aboutsummaryrefslogtreecommitdiffstats
path: root/backend/routes (follow)
Commit message (Collapse)AuthorAgeLines
* Don't include user mention for anonymous form submissionsGravatar Chris Lovering2022-01-21-1/+5
| | | | | | We currently use WEBHOOK_ENABLED to determine whether user data should be stored to the db. However, when webhooking a form submission this config is ignored, and the user mention is always included if available. This means that if a user login in using another form, and then submits an anonymous form with the same session, their name will be included in the webhook.
* Model: makes Form.id case insensitiveGravatar Matteo Bertucci2021-12-26-9/+6
| | | | Note that it will make any existing form with an upper case letter impossible to access until its ID is changed, which shouldn't be the case in production according to @HassanAbouelela
* Hash Cf-Connecting-IP if given, else remote hostGravatar Joe Banks2021-12-25-1/+5
|
* Uses Backend URL In EmbedGravatar Hassan Abouelela2021-07-06-1/+1
| | | | | | | Temporarily switches the URL in discord embeds from the frontend, to the backend, to allow for easier viewing until the frontend is ready. Signed-off-by: Hassan Abouelela <[email protected]>
* Merge pull request #92 from python-discord/unittest_failuresGravatar Hassan Abouelela2021-06-20-15/+73
|\ | | | | Allow Unittest Failures
| * Updates Unittest Filter To Match New ModelGravatar Hassan Abouelela2021-06-19-1/+1
| | | | | | | | Signed-off-by: Hassan Abouelela <[email protected]>
| * Verifies Unittest Error ResponsesGravatar Hassan Abouelela2021-06-03-1/+14
| | | | | | | | Signed-off-by: Hassan Abouelela <[email protected]>
| * Handles Code Questions With No TestsGravatar Hassan Abouelela2021-06-03-1/+13
| | | | | | | | | | | | Adds a check to handle code questions with no test suites. Signed-off-by: Hassan Abouelela <[email protected]>
| * Documents Return Code Gravatar Hassan Abouelela2021-06-02-0/+1
| | | | | | | | | | Adds a comment which explains when a certain return_code is used. Co-authored-by: Joe Banks <[email protected]>
| * Uses 422 For Failed Tests Gravatar Hassan Abouelela2021-06-02-1/+1
| | | | | | | | | | Uses 422 instead of 403 to indicate a test has failed. Co-authored-by: Joe Banks <[email protected]>
| * Reports All Unittest Failure ReasonsGravatar Hassan Abouelela2021-06-02-2/+9
| | | | | | | | | | | | Records the reason of failure for non-zero exit codes. Signed-off-by: Hassan Abouelela <[email protected]>
| * Records Failed UnittestsGravatar Hassan Abouelela2021-06-02-8/+33
| | | | | | | | | | | | | | Adds logic for saving submissions of failed unittests. Updates schema docs. Signed-off-by: Hassan Abouelela <[email protected]>
| * Adds Code Question ModelGravatar Hassan Abouelela2021-06-02-4/+4
| | | | | | | | | | | | | | Adds an explicit model for questions of type `code`, to allow more complex parsing. Updates schema docs. Signed-off-by: Hassan Abouelela <[email protected]>
* | Merge pull request #90 from python-discord/auth-formGravatar Hassan Abouelela2021-06-20-5/+37
|\ \ | | | | | | Empty Authorization Form
| * | Adds An Empty Form For AuthorizationGravatar Hassan Abouelela2021-05-17-5/+37
| | | | | | | | | | | | | | | | | | | | | Returns a form with no questions, if the server is not running in production, and no other forms are found, to aid in setting up. Signed-off-by: Hassan Abouelela <[email protected]>
* | | Handles Null WebhooksGravatar Hassan Abouelela2021-06-04-5/+7
| | | | | | | | | | | | | | | | | | | | | | | | The form model specifies webhook as nullable, but the validator code does not properly handle them. This PR adds logic to handle that scenario. Signed-off-by: Hassan Abouelela <[email protected]>
* | | Reverts "Validates Form Patch Request"Gravatar Hassan Abouelela2021-06-03-2/+6
| |/ |/| | | | | | | | | | | Reverts the changes made in 4f28ae85 because they made it impossible to send a partial patch request. Changes to a simpler try/except instead. Signed-off-by: Hassan Abouelela <[email protected]>
* | Set Form Viewing URLGravatar Hassan Abouelela2021-05-30-1/+1
| | | | | | | | Signed-off-by: Hassan Abouelela <[email protected]>
* | Validates Form Patch RequestGravatar Hassan Abouelela2021-05-30-1/+3
|/ | | | | | Makes sure patch requests send a validated request. Signed-off-by: Hassan Abouelela <[email protected]>
* Adds A Dev Only Endpoint For Adding AdminsGravatar Hassan Abouelela2021-05-15-8/+35
