Many hyperlinks are disabled.
Use anonymous login to enable hyperlinks.

50 check-ins occurring around d5def0c8c4bb6f20.

Expanded the discussion of in-repo and out-of-repo resource links in check-in: 23fcd765 user: wyoung tags: trunk
Reworked the new introductory material in to be less about the CSP as last-resort and more about being a secondary filter to our other measures. Gave examples to clarify the tensions that prevent a purely server-side solution from being a practical solution. check-in: 1c4df5bf user: wyoung tags: trunk
"RaspberryPI" -> "Raspberry Pi" check-in: 5182be99 user: wyoung tags: trunk
Assorted refinements to the new pre- and post-activation advice sections in www/server/index.html: nix passive voice, add a few details, add some links to related docs, etc. Also fixed a CSS indenting problem preventing correct use of in , then made use of the new freedom in these sections' numbered lists. check-in: b5c2c9bf user: wyoung tags: trunk
Fix the $ROOT mechanism in HTML documents so that it accepts any whitespace character before href= and script=. Add $ROOT in appropriate places in the server documentation. check-in: 3e183bfa user: drh tags: trunk
Outline how to configure a repository before and after server activation. check-in: 154ea087 user: drh tags: trunk
Improvements to the althttpd documentation. check-in: 44f1df9f user: drh tags: trunk
Further improvements to the server document. check-in: c2c4d303 user: drh tags: trunk
Extra defenses against running fossil_atexit() more than once. check-in: bc7683e1 user: drh tags: trunk
Fix the "shell" command so that it avoids invoking the atexit() handler more than once. check-in: 07a5a211 user: drh tags: trunk
Server documentation updates. check-in: b2426c27 user: drh tags: trunk
Merge in recent developments on trunk. check-in: 70d091ea user: andybradford tags: test-updates
Disallow versioning of security sensitive settings tcl-setup, th1-setup, and th1-uri-regexp. For effective security, these settings should only be controllable by an administrator. check-in: 2da704c5 user: drh tags: trunk
Update to the default CSP page. Attempted to resolve merge conflicts, but more editting is likely necessary. check-in: 33a7b8ba user: drh tags: trunk
Added a header to the new XSS material in so we can refer directly to it. check-in: 7b843f2d user: wyoung tags: trunk
More thorough explanation of <script nonce> in www/, and explained the reason why Fossil has no way of providing that nonce in most content types rather than link to the "XSS via check-in rights" forum post. This new presentation of that post's ideas is more detailed and includes discussion of the feature's interaction with the TH1 docs feature. check-in: 8d43bb87 user: wyoung tags: trunk
Major improvements to the new article. Expanded the introductory material to better describe what the CSP does; added named anchors to headers; moved the discussion of $default_csp overrides into this document from, which now just says how you use that variable read-only; and added an entirely new section, "Replacing the Default CSP". check-in: 366b23a1 user: wyoung tags: trunk
Replaced the redundant copy of the default CSP in skins/bootstrap/header.txt with "$default_csp", allowing the TH1 setup script to override the CSP as in all the other stock skins. (Bootstrap is the last stock skin to define a custom <head> element.) check-in: 14ac2cac user: wyoung tags: trunk
Fix memcpy() compiler warnings. check-in: 7ae4b1a7 user: drh tags: trunk
Fix possible misaligned pointer to a 16-bit object. check-in: f7c41be8 user: drh tags: trunk
Updated and expanded documentation on how to set up a Fossil server. check-in: f146e21a user: drh tags: trunk
Add the --with-sanitizer option to the ./configure script. check-in: 231d6933 user: drh tags: trunk
Fixed a link punctuation bug introduced in [74a6578c]. Closed-Leaf check-in: c57e1793 user: wyoung tags: server-docs
The merge from trunk accidentally reverted part of the new text in www/ (This part was manually merged, and I missed a diff relative to trunk.) check-in: 8976a9da user: wyoung tags: server-docs
Missed a link to that should have been checked in with [74a6578c]. check-in: d5def0c8 user: wyoung tags: server-docs
Merged in trunk improvements check-in: 42d28c02 user: wyoung tags: server-docs
