Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								2fcf652fff 
								
							 
						 
						
							
							
								
								Merge branch 'main' into glitch-soc/merge-upstream  
							
							
							
						 
						
							2022-01-31 10:42:17 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Daniel Jakots 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								aa45404578 
								
							 
						 
						
							
							
								
								Bump NODE_VER to 16.13.2, to solve security issues ( #17399 )  
							
							... 
							
							
							
							Fixes CVE-2021-44532, CVE-2021-44533, and CVE-2022-21824.
See: https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/  
							
						 
						
							2022-01-31 00:32:03 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								a0e06c3c3e 
								
							 
						 
						
							
							
								
								Add more advanced migration tests ( #17393 )  
							
							... 
							
							
							
							- populate the database with some data when testing migrations
- try both one-step and two-step migrations (`SKIP_POST_DEPLOYMENT_MIGRATIONS`) 
							
						 
						
							2022-01-30 23:50:08 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								c6b291afc3 
								
							 
						 
						
							
							
								
								Change index corruption warning to be a little less scary ( #17395 )  
							
							
							
						 
						
							2022-01-30 23:49:52 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								b54e263712 
								
							 
						 
						
							
							
								
								Merge pull request  #1673  from ClearlyClaire/glitch-soc/merge-upstream  
							
							... 
							
							
							
							Merge upstream changes 
							
						 
						
							2022-01-30 22:51:32 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								a99adeaad3 
								
							 
						 
						
							
							
								
								Fix edge case in migration helpers that caused crash because of PostgreSQL quirks ( #17398 )  
							
							
							
						 
						
							2022-01-30 22:34:54 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								7679ddcd5e 
								
							 
						 
						
							
							
								
								Merge branch 'main' into glitch-soc/merge-upstream  
							
							
							
						 
						
							2022-01-30 22:33:30 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								ac583fce21 
								
							 
						 
						
							
							
								
								Fix some old migration scripts ( #17394 )  
							
							... 
							
							
							
							* Fix some old migration scripts
* Fix edge case in two-step migration from older releases 
							
						 
						
							2022-01-30 21:38:54 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								f5639e1cbe 
								
							 
						 
						
							
							
								
								Change public profile pages to be disabled for unconfirmed users ( #17385 )  
							
							... 
							
							
							
							Fixes  #17382 
Note that unconfirmed and unapproved accounts can still be searched for
and their (empty) account retrieved using the REST API. 
						
							2022-01-28 14:24:37 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								2ba6267f16 
								
							 
						 
						
							
							
								
								Merge pull request  #1668  from ClearlyClaire/glitch-soc/merge-upstream  
							
							... 
							
							
							
							Merge upstream changes 
							
						 
						
							2022-01-28 09:38:44 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								94a39f6b68 
								
							 
						 
						
							
							
								
								Fix Sidekiq warning when pushing DMs to direct timeline  
							
							
							
						 
						
							2022-01-28 09:07:56 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								b2915613fb 
								
							 
						 
						
							
							
								
								Merge branch 'main' into glitch-soc/merge-upstream  
							
							... 
							
							
							
							Conflicts:
- `Gemfile.lock`:
  Upstream-updated lib textually too close to glitch-soc-only dep.
  Updated like upstream. 
							
						 
						
							2022-01-28 08:58:32 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								e38fc319dc 
								
							 
						 
						
							
							
								
								Refactor and improve tests ( #17386 )  
							
							... 
							
							
							
							* Change account and user fabricators to simplify and improve tests
- `Fabricate(:account)` implicitly fabricates an associated `user` if
  no `domain` attribute is given (an account with `domain: nil` is
  considered a local account, but no user record was created), unless
  `user: nil` is passed
- `Fabricate(:account, user: Fabricate(:user))` should still be possible
  but is discouraged.
* Fix and refactor tests
- avoid passing unneeded attributes to `Fabricate(:user)` or
  `Fabricate(:account)`
- avoid embedding `Fabricate(:user)` into a `Fabricate(:account)` or the other
  way around
- prefer `Fabricate(:user, account_attributes: …)` to
  `Fabricate(:user, account: Fabricate(:account, …)`
- also, some tests were using remote accounts with local user records, which is
  not representative of production code. 
							
