| 
								
								
									 かっこかり | 98b4717c45 | fix(backend): SQLのサニタイズを強化 (#14920) * Fix code scanning alert no. 28: Incomplete string escaping or encoding (MisskeyIO#800)
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
(cherry picked from commit 443335c662b14f609d6a81a8f3807e95709aebc1)
* ✌️
---------
Co-authored-by: あわわわとーにゅ <17376330+u1-liquid@users.noreply.github.com> | 2024-11-09 10:51:28 +09:00 |  | 
				
					
						| 
								
								
									 Caramel | 03559156b9 | Improve performance of notes/following API | 2024-11-09 00:32:03 +01:00 |  | 
				
					
						| 
								
								
									 dakkar | f17d716d61 | fix upstream linting | 2024-11-08 17:53:42 +00:00 |  | 
				
					
						| 
								
								
									 dakkar | 0a15ffba55 | remove duplicate import | 2024-11-08 17:53:34 +00:00 |  | 
				
					
						| 
								
								
									 dakkar | 41ac75a113 | fix uses of renamed method `FederatedInstanceService.fetch` will now just load from the DB, it
won't do anything if the instance is not already there | 2024-11-08 16:45:51 +00:00 |  | 
				
					
						| 
								
								
									 dakkar | ec875d9c40 | fix merge mistakes in admin/accounts/create.ts | 2024-11-08 16:09:02 +00:00 |  | 
				
					
						| 
								
								
									 dakkar | ffebe778d4 | copy changes from NoteCreate to NoteEdit | 2024-11-08 15:55:50 +00:00 |  | 
				
					
						| 
								
								
									 dakkar | f079edaf3c | Merge tag '2024.10.1' into feature/2024.10 | 2024-11-08 15:52:37 +00:00 |  | 
				
					
						| 
								
								
									 4ster1sk | 794cb9ffe2 | fix(backend): followedMessageではなくdescriptionになっていたのを修正 (#14908) | 2024-11-07 17:16:51 +09:00 |  | 
				
					
						| 
								
								
									 4ster1sk | bca690f256 | fix(backend): フォロワーへのメッセージの絵文字をemojisに含めるように (#14904) | 2024-11-07 15:10:10 +09:00 |  | 
				
					
						| 
								
								
									 かっこかり | b1c82213a3 | fix(backend): FTT無効時にユーザーリストタイムラインが使用できない問題を修正 (#14878) * fix: return getfromdb when FanoutTimeline is not enabled
* Update Changelog
* fix
---------
Co-authored-by: Lhc_fl <lhcfl@outlook.com> | 2024-11-06 22:01:21 +09:00 |  | 
				
					
						| 
								
								
									 dakkar | 9fe5dc679a | check harder for connectibility `allSettled` does not throw if a promise is rejected, so
`check_connect` never actually failed | 2024-11-05 14:21:58 +00:00 |  | 
				
					
						| 
								
								
									 Kio! | 8477909af2 | Update report-abuse.ts | 2024-11-03 19:50:25 +00:00 |  | 
				
					
						| 
								
								
									 Julia | e783359aca | merge: Revert "Experimental: dont mark backfetched notes as silent" (!703) View MR for information: https://activitypub.software/TransFem-org/Sharkey/-/merge_requests/703
Approved-by: Julia <julia@insertdomain.name>
Approved-by: Hazelnoot <acomputerdog@gmail.com>
Approved-by: Marie <github@yuugi.dev> | 2024-11-03 19:39:00 +00:00 |  | 
				
					
						| 
								
								
									 かっこかり | 6718a54f6f | fix(backend): ノートを連合する際にリモートユーザーのacctの大小文字を区別して処理している問題を修正 (#14880) * fix: make sure outgoing remote mentions get resolved correctly if referenced with non-canonical casing (resolves #646)
* Update Changelog
* Update Changelog
* indent
---------
Co-authored-by: Laura Hausmann <laura@hausmann.dev> | 2024-11-03 08:26:51 +09:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | ddf572c22f | fix lint errors in FollowingEntityService.ts | 2024-11-02 17:43:11 -04:00 |  | 
				
					
						| 
								
								
									 Hazel K | 37fd454f70 | factor out shared code | 2024-11-02 17:39:16 -04:00 |  | 
				
					
						| 
								
								
									 Hazel K | 3a72bf453a | respect following privacy settings | 2024-11-02 17:39:16 -04:00 |  | 
				
					
						| 
								
								
									 Hazel K | 65d81a4ae2 | Revert "fix incorrect populated object in followers endpoint" This reverts commit 7b9473bf4c0b55facede0e1d1e33297d14184110. | 2024-11-02 17:39:16 -04:00 |  | 
				
					
						| 
								
								
									 Hazel K | 8f0df1f01c | check for blocks in following / followers endpoints | 2024-11-02 17:39:16 -04:00 |  | 
				
					
						| 
								
								
									 Hazel K | c566fa1f36 | require auth for followers & following endpoints | 2024-11-02 17:39:16 -04:00 |  | 
				
					
						| 
								
								
									 Marie | b8b077cbad | chore: replace recaptcha with frc | 2024-11-02 11:02:13 +00:00 |  | 
				
					
						| 
								
								
									 Marie | d786e96c2b | upd: add FriendlyCaptcha as a captcha solution FriendlyCaptcha is a german captcha solution which is GDPR compliant and has a non-commerical free license | 2024-11-02 02:20:35 +01:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | ade801ec58 | check token permissions in admin/accounts/create.ts | 2024-11-01 10:12:28 -04:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | 37ff2bb0ca | always approve the first / root user | 2024-11-01 09:29:40 -04:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | f36a1a5701 | allow admins to create approved users | 2024-11-01 09:29:40 -04:00 |  | 
				
