<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ticket search results</title><link>https://forge-allura.apache.org/p/allura/tickets/</link><description>You searched for status:closed</description><language>en</language><lastBuildDate>Thu, 10 Sep 2026 15:16:08 -0000</lastBuildDate><item><title>CWE-200 and CWE-862 Information exposure via search</title><link>https://forge-allura.apache.org/p/allura/tickets/8622/</link><description/><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kenton Taylor</dc:creator><pubDate>Thu, 03 Sep 2026 16:52:56 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8622/</guid></item><item><title>drop other urllib handlers</title><link>https://forge-allura.apache.org/p/allura/tickets/8621/</link><description/><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave Brondsema</dc:creator><pubDate>Thu, 03 Sep 2026 16:52:50 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8621/</guid></item><item><title>Fix git rename handling</title><link>https://forge-allura.apache.org/p/allura/tickets/8620/</link><description/><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave Brondsema</dc:creator><pubDate>Thu, 03 Sep 2026 16:44:15 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8620/</guid></item><item><title>html sanitization fixes, drop inline SVG tag support</title><link>https://forge-allura.apache.org/p/allura/tickets/8619/</link><description/><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave Brondsema</dc:creator><pubDate>Thu, 03 Sep 2026 16:52:53 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8619/</guid></item><item><title>Implement field level encryption for User tool data fields </title><link>https://forge-allura.apache.org/p/allura/tickets/8617/</link><description>Field level encryption for the following attributes in the User's tool data field
- tool_data.sfx.registration_ip
- tool_data.sfx.registration_rdns
- tool_data.sfx.normalized_email
- tool_data.temp_reg_fields.phone_ext</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Carlos Cruz</dc:creator><pubDate>Thu, 10 Sep 2026 15:16:08 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8617/</guid></item><item><title>Align REST checks/queries with web controllers</title><link>https://forge-allura.apache.org/p/allura/tickets/8616/</link><description/><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave Brondsema</dc:creator><pubDate>Mon, 24 Aug 2026 16:03:39 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8616/</guid></item><item><title>Upgrade packages</title><link>https://forge-allura.apache.org/p/allura/tickets/8615/</link><description/><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave Brondsema</dc:creator><pubDate>Mon, 24 Aug 2026 15:29:14 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8615/</guid></item><item><title>Implement field level encryption for more user fields</title><link>https://forge-allura.apache.org/p/allura/tickets/8614/</link><description>The scope of this ticket includes the following user fields:
- UserLoginDetails:
    - ip
- User:
    - last_access.session_ip
    - last_access.login_ip
    - socialnetworks.urls
    - telnumbers</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Carlos Cruz</dc:creator><pubDate>Mon, 24 Aug 2026 15:29:14 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8614/</guid></item><item><title>Implement field level encryption for email address in user preferences</title><link>https://forge-allura.apache.org/p/allura/tickets/8613/</link><description/><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Carlos Cruz</dc:creator><pubDate>Mon, 24 Aug 2026 15:29:14 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8613/</guid></item><item><title>Documentation and migration for encrypted fields</title><link>https://forge-allura.apache.org/p/allura/tickets/8611/</link><description>With all the new field-level encryption lately, we need to update our docs, configs, and migrations</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave Brondsema</dc:creator><pubDate>Mon, 29 Jun 2026 17:19:08 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8611/</guid></item><item><title>Implement field level encryption for User's email addresses list</title><link>https://forge-allura.apache.org/p/allura/tickets/8610/</link><description/><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Carlos Cruz</dc:creator><pubDate>Mon, 24 Aug 2026 15:29:14 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8610/</guid></item><item><title>Authentication code tweaks</title><link>https://forge-allura.apache.org/p/allura/tickets/8609/</link><description>If geo information is available make it available for the html template.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Guillermo Cruz</dc:creator><pubDate>Mon, 29 Jun 2026 17:19:08 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8609/</guid></item><item><title>Pin pre-commit dependencies</title><link>https://forge-allura.apache.org/p/allura/tickets/8608/</link><description/><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Guillermo Cruz</dc:creator><pubDate>Mon, 29 Jun 2026 17:19:08 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8608/</guid></item><item><title>Implement field level encryption for the email field from the EmailAddress model</title><link>https://forge-allura.apache.org/p/allura/tickets/8606/</link><description>Implement field level encryption for the email field in the EmailAddress model</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Carlos Cruz</dc:creator><pubDate>Mon, 29 Jun 2026 17:19:08 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8606/</guid></item><item><title>Remove locale en_US.UTF-8 dependency</title><link>https://forge-allura.apache.org/p/allura/tickets/8605/</link><description>More modern versions of python handle UTF-8 encoding perfectly with the default univervisal `C.UTF-8` encoding. The hard-coded `en_US.UTF-8` that's used by svn.py isn't necessary anymore.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dillon Walls</dc:creator><pubDate>Mon, 29 Jun 2026 17:19:08 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8605/</guid></item><item><title>Implement field level encryption for the User's display name</title><link>https://forge-allura.apache.org/p/allura/tickets/8604/</link><description>Implement field level encryption for the User's display name and update related tests</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Carlos Cruz</dc:creator><pubDate>Mon, 29 Jun 2026 17:19:08 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8604/</guid></item><item><title>tweak show domain on external links</title><link>https://forge-allura.apache.org/p/allura/tickets/8602/</link><description/><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dillon Walls</dc:creator><pubDate>Mon, 29 Jun 2026 17:19:08 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8602/</guid></item><item><title>email auth verification by link</title><link>https://forge-allura.apache.org/p/allura/tickets/8601/</link><description>With a link we can have a longer token for more security (still type-able if needed).  And the link will defeat some MITM phishing attacks, forcing you to the right site.

