Commit Graph

336 Commits

Author SHA1 Message Date
James Read 5fca2d9482
Merge branch 'next' into feat/better-prometheus-metrics 2026-06-28 23:17:28 +01:00
jamesread 57f3ef46ad fix: several merge messes 2026-06-28 22:52:16 +01:00
jamesread e63094e8e8 fix: several merge messes 2026-06-28 22:15:46 +01:00
jamesread 4b2e78926c Merge branch 'next' of github.com:OliveTin/OliveTin into next 2026-06-27 07:50:29 +01:00
jamesread 42003da384 fix: rerun args 2026-06-26 23:25:24 +01:00
jamesread abf4fc2cf0 feat: Windows icons and MSI support 2026-06-26 21:19:19 +01:00
jamesread d1787a3823 feat: Better prometheus support 2026-06-25 23:05:47 +01:00
James Read e61c8b036d
Substitute environment variables when loading yaml config to fix #840 (#880) 2026-06-20 01:45:29 +01:00
James Read d23fb2fd77
Merge branch 'next' into wip 2026-06-20 01:27:37 +01:00
jamesread 03d188337e fix: Parse templates in action (#1035) 2026-06-20 00:26:13 +01:00
jamesread c442efe204 chore: register executor listener before startup 2026-06-19 10:37:33 +01:00
jamesread 7bd6e77ae2 chore: fix race conditions and little bugs 2026-06-19 09:56:41 +01:00
jamesread 633d9ecd82 feat: action group sizing 2026-06-18 23:33:27 +01:00
jamesread 03a9a05e38 fix: action group display fixes 2026-06-18 11:55:14 +01:00
jamesread de63793b3a feat: circle indicator for running actions, justification support 2026-06-17 23:29:30 +01:00
jamesread f4b3c4289a chore: Fix many little niggly bugs, test flakes, etc 2026-06-17 22:18:26 +01:00
jamesread d9c8cfb573 feat: Logs filtering, and log queue with group concurrency 2026-06-16 14:30:39 +01:00
jamesread 6aa672e6c0 feat: Logs filtering, and log queue with group concurrency 2026-06-16 14:16:43 +01:00
jamesread 37cde0d982 fix: custom CSS and custom JS (#804 and #803) hopefully 2026-06-16 11:56:14 +01:00
James Read f6fc775ef7
feat: Action grouping for concurrency limit and queuing (#1048) 2026-06-16 11:42:31 +01:00
jamesread 9d64b64bf9 fix: configurable log directory for windows
9;133u

0;133u
2026-06-16 11:24:19 +01:00
jamesread 8622b5b06c chore: coderabbit suggestions 2026-06-16 11:17:15 +01:00
jamesread 0e8f7c7be3 chore: coderabbit suggestions 2026-06-16 11:02:37 +01:00
jamesread 3471e2fb12 chore: coderabbit suggestions 2026-06-16 09:51:55 +01:00
jamesread 92f564ab45 feat: Action grouping for concurrency limit and queuing 2026-06-16 01:34:41 +01:00
jamesread 21716e0a7e feat: log file save path on windows #932 2026-06-16 00:33:49 +01:00
jamesread 8f6d53a029 chore: tweak reconnect login to avoid reconnect spam 2026-06-15 00:50:04 +01:00
jamesread 65ed5c1ff4 feat: more intelligent reconnect method 2026-06-15 00:10:07 +01:00
jamesread 9ac6acefd0 fix: emoji names regression, and webhook execution helper info 2026-06-01 00:29:48 +01:00
jamesread ebffd9f040 security: GHSA-prj9-97mp-mwh2 (HIGH) Treat all ot_ system arguments as reserved, preventing RCE
Ensure OliveTin-owned arguments are injected only after filtering and validate system values before command execution.
