Compare commits

...
7 Commits
Author SHA1 Message Date
Arthur Cinader 61ab8c90f7 3.4.3 changelog and version bump 2019-06-13 09:51:07 -07:00
Arthur Cinader c9619bc525 Use master's travis 2019-06-13 09:37:42 -07:00
Arthur Cinader 0dd30a5051 Add 3.4.2 Changelog 2019-06-13 08:50:04 -07:00
Arthur Cinader e53514aa0f Get current changelog from master 2019-06-13 08:44:06 -07:00
Arthur Cinader f71db83c9c update version number 2019-06-13 08:40:48 -07:00
Diamond Lewis 4a71e118bf Update Dockerfile (#5676) 2019-06-13 08:36:41 -07:00
Diamond Lewis 7801b7d9ab Merge pull request from GHSA-2479-qvv7-47qq
* Failing test

* provide fix

* clearer test

* failing expect
2019-06-13 08:32:33 -07:00
7 changed files with 85 additions and 43 deletions
+33 -36
View File
@@ -1,27 +1,25 @@
language: node_js
dist: trusty
services:
- mongodb
- postgresql
- redis-server
- docker
- mongodb
- postgresql
- redis-server
- docker
addons:
postgresql: '9.5'
apt:
packages:
- postgresql-9.5-postgis-2.3
- postgresql-9.5-postgis-2.3
branches:
only:
- master
- /^[0-9]+.[0-9]+.[0-9]+(-.*)?$/
- "/^[0-9]+.[0-9]+.[0-9]+(-.*)?$/"
- 3.x
- /^greenkeeper/.*$/
- "/^greenkeeper/.*$/"
cache:
directories:
- "$HOME/.npm"
- "$HOME/.mongodb/versions"
# Test stage
stage: test
env:
global:
@@ -34,7 +32,7 @@ env:
- NODE_VERSION=11.4.0
matrix:
allow_failures:
- env: NODE_VERSION=11.4.0
- env: NODE_VERSION=11.4.0
before_install:
- nvm install $NODE_VERSION
- nvm use $NODE_VERSION
@@ -52,31 +50,30 @@ script:
after_script:
- greenkeeper-lockfile-upload
- bash <(curl -s https://codecov.io/bash)
jobs:
include:
# release on npm on tags
- stage: release
node_js: '8.10'
env:
before_script: skip
after_script: skip
script:
- ./release_docs.sh
deploy:
- provider: pages
skip_cleanup: true
github_token: $GITHUB_TOKEN # Set in travis-ci.org dashboard
local_dir: docs/
on:
all_branches: true
- provider: npm
skip_cleanup: true
email:
secure: $NPM_EMAIL
api_key:
secure: $NPM_TOKEN
on:
tags: true
all_branches: true
repo: parse-community/parse-server
- stage: release
node_js: '10'
env:
before_script: skip
after_script: skip
script:
- "./release_docs.sh"
deploy:
- provider: pages
skip_cleanup: true
github_token:
