<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/gitlab/gitlab-ce.git/lib/support/nginx/gitlab-ssl, branch use-queue_namespace</title>
<subtitle>gitlab.com: gitlab-org/gitlab-ce.git
</subtitle>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/gitlab/gitlab-ce.git/'/>
<entry>
<title>Filter sensitive query string parameters from NGINX access logs</title>
<updated>2017-08-10T11:28:04+00:00</updated>
<author>
<name>Nick Thomas</name>
<email>nick@gitlab.com</email>
</author>
<published>2017-08-10T11:28:04+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/gitlab/gitlab-ce.git/commit/?id=603b68186a62063802986477c15f5b46694c0100'/>
<id>603b68186a62063802986477c15f5b46694c0100</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge branch '3kami3/gitlab-ce-real_ip'</title>
<updated>2017-03-20T07:40:02+00:00</updated>
<author>
<name>Rémy Coutable</name>
<email>remy@rymai.me</email>
</author>
<published>2017-03-20T07:40:02+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/gitlab/gitlab-ce.git/commit/?id=691402fb2b361ba19db3b8bdf77b75e513883423'/>
<id>691402fb2b361ba19db3b8bdf77b75e513883423</id>
<content type='text'>
See merge request !9623.

Signed-off-by: Rémy Coutable &lt;remy@rymai.me&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
See merge request !9623.

Signed-off-by: Rémy Coutable &lt;remy@rymai.me&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>https://gitlab.com/gitlab-org/gitlab-ce/merge_requests/9623#note_24573655</title>
<updated>2017-03-03T13:20:29+00:00</updated>
<author>
<name>3kami3</name>
<email>github@yumimix.org</email>
</author>
<published>2017-03-03T13:20:29+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/gitlab/gitlab-ce.git/commit/?id=79c3ace80b690c9ccc2d6190fcf1f14f735f566c'/>
<id>79c3ace80b690c9ccc2d6190fcf1f14f735f566c</id>
<content type='text'>
Fixed issues pointed out.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Fixed issues pointed out.
</pre>
</div>
</content>
</entry>
<entry>
<title>Stop setting Strict-Transport-Securty header from within the app</title>
<updated>2017-03-03T11:05:24+00:00</updated>
<author>
<name>Paweł Chojnacki</name>
<email>pawel@chojnacki.ws</email>
</author>
<published>2017-03-03T11:05:24+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/gitlab/gitlab-ce.git/commit/?id=76e96878aad0a281f8c32ef98a276b499e2581ad'/>
<id>76e96878aad0a281f8c32ef98a276b499e2581ad</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Add real_ip setting to nginx example.</title>
<updated>2017-03-01T14:16:38+00:00</updated>
<author>
<name>3kami3</name>
<email>github@yumimix.org</email>
</author>
<published>2017-03-01T14:16:38+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/gitlab/gitlab-ce.git/commit/?id=1bc5dab7b4f2650b5afb7c0e4c70e5ac9f66eba0'/>
<id>1bc5dab7b4f2650b5afb7c0e4c70e5ac9f66eba0</id>
<content type='text'>
ref)
https://docs.gitlab.com/omnibus/settings/nginx.html#configuring-gitlab-trusted_proxies-and-the-nginx-real_ip-module
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
ref)
https://docs.gitlab.com/omnibus/settings/nginx.html#configuring-gitlab-trusted_proxies-and-the-nginx-real_ip-module
</pre>
</div>
</content>
</entry>
<entry>
<title>Upgrade NGINX configuration files to add websocket support</title>
<updated>2016-12-12T12:58:42+00:00</updated>
<author>
<name>Nick Thomas</name>
<email>nick@gitlab.com</email>
</author>
<published>2016-12-12T12:58:42+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/gitlab/gitlab-ce.git/commit/?id=eb09395b2b5527e271c8e155ff6403953f72fef6'/>
<id>eb09395b2b5527e271c8e155ff6403953f72fef6</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Revert "Defend against 'Host' header injection"</title>
<updated>2016-08-08T11:02:44+00:00</updated>
<author>
<name>Jacob Vosmaer</name>
<email>jacob@gitlab.com</email>
</author>
<published>2016-08-08T11:02:44+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/gitlab/gitlab-ce.git/commit/?id=427c9f0b5b5f6f0c242e75a98dca2434a27945d8'/>
<id>427c9f0b5b5f6f0c242e75a98dca2434a27945d8</id>
<content type='text'>
This reverts commit 47b5b441395921e9f8e9982bb3f560e5db5a67bc.

