Claire 
							
						 
					 
					
						
						
							
							
						
						
						
							
						
						
							328a9b8157 
							
						 
					 
					
						
						
							
							Change registrations to be disabled by default for new servers ( #29353 )  
						
						
						
						
					 
					
						2024-02-22 18:15:59 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
							
							
						
						
						
							
						
						
							4fd22acb4a 
							
						 
					 
					
						
						
							
							Fix auto-close email being sent to users with devops permissions instead of settings permissions ( #29356 )  
						
						
						
						
					 
					
						2024-02-22 18:15:38 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
							
							
						
						
						
							
						
						
							28b666b0d5 
							
						 
					 
					
						
						
							
							Automatically switch from open to approved registrations in absence of moderators ( #29337 )  
						
						
						
						
					 
					
						2024-02-22 14:39:42 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
							
							
						
						
						
							
						
						
							fbb07893b8 
							
						 
					 
					
						
						
							
							Update dependencies ( #29346 )  
						
						
						
						
					 
					
						2024-02-22 13:25:53 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							c5d56de98d 
							
						 
					 
					
						
						
							
							Fix linting failure  
						
						
						
						
					 
					
						2024-02-16 13:57:04 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							0e4e98fad1 
							
						 
					 
					
						
						
							
							Bump version to v4.2.7  
						
						
						
						
					 
					
						2024-02-16 11:57:02 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
							
							
						
						
						
							
						
						
							15de520201 
							
						 
					 
					
						
						
							
							Merge pull request from GHSA-jhrq-qvrm-qr36  
						
						... 
						
						
						
						* Fix insufficient Content-Type checking of fetched ActivityStreams objects
* Allow JSON-LD documents with multiple profiles 
						
						
					 
					
						2024-02-16 11:56:12 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							684f99908f 
							
						 
					 
					
						
						
							
							Update dependency pg to 1.5.5  
						
						
						
						
					 
					
						2024-02-16 09:19:35 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
							
							
						
						
						
							
						
						
							e4ec4ce217 
							
						 
					 
					
						
						
							
							Update nsa gem to version 0.3.0 ( #29065 ) ( #29206 )  
						
						... 
						
						
						
						Co-authored-by: Matt Jankowski <matt@jankowski.online> 
						
						
					 
					
						2024-02-14 23:27:02 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							870ee80fd3 
							
						 
					 
					
						
						
							
							Fix user creation failure handling in OAuth paths ( #29207 )  
						
						
						
						
					 
					
						2024-02-14 22:55:31 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							76a37bd040 
							
						 
					 
					
						
						
							
							Fix OmniAuth tests ( #29201 )  
						
						
						
						
					 
					
						2024-02-14 16:06:38 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							7c8ca0c6d6 
							
						 
					 
					
						
						
							
							Bump version to v4.2.6  
						
						
						
						
					 
					
						2024-02-14 15:16:34 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
							
							
						
						
						
							
						
						
							f1700523f1 
							
						 
					 
					
						
						
							
							Merge pull request from GHSA-vm39-j3vx-pch3  
						
						... 
						
						
						
						* Prevent different identities from a same SSO provider from accessing a same account
* Lock auth provider changes behind `ALLOW_UNSAFE_AUTH_PROVIDER_REATTACH=true`
* Rename methods to avoid confusion between OAuth and OmniAuth 
						
						
					 
					
						2024-02-14 15:16:07 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
							
							
						
						
						
							
						
						
							0b0c7af2c1 
							
						 
					 
					
						
						
							
							Merge pull request from GHSA-7w3c-p9j8-mq3x  
						
						... 
						
						
						
						* Ensure destruction of OAuth Applications notifies streaming
Due to doorkeeper using a dependent: delete_all relationship, the destroy of an OAuth Application bypassed the existing AccessTokenExtension callbacks for announcing destructing of access tokens.
* Ensure password resets revoke access to Streaming API
* Improve performance of deleting OAuth tokens
---------
Co-authored-by: Emelia Smith <ThisIsMissEm@users.noreply.github.com> 
						
						
					 
					
						2024-02-14 15:15:34 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							1a33d348d0 
							
						 
					 
					
						
						
							
							Add sidekiq_unique_jobs:delete_all_locks task and disable sidekiq-unique-jobs UI by default ( #29199 )  
						
						
						
						
					 
					
						2024-02-14 13:17:45 +01:00 
						 
				 
			
				
					
						
							
							
								Emelia Smith 
							
						 
					 
					
						
						
						
						
							
						
						
							6d43b63275 
							
						 
					 
					
						
						
							
							Disable administrative doorkeeper routes ( #29187 )  
						
						
						
						
					 
					
						2024-02-14 11:03:21 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							ae2dce813a 
							
						 
					 
					
						
						
							
							Update dependency sidekiq-unique-jobs to 7.1.33  
						
						
						
						
					 
					
						2024-02-14 11:02:55 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							b7230cd759 
							
						 
					 
					
						
						
							
							Update dependency nokogiri to 1.16.2  
						
						
						
						
					 
					
						2024-02-14 11:02:11 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
							
							
						
						
						
							
						
						
							a6641f828b 
							
						 
					 
					
						
						
							
							Merge pull request from GHSA-3fjr-858r-92rw  
						
						... 
						