Reverted src/doc.c to the trunk version. The "Plan Z" reversion in [8264fd75] was incomplete, causing bad TH1 variable expansion. I believe this explains the symptom I worked around in [9bdf650f0b8]. This check-in also cherry-picks [3d6a4fd95c] onto the branch. check-in: 3cdf764c user: wyoung tags: server-docs
Updated all of the internal hyperlinks referencing www/ to point at either www/server/index.html or one of the docs it now points at. check-in: 74a6578c user: wyoung tags: server-docs
Fixed an unwanted "$nonce" variable expansion within the new introduced by [9044fd2dbe] which only occurs *sometimes*: not on, and apparently not in my earlier ckout testing prior to checking it in, but now in a different ckout test. This has to be a TH1 thing, but I don't understand why we didn't see this earlier. This is just a workaround for the symptom. check-in: 9bdf650f user: wyoung tags: trunk
Fixed a link from the new material in to the new CSP material: that briefly lived in before checking it in, but then I moved it to a new document and forgot to update the link. check-in: f4cbfd5a user: wyoung tags: trunk
Fixed a couple of Tcl syntax fixes that caused the new --with-sanitizer code to a) run unconditionally irrespective of the option's setting and b) to check for the existence of libubsan whether it was actually needed or not. Closed-Leaf check-in: 66fdab76 user: wyoung tags: configure-updates
Added www/, which documents the default Content Security Policy applied by Fossil to the HTML pages it serves. Linked that into embeddeddoc.wik and, which touched on this topic before but didn't go into much detail. check-in: 4e6d36d7 user: wyoung tags: trunk
Fix a compiler warning in the security-audit page. check-in: 3243a6c1 user: drh tags: trunk
Added --with-sanitizer configure-time option for appending -fsanitize=VALUE to CFLAGS and LDFLAGS, plus automatic detection of -lubsan for GCC, which doesn't automatically link to that with -fsanitize=undefined as Clang does. EDIT: This check-in breaks the built on Ubuntu 18.04. check-in: 7907b6ff user: wyoung tags: configure-updates
Removed "known to work with IIS" bit from www/server/index.html in the CGI section, since that is not actually true. We can put it back once someone figures out the IIS + CGI + Fossil CPU pegging problem. check-in: 8b7c17de user: wyoung tags: server-docs
Removed documentation of the nonce="$NONCE" feature in www/, removed as part of [8264fd75]. check-in: d55f6b15 user: wyoung tags: server-docs
Fix a broken hyperlink on the new server-docs index page. check-in: 461c8f06 user: drh tags: server-docs
Updating links in www/server/windows/ to correct locations. check-in: 65d175ae user: ckennedy tags: server-docs
Plan Z check-in: 8264fd75 user: drh tags: server-docs
Have the security-audit page analyze and display the content security policy. check-in: 9cf90a4f user: drh tags: trunk
Increase the default HTTP request timeout to 10 minutes. Provide the FOSSIL_DEFAULT_TIMEOUT compile-time option for setting an alternative default. check-in: 7979989d user: drh tags: trunk
Added missing www/ file check-in: 80cd49f0 user: wyoung tags: server-docs
Updated www/server/index.html to no longer discuss launchd as a "maybe" option now that we have a document for it, and removed mention of Solaris SMF entirely. check-in: 1e6fbcf2 user: wyoung tags: server-docs
Added www/server/macos/ and then added macOS to the set of server OSes offered in www/server/index.html check-in: e0ad4b48 user: wyoung tags: server-docs
Assorted small tweaks to www/server/windows/ check-in: b5fefeec user: wyoung tags: server-docs
Small tweaks to the new "Serving as a Standalone Server on Windows" article. check-in: 3995a3c7 user: wyoung tags: server-docs
Assorted small tweaks to server docs, mainly around new systemd material. check-in: 9d4a4782 user: wyoung tags: server-docs
Added www/server/debian/, demonstrating systemd configuration of Fossil for the first time in the official docs, both as a user serivce and in socket activation mode as a system-level service. check-in: 94763aed user: wyoung tags: server-docs
Clarity tweak check-in: bc678e13 user: wyoung tags: server-docs
Grammar fix on previous check-in: d5c754f9 user: wyoung tags: server-docs