Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							1eb1629d9e 
							
						 
					 
					
						
						
							
							pluginhost: rework run_hooks() to be shorter, add callback variant; implement exception handling for both  
						
						
						
						
					 
					
						2021-02-08 14:24:45 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							3f972f8fed 
							
						 
					 
					
						
						
							
							public/subscribe: fix warnings  
						
						
						
						
					 
					
						2021-02-08 08:20:30 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							6e774a58fe 
							
						 
					 
					
						
						
							
							more php8 fixes mostly related to login  
						
						
						
						
					 
					
						2021-02-06 00:12:15 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							403dca154c 
							
						 
					 
					
						
						
							
							initial WIP for php8; bump php version requirement to 7.0  
						
						
						
						
					 
					
						2021-02-05 23:41:32 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							da0ad82c24 
							
						 
					 
					
						
						
							
							Archive cleanup:  
						
						... 
						
						
						
						- remove code to manually archive/unarchive articles
- remove ttrss_archived_feeds/orig_feed_id handling - the whole thing was implemented for
this data to be kept indefinitely; it doesn't make a lot of sense to deal with this stuff
now that it is expired after one month anyway (same reasons as feed browser being removed - privacy)
- remove "originally from"-related stuff because of the above
- also remove unused remaining frontend/backend code related to feed browser (rip) 
						
						
					 
					
						2021-01-17 14:55:11 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							40f38fc87f 
							
						 
					 
					
						
						
							
							pluginhost: load plugin data automatically (also marks load_data method as private)  
						
						
						
						
					 
					
						2021-01-15 08:32:06 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							f67f0f864b 
							
						 
					 
					
						
						
							
							HOOK_ARTICLE_EXPORT_FEED: also pass owner_uid  
						
						
						
						
					 
					
						2021-01-11 22:52:31 +03:00 
						 
				 
			
				
					
						
							
							
								JustAMacUser 
							
						 
					 
					
						
						
						
						
							
						
						
							fadf4dec96 
							
						 
					 
					
						
						
							
							Include tags for HOOK_ARTICLE_EXPORT_FEED.  
						
						
						
						
					 
					
						2021-01-10 03:23:16 -05:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							a8302fb253 
							
						 
					 
					
						
						
							
							use X-Real-IP headers if possible while authenticating  
						
						
						
						
					 
					
						2021-01-05 10:17:24 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							215f388992 
							
						 
					 
					
						
						
							
							move timestamp-related stuff to a separate class  
						
						
						
						
					 
					
						2020-09-23 13:04:26 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							74568df4ff 
							
						 
					 
					
						
						
							
							remove a lot of stuff from global context (functions.php), add a few helper classes instead  
						
						
						
						
					 
					
						2020-09-22 09:04:33 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							03a337a660 
							
						 
					 
					
						
						
							
							add basic safe mode which doesn't load any user plugins  
						
						
						
						
					 
					
						2020-09-18 15:48:22 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							37f41a5246 
							
						 
					 
					
						
						
							
							forgotpass: use type strict comparison for reset token  
						
						
						
						
					 
					
						2020-09-17 11:49:27 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							1f79d614c4 
							
						 
					 
					
						
						
							
							fix OTP QR code not displayed because of CSRF token passed as a query  
						
						... 
						
						
						
						parameter
use type-strict comparison when validating CSRF token on the backend 
						
						
					 
					
						2020-09-17 08:43:39 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							9d3c794983 
							
						 
					 
					
						
						
							
							subscribe: allow pre-filling feed URL if passed via query string  
						
						
						
						
					 
					
						2020-09-16 17:20:31 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							154417d80b 
							
						 
					 
					
						
						
							
							public/logout: require valid CSRF token  
						
						
						
						
					 
					
						2020-09-15 16:59:11 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							8080c525fd 
							
						 
					 
					
						
						
							
							- backend: require CSRF token to be passed via POST  
						
						... 
						
