discourse/app/controllers
Régis Hanol 34d04e7507
SECURITY: add pagination to post replies
When a post has some replies, and the user click on the button to show them, we would load ALL the replies. This could lead to DoS if there were a very large number of replies.

This adds support for pagination to these post replies.

Internal ref t/129773

FIX: Duplicated parent posts

DEV: Query refactor
2024-10-07 11:48:48 +08:00
..
admin DEV: Make params explicit for services in controllers 2024-10-03 16:56:39 +09:00
users FIX: store information about the login method in the database. (#28054) 2024-07-24 17:19:58 +10:00
about_controller.rb
application_controller.rb DEV: Make params explicit for services in controllers 2024-10-03 16:56:39 +09:00
associated_groups_controller.rb
badges_controller.rb
bookmarks_controller.rb
bootstrap_controller.rb
categories_controller.rb FEATURE: Support designating multiple groups as mods on category (#28655) 2024-09-04 04:38:46 +03:00
clicks_controller.rb
composer_controller.rb
composer_messages_controller.rb
csp_reports_controller.rb
custom_homepage_controller.rb
directory_columns_controller.rb
directory_items_controller.rb
do_not_disturb_controller.rb
drafts_controller.rb
edit_directory_columns_controller.rb
email_controller.rb
embed_controller.rb
exceptions_controller.rb
export_csv_controller.rb
extra_locales_controller.rb DEV: Upgrade the MessageFormat library (JS) 2024-07-10 09:51:25 +02:00
finish_installation_controller.rb
form_templates_controller.rb
forums_controller.rb
groups_controller.rb DEV: Remove old problem check system - Part 1 (#28772) 2024-09-06 17:00:25 +08:00
hashtags_controller.rb
highlight_js_controller.rb
inline_onebox_controller.rb
invites_controller.rb
list_controller.rb FIX: Don’t log an error when rendering a 404 2024-08-08 09:21:27 +02:00
metadata_controller.rb
new_topic_controller.rb
notifications_controller.rb
offline_controller.rb
onebox_controller.rb
pageview_controller.rb
permalinks_controller.rb FIX: Don’t raise an error on permalinks with external URL 2024-06-28 10:09:37 +02:00
post_action_users_controller.rb
post_actions_controller.rb
post_readers_controller.rb
posts_controller.rb SECURITY: add pagination to post replies 2024-10-07 11:48:48 +08:00
presence_controller.rb
published_pages_controller.rb
push_notification_controller.rb
qunit_controller.rb
reviewable_claimed_topics_controller.rb FEATURE: Support designating multiple groups as mods on category (#28655) 2024-09-04 04:38:46 +03:00
reviewables_controller.rb
robots_txt_controller.rb
safe_mode_controller.rb
search_controller.rb DEV: Add `user_agent` column to `search_logs` (#27742) 2024-07-05 14:05:00 -05:00
session_controller.rb FIX: Passkey login when Discourse used as SSO provider (#28672) 2024-09-03 11:46:23 -04:00
sidebar_sections_controller.rb
similar_topics_controller.rb
site_controller.rb
sitemap_controller.rb
slugs_controller.rb
static_controller.rb FIX: `StaticController#enter` should not redirect to invalid paths (#27913) 2024-07-15 14:39:37 +08:00
steps_controller.rb
stylesheets_controller.rb FIX: Write stylesheet cache atomically (#28457) 2024-08-21 12:44:17 +01:00
svg_sprite_controller.rb
tag_groups_controller.rb FEATURE: Log tag group changes in staff action log (#28787) 2024-09-09 10:50:48 +08:00
tags_controller.rb DEV: Ignore invalid tag parameter in TagsController (#28557) 2024-08-27 12:06:54 -04:00
test_requests_controller.rb FIX: Set sane default for `Net::HTTP` when processing a request (#28141) 2024-08-06 07:12:42 +08:00
theme_javascripts_controller.rb
topic_view_stats_controller.rb
topics_controller.rb FIX: Don't show move topic for private messages for TL4 (#28871) 2024-09-16 11:30:05 +08:00
uploads_controller.rb FEATURE: add `system_user_max_attachment_size_kb` site setting (#28351) 2024-08-16 11:03:39 -03:00
user_actions_controller.rb
user_api_keys_controller.rb
user_avatars_controller.rb
user_badges_controller.rb
user_status_controller.rb
users_controller.rb DEV: Convert account activation pages to use Ember (#28206) 2024-08-12 18:02:00 -03:00
users_email_controller.rb
webhooks_controller.rb
wizard_controller.rb