Compare commits

...
5 Commits
Author SHA1 Message Date
Arthur Cinader 0dd30a5051 Add 3.4.2 Changelog 2019-06-13 08:50:04 -07:00
Arthur Cinader e53514aa0f Get current changelog from master 2019-06-13 08:44:06 -07:00
Arthur Cinader f71db83c9c update version number 2019-06-13 08:40:48 -07:00
Diamond Lewis 4a71e118bf Update Dockerfile (#5676) 2019-06-13 08:36:41 -07:00
Diamond Lewis 7801b7d9ab Merge pull request from GHSA-2479-qvv7-47qq
* Failing test

* provide fix

* clearer test

* failing expect
2019-06-13 08:32:33 -07:00
6 changed files with 43 additions and 7 deletions
+11 -1
View File
@@ -2,7 +2,17 @@
### master
[Full Changelog](https://github.com/parse-community/parse-server/compare/3.4.0...master)
[Full Changelog](https://github.com/parse-community/parse-server/compare/3.4.2...master)
### 3.4.2
[Full Changelog](https://github.com/parse-community/parse-server/compare/3.4.1...3.4.2)
Fix: In my haste to get a [Security Fix](https://github.com/parse-community/parse-server/security/advisories/GHSA-2479-qvv7-47qq) out, I added [8709daf](https://github.com/parse-community/parse-server/commit/8709daf698ea69b59268cb66f0f7cee75b52daa5) to master instead of to 3.4.1. This commit fixes that. [Arthur Cinader](https://github.com/acinader)
### 3.4.1
[Full Changelog](https://github.com/parse-community/parse-server/compare/3.4.0...3.4.1)
Security Fix: see Advisory: [GHSA-2479-qvv7-47q](https://github.com/parse-community/parse-server/security/advisories/GHSA-2479-qvv7-47qq) for details [8709daf](https://github.com/parse-community/parse-server/commit/8709daf698ea69b59268cb66f0f7cee75b52daa5). Big thanks to: [Benjamin Simonsson](https://github.com/BenniPlejd) for identifying the issue and promptly bringing it to the Parse Community's attention and also big thanks to the indefatigable [Diamond Lewis](https://github.com/dplewis) for crafting a failing test and then a solution within an hour of the report.
### 3.4.0
[Full Changelog](https://github.com/parse-community/parse-server/compare/3.3.0...3.4.0)
+1 -1
View File
@@ -16,7 +16,7 @@ VOLUME /parse-server/cloud /parse-server/config
WORKDIR /parse-server
COPY package*.json ./
RUN npm ci --production
RUN npm ci --production --ignore-scripts
COPY bin bin
COPY public_html public_html
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "parse-server",
"version": "3.4.0",
"version": "3.4.2",
"lockfileVersion": 1,
"requires": true,
"dependencies": {
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "parse-server",
"version": "3.4.0",
"version": "3.4.2",
"description": "An express module providing a Parse-compatible API server",
"main": "lib/index.js",
"repository": {
+25
View File
@@ -1,6 +1,7 @@
const auth = require('../lib/Auth');
const Config = require('../lib/Config');
const rest = require('../lib/rest');
const request = require('../lib/request');
const AudiencesRouter = require('../lib/Routers/AudiencesRouter')
.AudiencesRouter;
@@ -438,4 +439,28 @@ describe('AudiencesRouter', () => {
});
});
});
it('should handle _Audience invalid fields via rest', async () => {
await reconfigureServer({
appId: 'test',
restAPIKey: 'test',
publicServerURL: 'http://localhost:8378/1',
});
try {
await request({
method: 'POST',
url: 'http://localhost:8378/1/classes/_Audience',
body: { lorem: 'ipsum', _method: 'POST' },
headers: {
'X-Parse-Application-Id': 'test',
'X-Parse-REST-API-Key': 'test',
'Content-Type': 'application/json',
},
});
expect(true).toBeFalsy();
} catch (e) {
expect(e.data.code).toBe(107);
expect(e.data.error).toBe('Could not add field lorem');
}
});
});
+4 -3
View File
@@ -228,9 +228,7 @@ function validateCLP(perms: ClassLevelPermissions, fields: SchemaFields) {
// @flow-disable-next
throw new Parse.Error(
Parse.Error.INVALID_JSON,
`'${
perms[operation]
}' is not a valid value for class level permissions ${operation}`
`'${perms[operation]}' is not a valid value for class level permissions ${operation}`
);
} else {
perms[operation].forEach(key => {
@@ -395,6 +393,9 @@ class SchemaData {
this.__data = {};
this.__protectedFields = protectedFields;
allSchemas.forEach(schema => {
if (volatileClasses.includes(schema.className)) {
return;
}
Object.defineProperty(this, schema.className, {
get: () => {
if (!this.__data[schema.className]) {