Skip to content

Fix/security 2026.3.1#27

Merged
tempei-kishi merged 6 commits intomainfrom
fix/security-2026.3.1
Mar 30, 2026
Merged

Fix/security 2026.3.1#27
tempei-kishi merged 6 commits intomainfrom
fix/security-2026.3.1

Conversation

@tempei-kishi
Copy link
Copy Markdown
Collaborator

What

Why

Additional info (optional)

Checklist

  • Read the contribution guide
  • Test working in a local environment
  • (If needed) Add story of storybook
  • (If needed) Update CHANGELOG.md
  • (If possible) Add tests

kakkokari-gtyih and others added 5 commits March 26, 2026 12:29
Co-authored-by: Julia Johannesen <julia@insertdomain.name>
Co-authored-by: Julia Johannesen <197614925+juliajohannesen@users.noreply.github.com>
* Tighten security in `HashtagChannel`

* Add isNoteVisibleForMe in stream channel

Co-Authored-By: Julia Johannesen <julia@insertdomain.name>

* Tighten note visibility checks in WebSocket (No.1)

* refactor

* Fix main channel

Co-Authored-By: Julia Johannesen <julia@insertdomain.name>

* fix typo

* fix missing lockdown (requireSigninToViewContents) checks

* fix(backend): streamingでのロックダウン挙動修正

* fix: 引用リノートを無条件で隠していた問題を修正

* fix: 引用リノートを単純にリノート場合に内容が見えることがある問題を修正

* refac

* fix

* fix

* fix

* Update docs

---------

Co-authored-by: Julia Johannesen <julia@insertdomain.name>
Co-authored-by: KanariKanaru <93921745+kanarikanaru@users.noreply.github.com>
* Tighten security on channels

* Fix main channel

* add comments, improve typing

* fix indent

* fix: missing membership checks in chat-room

* remove unnecessary check in chat-user

* fix

* refactor: use exists

* fix

---------

Co-authored-by: Julia Johannesen <julia@insertdomain.name>
@tempei-kishi tempei-kishi merged commit 5140a71 into main Mar 30, 2026
21 of 32 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants