Compare commits

...
18 Commits
Author SHA1 Message Date
semantic-release-bot 46761d3ae2 chore(release): 6.5.1 [skip ci]
## [6.5.1](https://github.com/parse-community/parse-server/compare/6.5.0...6.5.1) (2024-03-02)

### Bug Fixes

* Security upgrade @parse/push-adapter from 5.0.2 to 5.1.0 ([#8972](https://github.com/parse-community/parse-server/issues/8972)) ([bba24dd](https://github.com/parse-community/parse-server/commit/bba24dd8279ebb8e4084a5f00fbe3ab9fe6c01b4))
2024-03-02 20:43:02 +00:00
Parse Platform bba24dd827 fix: Security upgrade @parse/push-adapter from 5.0.2 to 5.1.0 (#8972) 2024-03-02 21:42:04 +01:00
Manuel 30258be121 docs: Remove incorrect change log entries (#8963) 2024-03-01 17:14:29 +01:00
semantic-release-bot 5f9a27fb8e chore(release): 6.5.0 [skip ci]
# [6.5.0](https://github.com/parse-community/parse-server/compare/6.4.0...6.5.0) (2024-03-01)

### Bug Fixes

* Context not passed to Cloud Code Trigger `beforeFind` when using `Parse.Query.include` ([#8765](https://github.com/parse-community/parse-server/issues/8765)) ([7d32d89](https://github.com/parse-community/parse-server/commit/7d32d8934f3ae7af7a7d8b9cc6a829c7d73973d3))
* Improve PostgreSQL injection detection; fixes security vulnerability [GHSA-6927-3vr9-fxf2](https://github.com/parse-community/parse-server/security/advisories/GHSA-6927-3vr9-fxf2) which affects Parse Server deployments using a Postgres database ([#8960](https://github.com/parse-community/parse-server/issues/8960)) ([a6e6549](https://github.com/parse-community/parse-server/commit/a6e654943536932904a69b51e513507fcf90a504))
* Parse Server option `fileUpload.fileExtensions` fails to determine file extension if filename contains multiple dots ([#8754](https://github.com/parse-community/parse-server/issues/8754)) ([3d6d50e](https://github.com/parse-community/parse-server/commit/3d6d50e0afff18b95fb906914e2cebd3839b517a))
* Security bump @babel/traverse from 7.20.5 to 7.23.2 ([#8777](https://github.com/parse-community/parse-server/issues/8777)) ([2d6b3d1](https://github.com/parse-community/parse-server/commit/2d6b3d18499179e99be116f25c0850d3f449509c))
* Security upgrade graphql from 16.6.0 to 16.8.1 ([#8758](https://github.com/parse-community/parse-server/issues/8758)) ([71dfd8a](https://github.com/parse-community/parse-server/commit/71dfd8a7ece8c0dd1a66d03bb9420cfd39f4f9b1))

### Features

* Add `$setOnInsert` operator to `Parse.Server.database.update` ([#8791](https://github.com/parse-community/parse-server/issues/8791)) ([f630a45](https://github.com/parse-community/parse-server/commit/f630a45aa5e87bc73a81fded061400c199b71a29))
* Add compatibility for MongoDB Atlas Serverless and AWS Amazon DocumentDB with collation options `enableCollationCaseComparison`, `transformEmailToLowercase`, `transformUsernameToLowercase` ([#8805](https://github.com/parse-community/parse-server/issues/8805)) ([09fbeeb](https://github.com/parse-community/parse-server/commit/09fbeebba8870e7cf371fb84371a254c7b368620))
* Add context to Cloud Code Triggers `beforeLogin` and `afterLogin` ([#8724](https://github.com/parse-community/parse-server/issues/8724)) ([a9c34ef](https://github.com/parse-community/parse-server/commit/a9c34ef1e2c78a42fb8b5fa8d569b7677c74919d))
* Allow setting `createdAt` and `updatedAt` during `Parse.Object` creation with maintenance key ([#8696](https://github.com/parse-community/parse-server/issues/8696)) ([77bbfb3](https://github.com/parse-community/parse-server/commit/77bbfb3f186f5651c33ba152f04cff95128eaf2d))
* Upgrade Parse Server Push Adapter to 5.0.2 ([#8813](https://github.com/parse-community/parse-server/issues/8813)) ([6ef1986](https://github.com/parse-community/parse-server/commit/6ef1986c03a1d84b7e11c05851e5bf9688d88740))

