Commit Graph
881 Commits
Author SHA1 Message Date
KernelDeimos d1b4458c74 fix: possible missing path properties in /sign
When /sign is called with UIDs instead of paths, it is possible to get a
response without 'path' properties present in "signed fs item" objects.
This commit addresses the issue by fetching paths from FS node objects
as a last resort.
2025-08-29 16:08:17 -04:00
KernelDeimos 6d8889e434 dev: add config.__set_config_object__() 2025-08-28 18:28:29 -04:00
Xiaochen Cui 0c39f83078 captcha: imporve condition checks for cloudflare turnstile (#1469)
* captcha: imporve condition checks for cloudflare turnstile

* captcha: fix undefined "resetTurnstile" func

* captcha: set appearance

* captcha: add the missing prefix
2025-08-28 15:23:26 -07:00
Xiaochen Cui a98cc45f22 feat: memory filesystem provider
* Reapply "dev: memory filesystem"

This reverts commit 6f3bace4c4.

* fs: improve the robustess of set/get_storage api
2025-08-28 16:08:21 -04:00
ProgrammerIn-wonderland 4027ad951f Merge branch 'captcha' of https://github.com/XiaochenCui/puter into XiaochenCui-captcha 2025-08-27 20:01:57 -04:00
ProgrammerIn-wonderland f0d1a424a6 dev: Range header support in puter hosting (puter.site) 2025-08-27 19:19:36 -04:00
XiaochenCui bb2c51b840 captcha: add captcha widget to the signup window 2025-08-27 16:19:06 -07:00
ProgrammerIn-wonderland e48179a1f9 fix: improve support for unbounded range headers 2025-08-27 18:01:19 -04:00
ProgrammerIn-wonderland 9863f92aaa better range header support 2025-08-27 17:33:11 -04:00
KernelDeimos 6f3bace4c4 Revert "dev: memory filesystem"
This reverts commit 1f6bbe1672.
2025-08-27 14:26:03 -04:00
Xiaochen Cui 1f6bbe1672 dev: memory filesystem
* fs/memory-provider: passed all apitests

* test: write benchmark

* fs: add benchmark for stat-intensive scenario

* apitest: update duration

* fs: remove "NodeSelector", add checks to memoryfs, passed simple test

* test: update apitest

* debug: remove a debug stmt
2025-08-27 14:12:31 -04:00
ProgrammerIn-wonderland c0c601ac8f return partial content header
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test (18.x) (push) Has been cancelled
test / test (20.x) (push) Has been cancelled
test / test (22.x) (push) Has been cancelled
2025-08-26 18:43:29 -04:00
KernelDeimos 64f7f928d6 dev: add expiresIn 2025-08-26 17:26:54 -04:00
KernelDeimos 915bcf5f07 fix: sometimes WebServer log doesn't have context 2025-08-26 16:46:17 -04:00
KernelDeimos b2d43a0783 dev: add access token permission scanner 2025-08-26 16:17:28 -04:00
ProgrammerIn-wonderland 3dc4bb0d7d dev: add range header to /token_read 2025-08-26 14:55:36 -04:00
ProgrammerIn-wonderland c610fc98e9 update ll_read cache logic to be more respectful of Range header 2025-08-26 14:41:26 -04:00
ProgrammerIn-wonderland 122a93af18 dev: direct range header support in /read 2025-08-26 14:15:43 -04:00
ProgrammerIn-wonderland a08948f905 fix: Diswhitelist credential sharing for CORS 2025-08-26 13:35:40 -04:00
Nariman Jelveh 4c3a68ee51 feat: improve 404 error handling in Puter sites with custom page support (#1466)
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test (18.x) (push) Has been cancelled
test / test (20.x) (push) Has been cancelled
test / test (22.x) (push) Has been cancelled
- Implement a new method to serve a custom 404.html file if it exists in the subdomain root path.
- Update existing error responses to utilize the new custom 404 handling.
- Ensure fallback to default error handling if the custom file is not found or an error occurs during reading.
2025-08-25 16:08:49 -07:00
ProgrammerIn-wonderland 1907e2db6a fix error in macOS's metadata rejection
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test (18.x) (push) Has been cancelled
test / test (20.x) (push) Has been cancelled
test / test (22.x) (push) Has been cancelled
2025-08-22 17:05:59 -04:00
Neal Shah c1f83bd85f macOS webdav pollution fix (#1462) 2025-08-22 16:59:17 -04:00
Neal Shah 64126179cc Fix: Microsoft office Bearer issue (#1461) 2025-08-22 14:01:28 -04:00
ProgrammerIn-wonderland a770c5ade6 Merge branch 'main' of https://github.com/HeyPuter/puter 2025-08-21 17:12:26 -04:00
ProgrammerIn-wonderland 439f5fa850 fix: dav: Allow macOS x-epected-entity-length 2025-08-21 17:12:24 -04:00
jelveh 0eb47ac1d3 Update DeepSeekService.js
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test (18.x) (push) Has been cancelled
test / test (20.x) (push) Has been cancelled
test / test (22.x) (push) Has been cancelled
2025-08-21 10:01:53 -07:00
XiaochenCui 04ef8fbc0f fs: fix wrong file content on read
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test (18.x) (push) Has been cancelled
test / test (20.x) (push) Has been cancelled
test / test (22.x) (push) Has been cancelled
2025-08-20 13:45:30 -04:00
Andrei Onel 7849776605 doc: various jsdoc additions
* Added reference documentation for: src/backend/src/services/auth/Actor.js

