Compare commits

...
47 Commits
Author SHA1 Message Date
semantic-release-bot 144781a855 chore(release): 6.5.9 [skip ci]
## [6.5.9](https://github.com/parse-community/parse-server/compare/6.5.8...6.5.9) (2024-10-03)

### Bug Fixes

* Custom object ID allows to acquire role privileges ([GHSA-8xq9-g7ch-35hg](https://github.com/parse-community/parse-server/security/advisories/GHSA-8xq9-g7ch-35hg)) ([#9318](https://github.com/parse-community/parse-server/issues/9318)) ([1bfbccf](https://github.com/parse-community/parse-server/commit/1bfbccf9ee7ea77533b2b2aa7c4c69f3bd35e66f))
2024-10-03 19:32:32 +00:00
Manuel 1bfbccf9ee fix: Custom object ID allows to acquire role privileges ([GHSA-8xq9-g7ch-35hg](https://github.com/parse-community/parse-server/security/advisories/GHSA-8xq9-g7ch-35hg)) (#9318) 2024-10-03 21:28:41 +02:00
semantic-release-bot 12ce46db81 chore(release): 6.5.8 [skip ci]
## [6.5.8](https://github.com/parse-community/parse-server/compare/6.5.7...6.5.8) (2024-09-12)

### Bug Fixes

* Various vulnerabilities related to cross-site scripting ([#9310](https://github.com/parse-community/parse-server/issues/9310)) ([d5290d4](https://github.com/parse-community/parse-server/commit/d5290d46e5ff9237970ae1ac2d2df4051cbf53e5))
2024-09-12 12:56:07 +00:00
Parse Platform d5290d46e5 fix: Various vulnerabilities related to cross-site scripting (#9310) 2024-09-12 14:42:50 +02:00
semantic-release-bot 52729fd15c chore(release): 6.5.7 [skip ci]
## [6.5.7](https://github.com/parse-community/parse-server/compare/6.5.6...6.5.7) (2024-06-30)

### Bug Fixes

* SQL injection when using Parse Server with PostgreSQL; fixes security vulnerability [GHSA-c2hr-cqg6-8j6r](https://github.com/parse-community/parse-server/security/advisories/GHSA-c2hr-cqg6-8j6r) ([#9168](https://github.com/parse-community/parse-server/issues/9168)) ([f332d54](https://github.com/parse-community/parse-server/commit/f332d54577608c5ad927255e06d8c694e2e0ff5b))
2024-06-30 01:51:47 +00:00
Manuel f332d54577 fix: SQL injection when using Parse Server with PostgreSQL; fixes security vulnerability [GHSA-c2hr-cqg6-8j6r](https://github.com/parse-community/parse-server/security/advisories/GHSA-c2hr-cqg6-8j6r) (#9168) 2024-06-30 03:50:41 +02:00
Parse Platform 3012ff72bb refactor: Security upgrade ws from 8.16.0 to 8.17.1 (#9157) 2024-06-22 21:48:59 +02:00
Manuel 0d5e01c26b test: Disable OAuth 1 tests with Twitter API (#9162) 2024-06-22 15:16:13 +02:00
semantic-release-bot 09ead54626 chore(release): 6.5.6 [skip ci]
## [6.5.6](https://github.com/parse-community/parse-server/compare/6.5.5...6.5.6) (2024-05-16)

### Bug Fixes

* Facebook Limited Login not workind due to incorrect domain in JWT validation ([#9120](https://github.com/parse-community/parse-server/issues/9120)) ([0e92f76](https://github.com/parse-community/parse-server/commit/0e92f765e43d1e39285c5958d60cfd7fb76a3c90))
2024-05-16 07:12:08 +00:00
Chris 0e92f765e4 fix: Facebook Limited Login not workind due to incorrect domain in JWT validation (#9120) 2024-05-16 09:11:02 +02:00
Parse Platform acea93c8a6 refactor: Upgrade graphql-relay from 0.10.0 to 0.10.1 (#9096) 2024-04-19 15:46:43 +02:00
Parse Platform 490898e11d refactor: Upgrade @babel/eslint-parser from 7.23.3 to 7.24.1 (#9091) 2024-04-18 00:24:11 +02:00
Parse Platform 63db281976 refactor: Upgrade winston from 3.11.0 to 3.12.0 (#9054) 2024-03-26 06:32:51 +01:00
Parse Platform 72ba762390 refactor: Upgrade express from 4.18.2 to 4.18.3 (#9042) 2024-03-22 17:15:36 +01:00
Parse Platform eba0da47ba refactor: Upgrade @babel/eslint-parser from 7.21.8 to 7.23.3 (#8868) 2024-03-21 16:09:16 +01:00
Manuel dc53521243 ci: Fix auto-release (#9035) 2024-03-19 22:21:07 +01:00
semantic-release-bot 9dc0235b5d chore(release): 6.5.5 [skip ci]
## [6.5.5](https://github.com/parse-community/parse-server/compare/6.5.4...6.5.5) (2024-03-19)

