0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-05 13:59:03 +08:00
discourse/app
discourse-patch-triage[bot] 1f1ded8dd3 SECURITY: Regular users can route multipart uploads into the admin backup store
## Summary

Applies security patch from triage.

## Security advisory

https://github.com/discourse/discourse/security/advisories/GHSA-3mvf-q9rg-w6m7

## Source

- Patch Triage: https://patch.discourse.org/patch-triage/1068
- Original commit:

---

🤖 Auto-generated from the patch diff via Patch Triage. Review carefully before merging.
2026-06-30 16:10:52 +02:00
..
assets FEATURE: Bulk suspend users and filter the admin users list by activation (#41227) 2026-06-29 11:26:34 +02:00
controllers SECURITY: Signup-time primary_group_id assignment grants whisperer access 2026-06-30 16:10:52 +02:00
helpers DEV: Track beacon browser pageviews behind dashboard_improvements (#40934) 2026-06-23 10:21:39 +08:00
jobs SECURITY: Authorize secure-upload hotlink downloads against post user 2026-06-30 16:10:52 +02:00
mailers FEATURE: Log in with a one-time email code (#40804) 2026-06-17 12:34:48 -07:00
models SECURITY: Signup-time primary_group_id assignment grants whisperer access 2026-06-30 16:10:52 +02:00
queries/reports FIX: Enforce can_see_ip checks across admin IP features (#40019) 2026-05-19 11:37:20 +08:00
serializers SECURITY: Hidden post revisions leak through adjacent visible diffs 2026-06-30 16:10:52 +02:00
services SECURITY: Regular users can route multipart uploads into the admin backup store 2026-06-30 16:10:52 +02:00
views FEATURE: Localizable /about page fields via its settings page (#41123) 2026-06-26 20:41:08 +08:00