						 
						
							2022-01-28 00:46:42 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								03d59340da 
								
							 
						 
						
							
							
								
								Fix Sidekiq warnings about JSON serialization ( #17381 )  
							
							... 
							
							
							
							* Fix Sidekiq warnings about JSON serialization
This occurs on every symbol argument we pass, and every symbol key in hashes,
because Sidekiq expects strings instead.
See https://github.com/mperham/sidekiq/pull/5071 
We do not need to change how workers parse their arguments because this has
not changed and we were already converting to symbols adequately or using
`with_indifferent_access`.
* Set Sidekiq to raise on unsafe arguments in test mode
In order to more easily catch issues that would produce warnings in production
code. 
							
						 
						
							2022-01-28 00:43:56 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								14c69a535b 
								
							 
						 
						
							
							
								
								Fix some old database migrations ( #17379 )  
							
							
							
						 
						
							2022-01-27 18:13:41 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								4942a7ce86 
								
							 
						 
						
							
							
								
								Bump pg from 1.2.3 to 1.3.0 ( #17349 )  
							
							... 
							
							
							
							Bumps [pg](https://github.com/ged/ruby-pg ) from 1.2.3 to 1.3.0.
- [Release notes](https://github.com/ged/ruby-pg/releases )
- [Changelog](https://github.com/ged/ruby-pg/blob/master/History.rdoc )
- [Commits](https://github.com/ged/ruby-pg/compare/v1.2.3...v1.3.0 )
---
updated-dependencies:
- dependency-name: pg
  dependency-type: direct:production
  update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-27 20:26:40 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								497b8eedda 
								
							 
						 
						
							
							
								
								Bump axios from 0.24.0 to 0.25.0 ( #17354 )  
							
							... 
							
							
							
							Bumps [axios](https://github.com/axios/axios ) from 0.24.0 to 0.25.0.
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/master/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v0.24.0...v0.25.0 )
---
updated-dependencies:
- dependency-name: axios
  dependency-type: direct:production
  update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-27 20:26:18 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								df78d83e95 
								
							 
						 
						
							
							
								
								Bump rdf-normalize from 0.4.0 to 0.5.0 ( #17226 )  
							
							... 
							
							
							
							Bumps [rdf-normalize](https://github.com/ruby-rdf/rdf-normalize ) from 0.4.0 to 0.5.0.
- [Release notes](https://github.com/ruby-rdf/rdf-normalize/releases )
- [Commits](https://github.com/ruby-rdf/rdf-normalize/compare/0.4.0...0.5.0 )
---
updated-dependencies:
- dependency-name: rdf-normalize
  dependency-type: direct:production
  update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-27 20:25:18 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								ad6ddb9bdd 
								
							 
						 
						
							
							
								
								Merge branch 'main' into glitch-soc/merge-upstream  
							
							... 
							
							
							
							Conflicts:
- `config/environments/production.rb`:
  Upstream changed a header but we had different default headers.
  Applied the same change, and also dropped HSTS headers redundant with
  Rails'. 
							
						 
						
							2022-01-26 22:32:21 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								166cc5b89d 
								
							 
						 
						
							
							
								
								Fix local distribution of edited statuses ( #17380 )  
							
							... 
							
							
							
							Because `FanOutOnWriteService#update?` was broken, edits were considered as new
toots and a regular `update` payload was sent. 
							
						 
						
							2022-01-26 20:53:50 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Su Yang 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								10188c7db7 
								
							 
						 
						
							
							
								
								Add healthcheck for sidekiq ( #17365 )  
							
							
							
						 
						
							2022-01-26 18:08:49 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Eugen Rochko 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								6505b39e5d 
								
							 
						 
						
							
							
								
								Fix poll updates being saved as status edits ( #17373 )  
							
							... 
							
							
							
							Fix  #17344  
						
							2022-01-26 18:05:39 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								5893019937 
								
							 
						 
						
							
							
								
								Merge pull request  #1667  from ClearlyClaire/glitch-soc/fixes/hcaptcha-text  
							
							... 
							
