diaspora/spec
Maxwell Salzberg 190fceaf5c [SECURITY FIX] please update your pod ASAP
This is a fix for public messages, where a malicious pod could spoof a message from someone a user was connected to, as the verified signatures were not checked that the object was also from said sender.  This hole only affected public messages, and the private part of code had the correct checks
THX to s-f-s(Stephan Schulz) for reporting and tracking down this issue, and props to Raven24(florian.staudacher@gmx.at) for helping me test the patch
2012-07-02 10:00:12 -07:00
..
controllers Rails.root and File.join cleanup 2012-06-11 03:13:20 -07:00
fixtures update xrd fixture to include namespace and remove namespace before trying to set fields in webfinger profile 2012-04-27 00:05:28 +02:00
helpers do not bypass pluralization in test 2012-06-24 13:03:22 +02:00
integration [SECURITY FIX] please update your pod ASAP 2012-07-02 10:00:12 -07:00
javascripts mixpanel on posting 2012-05-30 17:32:18 -07:00
lib [SECURITY FIX] please update your pod ASAP 2012-07-02 10:00:12 -07:00
mailers Make hashtags clickable in emails 2012-05-29 10:01:58 -07:00
models Rails.root and File.join cleanup 2012-06-11 03:13:20 -07:00
presenters Revert "update factory girl" new version does not support 1.8.7 :( 2012-05-16 17:43:56 -07:00
shared_behaviors freeze at a valid time, not 0000-01-01 ... 2012-04-15 13:03:33 +02:00
support Rails.root and File.join cleanup 2012-06-11 03:13:20 -07:00
factories.rb kill rich-media type with fire 2012-05-21 12:33:28 -07:00
helper_methods.rb ms iz rendering nothing for hcard and webfinger if account is closed, not showing aspect dropdown if the user account is closed 2011-12-08 16:32:18 -08:00
misc_spec.rb Revert "update factory girl" new version does not support 1.8.7 :( 2012-05-16 17:43:56 -07:00
parallel_spec.opts pull in parallel_testing to speed up rspec 2011-09-16 22:14:12 +02:00
spec-doc.rb This fixes issue #2298. 2011-11-02 23:51:12 -04:00
spec_helper.rb Get Spork running again 2012-06-14 00:53:10 -07:00