summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2024-09-27Implement request filtersMia Herkt
This moves preexisting blacklists to the database, and adds the following filter types: * IP address * IP network * MIME type * User agent In addition, IP address handling is now done with the ipaddress module.
2024-09-27Replace NSFW detector implementationMia Herkt
2024-03-30ModUI: Update for Textual 0.54.0Mia Herkt
2023-06-04Fix remote URL content length check off-by-onepolina4096
Fixes #85
2023-03-29ModUI: Handle opening filter panel with NULL user agentMia Herkt
2023-03-29ModUI: Allow LIKE matching for address filteringMia Herkt
2023-03-29Store user agent with filesMia Herkt
Needed for moderation.
2023-03-29URL: Explicitly set upper-case table nameMia Herkt
Looks like recent SQLAlchemy/Alembic chose to lower-case it by default. Try not to break existing schemas.
2023-01-15fix 500 error when file extension could not be guessedjonas-w
when a file without an extension was uploaded and the mimetypes.guess_extension returned None because there is no official file extension for that mimetype a NoneType was subscripted which yielded a 500 http error
2022-12-29ModUI: Fix crash when encountering null NSFW scoreMia Herkt
Fixes #78
2022-12-22ModUI: Add application/xml to text handlerMia Herkt
2022-12-22ModUI: Fix jinja2 func call in ban actionMia Herkt
2022-12-21README: Kitty support was merged in mpvMia Herkt
2022-12-20README: Add ModUI screenshotMia Herkt
2022-12-20ModUI: Add application/json to text handlerMia Herkt
2022-12-20Update requirements.txtMia Herkt
2022-12-20Add moderation TUIMia Herkt
This ended up way fancier than I imagined.
2022-12-20migrations: Fix file expirations on SQLiteMia Herkt
Well that was what we feared. I love arbitrary hardcoded limits.
2022-12-17Fix NSFW detectionMia Herkt
2022-12-13Prevent unreasonably long MIME typesMia Herkt
2022-12-13Fix URL test issueMia Herkt
2022-12-13File: Fix 404 case with secret URLsMia Herkt
2022-12-13Record file sizes in dbMia Herkt
Moderation interface is going to use this.
2022-12-13File: Add is_nsfw propertyMia Herkt
2022-12-12README: Add note about StreamMaxLength in clamd.confMia Herkt
2022-12-12Add support for ClamAVMia Herkt
2022-12-01index.html: Document appending file namesMia Herkt
2022-12-01Add support for “secret” file URLsMia Herkt
Closes #47
2022-12-01Fix 500 on invalid pathsMia Herkt
2022-12-01Fix handling double file name extensionsMia Herkt
Long names would get truncated at the end, causing problems including unresolvable file URLs. Example with default settings: .package.lst → .package. Fixes #61
2022-11-30Add X-Expires to file response headersMia Herkt
Tells clients when files will expire, in milliseconds since Unix epoch. Closes #50.
2022-11-30Allow changing expiration dateMia Herkt
2022-11-30templates/index: Remove unnecessary escapingMia Herkt
2022-11-30Allow management operations like deleting filesMia Herkt
This introduces the X-Token header field in the response of newly uploaded files as a simple way for users to manage their own files. It does not need to be particularly secure.
2022-11-29nsfw_detect: Use PyAV instead of ffmpegthumbnailerMia Herkt
2022-11-29nsfw_detect: Use pathlib, fix deprecation warningMia Herkt
Also fix glog suppression
2022-11-29README: Also run db upgrade after git pull!Mia Herkt
2022-11-29Add example systemd unit files for prune jobMia Herkt
2022-11-29nsfw_detect: Tolerate score computation failureMia Herkt
2022-11-29Add support for expiring filesEmi Simpson
SUPPLEMENTALLY: - Add an `expiration` field to the `file` table of the database - Produce a migration for the above change - Overhaul the cleanup script, and integrate into fhost.py (now run using FLASK_APP=fhost flask prune) - Replace the old cleanup script with a deprecation notice - Add information about how to expire files to the index - Update the README with information about the new script Squashed commits: Add a note explaining that expired files aren't immediately removed Show correct times on the index page graph Improve the migration script, removing the need for --legacy Use automap in place of an explicit file map in migration Remove vestigial `touch()` Don't crash when upgrading a fresh database Remove vestigial warning about legacy files More efficiently filter to unexpired files when migrating https://git.0x0.st/mia/0x0/pulls/72#issuecomment-224 Coalesce updates to the database during migration https://git.0x0.st/mia/0x0/pulls/72#issuecomment-226 Remove vestigial database model https://git.0x0.st/mia/0x0/pulls/72#issuecomment-261 prune: Stream expired files from the database (as opposed to collecting them all first) config.example.py: Add min & max expiration + description
2022-11-28config.example.py: Clarify MIME ext mappingMia Herkt
2022-11-28Add example configuration fileEmber Hearth
See #73.
2022-11-20README: Clarify why serving file requests from the app is badMia Herkt
2022-11-20README: Clarify how to change configurationMia Herkt
2022-08-19README: Warn users about URL fetch network security implicationsMia Herkt
2022-08-11Fix non-seekable file handlesMia Herkt
Closes #59
2022-08-01Open upload blacklist in text modeMia Herkt
This wasn’t working since Flask opens files in bin mode by default.
2022-01-01Fix mime splittingAlexey Sakovets
mime[:mime.find(";")] will remove last character if mime does not contain ";". Use mime.split(";") instead.
2021-12-01remove short_url and add in-tree URLencoder (#53)mia
This PR removes the short_url dependency as per issue #41. This implementation is pretty much the same as in short_url except I've rewritten the enbase() function to be iterative instead of recursive. The only functions of the class are enbase() and debase() since those were the only functions being used by fhost. Co-authored-by: 7415963987456321 <hrs70@hi.is> Reviewed-on: https://git.0x0.st/mia/0x0/pulls/53 Co-authored-by: mia <mia@0x0.st> Co-committed-by: mia <mia@0x0.st>
2021-08-06Fix some flake8 errors in cleanup and nsfw_detectNikolas Nyby
Just some minor code cleanup