secure: YU2lUqmW036AHBRu7xO/AwEeQ900Q/5O6FL96ZqWEfD7Gadaq4iapkNvhPR0HcZYRHqQV2/2LCHVnhd0dbj0ShkmVIHdQE7O+MF+j0v0GIVc8FPTPe1/d2Hy4apSWNe6FeCrYKVeliAu+ZqvNuFLhVmYvIeJdlJrMGOb6P76UZXRDv2srXhq4uBcCVUJuTajyyd5ttJfcNapymTP+xzEDYc7Hr4LJaubmv/wVD/xwPBbvfYFuBqysUpkPKi/ODlQbB0ybYh2fFnX71WUyFUGbtB5xI9ma951Zp4v3t73c31uUl27dJaHzO62EtVTdcUKAa804EtAtsvpeJWMVWKUgigm9UZcXdEwKa79fl5nLaq34lrSktAYOkexwPqYj+vbS6sn52JrluSxLE+4cEke7tYbnJ9X12SAQXKgcXY3n30+6gKf9RVqYdlNsYpEAqKVIDb6SlEkk86dP+uIg/XXb5RKEwxbDXnb6xdl9JRc+GTbeeY3/vg2h9QTdmFVblPtBhHrNenQYP/BS0n+EfUnAIBKqRmQgyhao3SiY5FMACM8higI2Lvvhpq46pDhXqsexYCz5F008C6YXGDh5gC93rJFec0pjh55DNdQu6uw3YMQ5jtf3QUXoPAoMFud3cTulMlnjC1WZG8QbqER8dzUZ4TcaQUdzribJI/mRriheBg=
local_dir: docs/
on:
all_branches: true
- provider: npm
api_key:
secure: Yrng6jsnMAtzrrln9DwRuY4xpcxl/WYS/1A5fckyQF6DsLmNlvqVtu3MWF+zdJgANF63G3jIee11tNBpYRecHl8FjPGwO0kc1vEgvIRVnveyR0bwIIDH6s/mR9dg4rZikflwG4XExsLyaQd7ko8aTIOIayfxJiv/u0yqwuBuBW2bFrL/41b1cKGK5+Iq2a+PdFENUPenKXISkACGaMnQF4Y/KVF98UwCiGLf957yFWc2sD6TFbjNDbAENSccvg1J3fBb+djbtzKzldl29ntp2mKVGSVASiKCRa6hSfgQulHiidFqFIKgpYJ1uATRr3UFr/NRVt1WbrgLnzY74OCX7y02c/xiYQMMEPRl/P8hHJu+KjQ3PBWsBvmsRN0QMUJv3PEjUPE3AY8sw49NoxiJZzJr7574vUBuM/dk0byYI6K/gwmUrPIhQjljzZqinS8JJJ4FjGjCdzXRhT5Q+PZvt5bF1rMOZXayNJZa+cICtmiJoU3vO2Yf6TXC3wY1veKvmcs24nws5lp4keJePTKAi1Ig7VoSxwAlgs3EGANIh7oBKx9zWnXQYMdmxbYsvLXAWcnnM+PcSCvooLmXWso3BQBeRuUUSS2oLaBpsFMsiniLNbA1cW4fwMkgUGz4oEDRi8wTD89E/1J2oNxzqtWRPawcVKpMpnBbDJHrWJPEHMw=
email:
secure: lomzDl71N995SzRczm7VE9OZE+PzMo4X8t3zU97agu/FMH5Qcj8BLwE+uVDTnA9Vblyj62ZsFKsNjP2Qp53Vcd+jHM4EJNWNRZYpEMIRO3LngX43r83qoFEHUvPu9s1oaa04a6FojcsJx0wl6B6Ke2AX74MXnJDLb9iZBy1mkpLUMVccVhSfhdoIzhkq3dhUw+6d8C024tNMHcgDW3VnRAsWFtiL7dCMpjLOdI+UxlkeGkQkxXXuRsZ0ZdjoSoM8NSkiYMc8x6EnekyRDoHTujX3OFxuU6+GAjrUmVzNmJWrBIqHVb0DXBQxjEaG3d/cNu5UsQyZYq5sxRRH0BaLs7F4oIQg95etasEtTtUkmsZ3pshVlsweiLU366UdbfuAf5hrJjqLrU12BKZyLjaAwyeKz031r8dA4sJtGIp5uVdXobQQTH6r958A88byJ20uaYSqhqjhZo3hkWXIQP0WQN2Ej/g57HbVNLB/nPKkMILfk/tpp7nBDLT0QrjbZxeo1dwCHqsBEV6z7ZyWyFf4xwpDsir4txL4t8ElzeGdlACjCqAJvIh5w9YzfrwijtoVMvvP6pWvn/iI640d4rsdIDe8egxgqZ1R/TMd/tdHYX+eI+ZfFmCVGj36/uXwdG7KIoIZVjRQ2tvWr9ZuydEPWPSRVGT4ycFeu6wbm3elM3I=
skip_cleanup: true
on:
tags: true
all_branches: true
repo: parse-community/parse-server
+20 -1
View File
@@ -2,7 +2,26 @@
### master
[Full Changelog](https://github.com/parse-community/parse-server/compare/3.4.0...master)
[Full Changelog](https://github.com/parse-community/parse-server/compare/3.4.4...master)
### 3.4.3
[Full Changelog](https://github.com/parse-community/parse-server/compare/3.4.3...3.4.4)
Fix: Commit changes
### 3.4.3
[Full Changelog](https://github.com/parse-community/parse-server/compare/3.4.2...3.4.3)
Fix: Use changes in master to travis configuration to enable pushing to npm and gh_pages. See diff for details.
