Commit Graph

  • 7717a1f93f
    Merge 3d42aab16d into 52f6fefed0 睡觉塞牙 2026-04-03 14:55:38 +0000
  • fd10a596b6
    Merge 3439917b33 into 52f6fefed0 Hans362 2026-03-31 09:19:58 +0800
  • 52f6fefed0
    chore: remove unavailable sponsor info dev Pig Fang 2026-03-30 21:42:23 +0800
  • 3439917b33
    feat: replace sha1 with sha256 hans362 2026-03-11 16:47:49 +0800
  • 840555df42
    make tests happy Steven Qiu 2026-03-09 23:13:47 +0800
  • 9aa867e8aa
    refactor: do not catch exceptions when cannot read options Steven Qiu 2026-03-09 20:21:43 +0800
  • b79d8884d1 Create change Gerrit User 1039230 2026-02-01 09:53:18 +0000
  • 35e730e153 Create change Gerrit User 1039230 2026-02-01 09:53:04 +0000
  • c6bea9a6f7 Create change Gerrit User 1039230 2026-02-01 09:52:52 +0000
  • 09fee85e35 Create change Gerrit User 1039230 2026-02-01 09:52:48 +0000
  • 69a60b8278 Create change Gerrit User 1039230 2026-02-01 09:52:45 +0000
  • d0694d5a9f Create change Gerrit User 1039230 2026-02-01 09:52:41 +0000
  • f14a0a34e3 Create change Gerrit User 1039230 2026-02-01 09:52:33 +0000
  • 8e1e509794 Create change Gerrit User 1039230 2026-02-01 09:52:26 +0000
  • b283df5693 Create change Gerrit User 1039230 2026-02-01 09:52:24 +0000
  • de5c018012 Create change Gerrit User 1039230 2026-02-01 09:52:18 +0000
  • e784e563b1 Create change Gerrit User 1039230 2026-02-01 09:52:13 +0000
  • 5ae64f5a39 Create change Gerrit User 1039237 2026-02-01 09:52:12 +0000
  • e5b7d55b95 Create change Gerrit User 1039238 2026-02-01 09:52:09 +0000
  • 022a497dee Create change Gerrit User 1039237 2026-02-01 09:52:08 +0000
  • 23b1c25d16 Create change Gerrit User 1039230 2026-02-01 09:52:08 +0000
  • 9a9f188c58 Create change Gerrit User 1039237 2026-02-01 09:52:06 +0000
  • 07bc0d01ca Create change Gerrit User 1039230 2026-02-01 09:51:58 +0000
  • 5b482f2468
    fix: update tests for email verification hans362 2026-01-29 09:55:35 +0800
  • 2b1ee0344e
    fix: add missing Carbon import in SendEmailVerification listener hans362 2026-01-26 17:37:56 +0800
  • ba3cc6fe91
    fix: generate temporary email verification link with email hash included hans362 2026-01-26 10:07:38 +0800
  • 3d42aab16d [Security] Dynamic Email Verification & Password Reset Links **Problem** 1. **Static Signature Vulnerability**: - Email verification links used a static signature algorithm (same link for lifetime), allowing account hijacking if links were leaked. - *Worst-case scenario*: Compromised AppKey + leaked link → full-site account under danger. 2. **Overly Long Reset Window**: - Password reset links remained valid for 1 hour, enabling attackers to hijack accounts if intercepted. - *Worst-case scenario*: Compromised AppKey + leaked link → full-site account account take over. shhzhang 2026-01-24 23:16:39 +0800
  • d70b39f445
    feat: add Auto-Submitted header to emails Steven Qiu 2025-10-09 01:54:37 +0800
  • de09deb356
    更换Imagick的数据处理 SANYE-YA 2025-08-07 05:23:18 +0800
  • 77a58bbe4a
    更改Imagick数据处理 SANYE-YA 2025-08-07 05:17:15 +0800
