Fix cookie domain for domain: all on two letter single level TLD.
John Hawthorn
Don't double log the controller, action, or namespaced_controller when using ActiveRecord::QueryLog
Previously if you set config.active_record.query_log_tags to an array that included
:controller, :namespaced_controller, or :action, that item would get logged twice.
This bug has been fixed.
Alex Ghiculescu
Rescue EOFError exception from rack on a multipart request.
Nikita Vasilevsky
Rescue JSON::ParserError in Cookies json deserializer to discards marshal dumps:
Without this change, if action_dispatch.cookies_serializer is set to :json and
the app tries to read a :marshal serialized cookie, it would error out which wouldn't
clear the cookie and force app users to manually clear it in their browser.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/puzzle/wagons/network/alerts).
Bumps actionpack from 7.0.4.3 to 7.0.5.1.
Release notes
Sourced from actionpack's releases.
... (truncated)
Changelog
Sourced from actionpack's changelog.
Commits
cdd14ce
Preparing for 7.0.5.1 release93b9c74
update changelogc9ab9b3
Added check for illegal HTTP header value in redirect_toe88857b
Preparing for 7.0.5 releaseac1fc34
Sync CHANGELOG98497a6
Merge branch '7-0-4-sec' into 7-0-stable799b300
Version 7.0.4.25bed458
Merge pull request #47087 from jhawthorn/cookie_domain848fd23
Merge pull request #47117 from higher-pixels/selenium-capabilities-deprecation54dfe5a
Document ActionController::Rendering#render [ci-skip]Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/puzzle/wagons/network/alerts).