					
						| 
								
								
									 Julia | 1520bc1715 | merge: Split character limits between local and remote notes (resolves #723) (!669) View MR for information: https://activitypub.software/TransFem-org/Sharkey/-/merge_requests/669
Closes #723
Approved-by: dakkar <dakkar@thenautilus.net>
Approved-by: Julia <julia@insertdomain.name> | 2024-10-29 03:04:25 +00:00 |  | 
				
					
						| 
								
								
									 かっこかり | f30d19051f | enhance(backend): check_connect.js で全RedisとDBへの接続を確認するように (#14853) * fix race conditions in check_connect.js
(cherry picked from commit 524ddb9677)
* fix
* Update Changelog
---------
Co-authored-by: Hazelnoot <acomputerdog@gmail.com> | 2024-10-28 21:06:54 +09:00 |  | 
				
					
						| 
								
								
									 Tamme Schichler | 8eb7749e44 | fix(backend): Accept arrays in ActivityPub iconandimageproperties (#14825)This is allowed according to the Activity vocabulary: https://www.w3.org/TR/activitystreams-vocabulary/#dfn-icon
The issue is noticeable in combination with Bridgy Fed: https://github.com/snarfed/bridgy-fed/issues/1408 | 2024-10-28 21:06:16 +09:00 |  | 
				
					
						| 
								
								
									 syuilo | 74847bce30 | enhance: アイコンデコレーション管理画面の改善 | 2024-10-28 20:42:14 +09:00 |  | 
				
					
						| 
								
								
									 かっこかり | ec4358d1e8 | fix(misskey-js): WebSocketの型定義をReconnectingWebsocketに依存するように (#14850) * fix(misskey-js): WebSocketの型定義をReconnectingWebsocketに依存するように
* Update Changelog
* run api extractor
* fix
* fix | 2024-10-28 11:43:05 +09:00 |  | 
				
					
						| 
								
								
									 dakkar | 276b30bdc0 | merge: Collapse user activity, files, and listenbrainz on mobile (resolves #747) (!718) View MR for information: https://activitypub.software/TransFem-org/Sharkey/-/merge_requests/718
Closes #747
Approved-by: Marie <github@yuugi.dev>
Approved-by: dakkar <dakkar@thenautilus.net> | 2024-10-27 12:12:30 +00:00 |  | 
				
					
						| 
								
								
									 dakkar | d72c40d157 | merge: fix race conditions in check_connect.js (!715) View MR for information: https://activitypub.software/TransFem-org/Sharkey/-/merge_requests/715
Approved-by: Marie <github@yuugi.dev>
Approved-by: dakkar <dakkar@thenautilus.net> | 2024-10-27 12:05:48 +00:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | a541eaba5e | fix test errors | 2024-10-26 17:34:42 -04:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | d2a4d6d9e0 | fix lint errors in home.vue / index.listenbrainz.vue | 2024-10-26 12:58:07 -04:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | 27b502fab5 | normalize re-fetch logic between InboxProcessorService and ActivityPubServerService | 2024-10-26 10:40:15 -04:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | c0a5955e0a | log key rotation | 2024-10-26 10:40:15 -04:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | 5eb9a263e2 | fix public key re-fetch logic | 2024-10-26 10:40:15 -04:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | 78a75171c2 | remove cached public keys after deletion | 2024-10-26 10:40:15 -04:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | ca1cdc4ea3 | fix poll option limit in masto API | 2024-10-26 10:38:29 -04:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | c5d9bde43f | expose CW limit to frontend | 2024-10-26 10:37:43 -04:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | 01e98c75ab | add separate limits for CW length | 2024-10-26 10:04:23 -04:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | 10d3d9f382 | fix unit tests | 2024-10-26 09:49:28 -04:00 |  | 
				
					
						| 
								
								
									 Hazel K | a6befca845 | clarify comment about MAX_NOTE_TEXT_LENGTH in tests | 2024-10-26 09:49:28 -04:00 |  | 
				
					
						| 
								
								
									 Hazel K | 67185a5d5d | fix UUID format | 2024-10-26 09:49:28 -04:00 |  | 
				
					
						| 
								
								
									 Hazel K | 560ee43dcf | separate character limits for local and remote notes | 2024-10-26 09:49:28 -04:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | 524ddb9677 | fix race conditions in check_connect.js | 2024-10-26 08:57:26 -04:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | 9562a830ed | merge: Merge upstream security advisary (!707) View MR for information: https://activitypub.software/TransFem-org/Sharkey/-/merge_requests/707
Approved-by: dakkar <dakkar@thenautilus.net>
Approved-by: Hazelnoot <acomputerdog@gmail.com> | 2024-10-25 15:22:21 +00:00 |  | 
				
					
						| 
								
								
									 Hazelnoot | 57ce32d44f | merge: fix: return getFromDb directly when fanoutTimeline is not enabled (!709) View MR for information: https://activitypub.software/TransFem-org/Sharkey/-/merge_requests/709
Approved-by: dakkar <dakkar@thenautilus.net>
Approved-by: Hazelnoot <acomputerdog@gmail.com> | 2024-10-25 15:20:06 +00:00 |  | 
				
					
						| 
								
								
									 かっこかり | eeea4ec00b | fix(backend): 招待コード発行可能残り数算出に使用すべきロールポリシーの値が違うのを修正 (#14834) * fix: should use invite limit cycle to calculate invite/limit
* Update Changelog
* Update changelog
---------
Co-authored-by: Lhc_fl <lhcfl@outlook.com> | 2024-10-25 15:09:37 +09:00 |  |