| Commit message (Expand) | Author | Age | Files | Lines |
... | |
* | | | | Merge pull request #32277 from derekprior/dp-deprecate-force-ssl | Guillermo Iguaran | 2018-03-30 | 2 | -15/+29 |
|\ \ \ \
| |/ / /
|/| | | |
|
| * | | | Deprecate controller level force_ssl | Derek Prior | 2018-03-30 | 2 | -15/+29 |
* | | | | Use ASCII-8BIT paths in ActionDispatch::Static | Andrew White | 2018-03-22 | 5 | -1/+12 |
|/ / / |
|
* | | | Check exclude before flagging cookies as secure in ActionDispatch::SSL (#32262) | Catherine Khuu | 2018-03-15 | 1 | -0/+8 |
* | | | Fix routing inspector tests broken in https://github.com/rails/rails/commit/6... | Kasper Timm Hansen | 2018-03-13 | 1 | -14/+15 |
* | | | Introduce `ActionDispatch::Routing::ConsoleFormatter::Base` | bogdanvlviv | 2018-03-13 | 1 | -11/+11 |
* | | | Merge pull request #32160 from bogdanvlviv/improve-rails-routes-expanded | Kasper Timm Hansen | 2018-03-11 | 1 | -5/+10 |
|\ \ \ |
|
| * | | | Draw line of a route name to the end of row console on `rails routes --expanded` | bogdanvlviv | 2018-03-05 | 1 | -5/+10 |
* | | | | Always yield a CSP policy instance | Andrew White | 2018-03-08 | 1 | -12/+58 |
* | | | | Add the ability to disable the global CSP in a controller | Andrew White | 2018-03-08 | 1 | -0/+14 |
|/ / / |
|
* | | | Ruby 2.4: take advantage of String#unpack1 | Jeremy Daer | 2018-03-01 | 1 | -1/+1 |
* | | | Add --expanded option to "rails routes" | Benoit Tigeot | 2018-02-28 | 1 | -2/+66 |
* | | | Uses the absolute path for system test screenshots | Zamith | 2018-02-27 | 1 | -5/+5 |
* | | | Merge branch 'master' into update_default_hsts_max_age | Guillermo Iguaran | 2018-02-24 | 39 | -260/+289 |
|\ \ \ |
|
| * \ \ | Merge pull request #32018 from rails/add-nonce-support-to-csp | Andrew White | 2018-02-22 | 1 | -0/+16 |
| |\ \ \ |
|
| | * | | | Add support for automatic nonce generation for Rails UJS | Andrew White | 2018-02-19 | 1 | -0/+16 |
| * | | | | We should call methods with `.method_name` not `::method_name`. | utilum | 2018-02-22 | 2 | -5/+6 |
| |/ / / |
|
| * | | | Remove trailing semi-colon from CSP | Andrew White | 2018-02-19 | 1 | -32/+32 |
| * | | | Revert "Merge pull request #32045 from eagletmt/skip-csp-header" | Andrew White | 2018-02-19 | 1 | -20/+2 |
| * | | | Skip generating empty CSP header when no policy is configured | Kohei Suzuki | 2018-02-18 | 1 | -2/+20 |
| * | | | Rails 6 requires Ruby 2.4.1+ | Jeremy Daer | 2018-02-17 | 2 | -2/+0 |
| * | | | Clean up and consolidate .gitignores | bogdanvlviv | 2018-02-17 | 1 | -0/+0 |
| * | | | Rails 6 requires Ruby 2.3+ | Jeremy Daer | 2018-02-17 | 1 | -16/+9 |
| * | | | Fix array routing constraints | fatkodima | 2018-02-17 | 1 | -2/+5 |
| * | | | Remove usage of strip_heredoc in the framework in favor of <<~ | Rafael Mendonça França | 2018-02-16 | 1 | -3/+2 |
| * | | | Make sure assert_recognizes can still find routes mounted after engines | Rafael Mendonça França | 2018-02-09 | 1 | -0/+6 |
| |/ / |
|
| * | | Consistent behavior for session and cookies with to_h and to_hash method | Igor Kasyanchuk | 2018-01-31 | 2 | -0/+7 |
| * | | Allow @ in X-Request-Id header | Daniel Colson | 2018-01-29 | 1 | -0/+5 |
| * | | Use assert_empty and assert_not_empty | Daniel Colson | 2018-01-25 | 9 | -17/+17 |
| * | | Use assert_predicate and assert_not_predicate | Daniel Colson | 2018-01-25 | 26 | -174/+174 |
| * | | Change refute to assert_not | Daniel Colson | 2018-01-25 | 3 | -12/+12 |
| * | | Use respond_to test helpers | Daniel Colson | 2018-01-25 | 7 | -9/+9 |
| * | | Merge pull request #31713 from aellispierce/refactor-browser-options | Eileen M. Uchitelle | 2018-01-17 | 1 | -3/+4 |
| |\ \ |
|
| | * | | Move browser checking to its own class | Ashley Ellis Pierce | 2018-01-15 | 1 | -3/+4 |
* | | | | Update default HSTS max-age value to 1 year | Grant Bourque | 2018-01-16 | 1 | -2/+2 |
|/ / / |
|
* | | | Add 'Referrer-Policy' header to default headers set | Guillermo Iguaran | 2018-01-08 | 1 | -2/+4 |
* | | | Merge pull request #31594 from yuki24/refactor-request-test | Eileen M. Uchitelle | 2018-01-04 | 1 | -89/+75 |
|\ \ \ |
|
| * | | | Use more realistic setup rather than stubbing | Yuki Nishijima | 2017-12-29 | 1 | -89/+75 |
| |/ / |
|
* / / | let drb make temprary server | Nobuyoshi Nakada | 2017-12-29 | 1 | -8/+1 |
|/ / |
|
* | | Generate tmpname on its own | yuuji.yaginuma | 2017-12-15 | 1 | -1/+6 |
* | | Suppress `warning: BigDecimal.new is deprecated` | Yasuo Honda | 2017-12-15 | 1 | -1/+1 |
* | | Merge pull request #31289 from witlessbird/fips-compatibility | Eileen M. Uchitelle | 2017-12-14 | 2 | -2/+2 |
|\ \ |
|
| * | | Introduced `ActiveSupport::Digest` that allows to specify hash function imple... | Dmitri Dolguikh | 2017-12-12 | 2 | -2/+2 |
* | | | Enable `Layout/LeadingCommentSpace` to not allow cosmetic changes in the future | Ryuta Kamizono | 2017-12-14 | 4 | -4/+3 |
* | | | Enable `Layout/SpaceBeforeComma` rubocop rule, and fixed more | Ryuta Kamizono | 2017-12-12 | 3 | -4/+4 |
* | | | Change the system tests to set Puma as default server only when the user have... | Guillermo Iguaran | 2017-12-09 | 1 | -1/+18 |
* | | | Add secure `X-Download-Options` and `X-Permitted-Cross-Domain-Policies` to de... | Guillermo Iguaran | 2017-12-09 | 2 | -3/+7 |
* | | | Merge pull request #30780 from JackMc/fix-chrome-referrer-invalidauthenticity... | Sean Griffin | 2017-12-07 | 1 | -0/+13 |
|\ \ \ |
|
| * | | | Add a better error message when a "null" Origin header occurs | Jack McCracken | 2017-11-03 | 1 | -0/+13 |
* | | | | Add headless firefox driver to System Tests | bogdanvlviv | 2017-12-07 | 3 | -0/+18 |