### Bug Fixes

* Server crashes on invalid Cloud Function or Cloud Job name; fixes security vulnerability [GHSA-6hh7-46r2-vf29](https://github.com/parse-community/parse-server/security/advisories/GHSA-6hh7-46r2-vf29) ([#9023](https://github.com/parse-community/parse-server/issues/9023)) ([5ae6d6a](https://github.com/parse-community/parse-server/commit/5ae6d6a36d75c4511029f0ba5673ae4b2999179b))
2024-03-19 16:43:32 +00:00
Manuel 5ae6d6a36d fix: Server crashes on invalid Cloud Function or Cloud Job name; fixes security vulnerability [GHSA-6hh7-46r2-vf29](https://github.com/parse-community/parse-server/security/advisories/GHSA-6hh7-46r2-vf29) (#9023) 2024-03-19 17:42:24 +01:00
semantic-release-bot 3773203a37 chore(release): 6.5.4 [skip ci]
## [6.5.4](https://github.com/parse-community/parse-server/compare/6.5.3...6.5.4) (2024-03-16)

### Bug Fixes

* Server crashes when receiving an array of `Parse.Pointer` in the request body ([#9012](https://github.com/parse-community/parse-server/issues/9012)) ([8ff444d](https://github.com/parse-community/parse-server/commit/8ff444d42ef51bfe6808c4c3a5fe666bfe302ebe))
2024-03-16 16:20:47 +00:00
Jayson Ng 8ff444d42e fix: Server crashes when receiving an array of Parse.Pointer in the request body (#9012) 2024-03-16 17:19:54 +01:00
semantic-release-bot 9cb44c08cc chore(release): 6.5.3 [skip ci]
## [6.5.3](https://github.com/parse-community/parse-server/compare/6.5.2...6.5.3) (2024-03-16)

### Bug Fixes

* Security upgrade follow-redirects from 1.15.5 to 1.15.6 ([#9019](https://github.com/parse-community/parse-server/issues/9019)) ([422958e](https://github.com/parse-community/parse-server/commit/422958e246da6f13011776c8dde028a00fb821cb))
2024-03-16 13:41:15 +00:00
Manuel 09b6a95264 ci: Fix auto-release (#9021) 2024-03-16 14:40:12 +01:00
Parse Platform 422958e246 fix: Security upgrade follow-redirects from 1.15.5 to 1.15.6 (#9019) 2024-03-16 10:10:50 +01:00
Manuel b8535b3db9 ci: Fix LTS releases are published as pre-releases (#8989) 2024-03-05 20:00:09 +01:00
Corey 9282bc595c ci: Fix failing Docker release by removing arm/v6 and arm/v7 support (#8977) 2024-03-05 08:56:40 +01:00
Parse Platform 47184f0734 refactor: Upgrade graphql-list-fields from 2.0.2 to 2.0.4 (#8973) 2024-03-03 00:46:54 +01:00
Parse Platform d53c1f3668 refactor: Upgrade winston-daily-rotate-file from 4.7.1 to 5.0.0 (#8974) 2024-03-03 00:03:05 +01:00
semantic-release-bot d3ec2e2be7 chore(release): 6.5.2 [skip ci]
## [6.5.2](https://github.com/parse-community/parse-server/compare/6.5.1...6.5.2) (2024-03-02)

### Bug Fixes

* Security upgrade @parse/push-adapter from 5.1.0 to 5.1.1 ([#8975](https://github.com/parse-community/parse-server/issues/8975)) ([0fa0aab](https://github.com/parse-community/parse-server/commit/0fa0aabefe6bc9d356ee70be78dafc5fa22d4e17))
2024-03-02 21:48:11 +00:00
Parse Platform 0fa0aabefe fix: Security upgrade @parse/push-adapter from 5.1.0 to 5.1.1 (#8975) 2024-03-02 22:47:16 +01:00
semantic-release-bot 46761d3ae2 chore(release): 6.5.1 [skip ci]
## [6.5.1](https://github.com/parse-community/parse-server/compare/6.5.0...6.5.1) (2024-03-02)

### Bug Fixes

* Security upgrade @parse/push-adapter from 5.0.2 to 5.1.0 ([#8972](https://github.com/parse-community/parse-server/issues/8972)) ([bba24dd](https://github.com/parse-community/parse-server/commit/bba24dd8279ebb8e4084a5f00fbe3ab9fe6c01b4))
2024-03-02 20:43:02 +00:00
Parse Platform bba24dd827 fix: Security upgrade @parse/push-adapter from 5.0.2 to 5.1.0 (#8972) 2024-03-02 21:42:04 +01:00
Manuel 30258be121 docs: Remove incorrect change log entries (#8963) 2024-03-01 17:14:29 +01:00
semantic-release-bot 5f9a27fb8e chore(release): 6.5.0 [skip ci]
# [6.5.0](https://github.com/parse-community/parse-server/compare/6.4.0...6.5.0) (2024-03-01)

### Bug Fixes

* Context not passed to Cloud Code Trigger `beforeFind` when using `Parse.Query.include` ([#8765](https://github.com/parse-community/parse-server/issues/8765)) ([7d32d89](https://github.com/parse-community/parse-server/commit/7d32d8934f3ae7af7a7d8b9cc6a829c7d73973d3))
* Improve PostgreSQL injection detection; fixes security vulnerability [GHSA-6927-3vr9-fxf2](https://github.com/parse-community/parse-server/security/advisories/GHSA-6927-3vr9-fxf2) which affects Parse Server deployments using a Postgres database ([#8960](https://github.com/parse-community/parse-server/issues/8960)) ([a6e6549](https://github.com/parse-community/parse-server/commit/a6e654943536932904a69b51e513507fcf90a504))
* Parse Server option `fileUpload.fileExtensions` fails to determine file extension if filename contains multiple dots ([#8754](https://github.com/parse-community/parse-server/issues/8754)) ([3d6d50e](https://github.com/parse-community/parse-server/commit/3d6d50e0afff18b95fb906914e2cebd3839b517a))
* Security bump @babel/traverse from 7.20.5 to 7.23.2 ([#8777](https://github.com/parse-community/parse-server/issues/8777)) ([2d6b3d1](https://github.com/parse-community/parse-server/commit/2d6b3d18499179e99be116f25c0850d3f449509c))
* Security upgrade graphql from 16.6.0 to 16.8.1 ([#8758](https://github.com/parse-community/parse-server/issues/8758)) ([71dfd8a](https://github.com/parse-community/parse-server/commit/71dfd8a7ece8c0dd1a66d03bb9420cfd39f4f9b1))

