Historie revizí

Autor SHA1 Zpráva Datum
  El RIDO 0e3a7196f9 set frame-ancestors to none před 4 roky
  El RIDO 18972ae0fa luckily the PHP ini parser doesn't interpret this as an empty block, replacing the one defined above před 5 roky
  El RIDO 3429d293d3 remove configurable dir for traffic & purge limiters před 5 roky
  Mark van Holsteijn 342270d6dd added Google Cloud Storage support před 5 roky
  LinQhost Managed hosting 63d6816c7c Merge branch 'api-ip-exempt' of https://github.com/rodehoed/PrivateBin into api-ip-exempt před 5 roky
  LinQhost Managed hosting 7d82c82fd9 Make it possible to exempt ips from the rate-limiter před 5 roky
  El RIDO fcb6422663 re-adding CSP directive sandbox allow-forms, it is needed for the password input form to work on the JS side před 5 roky
  rugk 3ca01024fd feat: disallow form submission alltogether před 5 roky
  rugk 5809a7cfa7 feat: add form-action CSP restriction před 5 roky
  rugk fd7d05e862 Add base URL as default CSP restriction před 5 roky
  El RIDO bb6a44ce7a remove double translation, avoid unsupported double quotes in INI file před 5 roky
  Andreas Schneider eb32ea1419 Make it possible to change the info text před 6 roky
  ZerooCool e61c44ef46 Make Opengraph really functional před 6 roky
  ZerooCool 13c2f8d968 Make Opengraph really functional před 6 roky
  El RIDO 45a0535640 adding new flag to sandbox policy, introduced and required by Chrome 83 - fixes #634 před 6 roky
  Haocen Xu bb9a5772bc Add resource: to script-src cspheader to allowed rendering of pdf in před 6 roky
  El RIDO 9aac073a49 clarifying for #525 that none is a string, as PHP might evaluate it to NULL instead před 6 roky
  El RIDO d5aeba60ca increase default size limit to 10 MiB, documenting change před 6 roky
  El RIDO 8e27dbff15 clarify the use of 'unsafe-eval' and what the impact removing it has - Firefox users may not care and disable it to improve security před 6 roky
  Haocen Xu ab75b183fb Fix click on new paste on clone paste editing view not removing custom před 7 roky
  El RIDO 11375a4f59 moved referrer policy from CSP & meta to proper HTTP header to avoid browser console error message about unknown CSP header and to ensure it always applies before HTML is parsed, fixes #196 před 7 roky
  El RIDO c2e060d464 made compression configurable, fixes #38 před 7 roky
  rugk b7db033bdd Adjust config text před 7 roky
  El RIDO 42c2003220 made notice configurable, fixing a few CSS glitches před 7 roky
  El RIDO 362045c664 re-add data-URLs to CSP for img-src, as these are used for the comment icons před 7 roky
  El RIDO f915af1a5a adjust CSP header to allow blob URLs před 7 roky
  El RIDO 398fabd664 Chrome requires unsafe-eval for it to parse and evaluate WASM modules před 7 roky
  El RIDO 720897b902 correct CSP to allow password prompt před 8 roky
  rugk 60d4ccb02c Add comment about blocked images před 8 roky
  El RIDO d6f203dc4c Removed option to hide clone button on expiring pastes, since this requires reading the paste for rendering the template, which leaks information on the pastes state před 8 roky