### Performance Improvements

* Improved IP validation performance for `masterKeyIPs`, `maintenanceKeyIPs` ([#8510](https://github.com/parse-community/parse-server/issues/8510)) ([b87daba](https://github.com/parse-community/parse-server/commit/b87daba0671a1b0b7b8d63bc671d665c91a04522))
2024-03-01 16:04:36 +00:00
Manuel 297faaece4 ci: Fix incorrect release branch config (#8962) 2024-03-01 17:03:43 +01:00
Manuel a6e6549435 fix: Improve PostgreSQL injection detection; fixes security vulnerability [GHSA-6927-3vr9-fxf2](https://github.com/parse-community/parse-server/security/advisories/GHSA-6927-3vr9-fxf2) which affects Parse Server deployments using a Postgres database (#8960) 2024-03-01 16:51:02 +01:00
Parse Platform 244e3431cf refactor: Upgrade redis from 4.6.12 to 4.6.13 (#8955) 2024-02-27 14:42:47 +01:00
Parse Platform 33c648dc81 refactor: Upgrade uuid from 9.0.0 to 9.0.1 (#8943) 2024-02-26 01:22:37 +01:00
Parse Platform 4524c35d51 refactor: Upgrade follow-redirects from 1.15.2 to 1.15.5 (#8931) 2024-02-24 17:30:05 +01:00
Parse Platform 70e0cb3744 refactor: Upgrade jwks-rsa from 2.1.5 to 3.1.0 (#8932) 2024-02-24 12:22:00 +01:00
Parse Platform 519dee9b89 refactor: Upgrade winston from 3.8.2 to 3.11.0 (#8933) 2024-02-23 18:18:24 +01:00
Parse Platform 897acb76a5 refactor: Upgrade semver from 7.5.2 to 7.5.4 (#8934) 2024-02-22 13:05:39 +01:00
Parse Platform e5de9daa18 refactor: Upgrade @parse/fs-files-adapter from 1.2.2 to 2.0.1 (#8930) 2024-02-20 18:17:11 +01:00
Parse Platform 223fde0f31 refactor: Upgrade pg-promise from 11.5.0 to 11.5.4 (#8924) 2024-02-17 00:41:11 +01:00
Parse Platform d0a5af33ca refactor: Upgrade otpauth from 9.1.2 to 9.2.2 (#8923) 2024-02-17 00:10:26 +01:00
Parse Platform 8fe0ae7a2c refactor: Upgrade ws from 8.13.0 to 8.16.0 (#8921) 2024-02-15 23:54:05 +01:00
Parse Platform 5179501885 refactor: Upgrade redis from 4.6.6 to 4.6.12 (#8922) 2024-02-15 19:35:22 +01:00
Parse Platform 933e8226df refactor: Upgrade lru-cache from 9.1.1 to 10.1.0 (#8870) 2024-01-08 12:15:33 +01:00
6 changed files with 3127 additions and 458 deletions
+14
View File
@@ -1,3 +1,17 @@
## [6.5.1](https://github.com/parse-community/parse-server/compare/6.5.0...6.5.1) (2024-03-02)
### Bug Fixes
* Security upgrade @parse/push-adapter from 5.0.2 to 5.1.0 ([#8972](https://github.com/parse-community/parse-server/issues/8972)) ([bba24dd](https://github.com/parse-community/parse-server/commit/bba24dd8279ebb8e4084a5f00fbe3ab9fe6c01b4))
# [6.5.0](https://github.com/parse-community/parse-server/compare/6.4.0...6.5.0) (2024-03-01)
### Bug Fixes
* Improve PostgreSQL injection detection; fixes security vulnerability [GHSA-6927-3vr9-fxf2](https://github.com/parse-community/parse-server/security/advisories/GHSA-6927-3vr9-fxf2) which affects Parse Server deployments using a Postgres database ([#8960](https://github.com/parse-community/parse-server/issues/8960)) ([a6e6549](https://github.com/parse-community/parse-server/commit/a6e654943536932904a69b51e513507fcf90a504))