### Features

* Add `$setOnInsert` operator to `Parse.Server.database.update` ([#8791](https://github.com/parse-community/parse-server/issues/8791)) ([f630a45](https://github.com/parse-community/parse-server/commit/f630a45aa5e87bc73a81fded061400c199b71a29))
* Add compatibility for MongoDB Atlas Serverless and AWS Amazon DocumentDB with collation options `enableCollationCaseComparison`, `transformEmailToLowercase`, `transformUsernameToLowercase` ([#8805](https://github.com/parse-community/parse-server/issues/8805)) ([09fbeeb](https://github.com/parse-community/parse-server/commit/09fbeebba8870e7cf371fb84371a254c7b368620))
* Add context to Cloud Code Triggers `beforeLogin` and `afterLogin` ([#8724](https://github.com/parse-community/parse-server/issues/8724)) ([a9c34ef](https://github.com/parse-community/parse-server/commit/a9c34ef1e2c78a42fb8b5fa8d569b7677c74919d))
* Allow setting `createdAt` and `updatedAt` during `Parse.Object` creation with maintenance key ([#8696](https://github.com/parse-community/parse-server/issues/8696)) ([77bbfb3](https://github.com/parse-community/parse-server/commit/77bbfb3f186f5651c33ba152f04cff95128eaf2d))
* Upgrade Parse Server Push Adapter to 5.0.2 ([#8813](https://github.com/parse-community/parse-server/issues/8813)) ([6ef1986](https://github.com/parse-community/parse-server/commit/6ef1986c03a1d84b7e11c05851e5bf9688d88740))