  • 33055ecbf9
    fix avatar (refactor needed) (#666) SANYE-YA 2025-08-07 05:08:13 +0800
  • 3731a35d0d
    add todo comment Steven Qiu 2025-08-07 05:06:49 +0800
  • 3409c98914
    临时修复[GD方式] SANYE-YA 2025-08-07 04:51:49 +0800
  • 2e39fbce77
    fix: avatar (refactor needed) Steven Qiu 2025-07-31 19:59:29 +0800
  • 1b3b020d52
    fix: make imagick sanitize result stable Steven Qiu 2025-07-27 03:34:35 +0800
  • 33d805ee82
    fix: skinlib 2d preview (refactor needed) Steven Qiu 2025-07-26 21:38:33 +0800
  • 57c02dd51c
    fix: check if imagick installed Steven Qiu 2025-07-25 17:43:53 +0800
  • 5b6bb98860
    chore: update README Steven Qiu 2025-07-25 17:39:02 +0800
  • c01112a6c1
    chore: use imagick for Intervention\Image Steven Qiu 2025-07-25 17:13:54 +0800
  • 064b0967fc
    chore: complete Facade namespaces in use statements Steven Qiu 2025-06-30 04:36:20 +0800
  • 9f4c59abec
    chore: no .DS_Store [skip ci] Steven Qiu 2025-06-30 04:23:09 +0800
  • d8547a0a3d
    refactor: use Intervention/Image to sanitize textures Steven Qiu 2025-07-02 19:10:52 +0800
  • 9c51bd602b chore: remove redundant VSCode launch profile Steven Qiu 2025-06-29 05:32:30 +0800
  • bc3f504ca3 chore: ci Steven Qiu 2025-06-29 05:31:34 +0800
  • 761cbb7828
    feat: max texture width & texture sanitize (#662) Steven Qiu 2025-06-29 16:09:55 +0800
  • f4526597ef
    Update skinlib.yml Steven Qiu 2025-06-29 16:07:14 +0800
  • c8ebe991df
    chore: set default value for max_texture_width option Steven Qiu 2025-06-29 06:57:38 +0800
  • f796a8d098
    style: apply php-cs-fixer fixes Steven Qiu 2025-06-29 06:44:10 +0800
  • a92c441b1a
    feat: limit max texture width to avoid png bomb Steven Qiu 2025-06-29 06:41:35 +0800
  • 16bf9ee659
    feat: sanitize uploaded file when user upload texture Steven Qiu 2025-06-29 05:30:48 +0800
  • 01fe3eb4cb
    chore: set filename for ci snapshot build artifact Steven Qiu 2025-06-28 17:48:16 +0800
  • f03dd8122b
    chore: remove redundant command in ci Steven Qiu 2025-06-28 17:47:28 +0800
  • cfda2a6bf8
    style: apply php-cs-fixer fixes Steven Qiu 2025-06-28 06:17:40 +0800
  • 74ce668221
    fix: phpunit test Steven Qiu 2025-06-28 06:16:14 +0800
  • 5a18d24464
    fix: db exception in tests Steven Qiu 2025-06-28 03:46:17 +0800
  • 5125862f80
    fix: unexpected db query during composer install Steven Qiu 2025-06-27 19:23:20 +0800
  • fa791857ec
    fix: ci snapshot build Steven Qiu 2025-06-26 21:47:35 +0800
  • 24ad29ea99
    style: apply php-cs-fixer fixes Steven Qiu 2025-06-26 21:16:56 +0800
  • cdfb972bd0 fix: scopes missing after cache clear Steven Qiu 2025-06-26 21:12:36 +0800
  • 7d76886947
    修复项目缺少 lcobucci/jwt 这个 PHP 包 521141 2025-06-26 13:25:39 +0800
  • b0f59652b4
    修复请求的 scope没有被 Laravel Passport 正确注册 521141 2025-06-26 13:23:50 +0800
  • 1985ce6ff8
    config: switch default registry Zephyr Lykos 2025-06-25 22:57:43 +0800
  • d84eb65d55
    Handle null route when request is handled by middleware Steven Qiu 2025-06-22 21:50:57 +0800
