aurweb merge requestshttps://gitlab.archlinux.org/archlinux/aurweb/-/merge_requests2022-08-19T01:28:12Zhttps://gitlab.archlinux.org/archlinux/aurweb/-/merge_requests/514fix: display "Unflag package" to users who initiated the flag2022-08-19T01:28:12ZKevin Morriskevr@0cost.orgfix: display "Unflag package" to users who initiated the flagThe original change which fixed another issue by introduced this
inconsistency was located in
https://gitlab.archlinux.org/archlinux/aurweb/-/merge_requests/488
What happened was:
1. Before !488, the "Unflag package" link was incorrectl...The original change which fixed another issue by introduced this
inconsistency was located in
https://gitlab.archlinux.org/archlinux/aurweb/-/merge_requests/488
What happened was:
1. Before !488, the "Unflag package" link was incorrectly shown to all
users, even if they couldn't use it. So, users without authority
were able to click the link which led them to a bad response.
2. !488 solved 1 by only displaying that link for co-maintiainers
and maintainers in particular.
3. With 2, this also removed the "Unflag package" link for the user
who initiated the flag on a package.
4. With this commit, we restore the ability for users who initiated
a flag to view the "Unflag package" link, while keeping it hidden
for other users which have nothing to do with the package (in terms
of flag state).
As of now, the following can both view and use "Unflag package":
- Maintainer of the package
- Co-maintainers of the package
- User who flagged the package
While all other users would be able to see the flag comment, but not
perform anything having to do with unflagging the package.
Closes #380
Signed-off-by: Kevin Morris <kevr@0cost.org>August release 6.1.0Kevin Morriskevr@0cost.orgKevin Morriskevr@0cost.orghttps://gitlab.archlinux.org/archlinux/aurweb/-/merge_requests/515fix: allow co-maintainers to see keyword form2022-08-16T06:53:11ZKevin Morriskevr@0cost.orgfix: allow co-maintainers to see keyword formThis addresses a severe security issue, which is omitted from this
git message for obscurity purposes.
Otherwise, it allows co-maintainers to see the keyword form when
viewing a package they co-maintain.
Closes #380This addresses a severe security issue, which is omitted from this
git message for obscurity purposes.
Otherwise, it allows co-maintainers to see the keyword form when
viewing a package they co-maintain.
Closes #380August release 6.1.0Kevin Morriskevr@0cost.orgKevin Morriskevr@0cost.orghttps://gitlab.archlinux.org/archlinux/aurweb/-/merge_requests/464fix: comaintainer url generation2022-02-18T23:25:19ZKevin Morriskevr@0cost.orgfix: comaintainer url generationCloses #305
Signed-off-by: Kevin Morris <kevr@0cost.org>Closes #305
Signed-off-by: Kevin Morris <kevr@0cost.org>Kevin Morriskevr@0cost.orgKevin Morriskevr@0cost.orghttps://gitlab.archlinux.org/archlinux/aurweb/-/merge_requests/341Fix timezone2021-12-16T20:50:32ZKevin Morriskevr@0cost.orgFix timezonePython/FastAPIKevin Morriskevr@0cost.orgKevin Morriskevr@0cost.orghttps://gitlab.archlinux.org/archlinux/aurweb/-/merge_requests/339fix(time): unquote timezone when producing it2021-12-16T19:14:28ZKevin Morriskevr@0cost.orgfix(time): unquote timezone when producing itSigned-off-by: Kevin Morris <kevr@0cost.org>Signed-off-by: Kevin Morris <kevr@0cost.org>Python/FastAPIKevin Morriskevr@0cost.orgKevin Morriskevr@0cost.org