							
							
							Improve explanations around the hCaptcha feature 
							
						 
						
							2022-01-26 14:24:10 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								b768a4dea9 
								
							 
						 
						
							
							
								
								Add link to /about/more to the CAPTCHA verification page  
							
							
							
						 
						
							2022-01-26 14:09:11 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								7c2204314a 
								
							 
						 
						
							
							
								
								Add some explanation text on the CAPTCHA confirmation page  
							
							
							
						 
						
							2022-01-26 13:24:51 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								f997a5463b 
								
							 
						 
						
							
							
								
								Add mention of accessibility issues to hCaptcha option in admin page  
							
							
							
						 
						
							2022-01-26 11:39:47 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								129bc42979 
								
							 
						 
						
							
							
								
								Merge pull request  #1665  from ClearlyClaire/glitch-soc/features/hcaptcha  
							
							... 
							
							
							
							Add optional hCaptcha support 
							
						 
						
							2022-01-26 00:13:24 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								b7cf3941b3 
								
							 
						 
						
							
							
								
								Change CAPTCHA handling to be only on email verification  
							
							... 
							
							
							
							This simplifies the implementation considerably, and while not providing
ideal UX, it's the most flexible approach. 
							
						 
						
							2022-01-25 23:56:57 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								0fb907441c 
								
							 
						 
						
							
							
								
								Add ability to set hCaptcha either on registration form or on e-mail validation  
							
							... 
							
							
							
							Upshot of CAPTCHA on e-mail validation is it does not need to break the in-band
registration API. 
							
						 
						
							2022-01-25 23:09:48 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								a9269f8786 
								
							 
						 
						
							
							
								
								Disable registrations flag in /api/v1/instance when CAPTCHA is enabled  
							
							... 
							
							
							
							This is to avoid apps trying and failing at using the registrations API,
which does not let us require a CAPTCHA and cannot be clearly signaled as
unavailable. 
							
						 
						
							2022-01-25 13:58:24 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								bebf9bf33f 
								
							 
						 
						
							
							
								
								Bump sass from 1.48.0 to 1.49.0 ( #17352 )  
							
							... 
							
							
							
							Bumps [sass](https://github.com/sass/dart-sass ) from 1.48.0 to 1.49.0.
- [Release notes](https://github.com/sass/dart-sass/releases )
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md )
- [Commits](https://github.com/sass/dart-sass/compare/1.48.0...1.49.0 )
---
updated-dependencies:
- dependency-name: sass
  dependency-type: direct:production
  update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-25 21:25:26 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								f0d73d82f8 
								
							 
						 
						
							
							
								
								Bump json-ld-preloaded from 3.1.6 to 3.2.0 ( #17353 )  
							
							... 
							
							
							
							Bumps [json-ld-preloaded](https://github.com/ruby-rdf/json-ld-preloaded ) from 3.1.6 to 3.2.0.
- [Release notes](https://github.com/ruby-rdf/json-ld-preloaded/releases )
- [Commits](https://github.com/ruby-rdf/json-ld-preloaded/compare/3.1.6...3.2.0 )
---
updated-dependencies:
- dependency-name: json-ld-preloaded
  dependency-type: direct:production
  update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-25 21:23:42 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								7b2c733dfc 
								
							 
						 
						
							
							
								
								Bump fabrication from 2.23.1 to 2.24.0 ( #17356 )  
							
							... 
							
							
							
							Bumps [fabrication](https://github.com/paulelliott/fabrication ) from 2.23.1 to 2.24.0.
- [Release notes](https://github.com/paulelliott/fabrication/releases )
- [Changelog](https://github.com/paulelliott/fabrication/blob/master/Changelog.markdown )
- [Commits](https://github.com/paulelliott/fabrication/commits )
---
updated-dependencies:
- dependency-name: fabrication
  dependency-type: direct:development
  update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-25 21:22:51 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								cea00f593e 
								
							 
						 
						
							
							
								
								Bump sidekiq from 6.3.1 to 6.4.0 ( #17350 )  
							
							... 
							
							
							
							Bumps [sidekiq](https://github.com/mperham/sidekiq ) from 6.3.1 to 6.4.0.
- [Release notes](https://github.com/mperham/sidekiq/releases )
- [Changelog](https://github.com/mperham/sidekiq/blob/main/Changes.md )
- [Commits](https://github.com/mperham/sidekiq/compare/v6.3.1...v6.4.0 )
---
updated-dependencies:
- dependency-name: sidekiq
  dependency-type: direct:production
  update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-25 21:22:10 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								69cb20bca4 
								
							 
						 
						
							
							
								
								Bump @babel/plugin-transform-runtime from 7.16.8 to 7.16.10 ( #17361 )  
							
							... 
							
