Skip to content

Commit

Permalink
Merge branch '6-0-sec' into 6-0-stable
Browse files Browse the repository at this point in the history
* 6-0-sec:
  Preparing for 6.0.4.3 release
  bump version
  update changelog
  Merge pull request #43868 from rails/fix-default-hosts
  Merge pull request #43863 from rails/yubikey-support
  • Loading branch information
tenderlove committed Dec 14, 2021
2 parents f8ef5c2 + 0cc179f commit bf9be16
Show file tree
Hide file tree
Showing 36 changed files with 165 additions and 71 deletions.
100 changes: 50 additions & 50 deletions Gemfile.lock
Original file line number Diff line number Diff line change
Expand Up @@ -32,79 +32,79 @@ GIT
PATH
remote: .
specs:
actioncable (6.0.4.2)
actionpack (= 6.0.4.2)
actioncable (6.0.4.3)
actionpack (= 6.0.4.3)
nio4r (~> 2.0)
websocket-driver (>= 0.6.1)
actionmailbox (6.0.4.2)
actionpack (= 6.0.4.2)
activejob (= 6.0.4.2)
activerecord (= 6.0.4.2)
activestorage (= 6.0.4.2)
activesupport (= 6.0.4.2)
actionmailbox (6.0.4.3)
actionpack (= 6.0.4.3)
activejob (= 6.0.4.3)
activerecord (= 6.0.4.3)
activestorage (= 6.0.4.3)
activesupport (= 6.0.4.3)
mail (>= 2.7.1)
actionmailer (6.0.4.2)
actionpack (= 6.0.4.2)
actionview (= 6.0.4.2)
activejob (= 6.0.4.2)
actionmailer (6.0.4.3)
actionpack (= 6.0.4.3)
actionview (= 6.0.4.3)
activejob (= 6.0.4.3)
mail (~> 2.5, >= 2.5.4)
rails-dom-testing (~> 2.0)
actionpack (6.0.4.2)
actionview (= 6.0.4.2)
activesupport (= 6.0.4.2)
actionpack (6.0.4.3)
actionview (= 6.0.4.3)
activesupport (= 6.0.4.3)
rack (~> 2.0, >= 2.0.8)
rack-test (>= 0.6.3)
rails-dom-testing (~> 2.0)
rails-html-sanitizer (~> 1.0, >= 1.2.0)
actiontext (6.0.4.2)
actionpack (= 6.0.4.2)
activerecord (= 6.0.4.2)
activestorage (= 6.0.4.2)
activesupport (= 6.0.4.2)
actiontext (6.0.4.3)
actionpack (= 6.0.4.3)
activerecord (= 6.0.4.3)
activestorage (= 6.0.4.3)
activesupport (= 6.0.4.3)
nokogiri (>= 1.8.5)
actionview (6.0.4.2)
activesupport (= 6.0.4.2)
actionview (6.0.4.3)
activesupport (= 6.0.4.3)
builder (~> 3.1)
erubi (~> 1.4)
rails-dom-testing (~> 2.0)
rails-html-sanitizer (~> 1.1, >= 1.2.0)
activejob (6.0.4.2)
activesupport (= 6.0.4.2)
activejob (6.0.4.3)
activesupport (= 6.0.4.3)
globalid (>= 0.3.6)
activemodel (6.0.4.2)
activesupport (= 6.0.4.2)
activerecord (6.0.4.2)
activemodel (= 6.0.4.2)
activesupport (= 6.0.4.2)
activestorage (6.0.4.2)
actionpack (= 6.0.4.2)
activejob (= 6.0.4.2)
activerecord (= 6.0.4.2)
activemodel (6.0.4.3)
activesupport (= 6.0.4.3)
activerecord (6.0.4.3)
activemodel (= 6.0.4.3)
activesupport (= 6.0.4.3)
activestorage (6.0.4.3)
actionpack (= 6.0.4.3)
activejob (= 6.0.4.3)
activerecord (= 6.0.4.3)
marcel (~> 1.0.0)
activesupport (6.0.4.2)
activesupport (6.0.4.3)
concurrent-ruby (~> 1.0, >= 1.0.2)
i18n (>= 0.7, < 2)
minitest (~> 5.1)
tzinfo (~> 1.1)
zeitwerk (~> 2.2, >= 2.2.2)
rails (6.0.4.2)
actioncable (= 6.0.4.2)
actionmailbox (= 6.0.4.2)
actionmailer (= 6.0.4.2)
actionpack (= 6.0.4.2)
actiontext (= 6.0.4.2)
actionview (= 6.0.4.2)
activejob (= 6.0.4.2)
activemodel (= 6.0.4.2)
activerecord (= 6.0.4.2)
activestorage (= 6.0.4.2)
activesupport (= 6.0.4.2)
rails (6.0.4.3)
actioncable (= 6.0.4.3)
actionmailbox (= 6.0.4.3)
actionmailer (= 6.0.4.3)
actionpack (= 6.0.4.3)
actiontext (= 6.0.4.3)
actionview (= 6.0.4.3)
activejob (= 6.0.4.3)
activemodel (= 6.0.4.3)
activerecord (= 6.0.4.3)
activestorage (= 6.0.4.3)
activesupport (= 6.0.4.3)
bundler (>= 1.3.0)
railties (= 6.0.4.2)
railties (= 6.0.4.3)
sprockets-rails (>= 2.0.0)
railties (6.0.4.2)
actionpack (= 6.0.4.2)
activesupport (= 6.0.4.2)
railties (6.0.4.3)
actionpack (= 6.0.4.3)
activesupport (= 6.0.4.3)
method_source
rake (>= 0.8.7)
thor (>= 0.20.3, < 2.0)
Expand Down
2 changes: 1 addition & 1 deletion RAILS_VERSION
Original file line number Diff line number Diff line change
@@ -1 +1 @@
6.0.4.2
6.0.4.3
5 changes: 5 additions & 0 deletions actioncable/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
## Rails 6.0.4.3 (December 14, 2021) ##