  • 16474fb5d0
    Remove locale cookie for API requests (#660) Steven Qiu 2025-06-22 17:48:48 +0800
  • f0faec3450
    Remove redundant code Steven Qiu 2025-06-22 17:46:16 +0800
  • 8f07b82c14
    Do not set locale cookie for API requests Steven Qiu 2025-06-22 17:43:57 +0800
  • 186138b884
    Fix Netlify links (#656) Jerry 2025-06-22 17:40:50 +0800
  • 068cba603c
    Fix Netlify link Steven Qiu 2025-06-22 17:40:17 +0800
  • 618910d695
    Update README-zh.md Jerry 2025-01-25 21:59:27 +0800
  • baefaf51cc
    cleanup: wip 6.2 cleanup Zephyr Lykos 2025-01-19 22:10:05 +0800
  • d48d332c83
    cleanup: wip 6.1 Zephyr Lykos 2025-01-19 15:25:15 +0800
  • 590ed9ce73
    cleanup: wip 6 Zephyr Lykos 2025-01-19 14:15:08 +0800
  • ea5be502b3
    chore: update deps, use bs-community/TwigBridge Zephyr Lykos 2025-01-18 17:04:51 +0800
  • 9ca6e37e39
    chore: update deps Zephyr Lykos 2025-01-18 16:44:15 +0800
  • c4cbf17418
    更改PHP版本 xycabcd 2024-05-16 16:59:07 -0400
  • 0d334e0ab7
    Change PHP version xycabcd 2024-05-16 16:58:27 -0400
  • b4671d3ec6
    删除病句 xycabcd 2024-05-16 16:48:34 -0400
  • aeefc6266c
    消歧义 xycabcd 2024-05-16 16:47:03 -0400
  • 187899d533
    Merge a50473c303 into 866e182c31 xycabcd 2024-04-28 17:26:14 -0400
  • a50473c303
    Change PHP requirment to PHP = 8.1.0 xycabcd 2024-04-28 17:26:00 -0400
  • 82bd3a0c19
    Merge 3f3e66e55f into 866e182c31 xycabcd 2024-04-28 17:23:48 -0400
  • 3f3e66e55f
    Add the right link of plugin store xycabcd 2024-04-28 17:23:07 -0400
  • f95ccdf0db
    Merge e50cc6ee28 into 866e182c31 Zephyr Lykos 2024-04-13 08:49:44 +0000
  • e50cc6ee28
    cleanup: upgrade deps & misc Zephyr Lykos 2024-04-13 16:49:28 +0800
  • 00639b7bc2
    cleanup: wip 5 Zephyr Lykos 2024-03-05 11:20:32 +0800
  • e7b4111d2b
    cleanup: wip 4 Zephyr Lykos 2024-03-05 10:38:01 +0800
  • 643f73c752
    fix: do not do type-only imports of React Zephyr Lykos 2024-03-05 10:28:07 +0800
  • e6665a3977
    cleanup: wip 3.2 Zephyr Lykos 2024-02-27 10:13:09 +0800
  • 9524a234cf
    cleanup: wip 3.1 Zephyr Lykos 2024-02-24 23:01:32 +0800
  • af2c13a8b4
    cleanup: wip part 3 Zephyr Lykos 2024-02-24 00:53:19 +0800
  • ae71d36c7f
    cleanup: wip part 2 Zephyr Lykos 2024-02-23 18:24:34 +0800
  • 2b196a95a8
    cleanup: wip part 1 Zephyr Lykos 2024-02-23 16:58:44 +0800
  • 866e182c31
    Fix #583 (#584) Steven Qiu 2024-01-12 20:44:58 +0800
  • 739b9c97d7
    tests: fix CheckRoleTest warning Zephyr Lykos 2024-01-12 20:41:37 +0800
  • 0a43c5aa67
    style: format code Zephyr Lykos 2024-01-12 20:37:11 +0800
  • 35bd4524e6
    ci: bump snapshot builds to PHP 8.2 Zephyr Lykos 2024-01-12 20:35:16 +0800
  • eba91d5f1d
    chore: update frontend deps Zephyr Lykos 2024-01-12 20:31:53 +0800
  • d764836244
    ci: update deps Zephyr Lykos 2024-01-12 20:31:37 +0800
  • b1b4a71c3e
    chore: update deps Zephyr Lykos 2024-01-12 20:24:47 +0800
  • 709c2231e9
    Merge branch 'bs-community:dev' into dev Steven Qiu 2023-09-12 22:52:38 +0800