### Performance Improvements

* Improved IP validation performance for `masterKeyIPs`, `maintenanceKeyIPs` ([#8510](https://github.com/parse-community/parse-server/issues/8510)) ([b87daba](https://github.com/parse-community/parse-server/commit/b87daba0671a1b0b7b8d63bc671d665c91a04522))
2024-03-01 16:04:36 +00:00
Manuel 297faaece4 ci: Fix incorrect release branch config (#8962) 2024-03-01 17:03:43 +01:00
Manuel a6e6549435 fix: Improve PostgreSQL injection detection; fixes security vulnerability [GHSA-6927-3vr9-fxf2](https://github.com/parse-community/parse-server/security/advisories/GHSA-6927-3vr9-fxf2) which affects Parse Server deployments using a Postgres database (#8960) 2024-03-01 16:51:02 +01:00
Parse Platform 244e3431cf refactor: Upgrade redis from 4.6.12 to 4.6.13 (#8955) 2024-02-27 14:42:47 +01:00
Parse Platform 33c648dc81 refactor: Upgrade uuid from 9.0.0 to 9.0.1 (#8943) 2024-02-26 01:22:37 +01:00
Parse Platform 4524c35d51 refactor: Upgrade follow-redirects from 1.15.2 to 1.15.5 (#8931) 2024-02-24 17:30:05 +01:00
Parse Platform 70e0cb3744 refactor: Upgrade jwks-rsa from 2.1.5 to 3.1.0 (#8932) 2024-02-24 12:22:00 +01:00
Parse Platform 519dee9b89 refactor: Upgrade winston from 3.8.2 to 3.11.0 (#8933) 2024-02-23 18:18:24 +01:00
Parse Platform 897acb76a5 refactor: Upgrade semver from 7.5.2 to 7.5.4 (#8934) 2024-02-22 13:05:39 +01:00
Parse Platform e5de9daa18 refactor: Upgrade @parse/fs-files-adapter from 1.2.2 to 2.0.1 (#8930) 2024-02-20 18:17:11 +01:00
Parse Platform 223fde0f31 refactor: Upgrade pg-promise from 11.5.0 to 11.5.4 (#8924) 2024-02-17 00:41:11 +01:00
Parse Platform d0a5af33ca refactor: Upgrade otpauth from 9.1.2 to 9.2.2 (#8923) 2024-02-17 00:10:26 +01:00
Parse Platform 8fe0ae7a2c refactor: Upgrade ws from 8.13.0 to 8.16.0 (#8921) 2024-02-15 23:54:05 +01:00
Parse Platform 5179501885 refactor: Upgrade redis from 4.6.6 to 4.6.12 (#8922) 2024-02-15 19:35:22 +01:00
Parse Platform 933e8226df refactor: Upgrade lru-cache from 9.1.1 to 10.1.0 (#8870) 2024-01-08 12:15:33 +01:00
19 changed files with 3018 additions and 816 deletions
+4 -4
View File
@@ -123,14 +123,14 @@ jobs:
uses: actions/checkout@v2
- name: Set up QEMU
id: qemu
uses: docker/setup-qemu-action@v1
uses: docker/setup-qemu-action@v2
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v1
uses: docker/setup-buildx-action@v2
- name: Build docker image
uses: docker/build-push-action@v2
uses: docker/build-push-action@v3
with:
context: .
platforms: linux/amd64
platforms: linux/amd64, linux/arm64/v8
check-lock-file-version:
name: NPM Lock File Version
timeout-minutes: 5
+7 -7
View File
@@ -56,18 +56,18 @@ jobs:
ref: ${{ needs.release.outputs.current_tag }}
- name: Set up QEMU
id: qemu
uses: docker/setup-qemu-action@v1
uses: docker/setup-qemu-action@v2
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v1
uses: docker/setup-buildx-action@v2
- name: Log into Docker Hub
if: github.event_name != 'pull_request'
uses: docker/login-action@v1
uses: docker/login-action@v2
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Extract Docker metadata
id: meta
uses: docker/metadata-action@v3
uses: docker/metadata-action@v4
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
flavor: |
@@ -75,10 +75,10 @@ jobs:
tags: |
type=semver,pattern={{version}},value=${{ needs.release.outputs.current_tag }}
- name: Build and push Docker image
uses: docker/build-push-action@v2
uses: docker/build-push-action@v3
with:
context: .
platforms: linux/amd64, linux/arm/v6, linux/arm/v7, linux/arm64/v8
platforms: linux/amd64, linux/arm64/v8
push: ${{ github.event_name != 'pull_request' }}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
@@ -112,4 +112,4 @@ jobs:
uses: peaceiris/actions-gh-pages@v3.7.3
with:
github_token: ${{ secrets.GITHUB_TOKEN }}
publish_dir: ./docs
publish_dir: ./docs
+6 -6
View File
@@ -28,18 +28,18 @@ jobs:
ref: ${{ github.event.inputs.ref }}
- name: Set up QEMU
id: qemu
uses: docker/setup-qemu-action@v1
uses: docker/setup-qemu-action@v2
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v1
uses: docker/setup-buildx-action@v2
- name: Log into Docker Hub
if: github.event_name != 'pull_request'
uses: docker/login-action@v1
uses: docker/login-action@v2
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Extract Docker metadata
id: meta
uses: docker/metadata-action@v3
uses: docker/metadata-action@v4
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
flavor: |
@@ -48,10 +48,10 @@ jobs:
type=semver,enable=true,pattern={{version}},value=${{ github.event.inputs.ref }}
type=raw,enable=${{ github.event.inputs.ref == '' }},value=latest
- name: Build and push Docker image
uses: docker/build-push-action@v2
uses: docker/build-push-action@v3
with:
context: .
platforms: linux/amd64, linux/arm/v6, linux/arm/v7, linux/arm64/v8
platforms: linux/amd64, linux/arm64/v8
push: ${{ github.event_name != 'pull_request' }}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
+2 -2
View File
@@ -1,7 +1,7 @@
############################################################
# Build stage
############################################################
FROM node:lts-alpine AS build
FROM node:18-alpine AS build
RUN apk --no-cache add git
