1. 09 Oct, 2019 1 commit
    • Kerri Miller's avatar
      Avoid #authenticate_user! in #route_not_found · 83950327
      Kerri Miller authored
      This method, #route_not_found, is executed as the final fallback for
      unrecognized routes (as the name might imply.) We want to avoid
      `#authenticate_user!` when calling `#route_not_found`;
      `#authenticate_user!` can, depending on the request format, return a 401
      instead of redirecting to a login page. This opens a subtle security
      exploit where anonymous users will receive a 401 response when
      attempting to access a private repo, while a recognized user will
      receive a 404, exposing the existence of the private, hidden repo.
      83950327
  2. 07 Oct, 2019 3 commits
  3. 06 Oct, 2019 3 commits
  4. 05 Oct, 2019 1 commit
  5. 04 Oct, 2019 8 commits
  6. 03 Oct, 2019 7 commits
  7. 02 Oct, 2019 11 commits
  8. 01 Oct, 2019 6 commits