Commit Graph

7 Commits

Author SHA1 Message Date
ignacionelson 8537ca58a9 Update shell-quote and source-map-js for their new advisories
shell-quote 1.10.0 -> 1.12.0 (GHSA-pqg4-j6r4-53mv, critical: command
injection through quote()) and source-map-js 1.2.1 -> 1.2.2
(GHSA-68fv-2mgg-jv7q, high: denial of service through section offsets).
Both arrive through build tools only, concurrently and vite's postcss,
so neither runs in what a release ships; updated so the release does not
carry an open critical alert. Within the ranges their parents already
allow, same maintainers, no dependencies or install scripts, and each
lockfile integrity matches the registry. npm audit --omit=dev reports
nothing.
2026-10-06 22:53:38 -03:00
ignacionelson 7a1aa4021b Update the dependencies behind the open security alerts
Composer, each package alone, nothing else in the lock moved:
laravel/framework 12.64.0 -> 12.69.3, league/commonmark 2.10.0 -> 2.10.3,
league/flysystem 3.35.2 -> 3.36.0, phpseclib/phpseclib 3.0.56 -> 3.0.57.
composer audit reports nothing.

npm, within the ranges package.json already allows: axios 1.19.0 ->
1.20.0, and brace-expansion 1.1.18 -> 1.1.21 and 2.1.4 -> 2.1.7 (both
dev-only, under minimatch). No new dependencies or install scripts, and
each lockfile integrity matches the registry. npm audit --omit=dev
reports nothing.
2026-10-04 04:19:11 -03:00
ignacionelson bbd424a8d1 Crop the logo from the Branding screen, and restore the original
A Crop button opens the uploaded image with a free-shape box, starting
from the last crop; Restore original appears once there is one. The box
is sent in the upload's own pixels and the server cuts the file. The
image is shown with image-orientation: none, the pixels as the server
reads them, since no image here has the exif extension to rotate by an
orientation tag.

Adds react-image-crop 11.1.2: no dependencies, no install scripts, and
its lockfile integrity matches the registry.
2026-10-03 12:07:26 -03:00
ignacionelson 9b99972a1a Update js-yaml to 4.3.2 to close a Dependabot alert
js-yaml 4.3.1 had a high-severity advisory: its limit on YAML merge
keys did not bound CPU use when the merge sources were empty. It is
only here as a dependency of ESLint's config loader, so it was never
part of a build or a release. ESLint's range (^4.3.0) already allowed
the patched version, so only the lockfile changes.
2026-09-13 16:25:41 -03:00
ignacionelson 7c9847981a Patch 8 pending security advisories in dependencies
league/commonmark 2.9.0 -> 2.10.0 fixes an XSS bypass and three DoS
issues; nanoid, qs, brace-expansion, and @humanfs/node bumped via
npm audit fix.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019iQNYLu5a65foArRdE9zzx
2026-09-03 11:57:15 -03:00
denkfabrik-li 7264c44fd7 Serve the interface font from the installation, not from a font CDN
app.blade.php is the root template for all three interfaces, and it opened
with two lines pointing at a third party:

    <link rel="preconnect" href="https://fonts.bunny.net">
    <link href="https://fonts.bunny.net/css?family=instrument-sans:400,500,600" rel="stylesheet" />

Every visitor to /login, /register, /forgot-password, /s/{token} and every
public listing page therefore made a request to a host the operator did
not choose and could not switch off, before they had done anything at all
-- handing it their IP address, their user agent, and through Origin the
hostname of the installation they were visiting. On the signed-out pages
that is a visitor who has agreed to nothing, and an operator who often has
told their own users that this server is where their files live.

There was no self-hosted copy in the repository, no setting, no mention in
INSTALL.md, DOCKER.md or SECURITY.md, and no SRI on the tag.

The font now ships with the application, through @fontsource/instrument-sans
-- the same font, the same three weights the URL asked for, from a
versioned dependency rather than binaries pasted into the repository.
Vite fingerprints and emits them like any other asset.

Cost, measured on this build: twelve files, 192 KB on disk. A browser
fetches only woff2 and only the subsets it needs, which is 73 KB for all
six woff2 files together and typically 41 KB (latin, three weights) for a
page in English. Against that, every page load loses a DNS lookup, a TLS
handshake and a round trip to another origin, so signed-out pages get
faster rather than slower.

This is a privacy change rather than a vulnerability fix, and worth saying
plainly: the share token does not leak this way. Referrer-Policy:
strict-origin-when-cross-origin is set in both nginx configs and in the
INSTALL.md snippet, so the path never travelled in the Referer. What
travelled was the visit itself.

Not changed: public/.htaccess still sets no security headers at all, so an
Apache installation has no Referrer-Policy. That is a real gap and a
separate change.

Verified: `npm run build` succeeds and emits the faces; no reference to
the CDN survives anywhere in public/build; `tsc --noEmit` and prettier are
clean. No test asserts on the font, before or after.
2026-08-29 00:50:02 +02:00
ignacionelson 6e47d76ba6 ProjectSend 2.0.0
Client file sharing, rebuilt from the ground up: a private area per
client, resumable uploads, folders, groups and categories, sharing with
expiry dates and download limits, comments, file versions, an activity
log, a REST API, and sixteen languages.

This repository begins here. ProjectSend 2 was developed privately, and
that development history is not published — the previous generation
remains available, with its own history, at projectsend/legacy.

Free software under the GNU General Public License v2, or (at your
option) any later version.
2026-08-14 01:38:12 -03:00