* No changes.


## Rails 6.0.4.2 (December 14, 2021) ##

* No changes.
Expand Down
2 changes: 1 addition & 1 deletion actioncable/lib/action_cable/gem_version.rb
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ module VERSION
MAJOR = 6
MINOR = 0
TINY = 4
PRE = "2"
PRE = "3"

STRING = [MAJOR, MINOR, TINY, PRE].compact.join(".")
end
Expand Down
2 changes: 1 addition & 1 deletion actioncable/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@rails/actioncable",
"version": "6.0.4-2",
"version": "6.0.4-3",
"description": "WebSocket framework for Ruby on Rails.",
"main": "app/assets/javascripts/action_cable.js",
"files": [
Expand Down
5 changes: 5 additions & 0 deletions actionmailbox/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
## Rails 6.0.4.3 (December 14, 2021) ##

* No changes.


## Rails 6.0.4.2 (December 14, 2021) ##

* No changes.
Expand Down
2 changes: 1 addition & 1 deletion actionmailbox/lib/action_mailbox/gem_version.rb
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ module VERSION
MAJOR = 6
MINOR = 0
TINY = 4
PRE = "2"
PRE = "3"

STRING = [MAJOR, MINOR, TINY, PRE].compact.join(".")
end
Expand Down
5 changes: 5 additions & 0 deletions actionmailer/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
## Rails 6.0.4.3 (December 14, 2021) ##

* No changes.


## Rails 6.0.4.2 (December 14, 2021) ##

* No changes.
Expand Down
2 changes: 1 addition & 1 deletion actionmailer/lib/action_mailer/gem_version.rb
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ module VERSION
MAJOR = 6
MINOR = 0
TINY = 4
PRE = "2"
PRE = "3"

STRING = [MAJOR, MINOR, TINY, PRE].compact.join(".")
end
Expand Down
5 changes: 5 additions & 0 deletions actionpack/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
## Rails 6.0.4.3 (December 14, 2021) ##

* No changes.


## Rails 6.0.4.2 (December 14, 2021) ##

* Fix X_FORWARDED_HOST protection. [CVE-2021-44528]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,8 @@ module ActionDispatch
# application will be executed and rendered. If no +response_app+ is given, a
# default one will run, which responds with +403 Forbidden+.
class HostAuthorization
ALLOWED_HOSTS_IN_DEVELOPMENT = [".localhost", /\A([a-z0-9-]+\.)?localhost:\d+\z/, IPAddr.new("0.0.0.0/0"), IPAddr.new("::/0")]

class Permissions # :nodoc:
def initialize(hosts)
@hosts = sanitize_hosts(hosts)
Expand Down
2 changes: 1 addition & 1 deletion actionpack/lib/action_pack/gem_version.rb
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ module VERSION
MAJOR = 6
MINOR = 0
TINY = 4
PRE = "2"
PRE = "3"

STRING = [MAJOR, MINOR, TINY, PRE].compact.join(".")
end
Expand Down
12 changes: 12 additions & 0 deletions actionpack/test/dispatch/host_authorization_test.rb
Original file line number Diff line number Diff line change
Expand Up @@ -143,6 +143,18 @@ class HostAuthorizationTest < ActionDispatch::IntegrationTest
assert_equal "Custom", body
end

test "localhost works in dev" do
@app = ActionDispatch::HostAuthorization.new(App, ActionDispatch::HostAuthorization::ALLOWED_HOSTS_IN_DEVELOPMENT)

get "/", env: {
"HOST" => "localhost:3000",
"action_dispatch.show_detailed_exceptions" => true
}

assert_response :ok
assert_match "Success", response.body
end

test "blocks requests with spoofed X-FORWARDED-HOST" do
@app = ActionDispatch::HostAuthorization.new(App, [IPAddr.new("127.0.0.1")])

Expand Down
5 changes: 5 additions & 0 deletions actiontext/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,11 @@

*Jonathan Hefner*

## Rails 6.0.4.3 (December 14, 2021) ##

* No changes.