WORKDIR /tmp
@@ -24,7 +24,7 @@ RUN npm ci --omit=dev --ignore-scripts \
############################################################
# Release stage
############################################################
FROM node:lts-alpine AS release
FROM node:18-alpine AS release
VOLUME /parse-server/cloud /parse-server/config
+70
View File
@@ -1,3 +1,73 @@
## [6.5.9](https://github.com/parse-community/parse-server/compare/6.5.8...6.5.9) (2024-10-03)
### Bug Fixes
* Custom object ID allows to acquire role privileges ([GHSA-8xq9-g7ch-35hg](https://github.com/parse-community/parse-server/security/advisories/GHSA-8xq9-g7ch-35hg)) ([#9318](https://github.com/parse-community/parse-server/issues/9318)) ([1bfbccf](https://github.com/parse-community/parse-server/commit/1bfbccf9ee7ea77533b2b2aa7c4c69f3bd35e66f))
## [6.5.8](https://github.com/parse-community/parse-server/compare/6.5.7...6.5.8) (2024-09-12)
### Bug Fixes
* Various vulnerabilities related to cross-site scripting ([#9310](https://github.com/parse-community/parse-server/issues/9310)) ([d5290d4](https://github.com/parse-community/parse-server/commit/d5290d46e5ff9237970ae1ac2d2df4051cbf53e5))
## [6.5.7](https://github.com/parse-community/parse-server/compare/6.5.6...6.5.7) (2024-06-30)
### Bug Fixes
* SQL injection when using Parse Server with PostgreSQL; fixes security vulnerability [GHSA-c2hr-cqg6-8j6r](https://github.com/parse-community/parse-server/security/advisories/GHSA-c2hr-cqg6-8j6r) ([#9168](https://github.com/parse-community/parse-server/issues/9168)) ([f332d54](https://github.com/parse-community/parse-server/commit/f332d54577608c5ad927255e06d8c694e2e0ff5b))
## [6.5.6](https://github.com/parse-community/parse-server/compare/6.5.5...6.5.6) (2024-05-16)
### Bug Fixes
* Facebook Limited Login not workind due to incorrect domain in JWT validation ([#9120](https://github.com/parse-community/parse-server/issues/9120)) ([0e92f76](https://github.com/parse-community/parse-server/commit/0e92f765e43d1e39285c5958d60cfd7fb76a3c90))
## [6.5.5](https://github.com/parse-community/parse-server/compare/6.5.4...6.5.5) (2024-03-19)
### Bug Fixes
* Server crashes on invalid Cloud Function or Cloud Job name; fixes security vulnerability [GHSA-6hh7-46r2-vf29](https://github.com/parse-community/parse-server/security/advisories/GHSA-6hh7-46r2-vf29) ([#9023](https://github.com/parse-community/parse-server/issues/9023)) ([5ae6d6a](https://github.com/parse-community/parse-server/commit/5ae6d6a36d75c4511029f0ba5673ae4b2999179b))
## [6.5.4](https://github.com/parse-community/parse-server/compare/6.5.3...6.5.4) (2024-03-16)
### Bug Fixes
* Server crashes when receiving an array of `Parse.Pointer` in the request body ([#9012](https://github.com/parse-community/parse-server/issues/9012)) ([8ff444d](https://github.com/parse-community/parse-server/commit/8ff444d42ef51bfe6808c4c3a5fe666bfe302ebe))
## [6.5.3](https://github.com/parse-community/parse-server/compare/6.5.2...6.5.3) (2024-03-16)
### Bug Fixes
* Security upgrade follow-redirects from 1.15.5 to 1.15.6 ([#9019](https://github.com/parse-community/parse-server/issues/9019)) ([422958e](https://github.com/parse-community/parse-server/commit/422958e246da6f13011776c8dde028a00fb821cb))
## [6.5.2](https://github.com/parse-community/parse-server/compare/6.5.1...6.5.2) (2024-03-02)
### Bug Fixes
* Security upgrade @parse/push-adapter from 5.1.0 to 5.1.1 ([#8975](https://github.com/parse-community/parse-server/issues/8975)) ([0fa0aab](https://github.com/parse-community/parse-server/commit/0fa0aabefe6bc9d356ee70be78dafc5fa22d4e17))
## [6.5.1](https://github.com/parse-community/parse-server/compare/6.5.0...6.5.1) (2024-03-02)
### Bug Fixes
* Security upgrade @parse/push-adapter from 5.0.2 to 5.1.0 ([#8972](https://github.com/parse-community/parse-server/issues/8972)) ([bba24dd](https://github.com/parse-community/parse-server/commit/bba24dd8279ebb8e4084a5f00fbe3ab9fe6c01b4))
# [6.5.0](https://github.com/parse-community/parse-server/compare/6.4.0...6.5.0) (2024-03-01)
### Bug Fixes
* Improve PostgreSQL injection detection; fixes security vulnerability [GHSA-6927-3vr9-fxf2](https://github.com/parse-community/parse-server/security/advisories/GHSA-6927-3vr9-fxf2) which affects Parse Server deployments using a Postgres database ([#8960](https://github.com/parse-community/parse-server/issues/8960)) ([a6e6549](https://github.com/parse-community/parse-server/commit/a6e654943536932904a69b51e513507fcf90a504))
# [6.4.0](https://github.com/parse-community/parse-server/compare/6.3.1...6.4.0) (2023-11-16)
+2739 -740
View File
File diff suppressed because it is too large Load Diff
+21 -20
View File
@@ -1,6 +1,6 @@
{
"name": "parse-server",
"version": "6.5.0-alpha.2",
"version": "6.5.9",
"description": "An express module providing a Parse-compatible API server",
"main": "lib/index.js",
"repository": {
@@ -19,49 +19,49 @@
],
"license": "Apache-2.0",
"dependencies": {
"@babel/eslint-parser": "7.21.8",
"@babel/eslint-parser": "7.24.1",
"@graphql-tools/merge": "8.4.1",
"@graphql-tools/schema": "9.0.4",
"@graphql-tools/utils": "8.12.0",
"@graphql-yoga/node": "2.6.0",
"@parse/fs-files-adapter": "1.2.2",