2026-05-31 22:44:40 +01:00
jamesread 1a7e44eb42 chore: dep update May 26th 2026 2026-05-26 00:44:15 +01:00
James Read e0eea9bc90
feat default icon cli hugeicon (#1036) 2026-05-26 00:37:58 +01:00
James Read ae928625a6
Merge branch 'next' into feat-default-icon-cli-hugeicon 2026-05-25 21:34:54 +01:00
jamesread 82f749a9ce feat: Default icon is now a CLI HugeIcon instead of a smiley face 2026-05-25 20:47:39 +01:00
jamesread b1c74c9e04 fmt: Cleanup coderabbit issues from action details change 2026-05-23 11:38:10 +01:00
jamesread cbed6d68c2 feat: Show exec conditions in the UI, and allow right clicking buttons for action details 2026-05-23 10:32:50 +01:00
James Read 437255e247
Merge commit from fork
security: GHSA-f637-w7p2-m7fx (LOW) Validation endpoints allow argument enumeration
2026-05-22 00:10:49 +01:00
jamesread a3865704c8 security: GHSA-f637-w7p2-m7fx (LOW) Validation endpoints allow argument enumeration 2026-05-22 00:08:47 +01:00
James Read 9ea01bbd0b
Merge commit from fork
security: GHSA-7fq5-7wr8-rjwj (HIGH) Shared template instances could …
2026-05-21 23:57:01 +01:00
jamesread d74da93140 security: GHSA-7fq5-7wr8-rjwj (HIGH) Shared template instances could cause command contamination 2026-05-21 23:51:17 +01:00
jamesread 6bd8c1e838 chore: allow case insensitive bearer 2026-05-21 23:12:49 +01:00
jamesread 246e33d565 feat: API Key (bearer) auth 2026-05-21 22:59:12 +01:00
jamesread fe68264c2b feat: popupOnStart history, and logs in reverse order on action details view 2026-05-19 23:19:42 +01:00
jamesread be1db222bb chore: dep update May 19 2026 2026-05-19 22:16:18 +01:00
jamesread 95a14c5aa5 chore: dep update 20260511 2026-05-11 09:08:45 +01:00
jamesread 196c5ccfc0 chore: dep update 20260510 2026-05-10 09:37:39 +01:00
jamesread 841ef770f3 chore: Dep update March 24th 2026-03-24 22:52:17 +00:00
jamesread cb3aa3362e chore: fix potential panic in tests 2026-03-11 00:29:56 +00:00
jamesread 606b705bdd chore: fix potential panic in tests 2026-03-11 00:27:42 +00:00
jamesread acd6cb839e security: GHSA-228v-wc5r-j8m7 (HIGH) Unauthorized Action Output Disclosure via EventStream 2026-03-10 23:47:35 +00:00
jamesread 86c35f40c3 chore: remove unneeded comment 2026-03-10 23:28:17 +00:00
jamesread bc5e9fbe1e security: GHSA-xx6g-43w2-9g6g (MODERATE) Email argument makes compliance harder, enables log injection 2026-03-10 23:27:09 +00:00
jamesread b33aded230 chore: Use a constant for the default CSP 2026-03-09 10:00:47 +00:00
jamesread b298a6bd8c chore: Treat root fieldset separately for ordering 2026-03-09 09:31:40 +00:00
jamesread dcb5bd0c82 chore: Allow entity key ordering for actionless components 2026-03-09 09:18:24 +00:00
jamesread 93a9636a82 chore: additional test coverage for view permission 2026-03-09 08:55:47 +00:00
jamesread 2f77000de4 security: GHSA-364q-w7vh-vhpc (HIGH) Unsafe parsing of UniqueTrackingId can be used to write files 2026-03-08 23:29:00 +00:00
jamesread 71bb999950 security: Actions that people didnt have permission to view were being returned (#921) 2026-03-08 22:45:46 +00:00
jamesread 5ff6b5d080 fix: Entity ordering (#886, #762) 2026-03-08 22:16:24 +00:00
jamesread 3f46007281 fix: Relax default CSP to allow iconify to work 2026-03-08 20:46:52 +00:00
jamesread b032ae5e5e chore: fix regression on arguments not being found 2026-03-05 08:29:30 +00:00
James Read 93d983c506
Merge branch 'next' into advisory-fix-1 2026-03-05 03:24:12 -05:00
jamesread d7962710e7 security: GHSA-jf73-858c-54pg (MODERATE) View permission not being checked when returning dashboards 2026-03-05 08:20:02 +00:00
jamesread 9080577f2b chore: potential crash in unit tests 2026-03-05 08:10:56 +00:00
James Read 5e0c052e68
Merge branch 'next' into advisory-fix-1 2026-03-04 19:16:07 -05:00
James Read 6202736d53
Merge commit from fork
security: GHSA-p443-p7w5-2f7f (MODERATE) RestartAction always runs actions as guest
2026-03-04 19:05:48 -05:00
jamesread cb46a597b2 security: GHSA-p443-p7w5-2f7f (MODERATE) RestartAction always runs actions as guest 2026-03-05 00:04:58 +00:00
James Read 32c7fd73b8
Merge commit from fork
security: GHSA-gq2m-77hf-vwgh (MODERATE) Session Fixation: Logout Fails to Invalidate Server-Side Session
