gitlab-org--gitlab-foss/app
Robert Speicher edf7dbfacd Merge branch 'html-safe-diff-line-content' into 'security'
Don't accidentally mark unsafe diff lines as HTML safe

Fixes potential XSS issue when a legacy diff note is created on a merge
request whose diff contained HTML

See https://gitlab.com/gitlab-org/gitlab-ce/issues/25249

See merge request !2040
2016-12-08 21:38:35 -03:00
..
assets Merge branch 'fix-reset-template' into 'master' 2016-12-08 20:07:10 +00:00
controllers Merge branch 'destroy-session' into 'security' 2016-12-08 21:21:06 -03:00
finders Merge branch '24733-archived-project-merge-request-count' into 'master' 2016-12-06 14:02:45 +00:00
helpers Merge branch 'html-safe-diff-line-content' into 'security' 2016-12-08 21:38:35 -03:00
mailers Add new template to handle both commit & mr notes 2016-11-25 15:23:49 +00:00
models Merge branch 'pipeline-stage' into 'master' 2016-12-08 15:59:49 +00:00
policies Update effected tests 2016-12-04 17:32:33 +01:00
serializers Merge branch 'fix/ca-no-date' into 'master' 2016-11-30 10:01:56 +00:00
services Merge branch 'pipeline-stage' into 'master' 2016-12-08 15:59:49 +00:00
uploaders Remove event caching code 2016-11-23 14:17:07 +01:00
validators Add nested groups support to the routing 2016-11-23 14:08:36 +02:00
views Merge branch 'pipeline-stage' into 'master' 2016-12-08 15:59:49 +00:00
workers Merge branch 'fix/rename-mwbs-to-merge-when-pipeline-succeeds' into 'master' 2016-12-05 11:07:57 +00:00