"@parse/push-adapter": "5.0.2",
"@parse/fs-files-adapter": "2.0.1",
"@parse/push-adapter": "5.1.1",
"bcryptjs": "2.4.3",
"body-parser": "1.20.2",
"body-parser": "1.20.3",
"commander": "10.0.1",
"cors": "2.8.5",
"deepcopy": "2.1.0",
"express": "4.18.2",
"express": "4.21.0",
"express-rate-limit": "6.7.0",
"follow-redirects": "1.15.2",
"follow-redirects": "1.15.6",
"graphql": "16.8.1",
"graphql-list-fields": "2.0.2",
"graphql-relay": "0.10.0",
"graphql-list-fields": "2.0.4",
"graphql-relay": "0.10.1",
"graphql-tag": "2.12.6",
"intersect": "1.0.1",
"jsonwebtoken": "9.0.0",
"jwks-rsa": "2.1.5",
"jwks-rsa": "3.1.0",
"ldapjs": "2.3.3",
"lodash": "4.17.21",
"lru-cache": "9.1.1",
"lru-cache": "10.1.0",
"mime": "3.0.0",
"mongodb": "4.10.0",
"mustache": "4.2.0",
"otpauth": "9.1.2",
"parse": "4.1.0",
"otpauth": "9.2.2",
"parse": "4.2.0",
"path-to-regexp": "6.2.1",
"pg-monitor": "2.0.0",
"pg-promise": "11.5.0",
"pg-promise": "11.5.4",
"pluralize": "8.0.0",
"rate-limit-redis": "3.0.2",
"redis": "4.6.6",
"semver": "7.5.2",
"redis": "4.6.13",
"semver": "7.5.4",
"subscriptions-transport-ws": "0.11.0",
"tv4": "1.3.0",
"uuid": "9.0.0",
"winston": "3.8.2",
"winston-daily-rotate-file": "4.7.1",
"ws": "8.13.0"
"uuid": "9.0.1",
"winston": "3.12.0",
"winston-daily-rotate-file": "5.0.0",
"ws": "8.17.1"
},
"devDependencies": {
"@actions/core": "1.9.1",
@@ -124,6 +124,7 @@
"test:mongodb:4.4.13": "npm run test:mongodb --dbversion=4.4.13",
"test:mongodb:5.3.2": "npm run test:mongodb --dbversion=5.3.2",
"test:mongodb:6.0.2": "npm run test:mongodb --dbversion=6.0.2",
"test:postgres:testonly": "cross-env PARSE_SERVER_TEST_DB=postgres PARSE_SERVER_TEST_DATABASE_URI=postgres://postgres:password@localhost:5432/parse_server_postgres_adapter_test_database npm run testonly",
"posttest:mongodb": "mongodb-runner stop",
"pretest": "cross-env MONGODB_VERSION=${MONGODB_VERSION:=5.3.2} MONGODB_TOPOLOGY=${MONGODB_TOPOLOGY:=standalone} mongodb-runner start",
"testonly": "cross-env MONGODB_VERSION=${MONGODB_VERSION:=5.3.2} MONGODB_TOPOLOGY=${MONGODB_TOPOLOGY:=standalone} TESTING=1 jasmine",
+4 -15
View File
@@ -24,11 +24,11 @@ const templates = {
async function config() {
// Get branch
const branch = ref.split('/').pop().split('-')[0];
const branch = ref.split('/').pop();
console.log(`Running on branch: ${branch}`);
// Set changelog file
const changelogFile = `./changelogs/CHANGELOG_${branch}.md`;
const changelogFile = `./changelogs/CHANGELOG_release.md`;
console.log(`Changelog file output to: ${changelogFile}`);
// Load template file contents
@@ -39,9 +39,8 @@ async function config() {
'release',
{ name: 'alpha', prerelease: true },
{ name: 'beta', prerelease: true },
'next-major',
// Long-Term-Support branches; defined as GLOB pattern
'release-+([0-9]).x.x',
// Long-Term-Support branches
{ name: 'release-6.x.x', range: '6.x.x', channel: '6.x.x' },
],
dryRun: false,
debug: true,
@@ -85,16 +84,6 @@ async function config() {
labels: ['type:ci'],
releasedLabels: ['state:released<%= nextRelease.channel ? `-\${nextRelease.channel}` : "" %>']
}],
// Back-merge module runs last because if it fails it should not impede the release process
[
"@saithodev/semantic-release-backmerge",
{
"branches": [
{ from: "beta", to: "alpha" },
{ from: "release", to: "beta" },
]
}
],
],
};
+8 -8
View File
@@ -2081,7 +2081,7 @@ describe('facebook limited auth adapter', () => {
it('should use algorithm from key header to verify id_token', async () => {
const fakeClaim = {
iss: 'https://facebook.com',
iss: 'https://www.facebook.com',
aud: 'secret',
exp: Date.now(),
sub: 'the_user_id',
@@ -2145,7 +2145,7 @@ describe('facebook limited auth adapter', () => {
it('(using client id as string) should verify id_token', async () => {
const fakeClaim = {
iss: 'https://facebook.com',
iss: 'https://www.facebook.com',
aud: 'secret',
exp: Date.now(),
sub: 'the_user_id',
@@ -2172,7 +2172,7 @@ describe('facebook limited auth adapter', () => {
it('(using client id as array) should verify id_token', async () => {
const fakeClaim = {
iss: 'https://facebook.com',
iss: 'https://www.facebook.com',
aud: 'secret',
exp: Date.now(),
sub: 'the_user_id',
@@ -2199,7 +2199,7 @@ describe('facebook limited auth adapter', () => {
it('(using client id as array with multiple items) should verify id_token', async () => {
const fakeClaim = {
iss: 'https://facebook.com',
iss: 'https://www.facebook.com',
aud: 'secret',
exp: Date.now(),
sub: 'the_user_id',
@@ -2250,7 +2250,7 @@ describe('facebook limited auth adapter', () => {
fail();
} catch (e) {
expect(e.message).toBe(
'id token not issued by correct OpenID provider - expected: https://facebook.com | from: https://not.facebook.com'
'id token not issued by correct OpenID provider - expected: https://www.facebook.com | from: https://not.facebook.com'
);
}
});
@@ -2286,7 +2286,7 @@ describe('facebook limited auth adapter', () => {
fail();
} catch (e) {
expect(e.message).toBe(
'id token not issued by correct OpenID provider - expected: https://facebook.com | from: https://not.facebook.com'
'id token not issued by correct OpenID provider - expected: https://www.facebook.com | from: https://not.facebook.com'
);
}
});
