Skip to content

Tags: weburnit/grist-core

Tags

v1.4.2

Toggle v1.4.2's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
v1.4.2 (gristlabs#1459)

v1.4.1

Toggle v1.4.1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
v1.4.1 (gristlabs#1457)

v1.4.0

Toggle v1.4.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
v1.4.0 (gristlabs#1448)

New Grist release, new feature being released.

1.3.2

Toggle 1.3.2's commit message
(core) Fix attachment and hyperlink vulnerabilities

Summary:
Attachments were prone to XSS-based attacks if attachments injected with scripts
were previewed or opened. This is now addressed by CSP.

Hyperlink cells were prone to similar attacks if `javascript:...` URLs were inserted into
cells. This has also been addressed by sanitizing URLs.

Thank you to Florent <[email protected]> and Grégoire Cutzach <[email protected]>
for reporting and co-authoring these changes.

Co-authored-by: Florent <[email protected]>
Co-authored-by: Grégoire Cutzach <[email protected]>

Test Plan: Browser and unit tests.

Reviewers: dsagal, paulfitz

Reviewed By: dsagal, paulfitz

Subscribers: dsagal, paulfitz, fflorent

Differential Revision: https://phab.getgrist.com/D4413

1.3.1

Toggle 1.3.1's commit message
(core) Revert "Document type conversion UX/UI (gristlabs#1181)"

Summary:
The recently-landed document type conversion feature was broken, failing
to change the document's type in both Jenkins CI runs and during manual
testing of the SaaS build of Grist.

This reverts the feature until a fix is ready.

Test Plan: N/A

Reviewers: dsagal

Reviewed By: dsagal

Differential Revision: https://phab.getgrist.com/D4411

v1.3.1

Toggle v1.3.1's commit message
(core) Revert "Document type conversion UX/UI (gristlabs#1181)"

Summary:
The recently-landed document type conversion feature was broken, failing
to change the document's type in both Jenkins CI runs and during manual
testing of the SaaS build of Grist.

This reverts the feature until a fix is ready.

Test Plan: N/A

Reviewers: dsagal

Reviewed By: dsagal

Differential Revision: https://phab.getgrist.com/D4411