### 3.4.2
[Full Changelog](https://github.com/parse-community/parse-server/compare/3.4.1...3.4.2)
Fix: In my haste to get a [Security Fix](https://github.com/parse-community/parse-server/security/advisories/GHSA-2479-qvv7-47qq) out, I added [8709daf](https://github.com/parse-community/parse-server/commit/8709daf698ea69b59268cb66f0f7cee75b52daa5) to master instead of to 3.4.1. This commit fixes that. [Arthur Cinader](https://github.com/acinader)
### 3.4.1
[Full Changelog](https://github.com/parse-community/parse-server/compare/3.4.0...3.4.1)
Security Fix: see Advisory: [GHSA-2479-qvv7-47q](https://github.com/parse-community/parse-server/security/advisories/GHSA-2479-qvv7-47qq) for details [8709daf](https://github.com/parse-community/parse-server/commit/8709daf698ea69b59268cb66f0f7cee75b52daa5). Big thanks to: [Benjamin Simonsson](https://github.com/BenniPlejd) for identifying the issue and promptly bringing it to the Parse Community's attention and also big thanks to the indefatigable [Diamond Lewis](https://github.com/dplewis) for crafting a failing test and then a solution within an hour of the report.
### 3.4.0
[Full Changelog](https://github.com/parse-community/parse-server/compare/3.3.0...3.4.0)
+1 -1
View File
@@ -16,7 +16,7 @@ VOLUME /parse-server/cloud /parse-server/config
WORKDIR /parse-server
COPY package*.json ./
RUN npm ci --production
RUN npm ci --production --ignore-scripts
COPY bin bin
COPY public_html public_html
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "parse-server",
"version": "3.4.0",
"version": "3.4.4",
"lockfileVersion": 1,
"requires": true,
"dependencies": {
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "parse-server",
"version": "3.4.0",
"version": "3.4.4",
"description": "An express module providing a Parse-compatible API server",
"main": "lib/index.js",
"repository": {
+25
View File
@@ -1,6 +1,7 @@
const auth = require('../lib/Auth');
const Config = require('../lib/Config');
const rest = require('../lib/rest');
const request = require('../lib/request');
const AudiencesRouter = require('../lib/Routers/AudiencesRouter')
.AudiencesRouter;
@@ -438,4 +439,28 @@ describe('AudiencesRouter', () => {
});
});
});
it('should handle _Audience invalid fields via rest', async () => {
await reconfigureServer({
appId: 'test',
restAPIKey: 'test',
publicServerURL: 'http://localhost:8378/1',
});
try {
await request({
method: 'POST',
url: 'http://localhost:8378/1/classes/_Audience',
body: { lorem: 'ipsum', _method: 'POST' },
headers: {
'X-Parse-Application-Id': 'test',
'X-Parse-REST-API-Key': 'test',
'Content-Type': 'application/json',
},
});
expect(true).toBeFalsy();
} catch (e) {
expect(e.data.code).toBe(107);
expect(e.data.error).toBe('Could not add field lorem');
}
});
});
+4 -3
View File
@@ -228,9 +228,7 @@ function validateCLP(perms: ClassLevelPermissions, fields: SchemaFields) {
// @flow-disable-next
throw new Parse.Error(
Parse.Error.INVALID_JSON,
`'${
perms[operation]
}' is not a valid value for class level permissions ${operation}`
`'${perms[operation]}' is not a valid value for class level permissions ${operation}`
);
} else {
perms[operation].forEach(key => {
@@ -395,6 +393,9 @@ class SchemaData {
this.__data = {};
this.__protectedFields = protectedFields;
allSchemas.forEach(schema => {
if (volatileClasses.includes(schema.className)) {
return;
}
Object.defineProperty(this, schema.className, {
get: () => {
if (!this.__data[schema.className]) {