# [6.4.0](https://github.com/parse-community/parse-server/compare/6.3.1...6.4.0) (2023-11-16)
+3072 -442
View File
File diff suppressed because it is too large Load Diff
+13 -13
View File
@@ -1,6 +1,6 @@
{
"name": "parse-server",
"version": "6.5.0-alpha.2",
"version": "6.5.1",
"description": "An express module providing a Parse-compatible API server",
"main": "lib/index.js",
"repository": {
@@ -24,8 +24,8 @@
"@graphql-tools/schema": "9.0.4",
"@graphql-tools/utils": "8.12.0",
"@graphql-yoga/node": "2.6.0",
"@parse/fs-files-adapter": "1.2.2",
"@parse/push-adapter": "5.0.2",
"@parse/fs-files-adapter": "2.0.1",
"@parse/push-adapter": "5.1.0",
"bcryptjs": "2.4.3",
"body-parser": "1.20.2",
"commander": "10.0.1",
@@ -33,35 +33,35 @@
"deepcopy": "2.1.0",
"express": "4.18.2",
"express-rate-limit": "6.7.0",
"follow-redirects": "1.15.2",
"follow-redirects": "1.15.5",
"graphql": "16.8.1",
"graphql-list-fields": "2.0.2",
"graphql-relay": "0.10.0",
"graphql-tag": "2.12.6",
"intersect": "1.0.1",
"jsonwebtoken": "9.0.0",
"jwks-rsa": "2.1.5",
"jwks-rsa": "3.1.0",
"ldapjs": "2.3.3",
"lodash": "4.17.21",
"lru-cache": "9.1.1",
"lru-cache": "10.1.0",
"mime": "3.0.0",
"mongodb": "4.10.0",
"mustache": "4.2.0",
"otpauth": "9.1.2",
"otpauth": "9.2.2",
"parse": "4.1.0",
"path-to-regexp": "6.2.1",
"pg-monitor": "2.0.0",
"pg-promise": "11.5.0",
"pg-promise": "11.5.4",
"pluralize": "8.0.0",
"rate-limit-redis": "3.0.2",
"redis": "4.6.6",
"semver": "7.5.2",
"redis": "4.6.13",
"semver": "7.5.4",
"subscriptions-transport-ws": "0.11.0",
"tv4": "1.3.0",
"uuid": "9.0.0",
"winston": "3.8.2",
"uuid": "9.0.1",
"winston": "3.11.0",
"winston-daily-rotate-file": "4.7.1",
"ws": "8.13.0"
"ws": "8.16.0"
},
"devDependencies": {
"@actions/core": "1.9.1",
+2 -2
View File
@@ -40,8 +40,8 @@ async function config() {
{ name: 'alpha', prerelease: true },
{ name: 'beta', prerelease: true },
'next-major',
// Long-Term-Support branches; defined as GLOB pattern
'release-+([0-9]).x.x',
// Long-Term-Support branch of previous major version
'release-6.x.x',
],
dryRun: false,
debug: true,
+25
View File
@@ -459,3 +459,28 @@ describe('Vulnerabilities', () => {
});
});
});
describe('Postgres regex sanitizater', () => {
it('sanitizes the regex correctly to prevent Injection', async () => {
const user = new Parse.User();
user.set('username', 'username');
user.set('password', 'password');
user.set('email', 'email@example.com');
await user.signUp();
const response = await request({
method: 'GET',
url:
"http://localhost:8378/1/classes/_User?where[username][$regex]=A'B'%3BSELECT+PG_SLEEP(3)%3B--",
headers: {
'Content-Type': 'application/json',
'X-Parse-Application-Id': 'test',
'X-Parse-REST-API-Key': 'rest',
},
});
expect(response.status).toBe(200);
expect(response.data.results).toEqual(jasmine.any(Array));
expect(response.data.results.length).toBe(0);
});
});
@@ -2656,7 +2656,7 @@ function literalizeRegexPart(s: string) {
.replace(/([^\\])(\\Q)/, '$1')
.replace(/^\\E/, '')
.replace(/^\\Q/, '')
.replace(/([^'])'/, `$1''`)
.replace(/([^'])'/g, `$1''`)
.replace(/^'([^'])/, `''$1`);
}