							
							
							Bumps [@babel/plugin-transform-runtime](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-runtime ) from 7.16.8 to 7.16.10.
- [Release notes](https://github.com/babel/babel/releases )
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md )
- [Commits](https://github.com/babel/babel/commits/v7.16.10/packages/babel-plugin-transform-runtime )
---
updated-dependencies:
- dependency-name: "@babel/plugin-transform-runtime"
  dependency-type: direct:production
  update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-25 20:52:40 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								daf2d8952d 
								
							 
						 
						
							
							
								
								Bump cld3 from 3.4.3 to 3.4.4 ( #17357 )  
							
							... 
							
							
							
							Bumps [cld3](https://github.com/akihikodaki/cld3-ruby ) from 3.4.3 to 3.4.4.
- [Release notes](https://github.com/akihikodaki/cld3-ruby/releases )
- [Commits](https://github.com/akihikodaki/cld3-ruby/compare/v3.4.3...v3.4.4 )
---
updated-dependencies:
- dependency-name: cld3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-25 20:48:05 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								2dfb67f0c9 
								
							 
						 
						
							
							
								
								Bump aws-sdk-s3 from 1.111.1 to 1.111.3 ( #17368 )  
							
							... 
							
							
							
							Bumps [aws-sdk-s3](https://github.com/aws/aws-sdk-ruby ) from 1.111.1 to 1.111.3.
- [Release notes](https://github.com/aws/aws-sdk-ruby/releases )
- [Changelog](https://github.com/aws/aws-sdk-ruby/blob/version-3/gems/aws-sdk-s3/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-ruby/commits )
---
updated-dependencies:
- dependency-name: aws-sdk-s3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-25 20:46:52 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								029d89bfea 
								
							 
						 
						
							
							
								
								Bump bootsnap from 1.10.1 to 1.10.2 ( #17367 )  
							
							... 
							
							
							
							Bumps [bootsnap](https://github.com/Shopify/bootsnap ) from 1.10.1 to 1.10.2.
- [Release notes](https://github.com/Shopify/bootsnap/releases )
- [Changelog](https://github.com/Shopify/bootsnap/blob/main/CHANGELOG.md )
- [Commits](https://github.com/Shopify/bootsnap/compare/v1.10.1...v1.10.2 )
---
updated-dependencies:
- dependency-name: bootsnap
  dependency-type: direct:production
  update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-25 20:45:45 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								ee7fafe1c8 
								
							 
						 
						
							
							
								
								Bump node-fetch from 2.6.1 to 2.6.7 ( #17366 )  
							
							... 
							
							
							
							Bumps [node-fetch](https://github.com/node-fetch/node-fetch ) from 2.6.1 to 2.6.7.
- [Release notes](https://github.com/node-fetch/node-fetch/releases )
- [Commits](https://github.com/node-fetch/node-fetch/compare/v2.6.1...v2.6.7 )
---
updated-dependencies:
- dependency-name: node-fetch
  dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-25 20:44:01 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								2033ca6b31 
								
							 
						 
						
							
							
								
								Bump nanoid from 3.1.23 to 3.2.0 ( #17342 )  
							
							... 
							
							
							
							Bumps [nanoid](https://github.com/ai/nanoid ) from 3.1.23 to 3.2.0.
- [Release notes](https://github.com/ai/nanoid/releases )
- [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md )
- [Commits](https://github.com/ai/nanoid/compare/3.1.23...3.2.0 )
---
updated-dependencies:
- dependency-name: nanoid
  dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-25 20:41:22 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								4b5629cc3d 
								
							 
						 
						
							
							
								
								Bump @babel/preset-env from 7.16.8 to 7.16.11 ( #17358 )  
							
							... 
							