						
						
						- do not leak CSRF token via GET request in feed debugger
- rework Article/redirect to use POST 
						
						
					 
					
						2020-09-15 16:12:53 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							da98ba662e 
							
						 
					 
					
						
						
							
							public/subscribe: require valid CSRF token when validating the form  
						
						
						
						
					 
					
						2020-09-14 20:21:22 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							c3d14e1fa5 
							
						 
					 
					
						
						
							
							- fix multiple vulnerabilities in af_proxy_http  
						
						... 
						
						
						
						- fix vulnerability in rewrite_relative_url() which prevented some URLs from being properly absolutized
- fetch_file_contents: validate all URLs before requesting them
- validate URLs: explicitly whitelist http and https scheme, forbid everything else
- DiskCache/cached_url: only serve whitelisted content types (images, video)
- simplify filename/URL handling code, remove and consolidate some less-used functions 
						
						
					 
					
						2020-09-14 19:46:52 +03:00 
						 
				 
			
				
					
						
							
							
								Rodney Stromlund 
							
						 
					 
					
						
						
						
						
							
						
						
							88ced02622 
							
						 
					 
					
						
						
							
							Silence php 7.2 error message generated in session_set_cookie_params.  
						
						
						
						
					 
					
						2020-08-14 10:47:46 -05:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							dfa65e9374 
							
						 
					 
					
						
						
							
							move order_by to SQL override logic into a separate function  
						
						
						
						
					 
					
						2020-08-13 11:52:32 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							48be005774 
							
						 
					 
					
						
						
							
							instead of taking batch timestamp and score (?) into account, make oldest first sorting work consistently with newest first - i.e. rely on feed-provided timestamp  
						
						
						
						
					 
					
						2020-08-11 13:29:09 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							1f2a721905 
							
						 
					 
					
						
						
							
							allow overriding built-in templates via templates.local  
						
						
						
						
					 
					
						2020-03-13 14:40:35 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							bdb1e475e7 
							
						 
					 
					
						
						
							
							external subscribe dialog: support dark theme  
						
						
						
						
					 
					
						2020-02-27 13:40:32 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							b2876f6c72 
							
						 
					 
					
						
						
							
							share anything dialog: support dark theme  
						
						
						
						
					 
					
						2020-02-27 13:38:24 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							4ab3854aed 
							
						 
					 
					
						
						
							
							don't generate default.css, replace with themes/light.css as a default root CSS file  
						
						
						
						
					 
					
						2020-02-22 16:22:44 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							aa56bcaf44 
							
						 
					 
					
						
						
							
							support night mode when using share by URL  
						
						
						
						
					 
					
						2020-01-19 10:51:08 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							f47998f569 
							
						 
					 
					
						
						
							
							generate_syndicated_feed: use local media in generated feeds if it is available  
						
						
						
						
					 
					
						2020-01-13 17:02:14 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							72d0fac80c 
							
						 
					 
					
						
						
							
							remove version.php and VERSION global constant, do version-related things in a slightly less ridiculous way  
						
						
						
						
					 
					
						2019-12-18 14:27:40 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							ef514bc4bd 
							
						 
					 
					
						
						
							
							add notifications for mail and password changes  
						
						... 
						
						
						
						update and shorten some other message templates 
						
						
					 
					
						2019-10-09 09:04:51 +03:00 
						 
				 
			
				
					
						
							
							
								Rodney Stromlund 
							
						 
					 
					
						
						
						
						
							
						
						
							958c4dc124 
							
						 
					 
					
						
						
							
							Removed extra php end tag that was showing in the page title  
						
						
						
						
					 
					
						2019-09-17 09:11:30 -05:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							3e4701116d 
							
						 
					 
					
						
						
							
							af_readability: add missing file  
						
						
						
						
					 
					
						2019-08-16 15:29:24 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							0e3b71c535 
							
						 
					 
					
						
						
							
							public/pluginhandler: log invalid requests  
						
						
						
						
					 
					
						2019-08-15 17:17:25 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							d4df57e1a4 
							
						 
					 
					
						
						
							
							Article::get_article_image() - also return stream URI if possible  
						
						
						
						
					 
					
						2019-08-14 17:04:14 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							68e2b05f65 
							
						 
					 
					
						
						
							
							* move get_article_image to Article; implement better og:image detection (similar to android app)  
						
						... 
						