We can apply this to 2FA accounts too (currently being skipped) so they get the MITM protections too

Downside is if you don't have email access on the same computer you're logging in to :(</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave Brondsema</dc:creator><pubDate>Mon, 29 Jun 2026 17:19:08 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8601/</guid></item><item><title>Python Packages Upgrade</title><link>https://forge-allura.apache.org/p/allura/tickets/8600/</link><description>Upgrade Python packages to the latest versions.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Daniel Castillo</dc:creator><pubDate>Mon, 29 Jun 2026 17:19:08 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8600/</guid></item><item><title>show domain on external links, if misleading</title><link>https://forge-allura.apache.org/p/allura/tickets/8599/</link><description>When showing links (e.g originating from markdown, but really any html output) we should do something about links that could be misleading.  For example with `&lt;a href=https://evil.com/&gt;sourceforge.net/auth/&lt;/a&gt;` we could automatically append `(evil.com)` into the output so its obvious when its misleading.

We should also check for non-ascii domain names (IDN) and if they have chars that are potentially confusing with normal ascii, then show the decoded domain name (even if the link &amp; text match, if the chars could be confusing)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave Brondsema</dc:creator><pubDate>Mon, 29 Jun 2026 17:19:08 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8599/</guid></item><item><title>Upgrade Underscore Library</title><link>https://forge-allura.apache.org/p/allura/tickets/8598/</link><description>Upgrade from 1.13.6 -&gt; 1.13.8 to protect against known vulnerability https://github.com/jashkenas/underscore/issues/3011</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dillon Walls</dc:creator><pubDate>Mon, 29 Jun 2026 17:19:08 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8598/</guid></item><item><title>improve bad markdown performance</title><link>https://forge-allura.apache.org/p/allura/tickets/8597/</link><description>In some very specific cases the performance of markdown can be quite bad</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave Brondsema</dc:creator><pubDate>Mon, 29 Jun 2026 17:19:08 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8597/</guid></item><item><title>Escape specific values in notification emails</title><link>https://forge-allura.apache.org/p/allura/tickets/8596/</link><description>We send out notification emails when a user performs an action, we should escape some of the values including in these emails like usernames.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Guillermo Cruz</dc:creator><pubDate>Mon, 29 Jun 2026 17:19:08 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/8596/</guid></item></channel></rss>