Commit Graph

107 Commits

Author SHA1 Message Date
Ville Rantanen
f1c453d3d4 moved config to a json, which makes adding more variables easier, but perhaps otherwise adds complexity 2023-07-28 13:08:54 +03:00
Ville Rantanen
80af9c321c start at boot 2023-07-26 12:20:09 +03:00
Ville Rantanen
1c6cbbe9ed better auto-link 2023-07-24 22:22:16 +03:00
Ville Rantanen
384051bcd4 link to favicon 2023-07-24 21:08:13 +03:00
Ville Rantanen
b99e18f3b2 editable button 2023-07-24 20:45:59 +03:00
Ville Rantanen
875bec721f restructure for docker 2023-07-24 20:03:36 +03:00
Ville Rantanen
a0c0d69c5e restructure for docker 2023-07-24 20:02:49 +03:00
Ville Rantanen
58abf04d2c restructure for docker 2023-07-24 20:02:45 +03:00
Ville Rantanen
79780f0769 allow user css 2023-07-23 22:11:15 +03:00
Ville Rantanen
9437e64936 use markdown2, add forced login. Added breadcrumbs 2023-07-23 20:23:48 +03:00
David Hoppenbrouwers
09f56bd1fe Merge pull request #22 from Demindiro/security-fixes 2023-02-01 12:06:44 +01:00
David Hoppenbrouwers
a372d7d4e7 Forbid iframes
This prevents clickjacking attacks.
2023-02-01 12:02:08 +01:00
David Hoppenbrouwers
0827fb2c24 Fix cookie SameSite not being set 2023-01-26 09:34:26 +01:00
David Hoppenbrouwers
9b63006361 Create SECURITY.md
Fixes #21
2023-01-25 18:51:17 +01:00
David Hoppenbrouwers
43a0aefea3 Merge pull request #20 from Demindiro/fix-non-moderator-visible-ban-dialog 2022-10-28 18:27:20 +02:00
David Hoppenbrouwers
8abaa288b6 Fix non-moderators seeing the ban dialog on user info pages.
It's purely a UI bug, so it's not a security issue.
2022-10-26 18:32:00 +02:00
David Hoppenbrouwers
4749e4fb21 Merge pull request #18 from Demindiro/anonymous-create-thread 2022-10-26 18:25:15 +02:00
David Hoppenbrouwers
2260d12221 Merge pull request #19 from Demindiro/permanent-session 2022-10-26 18:25:00 +02:00
David Hoppenbrouwers
7f349d7338 Make session cookie "permanent" (31 days)
This is to avoid being logged out unpredictably.
2022-10-24 20:26:08 +02:00
David Hoppenbrouwers
5610b26220 Show borders for table.form elements 2022-10-24 19:11:27 +02:00
David Hoppenbrouwers
fce0e8d595 Auto-register user when creating thread without account 2022-10-24 19:10:35 +02:00
David Hoppenbrouwers
fc9ad4667b Merge pull request #17 from bilelz/feature/form_required_input 2022-10-21 19:48:31 +02:00
Bilelz
eba22b2411 feat(form): add required to captcha field 2022-10-21 10:16:37 +02:00
Bilelz
534499e972 feat(form): add required attribute 2022-10-21 10:15:01 +02:00
David Hoppenbrouwers
8cd649eac0 Merge pull request #15 from Demindiro/minify-requirements 2022-10-20 20:21:15 +02:00
David Hoppenbrouwers
deb0b153d6 Merge pull request #13 from Demindiro/register-on-comment 2022-10-20 20:20:50 +02:00
David Hoppenbrouwers
6be1c8d806 Remove non-top-level dependencies from requirements.txt 2022-10-20 16:46:00 +02:00
David Hoppenbrouwers
736ef17f8e Improve style of comment & login forms 2022-10-19 18:57:50 +02:00
David Hoppenbrouwers
eafa141a2f Autoregister on comment 2022-10-15 22:36:36 +02:00
David Hoppenbrouwers
17844fa11c Separate register/register_user, auto log in user on register 2022-10-15 22:12:25 +02:00
David Hoppenbrouwers
7963bd1bf2 Enable registrations when testing
It's a tad more convenient
2022-10-15 21:56:42 +02:00
David Hoppenbrouwers
23c9b35950 Merge pull request #12 from Demindiro/strip-whitespace 2022-10-15 19:50:38 +02:00
David Hoppenbrouwers
a0747ad62f Forbid any whitespace in usernames
This should prevent confusion between e.g. 'A B' and 'A  B'
2022-10-15 19:49:58 +02:00
David Hoppenbrouwers
18d914b889 Strip whitespace from user names and thread titles 2022-10-14 20:23:13 +02:00
David Hoppenbrouwers
5535c6b900 Merge pull request #9 from Demindiro/mod-hide-threads 2022-10-14 20:11:53 +02:00
David Hoppenbrouwers
648fce5a68 Clarify database upgrades 2022-10-14 20:11:12 +02:00
David Hoppenbrouwers
136d7aeceb Don't show hidden threads in Last update column 2022-10-12 22:24:24 +02:00
David Hoppenbrouwers
e066a7c91e Show hidden comments if the logged in user replied to it in the chain 2022-10-12 22:16:08 +02:00
David Hoppenbrouwers
8e54c95c40 Implement comment hiding
Currently hides replies too, even comments from users who are logged in.
2022-10-12 22:15:58 +02:00
David Hoppenbrouwers
8f53d143db Update schema.txt 2022-10-12 22:02:10 +02:00
David Hoppenbrouwers
cb48fb505d Merge pull request #10 from anthmn/master 2022-10-12 21:16:11 +02:00
anthmn
896c69e92a Add generator meta tag 2022-10-11 21:41:11 -04:00
David Hoppenbrouwers
77e9051334 Implement thread hiding 2022-10-11 21:05:45 +02:00
David Hoppenbrouwers
61ad1e2716 Typoed security email 2022-10-11 01:12:37 +02:00
David Hoppenbrouwers
a1cedf5376 Add mail for security stuff to README 2022-10-11 01:12:10 +02:00
David Hoppenbrouwers
7bb7226204 Merge pull request #1 from zdhickman/patch-1 2022-10-11 01:09:26 +02:00
David Hoppenbrouwers
dd0baf7898 Add missing admin checks
Fixes #2
2022-10-11 01:07:47 +02:00
Zack
3d7a20d398 Add cursor: pointer to comment collapse inputs 2022-10-10 15:33:18 -07:00
David Hoppenbrouwers
8009045c14 s/admin_ban_user/admin_unban_user 2022-10-11 00:21:54 +02:00
David Hoppenbrouwers
cb591b7e25 Merge branch 'mod-ban' 2022-10-11 00:18:43 +02:00