Commit message (Collapse) | Author | Age | Lines | ||
---|---|---|---|---|---|
... | |||||
* | [TfL] Restrict reports on cobrand to post go-live. | Matthew Somerville | 2019-12-09 | -8/+1 | |
| | |||||
* | [TfL] Remove Email::TfL send method as no longer needed | Dave Arter | 2019-12-09 | -33/+0 | |
| | |||||
* | [TfL] Mandate 2FA for non-internal-IP staff users. | Matthew Somerville | 2019-12-09 | -0/+1 | |
| | |||||
* | Allow cobrands to skip 2FA requirement. | Matthew Somerville | 2019-12-09 | -1/+19 | |
| | |||||
* | Record first time fixed/closed update sent to reporter in email. | Matthew Somerville | 2019-12-09 | -0/+3 | |
| | |||||
* | Include areas in query param for inspector post-login redirect to all reports | Dave Arter | 2019-12-09 | -0/+68 | |
| | | | | | Performs a proper redirect instead of detaching to /my/inspector_redirect so any request params from sign-in (e.g. password!) aren't carried through. | ||||
* | Group categories on response template edit page, if cobrand allows | Dave Arter | 2019-12-09 | -0/+45 | |
| | |||||
* | [UK Councils] Ensure response templates owned by other bodies aren’t visible | Dave Arter | 2019-12-09 | -6/+71 | |
| | |||||
* | Switch to default-escaped in email templates. | Matthew Somerville | 2019-12-09 | -3/+11 | |
| | | | | | We add a way to process a template with no auto-escaping, that can be used for the text parts of emails, and mark various HTML output as safe. | ||||
* | Switch to default-escaped in templates. | Matthew Somerville | 2019-12-09 | -1/+1 | |
| | | | | | | | This means any variable used in a template is automatically HTML-escaped, unless it is marked as safe either in code by using a SafeString, or in the template with the `mark_safe` function or the `safe` filter. | ||||
* | Fix broken alert_type test. | Matthew Somerville | 2019-12-08 | -12/+15 | |
| | |||||
* | [Peterborough] add title length restriction | Struan Donald | 2019-12-03 | -1/+27 | |
| | | | | Fixes mysociety/fixmystreet-freshdesk#102 | ||||
* | Merge branch 'csp-uk' | Matthew Somerville | 2019-11-25 | -2/+29 | |
|\ | |||||
| * | Add configuration for setting CSP header. | Matthew Somerville | 2019-11-25 | -2/+29 | |
| | | | | | | | | | | | | This allows you to output a working Content-Security-Policy header, with optional third-party domains, by setting a new CONTENT_SECURITY_POLICY configuration option. | ||||
* | | Merge branch 'qr-code-generator' | Matthew Somerville | 2019-11-25 | -1/+0 | |
|\ \ | |||||
| * | | Switch to internal QR code generator. | Matthew Somerville | 2019-11-23 | -1/+0 | |
| | | | |||||
* | | | [Oxfordshire] re-enable inspector permissions | Struan Donald | 2019-11-22 | -27/+0 | |
|/ / | | | | | | | | | Re-enable the inspector permissions that were disabled at a cobrand level | ||||
* | | Rotate session ID after successful login. | Matthew Somerville | 2019-11-22 | -12/+11 | |
| | | |||||
* | | Replace use of FixMyStreet::App with DB in tests. | Matthew Somerville | 2019-11-22 | -219/+208 | |
|/ | |||||
* | Remove cached photos before updating db field. | Matthew Somerville | 2019-11-18 | -13/+34 | |
| | | | | | If the photo field is updated first, then the cache removal doesn't think there are any photos to remove. | ||||
* | Merge branch 'issues/freshdesk/98-staff-ignore-emergency-message' | Struan Donald | 2019-11-15 | -0/+51 | |
|\ | |||||
| * | allow staff to submit in disabled categories | Struan Donald | 2019-11-15 | -0/+51 | |
| | | | | | | | | | | | | | | If a user belongs to a body override the disabled form check upon submission as mostly staff users can submit in those categories. Fixes mysociety/fixmystreet-freshdesk#98 | ||||
