandYorick Peterse 2b4313140d Merge branch 'merge-button-color-fix' into 'master'
Fixed issue with button color when no CI enabled

## What does this MR do?

Fixes an issue with the color of the merge button when no CI is setup.

## What are the relevant issue numbers?

Closes #17844

## Screenshots

![Screen_Shot_2016-05-25_at_09.58.44](/uploads/87aac74c5e2f8bfd2831e99c5915856d/Screen_Shot_2016-05-25_at_09.58.44.png)

See merge request !4287
2016-06-02 13:21:58 +02:00
Jacob SchatzandYorick Peterse c4abaf416c Merge branch 'generic-commit-status' into 'master'
Move tags to column in generic_commit_status

Part of https://gitlab.com/gitlab-org/gitlab-ce/merge_requests/4249    

cc @ayufan 



See merge request !4277
2016-06-02 13:21:31 +02:00
Yorick Peterse cf6ce9ae5d Moved CHANGELOG entry for !4230 2016-06-02 13:21:06 +02:00
Douwe MaanandYorick Peterse 66c01627af Merge branch 'improve-pipeline-design' into 'master'
Improve design of Pipeline view

## What does this MR do?

Improves current design of Pipelines view when there is multiple stages.
This makes the statuses clickable and makes the view more compact.

## Screenshots (if relevant)

![Screen_Shot_2016-05-21_at_01.20.40](/uploads/dd031b7af7005c7a61f3165fefa8b7c9/Screen_Shot_2016-05-21_at_01.20.40.png)

cc @DouweM @markpundsack @rspeicher @marin 

See merge request !4230
2016-06-02 13:20:51 +02:00