						
						
						* pass article image to API clients in headlines row object 
						
						
					 
					
						2019-08-14 16:55:38 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							39f459eb04 
							
						 
					 
					
						
						
							
							public/cached_url: forbid sending files with extensions  
						
						
						
						
					 
					
						2019-08-14 10:45:46 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							3c075bfd21 
							
						 
					 
					
						
						
							
							DiskCache: more strict checking for input filenames, getUrl() is no longer static  
						
						
						
						
					 
					
						2019-08-14 09:49:18 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							fdb6066bf6 
							
						 
					 
					
						
						
							
							* HOOK_ENCLOSURE_ENTRY: pass article_id to handler  
						
						... 
						
						
						
						* DiskCache: multiple fixes; support isWritable() for cache entries, set content-disposition for send()
* public/cached_url: allow selecting files from sub-caches other than images
* plugins/Cache_Starred_Images: rework to use DiskCache, can be enabled per-user, properly handles article enclosures, etc 
						
						
					 
					
						2019-08-13 16:40:21 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							133c2b482b 
							
						 
					 
					
						
						
							
							move rewrite_cached_urls to DiskCache::rewriteUrls()  
						
						
						
						
					 
					
						2019-08-13 12:46:57 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							b1dd38f880 
							
						 
					 
					
						
						
							
							add DiskCache.getUrl() and use it in a bunch of places  
						
						
						
						
					 
					
						2019-08-13 12:39:21 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							ea30061cce 
							
						 
					 
					
						
						
							
							public: fix share() returning random unshared articles if uuid is not given  
						
						
						
						
					 
					
						2019-07-05 16:02:51 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							4fa9aee4e7 
							
						 
					 
					
						
						
							
							move several more global functions to more appropriate classes  
						
						
						
						
					 
					
						2019-06-20 08:14:06 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							6d746453c7 
							
						 
					 
					
						
						
							
							get_feeds_from_html: remove XML preamble hack  
						
						... 
						
						
						
						move several related helper functions to Feeds class 
						
						
					 
					
						2019-06-20 07:51:48 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							671f4cee65 
							
						 
					 
					
						
						
							
							domdocument: remove old meta charset unicode hacks, replace with shorter xml preamble utf8 hack (on loadhtml where it makes sense)  
						
						... 
						
						
						
						af_readability: better (?) charset hack for non-unicode pages 
						
						
					 
					
						2019-03-21 21:08:02 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							6ae0a3dd3e 
							
						 
					 
					
						
						
							
							share: further improve og:description excerpt logic, minor layout stuff  
						
						
						
						
					 
					
						2019-03-19 20:41:38 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							74e8661351 
							
						 
					 
					
						
						
							
							share: decode entities in metadata fields so that length limits would make more sense  
						
						
						
						
					 
					
						2019-03-19 15:53:32 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							19f162dbe3 
							
						 
					 
					
						
						
							
							css: insensitive -> text-muted  
						
						
						
						
					 
					
						2019-03-08 10:11:57 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							44858ca2dd 
							
						 
					 
					
						
						
							
							Merge branch 'master' of git.fakecake.org:tt-rss  
						
						
						
						
					 
					
						2019-03-07 06:45:04 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							e91223ec7d 
							
						 
					 
					
						
						
							
							update CLI schema updater with newer warnings  
						
						
						
						
					 
					
						2019-03-07 06:44:59 +03:00 
						 
				 
			
				
					
						
							
							
								Andrew Dolgov 
							
						 
					 
					
						
						
						
						
							
						
						
							609662d48c 
							
						 
					 
					
						
						
							
							oops, fix typo  
						
						
						
						
					 
					
						2019-03-06 22:48:10 +03:00