| | |
| | | note: "The default access restriction has been elevated from NONE to PUSH and anonymous push access has been disabled." |
| | | html: ~ |
| | | text: ~ |
| | | security: ~ |
| | | security: |
| | | - ''issue-361: Cookies were not reset on administrative password change of a user account. |
| | | This allowed accounts with changed passwords to continue authenticating. |
| | | Cookies are now reset on password changes, they are validated on each page request, |
| | | AND they will now expire 7 days after generation. |
| | | '' |
| | | fixes: |
| | | - Fixed incorrect tagger attribution in the dashboard (issue-276) |
| | | - Fixed support for implied SSH urls in web.otherUrls (issue-311) |
| | | - Bind LDAP connection after establishing TLS initialization (issue-343) |
| | | - Fixed NPE when attempting to add a permission without a registrant (issue-344) |
| | | - Invalidate all cached repository data on "clear cache" (issue-346) |
| | | - Fix chart failures when an apostrophe is in a user display name (issue-350, pr-128) |
| | | - Fix exception in create repository when not selecting a garbage collection period (issue-366) |
| | | - Stop setting admin permission based on undocumented Redmine REST API behavior (issue-368) |
| | | - Fix support url decoding with non-ascii characters (pr-136) |
| | | - Fix potential NPE on removing uncached repository from cache |
| | | - Ignore the default contents of .git/description file |
| | | - Fix error on generating activity page when there is no activity |
| | |
| | | - Reversed line links in blob view (issue-309) |
| | | - Dashboard and Activity pages now obey the web.generateActivityGraph setting (issue-310) |
| | | - Do not log passwords on failed authentication attempts (issue-316) |
| | | - LDAP synchronization is now scheduled rather than on-demand (issue-336) |
| | | - Show displayname and username in palettes (issue-364) |
| | | - Updated default binary and Lucene ignore extensions |
| | | - Change the WAR baseFolder context parameter to a JNDI env-entry to improve enterprise deployments |
| | | - Removed internal Gitblit ref exclusions in the upload pack |
| | |
| | | - Revised committer verification to require a matching displayname or account name AND the email address |
| | | - Serve repositories on both /r and /git, displaying /r because it is shorter |
| | | additions: |
| | | - Added color modes for the blame page (issue-2) |
| | | - Added an optional MirrorExecutor which will periodically fetch ref updates from source repositories for mirrors (issue-5). Repositories must be manually cloned using native git and "--mirror". |
| | | - Added branch graph image servlet based on EGit's branch graph renderer (issue-194) |
| | | - Added option to render Markdown commit messages (issue-203) |
| | |
| | | - Set Link: <url>; rel="canonical" http header for SEO (issue-304) |
| | | - Added raw links to the commit, commitdiff, and compare pages (issue-319) |
| | | - Support intradocument linking in Markdown content using [[WikiLinks]] syntax (issue-324) |
| | | - Support Markdown image links relative to the repository root (issue-324) |
| | | - Added filesystem write permission check (issue-345) |
| | | - Added GO launch parameter for redirecting logging to a rolling, daily log file (issue-348) |
| | | - Added settings to Windows authentication provider to permit/prohibit BUILTIN\Administrators from being Gitblit Admins (issue-354) |
| | | - Support rendering confluence, mediawiki, textile, tracwiki, and twiki markup documents |
| | | - Added setting to globally disable anonymous pushes in the receive pack |
| | | - Added a normalized diffstat display to the commit, commitdiff, and compare pages |
| | | - Added GO setting to automatically redirect all http requests to the secure https connector |
| | | - Automatically display common repository root documents as tabs on the docs page |
| | | - Support bugtraq configuration in collaboration with syntevo |
| | | - Added FishEye hook script (pr-137) |
| | | - Added Redmine Fetch hook script (issue-359) |
| | | dependencyChanges: |
| | | - updated to Jetty 8.1.13 |
| | | - updated to JGit 3.1.0 |
| | | - replaced MarkdownPapers with pegdown 1.4.1 |
| | | - updated to JGit 3.2.0 |
| | | - updated to Lucene 4.6.0 |
| | | - updated to BouncyCastle 1.49 |
| | | - replaced MarkdownPapers with pegdown 1.4.2 |
| | | - added Dagger 1.1.0 |
| | | - added Eclipse WikiText libraries for processing confluence, mediawiki, textile, tracwiki, and twiki |
| | | - added FontAwesome 4.0.3 |
| | | settings: |
| | | - { name: 'git.createRepositoriesShared', defaultValue: 'false' } |
| | | - { name: 'git.allowAnonymousPushes', defaultValue: 'false' } |
| | |
| | | - { name: 'git.defaultAccessRestriction', defaultValue: 'PUSH' } |
| | | - { name: 'git.mirrorPeriod', defaultValue: '30 mins' } |
| | | - { name: 'realm.authenticationProviders', defaultValue: ' ' } |
| | | - { name: 'realm.ldap.groupEmptyMemberPattern', defaultValue: '(&(objectClass=group)(!(member=*)))' } |
| | | - { name: 'realm.ldap.synchronize', defaultValue: 'false' } |
| | | - { name: 'realm.ldap.syncPeriod', defaultValue: '5 MINUTES' } |
| | | - { name: 'realm.ldap.removeDeletedUsers', defaultValue: 'true' } |
| | | - { name: 'realm.windows.permitBuiltInAdministrators', defaultValue: 'true' } |
| | | - { name: 'web.commitMessageRenderer', defaultValue: 'plain' } |
| | | - { name: 'web.documents', defaultValue: 'readme home index changelog contributing submitting_patches copying license notice authors' } |
| | | - { name: 'web.showBranchGraph', defaultValue: 'true' } |
| | |
| | | - Chris Graham |
| | | - Guenter Dressel |
| | | - fpeters.fae |
| | | - David Ostrovsky |
| | | - Alex Lewis |
| | | - Marc Strapetz |
| | | - Benjamin Asbach |
| | | - Alfred Schmid |
| | | - Gareth Collins |
| | | - Martijn van der Kleijn |
| | | - Berke Viktor |
| | | - Vitaly Litvak |
| | | - Matthias Cullman |
| | | } |
| | | |
| | | # |