See https://gitlab.com/gitlab-org/gitlab-ce/issues/17877#note_13488047
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This reverts commit 47b5b441395921e9f8e9982bb3f560e5db5a67bc.

See https://gitlab.com/gitlab-org/gitlab-ce/issues/17877#note_13488047
</pre>
</div>
</content>
</entry>
<entry>
<title>Defend against 'Host' header injection</title>
<updated>2016-07-12T17:50:20+00:00</updated>
<author>
<name>Jacob Vosmaer</name>
<email>jacob@gitlab.com</email>
</author>
<published>2016-07-12T15:22:10+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/gitlab/gitlab-ce.git/commit/?id=47b5b441395921e9f8e9982bb3f560e5db5a67bc'/>
<id>47b5b441395921e9f8e9982bb3f560e5db5a67bc</id>
<content type='text'>
Closes https://gitlab.com/gitlab-org/gitlab-ce/issues/17877 .

This change adds 'defense in depth' against 'Host' HTTP header
injection. It affects normal users in the following way. Suppose your
GitLab server has IP address 1.2.3.4 and hostname gitlab.example.com.
Currently, if you enter 1.2.3.4 in your browser, you get redirected to
1.2.3.4/users/sign_in. After this change, you get redirected from
1.2.3.4 to gitlab.example.com/users/sign_in. This is because the
address you typed in the address bar of your browser ('1.2.3.4'),
which gets stored in the 'Host' header, is now being overwritten to
'gitlab.example.com' in NGINX.

In this change we also make NGINX clear the 'X-Forwarded-Host' header
because Ruby on Rails also uses that header the same wayas the 'Host'
header.

We think that for most GitLab servers this is the right behavior, and
if not then administrators can change this behavior themselves at the
NGINX level.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Closes https://gitlab.com/gitlab-org/gitlab-ce/issues/17877 .

This change adds 'defense in depth' against 'Host' HTTP header
injection. It affects normal users in the following way. Suppose your
GitLab server has IP address 1.2.3.4 and hostname gitlab.example.com.
Currently, if you enter 1.2.3.4 in your browser, you get redirected to
1.2.3.4/users/sign_in. After this change, you get redirected from
1.2.3.4 to gitlab.example.com/users/sign_in. This is because the
address you typed in the address bar of your browser ('1.2.3.4'),
which gets stored in the 'Host' header, is now being overwritten to
'gitlab.example.com' in NGINX.

In this change we also make NGINX clear the 'X-Forwarded-Host' header
because Ruby on Rails also uses that header the same wayas the 'Host'
header.

We think that for most GitLab servers this is the right behavior, and
if not then administrators can change this behavior themselves at the
NGINX level.
</pre>
</div>
</content>
</entry>
<entry>
<title>Add a branded 503 static error page</title>
<updated>2016-04-22T20:26:42+00:00</updated>
<author>
<name>Robert Speicher</name>
<email>rspeicher@gmail.com</email>
</author>
<published>2016-04-22T20:26:18+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/gitlab/gitlab-ce.git/commit/?id=d85f65ef4e07fc0c58d51b2e943ad2acb87ef461'/>
<id>d85f65ef4e07fc0c58d51b2e943ad2acb87ef461</id>
<content type='text'>
[ci skip]

Closes https://gitlab.com/gitlab-org/gitlab-ce/issues/15398
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
[ci skip]

Closes https://gitlab.com/gitlab-org/gitlab-ce/issues/15398
</pre>
</div>
</content>
</entry>
<entry>
<title>Do not serve anything via nginx as we have workhorse</title>
<updated>2016-03-11T14:04:04+00:00</updated>
<author>
<name>Artem Sidorenko</name>
<email>artem@posteo.de</email>
</author>
<published>2016-02-27T08:28:00+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/gitlab/gitlab-ce.git/commit/?id=fb5c2147a9f2b3acc6ad5297c737da0f5546c247'/>
<id>fb5c2147a9f2b3acc6ad5297c737da0f5546c247</id>
<content type='text'>
Otherwise this might 'hide' problems
https://github.com/gitlabhq/gitlabhq/issues/10053#issuecomment-188919319
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Otherwise this might 'hide' problems
https://github.com/gitlabhq/gitlabhq/issues/10053#issuecomment-188919319
</pre>
</div>
</content>
</entry>
</feed>