* | | Add cobrand-specific XSL to RSS feeds. | Matthew Somerville | 2019-11-15 | -0/+17 | |
|/ | |||||
* | Merge branch 'admin-auditing' | Matthew Somerville | 2019-11-10 | -8/+62 | |
|\ | |||||
| * | Add user admin log page. | Matthew Somerville | 2019-11-08 | -5/+54 | |
| | | |||||
| * | Store a moderation history on admin report edit. | Matthew Somerville | 2019-11-08 | -0/+7 | |
| | | |||||
| * | Add admin log entry for more objects and things. | Matthew Somerville | 2019-11-08 | -1/+1 | |
| | | | | | | | | | | Namely templates, roles, bodies, categories, various user edits, and when using the inspect form and changing category. | ||||
| * | Factor out admin template code to own controller. | Matthew Somerville | 2019-11-08 | -2/+0 | |
| | | |||||
* | | Store email addresses report sent to on the report | Matthew Somerville | 2019-11-10 | -0/+3 | |
|/ | |||||
* | Fix password reset on 2FA accounts again. | Matthew Somerville | 2019-11-05 | -0/+5 | |
| | | | | | | Just after fixing it, 3d593bc68 broke it again, because it took anyone who must have 2FA switched on to the must-have-2FA sign up flow, even if they already had 2FA set up. | ||||
* | Add optional enforced password expiry. | Matthew Somerville | 2019-11-04 | -0/+28 | |
| | |||||
* | Record time of password change. | Matthew Somerville | 2019-11-04 | -1/+3 | |
| | |||||
* | Merge branch '2fa-improvements' | Matthew Somerville | 2019-10-31 | -148/+203 | |
|\ | |||||
| * | If 2FA enforced, do it for an email login as well. | Matthew Somerville | 2019-10-30 | -0/+34 | |
| | | |||||
| * | Fix password reset on 2FA accounts. | Matthew Somerville | 2019-10-30 | -0/+23 | |
| | | |||||
| * | [UK] Mandate 2FA on superusers. | Matthew Somerville | 2019-10-30 | -7/+13 | |
| | | |||||
| * | Allow enforcement of 2FA for staff users. | Matthew Somerville | 2019-10-30 | -15/+111 | |
| | | |||||
| * | Require code to be entered when activating 2FA. | Matthew Somerville | 2019-10-28 | -6/+15 | |
| | | |||||
| * | Allow non-superusers to store 2FA secrets. | Matthew Somerville | 2019-10-28 | -4/+9 | |
| | | |||||
| * | Remove unused inspection required/reputation code. | Matthew Somerville | 2019-10-28 | -120/+0 | |
| | | |||||
* | | Fix some tests not running offline. | Matthew Somerville | 2019-10-28 | -4/+6 | |
|/ | |||||
* | Merge remote-tracking branch 'origin/master' | Matthew Somerville | 2019-10-28 | -0/+47 | |
|\ | |||||
| * | add a get_extra_field method to Extra role | Struan Donald | 2019-10-28 | -0/+47 | |
| | | | | | | | | | | accepts name or code for finding the field. Useful for checking for individual open311 fields that don't have a value. | ||||
* | | Allow editing of category name. | Matthew Somerville | 2019-10-25 | -1/+16 | |
| | | |||||
* | | Make contact edit note optional on staging sites. | Matthew Somerville | 2019-10-25 | -1/+1 | |
|/ | |||||
* | [Westminster] Test warnfixes. | Matthew Somerville | 2019-10-14 | -4/+5 | |
| | |||||
* | Test warnfix on confirmed comments lacking time. | Matthew Somerville | 2019-10-14 | -7/+7 | |
| | |||||
* | [Oxfordshire] Remove defect type front end code. | Matthew Somerville | 2019-10-10 | -27/+0 | |
| | |||||
* | [Oxfordshire] Remove raise defect/inspected code. | Matthew Somerville | 2019-10-10 | -30/+1 | |
| | |||||
*---. | Merge branches 'use-right-asset-name', 'deadlock', ↵ | Matthew Somerville | 2019-10-04 | -127/+131 | |
|\ \ \ | | | | | | | | | | | | | '2469-fancy-admin-category-form' and 'fix-missing-body-message-flash' |