@@ -2320,7 +2320,7 @@ describe('facebook limited auth adapter', () => {
fail();
} catch (e) {
expect(e.message).toBe(
'id token not issued by correct OpenID provider - expected: https://facebook.com | from: https://not.facebook.com'
'id token not issued by correct OpenID provider - expected: https://www.facebook.com | from: https://not.facebook.com'
);
}
});
@@ -2378,7 +2378,7 @@ describe('facebook limited auth adapter', () => {
it('should throw error with with invalid user id', async () => {
const fakeClaim = {
iss: 'https://facebook.com',
iss: 'https://www.facebook.com',
aud: 'invalid_client_id',
sub: 'a_different_user_id',
};
+2 -2
View File
@@ -87,7 +87,7 @@ describe('OAuth', function () {
done();
}
it('GET request for a resource that requires OAuth should fail with invalid credentials', done => {
xit('GET request for a resource that requires OAuth should fail with invalid credentials', done => {
/*
This endpoint has been chosen to make a request to an endpoint that requires OAuth which fails due to missing authentication.
Any other endpoint from the Twitter API that requires OAuth can be used instead in case the currently used endpoint deprecates.
@@ -105,7 +105,7 @@ describe('OAuth', function () {
});
});
it('POST request for a resource that requires OAuth should fail with invalid credentials', done => {
xit('POST request for a resource that requires OAuth should fail with invalid credentials', done => {
/*
This endpoint has been chosen to make a request to an endpoint that requires OAuth which fails due to missing authentication.
Any other endpoint from the Twitter API that requires OAuth can be used instead in case the currently used endpoint deprecates.
+18
View File
@@ -1267,6 +1267,24 @@ describe('miscellaneous', function () {
});
});
it('test cloud function query parameters with array of pointers', async () => {
Parse.Cloud.define('echoParams', req => {
return req.params;
});
const headers = {
'Content-Type': 'application/json',
'X-Parse-Application-Id': 'test',
'X-Parse-Javascript-Key': 'test',
};
const response = await request({
method: 'POST',
headers: headers,
url: 'http://localhost:8378/1/functions/echoParams',
body: '{"arr": [{ "__type": "Pointer", "className": "PointerTest" }]}',
});
const res = response.data.result;
expect(res.arr.length).toEqual(1);
});
it('can handle null params in cloud functions (regression test for #1742)', done => {
Parse.Cloud.define('func', request => {
expect(request.params.nullParam).toEqual(null);
+33
View File
@@ -694,3 +694,36 @@ describe('triggers', () => {
expect(req.context).toBeUndefined();
});
});
describe('sanitizing names', () => {
const invalidNames = [
`test'%3bdeclare%20@q%20varchar(99)%3bset%20@q%3d'%5c%5cxxxxxxxxxxxxxxx.yyyyy'%2b'fy.com%5cxus'%3b%20exec%20master.dbo.xp_dirtree%20@q%3b--%20`,
`test.function.name`,
];
it('should not crash server and return error on invalid Cloud Function name', async () => {
for (const invalidName of invalidNames) {
let error;
try {
await Parse.Cloud.run(invalidName);
} catch (err) {
error = err;
}
expect(error).toBeDefined();
expect(error.message).toMatch(/Invalid function/);
}
});
it('should not crash server and return error on invalid Cloud Job name', async () => {
for (const invalidName of invalidNames) {
let error;
try {
await Parse.Cloud.startJob(invalidName);
} catch (err) {
error = err;
}
expect(error).toBeDefined();
expect(error.message).toMatch(/Invalid job/);
}
});
});
+70
View File
@@ -1,6 +1,51 @@
const request = require('../lib/request');
describe('Vulnerabilities', () => {
describe('(GHSA-8xq9-g7ch-35hg) Custom object ID allows to acquire role privilege', () => {
beforeAll(async () => {
await reconfigureServer({ allowCustomObjectId: true });
Parse.allowCustomObjectId = true;
});
afterAll(async () => {
await reconfigureServer({ allowCustomObjectId: false });
Parse.allowCustomObjectId = false;
});
it('denies user creation with poisoned object ID', async () => {
await expectAsync(
new Parse.User({ id: 'role:a', username: 'a', password: '123' }).save()
).toBeRejectedWith(new Parse.Error(Parse.Error.OPERATION_FORBIDDEN, 'Invalid object ID.'));
});
describe('existing sessions for users with poisoned object ID', () => {
/** @type {Parse.User} */
let poisonedUser;
/** @type {Parse.User} */
let innocentUser;
beforeAll(async () => {
const parseServer = await global.reconfigureServer();
const databaseController = parseServer.config.databaseController;
[poisonedUser, innocentUser] = await Promise.all(
['role:abc', 'abc'].map(async id => {
// Create the users directly on the db to bypass the user creation check
await databaseController.create('_User', { objectId: id });
// Use the master key to create a session for them to bypass the session check
return Parse.User.loginAs(id);
})
);
});
it('refuses session token of user with poisoned object ID', async () => {
await expectAsync(
new Parse.Query(Parse.User).find({ sessionToken: poisonedUser.getSessionToken() })
).toBeRejectedWith(new Parse.Error(Parse.Error.INTERNAL_SERVER_ERROR, 'Invalid object ID.'));
await new Parse.Query(Parse.User).find({ sessionToken: innocentUser.getSessionToken() });
});
});
});