2026-03-04 18:36:22 -05:00
jamesread d6a0abc375 security: GHSA-gq2m-77hf-vwgh (MODERATE) Session Fixation: Logout Fails to Invalidate Server-Side Session 2026-03-04 23:31:15 +00:00
jamesread e97d8ecbd8 security: GHSA-g962-2j28-3cg9 (HIGH) JWT Audience Validation Bypass in Local Key and HMAC Modes 2026-03-04 23:13:39 +00:00
jamesread 00cb5a2abf fix: action triggers were broken #914 2026-03-04 23:12:20 +00:00
jamesread 0c47564652 chore: logs are written with 0600 instead of 0644 2026-03-04 23:12:20 +00:00
jamesread bb14c5da3e security: (MED) GHSA-fwhj-785h-43hh Crash on NPE by calling APIs with invalid bindings or log references 2026-03-04 22:51:58 +00:00
jamesread 0412b9ea1d Merge branch 'next' of github.com:OliveTin/OliveTin into next 2026-03-02 00:35:05 +00:00
jamesread d9804182ea security: GHSA-4fqm-6fmh-82mq Authentication bypass in KillAction - thanks for the responsible disclosure @kule500 and making OliveTin better 2026-03-02 00:29:02 +00:00
James Read 58b0a7b8f6
Security remote crash in oauth2 (#910) 2026-03-01 19:14:36 -05:00
jamesread f044d90d55 security: Remote crash in OAuth2 GHSA-45m3-398w-m2m9 Thanks @kule500 for the responsible disclosure. CVE to follow. 2026-03-01 23:52:25 +00:00
James Read e67fac17d0
Merge branch 'next' into dependabot/go_modules/service/next/github.com/bufbuild/buf-1.66.0 2026-03-01 17:16:45 -05:00
jamesread aa2bd95ccb feat(policy): add policy to show/hide version number
Made-with: Cursor
2026-02-27 21:26:55 +00:00
jamesread 54eb2a6586 fix: User login log message fixed when password matches, but user lookup fails 2026-02-27 00:10:45 +00:00
jamesread 03da2ff2e7 security: Try to set cookies secure, with force override option 2026-02-26 23:43:50 +00:00
jamesread 4744169aa0 chore: code cleanup, remove todos, etc 2026-02-26 23:07:07 +00:00
jamesread e9a3863b1b chore: codestyle 2026-02-26 20:56:51 +00:00
jamesread f3549b035e Remove dead CORS package (L-2)
The CORS helper was unused; its import was commented out in webuiServer.go.
Deleting the package removes the dormant origin-reflection security issue.
2026-02-26 20:46:11 +00:00
jamesread 4af4d516be fix: ShowDiagnostics now behind policy checks 2026-02-26 20:43:14 +00:00
jamesread 24cced0c8c security: IDOR on ExecutionStatus API 2026-02-26 20:23:48 +00:00
James Read 6dfffd1170
security: 10-slot Semaphore around password hash functions to prevent… (#904) 2026-02-26 12:12:06 -05:00
jamesread a7be68b359 security: 10-slot Semaphore around password hash functions to prevent resource exhaustion attacks 2026-02-26 16:49:29 +00:00
jamesread cb71ddf401 fix: Set common security headers by default 2026-02-26 16:14:41 +00:00
dependabot[bot] ff3620bca9
chore(deps): bump github.com/bufbuild/buf in /service
Bumps [github.com/bufbuild/buf](https://github.com/bufbuild/buf) from 1.65.0 to 1.66.0.
- [Release notes](https://github.com/bufbuild/buf/releases)
- [Changelog](https://github.com/bufbuild/buf/blob/main/CHANGELOG.md)
- [Commits](https://github.com/bufbuild/buf/compare/v1.65.0...v1.66.0)

---
updated-dependencies:
- dependency-name: github.com/bufbuild/buf
  dependency-version: 1.66.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-26 07:24:25 +00:00
jamesread 1335302e80 chore: codestyle 2026-02-26 00:48:21 +00:00
James Read bee81b43f2
Merge branch 'next' into fix-883-logs-pagination 2026-02-25 18:51:46 -05:00
jamesread 38d6b57077 chore: codefmt 2026-02-25 23:24:02 +00:00
James Read 26e77a961d
Merge commit from fork
Advisory fix 1
2026-02-22 17:27:07 +00:00
jamesread 4bbd2eab15 security: GHSA-49gm-hh7w-wfvf 2026-02-22 10:19:08 +00:00
jamesread ea4cdf9df2 fix: Logs page pagination (#883) 2026-02-19 20:33:51 +00:00
Andrew Savinykh f58eeef49d
check return value from `unmarshalRoot` in test and fail if false
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-02-15 21:28:23 +13:00
Andrew Savinykh 2fe6d306aa substitute environment variables when loading yaml config 2026-02-15 20:36:03 +13:00
jamesread 544515c2a6 chore: #829, json support in template engine 2026-02-15 00:19:36 +00:00
James Read 321e8f9cb2
Fix: Remove JSON quotes from webhook JSONPath string extraction (#864) 2026-02-13 23:55:37 +00:00