Age | Commit message (Collapse) | Author | |
---|---|---|---|
2020-09-15 | validate_url: add clean() | Andrew Dolgov | |
2020-09-15 | rename base64_img() to image_to_base64() | Andrew Dolgov | |
2020-09-15 | cached_url: perform mimetype validation before possible HOOK_SEND_LOCAL_FILE ↵ | Andrew Dolgov | |
hooks | |||
2020-09-14 | remove csrf token from rpc method sanityCheck | Andrew Dolgov | |
2020-09-14 | - fix multiple vulnerabilities in af_proxy_http | Andrew Dolgov | |
- fix vulnerability in rewrite_relative_url() which prevented some URLs from being properly absolutized - fetch_file_contents: validate all URLs before requesting them - validate URLs: explicitly whitelist http and https scheme, forbid everything else - DiskCache/cached_url: only serve whitelisted content types (images, video) - simplify filename/URL handling code, remove and consolidate some less-used functions | |||
2020-06-15 | better support for image srcset attributes as discussed in ↵ | Andrew Dolgov | |
https://community.tt-rss.org/t/problem-with-img-srcset/3519 | |||
2020-05-23 | only bind up/down in 3 panel mode | Andrew Dolgov | |
2020-05-23 | Revert "unbind up/down by default (use native scrolling for consistency with ↵ | Andrew Dolgov | |
pgup/pgdn)" This reverts commit 6fc18e450b72306693de8723464f4176e73c5a5b. | |||
2020-05-23 | unbind up/down by default (use native scrolling for consistency with pgup/pgdn) | Andrew Dolgov | |
2020-05-17 | implement keyboard-related changes discussed in ↵ | Andrew Dolgov | |
https://community.tt-rss.org/t/changing-the-amount-of-scroll-by-arrow-key/3452/7 | |||
2020-05-15 | Make iframes size responsively. | JustAMacUser | |
2020-05-09 | sanitize: forbid "allow" attribute | Andrew Dolgov | |
CSS: remove auto hyphens stuff, remove iframe width clipping to 98% because they get squished | |||
2020-05-09 | add hotkey "\" to cancel current search | Andrew Dolgov | |
2020-04-29 | sanitize: simplify initial attribute processing | Andrew Dolgov | |
2020-04-29 | sanitize: remove srcset plain-http hack, globally disallow width and height ↵ | Andrew Dolgov | |
attributes for all elements | |||
2020-04-29 | sanitize: handle picture[@srcset] elements properly, i.e. rewrite relative URLs | Andrew Dolgov | |
2020-03-25 | Fix documentation for _noexpand commands | Martin Stone | |
2020-03-02 | In get_version() disable DIRECTORY_SEPARATOR check, permit using git on ↵ | Toby Simmons | |
Windows to get version details; | |||
2020-02-28 | af_readability: allow get full text button to work as a toggle; in cdm, ↵ | Andrew Dolgov | |
scroll to article after embedding | |||
2020-02-27 | update toggle_embed_original hotkey to invoke readability embed instead of ↵ | Andrew Dolgov | |
removed embed_original plugin | |||
2020-02-22 | don't generate default.css, replace with themes/light.css as a default root ↵ | Andrew Dolgov | |
CSS file | |||
2020-02-13 | add support for image loading=lazy attribute | Andrew Dolgov | |
2020-01-24 | scrap counter cache system; rework counters to sum() booleans instead | Andrew Dolgov | |
2020-01-17 | disable MAX_FETCH_REQUESTS_PER_HOST warnings for the time being | Andrew Dolgov | |
2020-01-14 | get_version: don't rely on exec() exit code to determine whether output is valid | Andrew Dolgov | |
2019-12-20 | get_version: fix commit/timestamp lost on subsequent invocations because of ↵ | Andrew Dolgov | |
misbehaving caching | |||
2019-12-19 | force-disable php display_errors/display_startup_errors on startup | Andrew Dolgov | |
2019-12-19 | get_version: filter out Darwin | Andrew Dolgov | |
2019-12-18 | get_version: always return unsupported on windows | Andrew Dolgov | |
2019-12-18 | SELF_USER_AGENT: switch to get_version() | Andrew Dolgov | |
2019-12-18 | get_version: don't pass useless root dir to git, instead log it in case of ↵ | Andrew Dolgov | |
failure | |||
2019-12-18 | remove version.php and VERSION global constant, do version-related things in ↵ | Andrew Dolgov | |
a slightly less ridiculous way | |||
2019-12-12 | implement automatic night mode detection using MQL | Andrew Dolgov | |
add separate light.css to force light theme remove manual night mode toggle and related code | |||
2019-12-11 | - update descriptions of changed hotkeys | Andrew Dolgov | |
- bind noscroll variants of move article hotkeys to n/p by default - update N/P (i.e. scroll article content) hotkeys to scroll by fraction of viewport height instead of hardcoded pixel distance - minor fixes w/ checking for undefined | |||
2019-12-09 | exp: unbind from pgup/pgdn buttons by default | Andrew Dolgov | |
2019-12-06 | Fix Shift+PageUp/Down hotkeys | Michael Kuhn | |
2019-12-06 | user css dialog: allow saving and applying CSS without closing the dialog | Andrew Dolgov | |
2019-12-05 | pgup/pgdown hotkey normalization: | Andrew Dolgov | |
- pgup/pgdown without modifier scroll headline buffer - shift+pgup/pgdown work similarly to shift+up/down but operating on pages | |||
2019-12-05 | versioning changes | Andrew Dolgov | |
- remove VERSION_STATIC - https://community.tt-rss.org/t/versioning-changes-for-trunk/2974 - report git commit/timestamp properly by invoking git instead of trying to parse .git/HEAD etc - remove git-related global constants used when checking for updates | |||
2019-12-04 | add hotkeys to scroll headlines/articles (whichever is active) by one page | Andrew Dolgov | |
2019-11-27 | remove hardcoded iframe domain whitelist, make iframe script whitelisting ↵ | Andrew Dolgov | |
configurable by plugins (HOOK_IFRAME_WHITELISTED) | |||
2019-11-25 | cache media: set referrer to source URL when fetching images | Andrew Dolgov | |
2019-11-17 | reset domain hit quota on feed update start | Andrew Dolgov | |
2019-11-14 | implement MAX_FETCH_REQUESTS_PER_HOST: only generating a warning on exceeded ↵ | Andrew Dolgov | |
quota for the time being | |||
2019-11-01 | add placeholder authentication via app passwords if service is passed | Andrew Dolgov | |
forbid logins via regular passwords for services remove AUTH_DISABLE_OTP | |||
2019-11-01 | update schema for app-specific passwords | Andrew Dolgov | |
2019-09-23 | Removed redundant text for next/prev article without scroll. | JustAMacUser | |
2019-09-22 | Try to clarify next/prev article keyboard shortcut help. | JustAMacUser | |
2019-08-16 | af_readability: add missing file | Andrew Dolgov | |
2019-08-14 | retire MIN_CACHE_FILE_SIZE | Andrew Dolgov | |