* Added reference documentation for: src/backend/src/om/proptypes/__all__.js

* Added reference documentation for: src/backend/src/middleware/anticsrf.js

* Added reference documentation for: src/backend/src/services/auth/AntiCSRFService.js

* Revert "Added reference documentation for: src/backend/src/om/proptypes/__all__.js"

This reverts commit a9bb0fb48b.
2025-08-18 19:01:27 -04:00
ProgrammerIn-wonderland a27f4b60e4 fix: webdav service name for undefined origin 2025-08-18 18:03:57 -04:00
ProgrammerIn-wonderland a046f186d8 fix: webdavfs class init method name init to _init 2025-08-18 17:50:13 -04:00
Neal Shah fcb5aa4078 Dav (#1450)
* Windows WebDav support

* feat: 2fa support for dav

* fix auth cookie when Basic auth present

* dev: dav: refactor handler, support root level navigation

* dev: dav: JSDOCing important things

* fix: possible edge case of password containing colon character

* feat: direct token login for webdav

* set cookie to not be session cookie

* fx: webdav undefined origin support
2025-08-18 17:32:29 -04:00
ProgrammerIn-wonderland aa4bd72b92 take DomainModule to be not DNSModule
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test (18.x) (push) Has been cancelled
test / test (20.x) (push) Has been cancelled
test / test (22.x) (push) Has been cancelled
2025-08-14 19:00:57 -04:00
ProgrammerIn-wonderland 1a9ff9e954 fix: (for node 18) import parse-domain as esmodule 2025-08-14 18:47:23 -04:00
ProgrammerIn-wonderland 686053a0fe dev: add verification for entri webhooks 2025-08-14 18:32:22 -04:00
ProgrammerIn-wonderland aac6ff14ac custom domains webhook 2025-08-14 18:32:22 -04:00
ProgrammerIn-wonderland d105b341d5 Entri token service 2025-08-14 18:32:22 -04:00
ProgrammerIn-wonderland 58800e5d19 rebase fixes 2025-08-14 18:32:22 -04:00
KernelDeimos 4fadd26459 dev: add TXT record verification for domain names 2025-08-14 18:32:22 -04:00
KernelDeimos df602d5edb dev: continue work on custom domains
Adds service for querying controlling user for a domain. If no user is
verified as allowed to control the domain then we give control to the
'admin' user (to support local configurations of Puter).

After this point, I find myself a bit stuck because DNS queries are
incredibly difficult to test locally when you use tailscale.
2025-08-14 18:32:22 -04:00
KernelDeimos 49b0805014 dev: custom domain routing (the easy part)
With this commit alone, any user can specify "domain" on their
subdomains. This means they could affect the route for domains they
don't control, so this is not production-ready without further changes.
2025-08-14 18:32:22 -04:00
Nariman Jelveh 436f2d679f Update WebServerService.js 2025-08-14 12:04:47 -07:00
Nariman Jelveh 8e43fff19d Update WebServerService.js 2025-08-14 11:50:05 -07:00
Nariman Jelveh e225cb92f6 Update WebServerService.js 2025-08-14 11:41:41 -07:00
jelveh 2ddce7166f Add sentry-trace and baggage to allowed headers
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test (18.x) (push) Has been cancelled
test / test (20.x) (push) Has been cancelled
test / test (22.x) (push) Has been cancelled
2025-08-13 12:38:56 -07:00
KernelDeimos 4ba2f97da0 fix: move temp users to 'user' group when email is confirmed
Temporary users can go through email confirmation which effectively
makes these users registered/permanent users. When email is confirmed
they should be moved to the default group for registered users.
2025-08-13 15:15:36 -04:00
Xiaochen Cui ffc9246070 dev: consolidate fs.written to fs.write (#1392) 2025-08-13 13:21:07 -04:00
ProgrammerIn-wonderland 82c1f64b37 remove todo comment 2025-08-07 16:15:20 -04:00
ProgrammerIn-wonderland c8c7e22007 add check so workers can only be associated with the context's app 2025-08-07 16:15:20 -04:00
ProgrammerIn-wonderland 66288f798e add ability to specify app for worker 2025-08-07 16:15:20 -04:00
jelveh acc29a35c4 add gpt-5-chat-latest 2025-08-07 11:52:11 -07:00