From d5ee557ef1370b5b9953dca1c8d3b14d0bd68a98 Mon Sep 17 00:00:00 2001 From: James Moger <james.moger@gitblit.com> Date: Thu, 02 May 2013 22:31:58 -0400 Subject: [PATCH] Do not use problematic WicketUtils fluid api --- releases.moxie | 71 ++++++++++++++++++++++++++++++++--- 1 files changed, 64 insertions(+), 7 deletions(-) diff --git a/releases.moxie b/releases.moxie index 453709c..c065435 100644 --- a/releases.moxie +++ b/releases.moxie @@ -5,25 +5,82 @@ title: Gitblit ${project.version} Released id: ${project.version} date: ${project.buildDate} + security: + - Raw servlet was insecure. If someone knew the exact repository name and path to a file, the raw blob could be retrieved bypassing security constraints. (issue 198) fixes: - Could not reset settings with $ or { characters through Gitblit Manager because they are not properly escaped + - Added more error checking to blob page and blame page + - Disable SNI extensions for client SSL connections + - Fixed prettify language extension loading + - Use bash instead of sh in Linux/OSX shell scripts (issue 154) + - Fix NPE when getting user's fork without repository list caching (issue 182) + - Fix internal error on folder history links (issue 192) + - Fixed incorrect icon file name for .doc files (issue 200) + - Do not queue emails with no recipients (issue 201) + - Disable view and blame links for deleted blobs (issue 216) + - Fixed 1.2.x regression with individually symlinked repositories (issue 217) + - Fixed UTF-8 encoding errors in email notifications (issue 218) + - Fixed NPE in 1.2.1 Federation Client (issue 219) + - Fixed extracting Groovy scripts on Express installs (issue 220) + - Ensure Redmine url is properly formatted (issue 223) + - Use standard ServletRequestWrapper instead of custom wrapper (issue 224) + changes: + - Improve Gerrit change ref decoration in the refs panel (issue 206) + - Disable Gson's pretty printing which has a huge performance gain + - Properly set application/json content-type on api calls + - Updated Polish translation + - Updated Japanese translation + additions: - - Option to force client-side basic authentication instead of form-based authentication if web.authenticateViewPages=true (issue 222) + - Added a server setting to force a particular translation/Locale for all sessions + - Added Git Daemon serving + - Option to automatically tag branch tips on each push with an incremental revision number + - Implemented multiple repository owners - Optional periodic LDAP user and team pre-fetching & synchronization - Display name and version in Tomcat Manager - FogBugz post-receive hook script - - Implemented multiple repository owners - Chinese translation + - Support --baseFolder parameter in Federation Client + - Added weblogic.xml to WAR for deployment on WebLogic (issue 199) + - Support username substitution in web.otherUrls (issue 213) + - Option to force client-side basic authentication instead of form-based authentication if web.authenticateViewPages=true (issue 222) contributors: - - github/furinzen - - github/mschaefers - - github/thefake - - github/djschny + - Bandarupalli Satyanarayana + - Christian Aistleitner + - David Ostrovsky + - Egbert Teeselink + - Hige Maniya + - Ikslawek + - Jay Meyer + - John Crygier + - Kensuke Matsuzaki + - Laurens Vrijnsen + - Lee Grofit + - Lukasz Jader + - Martijn Laan + - Michael Schaefers + - Philip Boutros + - Rafael Cavazin + - Ryan Schneider + - Sakurai Youhei + - Sarah Haselbauer + - Slawomir Bochenski + - Stardrad Yin + - Thomas Pummer + - Yukihiko Sawanobori - github/akquinet - github/dapengme - - github/yin8086 + + dependencyChanges: + - JGit 3.0.0-SNAPSHOT + + settings: + - { name: 'git.daemonBindInterface', defaultValue: 'localhost' } + - { name: 'git.daemonPort', defaultValue: 0 } + - { name: 'git.defaultIncrementalPushTagPrefix', defaultValue: 'r' } + - { name: 'web.forceDefaultLocale', defaultValue: ' ' } } # -- Gitblit v1.9.1