							
							
							Bumps [@babel/preset-env](https://github.com/babel/babel/tree/HEAD/packages/babel-preset-env ) from 7.16.8 to 7.16.11.
- [Release notes](https://github.com/babel/babel/releases )
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md )
- [Commits](https://github.com/babel/babel/commits/v7.16.11/packages/babel-preset-env )
---
updated-dependencies:
- dependency-name: "@babel/preset-env"
  dependency-type: direct:production
  update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-25 20:39:43 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								0d82c0359d 
								
							 
						 
						
							
							
								
								Bump rubocop from 1.24.1 to 1.25.0 ( #17322 )  
							
							... 
							
							
							
							Bumps [rubocop](https://github.com/rubocop/rubocop ) from 1.24.1 to 1.25.0.
- [Release notes](https://github.com/rubocop/rubocop/releases )
- [Changelog](https://github.com/rubocop/rubocop/blob/master/CHANGELOG.md )
- [Commits](https://github.com/rubocop/rubocop/compare/v1.24.1...v1.25.0 )
---
updated-dependencies:
- dependency-name: rubocop
  dependency-type: direct:development
  update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-25 20:39:08 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								d528db801f 
								
							 
						 
						
							
							
								
								Bump @babel/core from 7.16.7 to 7.16.12 ( #17360 )  
							
							... 
							
							
							
							Bumps [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core ) from 7.16.7 to 7.16.12.
- [Release notes](https://github.com/babel/babel/releases )
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md )
- [Commits](https://github.com/babel/babel/commits/v7.16.12/packages/babel-core )
---
updated-dependencies:
- dependency-name: "@babel/core"
  dependency-type: direct:production
  update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 
							
						 
						
							2022-01-25 20:34:55 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									dependabot[bot] 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								808e7cd906 
								
							 
						 
						
							
							
								
								Bump rails from 6.1.4.1 to 6.1.4.4 ( #17159 )  
							
							... 
							
							
							
							* Bump rails from 6.1.4.1 to 6.1.4.4
Bumps [rails](https://github.com/rails/rails ) from 6.1.4.1 to 6.1.4.4.
- [Release notes](https://github.com/rails/rails/releases )
- [Commits](https://github.com/rails/rails/compare/v6.1.4.1...v6.1.4.4 )
---
updated-dependencies:
- dependency-name: rails
  dependency-type: direct:production
  update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
* Revert marcel to 1.0.1
Avoid some regression that need to be investigated
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Claire <claire.github-309c@sitedethib.com> 
							
						 
						
							2022-01-25 20:34:37 +09:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								bf351d72af 
								
							 
						 
						
							
							
								
								Disable captcha if registrations are disabled for various reasons  
							
							
							
						 
						
							2022-01-24 22:12:57 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								6a2f248fe4 
								
							 
						 
						
							
							
								
								Renew Rails session ID on successful registration  
							
							
							
						 
						
							2022-01-24 22:01:05 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								3f6a36168f 
								
							 
						 
						
							
							
								
								Fix tests  
							
							
							
						 
						
							2022-01-24 21:36:22 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								04050fbd46 
								
							 
						 
						
							
							
								
								Please CodeClimate  
							
							
							
						 
						
							2022-01-24 21:29:50 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Claire 
								
							 
						 
						
							
							
							
							
								
							
							
								1b493c9fee 
								
							 
						 
						
							
							
								
								Add optional hCaptcha support  
							
							... 
							
							
							
							Fixes  #1649 
This requires setting `HCAPTCHA_SECRET_KEY` and `HCAPTCHA_SITE_KEY`, then
enabling the admin setting at
`/admin/settings/edit#form_admin_settings_captcha_enabled`
Subsequently, a hCaptcha widget will be displayed on `/about` and
`/auth/sign_up` unless:
- the user is already signed-up already
- the user has used an invite link
- the user has already solved the captcha (and registration failed for another
  reason)
The Content-Security-Policy headers are altered automatically to allow the
third-party hCaptcha scripts on `/about` and `/auth/sign_up` following the same
rules as above. 
						
							2022-01-24 21:22:13 +01:00 
							
								 
							
						 
					 
				
					
						
							
								
								
									Wonderfall 
								
							 
						 
						
							
							
								
								
							
							
							
								
							
							
								244726e2e8 
								
							 
						 
						
							
							
								
								disable legacy XSS filtering ( #17289 )  
							
							... 
							
							
							
							Browsers are phasing out X-XSS-Protection, but Safari and IE still support it. 
							
						 
						
							2022-01-24 13:14:26 +01:00