Commit Graph

510 Commits

Author SHA1 Message Date
El RIDO 40d35ab3c2
update SRI-hashes 2022-03-27 08:28:54 +02:00
El RIDO 75dc346f0f
be more specific on the base type match and less specific on the subtype, in order to fail-safe (avoid being tricked into not sanitizing - the mime type is a user provided input) 2022-03-27 08:27:24 +02:00
El RIDO 36cb37c029
prevent error when attachments are disabled, but paste with attachment gets displayed 2022-03-13 20:18:51 +01:00
El RIDO 5617612eb3
upgrade to showdown 2.0.3 2022-03-13 20:05:38 +01:00
El RIDO 2a4d572c1e
Sanitize SVG preview, preventing script execution in instance context, while dropping support for attachment download in IE 2022-03-13 19:56:12 +01:00
El RIDO 6c1f0dde0c
set CSP also as meta tag, to deal with misconfigured webservers mangling the HTTP header 2022-03-13 18:11:13 +01:00
El RIDO f83f80b5f6
Merge branch 'master' into stevenandres-master 2022-02-26 11:56:58 +01:00
El RIDO fbf0eae513
update bootstrap JS library to 3.4.1
note that this fails one of our unit tests
2022-02-20 16:13:54 +01:00
El RIDO 7277d2bb43
update all libraries 2022-02-18 07:36:09 +01:00
El RIDO 9df6754dfa
Merge pull request #881 from PrivateBin/jbobau
Lojban translation
2022-02-13 08:58:29 +01:00
El RIDO 8faf0501f4
improve Lojban support
- Crowdin has to use the 3 letter language code, since Lojban has no 2 letter code. Added support for this in the PHP backend and renamed the translation file.
- Lojban has no plural cases, updated the plural-formulas accordingly.
- Credited the change and documented it.
- Updated the SRI hashes.
2022-02-12 16:17:09 +01:00
Bjoern Becker 832f000576
update jquery 2022-02-11 12:22:16 +01:00
El RIDO 0e78534e48
re-label "Download" button to "Save paste" 2021-04-18 09:07:57 +02:00
El RIDO 3181cfe58a
translate download button, add it to page template 2021-04-17 09:15:00 +02:00
El RIDO bc11452259
make filename unique per paste ID 2021-04-17 09:08:11 +02:00
El RIDO 853a4f386f
fix indentation 2021-04-17 08:51:25 +02:00
El RIDO 47029fb04e
Merge branch 'master' into download-feature 2021-04-17 08:47:14 +02:00
El RIDO 1dc8b24665
transmit cookie only over HTTPS, fixes #472 2021-04-16 20:15:12 +02:00
Christian Pierre MOMON ed66351337
Added download feature (#5318). 2021-04-16 19:29:03 +02:00
El RIDO 175d14224e
set plurals for and credit Estonian translation 2021-04-16 18:27:12 +02:00
El RIDO d65bf02d78
upgraded kjua 2021-04-05 17:33:07 +02:00
El RIDO 458ebcb321
incrementing version 2021-04-05 17:05:14 +02:00
El RIDO a369202c51
add missing expiration reset 2021-04-05 13:47:37 +02:00
El RIDO 77ee40909f
record defaults during initialization, fixes #682 2021-04-05 13:24:53 +02:00
El RIDO 2e10bdbd22
update DOMpurify to version 2.2.7 2021-04-02 09:09:47 +02:00
El RIDO da0896fe42
set plurals for and credit Catalan translation 2021-04-02 09:00:27 +02:00
El RIDO 5a9bcea3a9
set plurals for and credit Indonesian translation 2021-03-09 05:54:06 +01:00
El RIDO e6e985d92d
apply StyleCI 2021-03-07 19:56:19 +01:00
hogren 42e609e66f Avoid the use of <i> markup in a translation. 2021-03-06 14:12:59 +01:00
El RIDO b38ebc503e
plural rules and documenting newly added languages 2021-01-07 21:16:03 +01:00
techboyg5 283561e34f
Language dropdown menu to the right 2020-11-22 15:13:43 -06:00
El RIDO bb6a44ce7a
remove double translation, avoid unsupported double quotes in INI file 2020-10-13 07:28:35 +02:00
Andreas Schneider eb32ea1419 Make it possible to change the info text
This makes it possible to change the last part of the info text and
replace it with something individual. E.g pointing to the cmdline
client.

Signed-off-by: Andreas Schneider <asn@cryptomilk.org>
2020-10-11 17:04:08 +02:00
El RIDO 417b17f86d
didn't figure out which StyleCI change suddenly requires this, so just apply the patch to stop it nagging about it 2020-10-04 12:16:42 +02:00
El RIDO 1614342248
update DOMpurify to version 2.0.14 2020-08-30 08:34:38 +02:00
ZerooCool e61c44ef46 Make Opengraph really functional
Make Opengraph really functional

Change : #664 for #651
2020-07-01 19:47:12 +02:00
ZerooCool 13c2f8d968 Make Opengraph really functional
3 URLs of images used on social networks are passed in absolute URL.

Note that I did not pass all the images in absolute URLs, but, it could be consistent to do so, but, if the images work, maybe a relative call is more efficient?

Remove the version of PrivateBin, at the end of each image. This apparently prevents the opengraph from working, and, so I deleted on all of the images, to remain consistent at this level. This will make fewer requests, and, anyway, the images are not intended to change with each version.
2020-06-30 22:42:12 +02:00
El RIDO 0673c1cde1
fix display of empty files #663 2020-06-30 20:10:56 +02:00
Haocen Xu f1d4792d3e
Update SRI 2020-06-02 09:06:12 -04:00
unknown 9b138fd5fd
Update SRI 2020-06-01 02:35:06 +08:00
Haocen Xu 420f0d6634
Update SRI 2020-05-30 06:22:35 -04:00
rugk 38a1726e22
Regenerate SRI 2020-04-23 12:07:38 +02:00
El RIDO 7e77b94158
revert the revert caused by the merge of master 2020-03-23 18:58:26 +01:00
El RIDO 9914c37683
incrementing version 2020-03-22 06:44:04 +01:00
El RIDO 1439bb291f
allow pasting password on paste with attachment - big kudos @rugk for finding it! - fixes #565, fixes #595 2020-03-21 16:53:55 +01:00
rugk 7cb830e22f
It includes a change in the RegEx for URLs because that was broken when a
& character later followed at any time after a link (even after a newline).
(with a negative lookahead)

Test with https://regex101.com/r/i7bZ73/1

Now the RegEx does not check for _all_ chars after a link, but just for the
one following the link.
(So the lookahead is not * anymore. I guess thsi behaviour was
the expectation when it has been implemented.)
2020-03-06 22:37:12 +01:00
El RIDO c334d2d00d
Merge branch 'master' into preview-encoding 2020-03-06 22:23:40 +01:00
El RIDO c11dc8e17e
reverting Helper.urls2links() method to old style, applied to element instead of string, allows inserting plain text as text node 2020-03-06 22:18:38 +01:00
El RIDO 8a6dcf910a
Revert "in Helper.urls2links(), encode HTML entities, find and insert links, partially decoding only the href property of it"
This reverts commit 5340f417e0.
2020-03-06 20:57:15 +01:00
El RIDO f391773c65
generalize date string handling, replacing hardcoded lookups, fixes #586 2020-03-01 08:54:48 +01:00