## Rails 6.0.4.2 (December 14, 2021) ##

* No changes.
Expand Down
2 changes: 1 addition & 1 deletion actiontext/lib/action_text/gem_version.rb
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ module VERSION
MAJOR = 6
MINOR = 0
TINY = 4
PRE = "2"
PRE = "3"

STRING = [MAJOR, MINOR, TINY, PRE].compact.join(".")
end
Expand Down
2 changes: 1 addition & 1 deletion actiontext/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@rails/actiontext",
"version": "6.0.4-2",
"version": "6.0.4-3",
"description": "Edit and display rich text in Rails applications",
"main": "app/javascript/actiontext/index.js",
"files": [
Expand Down
5 changes: 5 additions & 0 deletions actionview/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
## Rails 6.0.4.3 (December 14, 2021) ##

* No changes.


## Rails 6.0.4.2 (December 14, 2021) ##

* No changes.
Expand Down
2 changes: 1 addition & 1 deletion actionview/lib/action_view/gem_version.rb
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ module VERSION
MAJOR = 6
MINOR = 0
TINY = 4
PRE = "2"
PRE = "3"

STRING = [MAJOR, MINOR, TINY, PRE].compact.join(".")
end
Expand Down
2 changes: 1 addition & 1 deletion actionview/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@rails/ujs",
"version": "6.0.4-2",
"version": "6.0.4-3",
"description": "Ruby on Rails unobtrusive scripting adapter",
"main": "lib/assets/compiled/rails-ujs.js",
"files": [
Expand Down
5 changes: 5 additions & 0 deletions activejob/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
## Rails 6.0.4.3 (December 14, 2021) ##

* No changes.


## Rails 6.0.4.2 (December 14, 2021) ##

* No changes.
Expand Down
2 changes: 1 addition & 1 deletion activejob/lib/active_job/gem_version.rb
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ module VERSION
MAJOR = 6
MINOR = 0
TINY = 4
PRE = "2"
PRE = "3"

STRING = [MAJOR, MINOR, TINY, PRE].compact.join(".")
end
Expand Down
5 changes: 5 additions & 0 deletions activemodel/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
## Rails 6.0.4.3 (December 14, 2021) ##

* No changes.


## Rails 6.0.4.2 (December 14, 2021) ##

* No changes.
Expand Down
2 changes: 1 addition & 1 deletion activemodel/lib/active_model/gem_version.rb
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ module VERSION
MAJOR = 6
MINOR = 0
TINY = 4
PRE = "2"
PRE = "3"

STRING = [MAJOR, MINOR, TINY, PRE].compact.join(".")
end
Expand Down
5 changes: 5 additions & 0 deletions activerecord/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
## Rails 6.0.4.3 (December 14, 2021) ##

* No changes.


## Rails 6.0.4.2 (December 14, 2021) ##

* No changes.
Expand Down
2 changes: 1 addition & 1 deletion activerecord/lib/active_record/gem_version.rb
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ module VERSION
MAJOR = 6
MINOR = 0
TINY = 4
PRE = "2"
PRE = "3"

STRING = [MAJOR, MINOR, TINY, PRE].compact.join(".")
end
Expand Down
5 changes: 5 additions & 0 deletions activestorage/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
## Rails 6.0.4.3 (December 14, 2021) ##

* No changes.


## Rails 6.0.4.2 (December 14, 2021) ##

* No changes.
Expand Down
2 changes: 1 addition & 1 deletion activestorage/lib/active_storage/gem_version.rb
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ module VERSION
MAJOR = 6
MINOR = 0
TINY = 4
PRE = "2"
PRE = "3"

STRING = [MAJOR, MINOR, TINY, PRE].compact.join(".")
end
Expand Down
2 changes: 1 addition & 1 deletion activestorage/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@rails/activestorage",
"version": "6.0.4-2",
"version": "6.0.4-3",
"description": "Attach cloud and local files in Rails applications",
"main": "app/assets/javascripts/activestorage.js",
"files": [
Expand Down
5 changes: 5 additions & 0 deletions activesupport/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
## Rails 6.0.4.3 (December 14, 2021) ##

* No changes.


## Rails 6.0.4.2 (December 14, 2021) ##

* No changes.
Expand Down
2 changes: 1 addition & 1 deletion activesupport/lib/active_support/gem_version.rb
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ module VERSION
MAJOR = 6
MINOR = 0
TINY = 4
PRE = "2"
PRE = "3"

STRING = [MAJOR, MINOR, TINY, PRE].compact.join(".")
end
Expand Down

0 comments on commit bf9be16

Please sign in to comment.