15 Jan, 2014

1 commit


14 Jan, 2014

1 commit


13 Jan, 2014

3 commits


10 Jan, 2014

1 commit


07 Jan, 2014

1 commit


02 Jan, 2014

1 commit


23 Dec, 2013

2 commits


16 Dec, 2013

1 commit

  • When doing an HTTP push, git (as of v1.7.9) first do an info/refs
    request, and only if this request requires authentication it asks the
    user for its password and authenticates further requests.
    
    The initial request normally clears without auth on public repos as it
    doesn't update any ref. This patch forces every git-receive-pack
    requests to provide authentication.
    Thomas Guyot-Sionnest
     

14 Dec, 2013

2 commits


13 Dec, 2013

4 commits


10 Dec, 2013

2 commits


09 Dec, 2013

2 commits


01 Dec, 2013

1 commit


26 Nov, 2013

1 commit


22 Nov, 2013

2 commits


20 Nov, 2013

4 commits


19 Nov, 2013

3 commits


13 Nov, 2013

1 commit


11 Nov, 2013

1 commit


07 Nov, 2013

1 commit


05 Nov, 2013

1 commit


03 Nov, 2013

1 commit

  • The blocked? method is used to check whether a user exists in LDAP. Prior to this change, if the LDAP server had more objects below the one pointed to by the DN, those objects would also be picked up by the search, causing the method to determine the user should be blocked.
    
    One case where this can happen is when using Active Directory and a user have a mobile phone assigned. In this case, Exchange will add an entry called ExchangeActiveSyncDevices under the users entry. The user-visible behaviour is then that a user loses Gitlab access when he enables a mobile device.
    
    This fix sets the search scope to BaseObject in order to ensure that only the user itself is returned.
    Elias Mårtenson
     

01 Nov, 2013

2 commits


31 Oct, 2013

1 commit