						
						
						* Fix insufficient origin validation
* Bump version to v4.2.5 
						
						
					 
					
						2024-02-01 15:56:46 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							4633bb8ce0 
							
						 
					 
					
						
						
							
							Bump version to v4.2.4  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							1ab050eb52 
							
						 
					 
					
						
						
							
							Change PostgreSQL version check to check for PostgreSQL 10+  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							4eb98ef755 
							
						 
					 
					
						
						
							
							Ignore the devise-two-factor advisory as we have rate limits in place ( #28733 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							7a22999f92 
							
						 
					 
					
						
						
							
							Bump ruby version to 3.2.3  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							c5c464804d 
							
						 
					 
					
						
						
							
							Update dependency puma to v6.4.2  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							779237f054 
							
						 
					 
					
						
						
							
							Fix error when processing remote files with unusually long names ( #28823 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							b377f82b1d 
							
						 
					 
					
						
						
							
							Fix processing of compacted single-item JSON-LD collections ( #28816 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							6fe2a47357 
							
						 
					 
					
						
						
							
							Add rate-limit of TOTP authentication attempts at controller level ( #28801 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Jonathan de Jong 
							
						 
					 
					
						
						
						
						
							
						
						
							2dbf176d23 
							
						 
					 
					
						
						
							
							Retry 401 errors on replies fetching ( #28788 )  
						
						... 
						
						
						
						Co-authored-by: Claire <claire.github-309c@sitedethib.com> 
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Jeong Arm 
							
						 
					 
					
						
						
						
						
							
						
						
							499bc716a5 
							
						 
					 
					
						
						
							
							Ignore RecordNotUnique errors in LinkCrawlWorker ( #28748 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							3837ec2227 
							
						 
					 
					
						
						
							
							Fix Mastodon not correctly processing HTTP Signatures with query strings ( #28476 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							1998c561b2 
							
						 
					 
					
						
						
							
							Convert signature verification specs to request specs ( #28443 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							c0a9db3611 
							
						 
					 
					
						
						
							
							Fix potential redirection loop of streaming endpoint ( #28665 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							01caa18e5b 
							
						 
					 
					
						
						
							
							Fix streaming API redirection ignoring the port of streaming_api_base_url ( #28558 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							c609b726cb 
							
						 
					 
					
						
						
							
							Fix error when processing link preview with an array as inLanguage ( #28252 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Eugen Rochko 
							
						 
					 
					
						
						
						
						
							
						
						
							4d96d716c4 
							
						 
					 
					
						
						
							
							Fix unsupported time zone or locale preventing sign-up ( #28035 )  
						
						... 
						
						
						
						Co-authored-by: Claire <claire.github-309c@sitedethib.com> 
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Brian Holley 
							
						 
					 
					
						
						
						
						
							
						
						
							3ecc991f63 
							
						 
					 
					
						
						
							
							Fix "Hide these posts from home" list setting not refreshing when switching lists ( #27763 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Eugen Rochko 
							
						 
					 
					
						
						
						
						
							
						
						
							8f2dac0567 
							
						 
					 
					
						
						
							
							Fix missing background behind dismissable banner in web UI ( #27479 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							dfc8fcc6f0 
							
						 
					 
					
						
						
							
							Fix width of large text icon buttons ( #27127 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								gunchleoc 
							
						 
					 
					
						
						
						
						
							
						
						
							e8c5754142 
							
						 
					 
					
						
						
							
							Fix line wrapping of language selection button with long locale codes ( #27100 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								MitarashiDango 
							
						 
					 
					
						
						
						
						
							
						
						
							0a01bc01d2 
							
						 
					 
					
						
						
							
							Fix Undo Announce activity is not sent, when not followed by the reblogged post author ( #18482 )  
						
						... 
						
						
						
						Co-authored-by: Claire <claire.github-309c@sitedethib.com> 
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							a12b7551cf 
							
						 
					 
					
						
						
							
							Fix N+1s because of association preloaders not actually getting called ( #28339 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							7abc61887f 
							
						 
					 
					
						
						
							
							Fix empty column explainer getting cropped under certain conditions ( #28337 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							279be07679 
							
						 
					 
					
						
						
							
							Fix LinkCrawlWorker error when encountering empty OEmbed response ( #28268 )  
						
						
						
						
					 
					
						2024-01-24 15:31:13 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
							
							
						
						
						
							
						
						
							d7875adad2 
							
						 
					 
					
						
						
							
							Fix call to inefficient delete_matched cache method in domain blocks ( #28367 )  
						
						
						
						
					 
					
						2023-12-19 11:27:37 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							90371a4fc4 
							
						 
					 
					
						
						
							
							Bump version to v4.2.3  
						
						
						
						
					 
					
						2023-12-05 15:35:05 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							71b60b09f4 
							
						 
					 
					
						
						
							
							Update dependency json-ld to v3.3.1  
						
						
						
						
					 
					
						2023-12-05 15:35:05 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							4b8fe9df73 
							
						 
					 
					
						
						
							
							Bump version to v4.2.2  
						
						
						
						
					 
					
						2023-12-04 15:28:15 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							7b9496322f 
							
						 
					 
					
						
						
							
							Change dismissed banners to be stored server-side ( #27055 )  
						
						
						
						
					 
					
						2023-12-04 15:28:15 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							09115731d6 
							
						 
					 
					
						
						
							
							Change GIF max matrix size error to explicitly mention GIF files ( #27927 )  
						
						
						
						
					 
					
						2023-12-04 15:28:15 +01:00 
						 
				 
			
				
					
						
							
							
								Claire 
							
						 
					 
					
						
						
						
						
							
						
						
							e11100d782 
							
						 
					 
					
						
						
							
							Clamp dates when serializing to Elasticsearch API ( #28081 )  
						
						
						
						
					 
					
						2023-12-04 15:28:15 +01:00