| | | | | | | Copies the admin adding endpoint into an unprotected endpoint that is only registered in non-production builds. Signed-off-by: Hassan Abouelela <[email protected]>
* Simplify role assigning rate limit handlingGravatar ks1292021-03-09-12/+6
| | | Co-authored-by: Hassan Abouelela <[email protected]>
* Merge branch 'main' into ks123/role-assigningGravatar ks1292021-03-09-21/+291
|\
| * Corrects Token Cookie DomainGravatar Hassan Abouelela2021-03-07-4/+2
| | | | | | | | | | | | Removes schema from the token cookie's domain field. Signed-off-by: Hassan Abouelela <[email protected]>
| * Switches Forwarded Protocol HeaderGravatar Hassan Abouelela2021-03-07-12/+9
| | | | | | | | | | | | | | | | Traefik forwards https traffic to http, which causes issues with the protocol in a request's URL. This switch uses the protocol header to correctly set the protocol. Signed-off-by: Hassan Abouelela <[email protected]>
| * Corrects Domain On Token CookieGravatar Hassan Abouelela2021-03-07-1/+2
| | | | | | | | | | | | Correctly formats the domain set on the cookie used for tokens. Signed-off-by: Hassan Abouelela <[email protected]>
| * Corrects Domain On Token CookieGravatar Hassan Abouelela2021-03-07-2/+3
| | | | | | | | Signed-off-by: Hassan Abouelela <[email protected]>
| * Fixes Domain URL On Token CookieGravatar Hassan Abouelela2021-03-07-11/+18
| | | | | | | | Signed-off-by: Hassan Abouelela <[email protected]>
| * Makes Helper To Handle Token SameSite LogicGravatar Hassan Abouelela2021-03-07-17/+41
| | | | | | | | | | | | Adds a helper method to allow tokens to work on deploy previews. Signed-off-by: Hassan Abouelela <[email protected]>
| * Revert "Sets Token Cookie To Same Site To Lax"Gravatar Hassan Abouelela2021-03-06-2/+2
| | | | | | | | | | | | This reverts commit 013ea900 Signed-off-by: Hassan Abouelela <[email protected]>
| * Sets Token Cookie To Same Site To LaxGravatar Hassan Abouelela2021-03-06-2/+2
| | | | | | | | | | | | | | Sets the authorization token cookie's security policy to lax, to allow it to work on the site. Signed-off-by: Hassan Abouelela <[email protected]>
| * Formats Authorize FileGravatar Hassan Abouelela2021-03-06-3/+2
| | | | | | | | | | | | | | | | Cleans up the authorize file, and the __init__ to maintain the project's code style. Co-authored-by: Joe Banks <[email protected]> Signed-off-by: Hassan Abouelela <[email protected]>
| * Renames Token To `token` Gravatar Hassan Abouelela2021-03-06-3/+3
| | | | | | | | | | Changes the name for the token used to authorize with the backend. Co-authored-by: Joe Banks <[email protected]>
| * Merge branch 'main' into token-expiryGravatar Hassan Abouelela2021-02-28-1/+153
| |\ | | | | | | | | | | | | | | | # Conflicts: # backend/routes/forms/form.py # backend/routes/forms/submit.py
| | * Obliterate the _unit_cache variableGravatar Matteo Bertucci2021-02-27-3/+0
| | |
| | * Use base64 encoded code snippetsGravatar Matteo Bertucci2021-02-26-4/+4
| | |
| | * Properly hadnle hidden tests starting with test_Gravatar Matteo Bertucci2021-02-25-1/+1
| | |
| | * Remove unused importGravatar Matteo Bertucci2021-02-25-2/+4
| | |
| | * Make _make_unit_code more readableGravatar Matteo Bertucci2021-02-25-1/+4
| | |
| | * Remove unneeded temp variableGravatar Matteo Bertucci2021-02-25-4/+2
| | |
| | * Only filter units if we aren't using an admin tokenGravatar Matteo Bertucci2021-02-25-1/+2
| | |
| | * Make use of list.copy() instead of [:]Gravatar Matteo Bertucci2021-02-25-2/+2
| | |
| | * Don't try to parse the composed codeGravatar Matteo Bertucci2021-02-25-40/+32
| | |
| | * Make use of .raise_for_status()Gravatar Matteo Bertucci2021-02-25-8/+6
| | | | | | | | | | | | Co-authored-by: Hassan Abouelela <[email protected]>
| | * Add return code 7 for processes killed by NsJailGravatar Matteo Bertucci2021-02-25-22/+25
| | |
| | * Add return code 6 for exceptions when loading moduleGravatar Matteo Bertucci2021-02-25-1/+1
| | |
| | * Properly handle return codes 5 and 99Gravatar Matteo Bertucci2021-02-24-14/+18
| | |
| | * Document unittest codeGravatar Matteo Bertucci2021-02-24-6/+16
| | |
| | * Censor unittests on GET /forms/$idGravatar Matteo Bertucci2021-02-24-0/+16
| | |
| | * Add support for hidden testsGravatar Matteo Bertucci2021-02-24-2/+17
| | |
| | * Return 403 on failed testsGravatar Matteo Bertucci2021-02-24-1/+1
| | |