describe('Object prototype pollution', () => {
it('denies object prototype to be polluted with keyword "constructor"', async () => {
const headers = {
@@ -459,3 +504,28 @@ describe('Vulnerabilities', () => {
});
});
});
describe('Postgres regex sanitizater', () => {
it('sanitizes the regex correctly to prevent Injection', async () => {
const user = new Parse.User();
user.set('username', 'username');
user.set('password', 'password');
user.set('email', 'email@example.com');
await user.signUp();
const response = await request({
method: 'GET',
url:
"http://localhost:8378/1/classes/_User?where[username][$regex]=A'B'%3BSELECT+PG_SLEEP(3)%3B--",
headers: {
'Content-Type': 'application/json',
'X-Parse-Application-Id': 'test',
'X-Parse-REST-API-Key': 'rest',
},
});
expect(response.status).toBe(200);
expect(response.data.results).toEqual(jasmine.any(Array));
expect(response.data.results.length).toBe(0);
});
});
+1 -1
View File
@@ -7,7 +7,7 @@ const jwt = require('jsonwebtoken');
const httpsRequest = require('./httpsRequest');
const authUtils = require('./utils');
const TOKEN_ISSUER = 'https://facebook.com';
const TOKEN_ISSUER = 'https://www.facebook.com';
function getAppSecretPath(authData, options = {}) {
const appSecret = options.appSecret;
@@ -2614,16 +2614,16 @@ function isAnyValueRegexStartsWith(values) {
});
}
function createLiteralRegex(remaining) {
function createLiteralRegex(remaining: string) {
return remaining
.split('')
.map(c => {
const regex = RegExp('[0-9 ]|\\p{L}', 'u'); // Support all unicode letter chars
const regex = RegExp('[0-9 ]|\\p{L}', 'u'); // Support all Unicode letter chars
if (c.match(regex) !== null) {
// don't escape alphanumeric characters
// Don't escape alphanumeric characters
return c;
}
// escape everything else (single quotes with single quotes, everything else with a backslash)
// Escape everything else (single quotes with single quotes, everything else with a backslash)
return c === `'` ? `''` : `\\${c}`;
})
.join('');
@@ -2633,14 +2633,14 @@ function literalizeRegexPart(s: string) {
const matcher1 = /\\Q((?!\\E).*)\\E$/;
const result1: any = s.match(matcher1);
if (result1 && result1.length > 1 && result1.index > -1) {
// process regex that has a beginning and an end specified for the literal text
// Process Regex that has a beginning and an end specified for the literal text
const prefix = s.substring(0, result1.index);
const remaining = result1[1];
return literalizeRegexPart(prefix) + createLiteralRegex(remaining);
}
// process regex that has a beginning specified for the literal text
// Process Regex that has a beginning specified for the literal text
const matcher2 = /\\Q((?!\\E).*)$/;
const result2: any = s.match(matcher2);
if (result2 && result2.length > 1 && result2.index > -1) {
@@ -2650,14 +2650,18 @@ function literalizeRegexPart(s: string) {
return literalizeRegexPart(prefix) + createLiteralRegex(remaining);
}
// remove all instances of \Q and \E from the remaining text & escape single quotes
// Remove problematic chars from remaining text
return s
// Remove all instances of \Q and \E
.replace(/([^\\])(\\E)/, '$1')
.replace(/([^\\])(\\Q)/, '$1')
.replace(/^\\E/, '')
.replace(/^\\Q/, '')
.replace(/([^'])'/, `$1''`)
.replace(/^'([^'])/, `''$1`);
// Ensure even number of single quote sequences by adding an extra single quote if needed;
// this ensures that every single quote is escaped
.replace(/'+/g, match => {
return match.length % 2 === 0 ? match : match + "'";
});
}
var GeoPointCoder = {
+5
View File
@@ -173,6 +173,11 @@ const getAuthForSessionToken = async function ({
throw new Parse.Error(Parse.Error.INVALID_SESSION_TOKEN, 'Session token is expired.');
}
const obj = session.user;
if (typeof obj['objectId'] === 'string' && obj['objectId'].startsWith('role:')) {
throw new Parse.Error(Parse.Error.INTERNAL_SERVER_ERROR, 'Invalid object ID.');
}
delete obj.password;
obj['className'] = '_User';
obj['sessionToken'] = sessionToken;
+7
View File
@@ -106,6 +106,13 @@ export class ClassesRouter extends PromiseRouter {
}
handleCreate(req) {
if (
this.className(req) === '_User' &&
typeof req.body?.objectId === 'string' &&
req.body.objectId.startsWith('role:')
) {
throw new Parse.Error(Parse.Error.OPERATION_FORBIDDEN, 'Invalid object ID.');
}
return rest.create(
req.config,
req.auth,
+1 -1
View File
@@ -12,7 +12,7 @@ import { logger } from '../logger';
function parseObject(obj, config) {
if (Array.isArray(obj)) {
return obj.map(item => {
return parseObject(item);
return parseObject(item, config);
});
} else if (obj && obj.__type == 'Date') {
return Object.assign(new Date(obj.iso), obj);
+7 -1
View File
@@ -86,6 +86,12 @@ const Category = {
};
function getStore(category, name, applicationId) {
const invalidNameRegex = /['"`]/;
if (invalidNameRegex.test(name)) {
// Prevent a malicious user from injecting properties into the store
return {};
}
const path = name.split('.');
path.splice(-1); // remove last component
applicationId = applicationId || Parse.applicationId;
@@ -94,7 +100,7 @@ function getStore(category, name, applicationId) {
for (const component of path) {
store = store[component];
if (!store) {
return undefined;
return {};
}
}
return store;