I2P Address: [http://git.idk.i2p]

Skip to content
Snippets Groups Projects
  1. Jul 26, 2014
    • zzz's avatar
      Console: · 58578d90
      zzz authored
        XSSFilter patch from str4d:
        XSSFilter and XSSRequestWrapper were from http://ricardozuasti.com/2012/stronger-anti-cross-site-scripting-xss-filter-for-java-web-apps/
        No provided license, but it is clearly intended for public consumption.
        But most of it is boilerplate provided by the Servlet Filter system.
        In fact, now that I have stripped out his JS-specific patterns and replaced it with the whitelist,
        it is effectively identical to what I would have written from scratch.
      58578d90
    • zzz's avatar
      * Console: · af575d6c
      zzz authored
        - Fix several XSS issues (thx Aaron Portnoy of Exodus Intel)
        - Add Content-Security-Policy and X-XSS-Protection headers
        - Disable changing news feed URL from UI
        - Disable plugin install from UI
        - Disable setting unsigned update URL from UI
        - Disable /configadvanced
      * DataHelper: Disallow \r in storeProps() (thx joernchen of Phenoelit)
      * ExecNamingService: Disable (thx joernchen of Phenoelit)
      * Startup: Add susimail.config to migrated files
      af575d6c
    • str4d's avatar
      Updated Eclipse settings · e9c8748c
      str4d authored
      e9c8748c
  2. Jul 23, 2014
  3. Jul 22, 2014
  4. Jul 21, 2014
  5. Jul 19, 2014
  6. Jul 15, 2014
  7. Jul 14, 2014
  8. Jul 13, 2014
  9. Jul 11, 2014
    • zzz's avatar
      * Datagrams: · 2c185ea7
      zzz authored
        - Redefine the repliable datagram signature for non-DSA_SHA1 sig types;
          was the sig of the SHA-256 of the payload, now the sig of the payload itself.
          This is an incompatible change but nobody is yet using the new
          sig types for datagram applications.
        - Don't pollute the hash cache with hashes of payloads
        - Check for too-big datagrams
        - Remove assertion check
        - Cleanups
      2c185ea7
    • zzz's avatar
      javadoc · 39e859c3
      zzz authored
      39e859c3
  10. Jul 09, 2014
  11. Jul 05, 2014
Loading