Dandelion is a fair source project. View the code on Github
Commits on Oct 12, 2025
| 5143d62 |
♻️ (pmails/_exclude.erb): remove |
| 68d3bf5 |
🔥 Remove deprecated
|
| 3373510 |
🐛 Extend bot blocking to cover |
| 251ba95 |
🐛 (payments.erb): add data-sort attribute to created_at cell Enable correct chronological sorting in the payments table by exposing a machine-readable timestamp while keeping the human-readable display. |
| ed3f4d7 |
🎨 (payments.erb): replace inline ERB output with safer block syntax |
| 650618d |
🐛 Fix HTML escaping in payments view to render icon |
| 2d3f4a8 |
🐛 (payments.erb): remove membership filter to show all gathering payments |
| 804ccae |
✨ Add payments listing page for gatherings
|
| 5b28006 |
🐛 (rack_attack_throttle): add missing “-bot” pattern to bot detection |
| 9830d13 |
♻️ Refactor bot pattern list for clarity and maintainability |
| 82d36e4 |
🔒️ Fix XSS vulnerability in blocklisted responder |
| a3c575b |
♻️ (rack_attack_throttle.rb): replace hard-coded path list with regex patterns to support dynamic org slugs
|
| bec5d66 |
🐛 (rack_attack_throttle.rb): replace regex patterns with exact path matching to reduce false positives
|
Commits on Oct 11, 2025
| 3c37bff |
♻️ (rack_attack_throttle.rb): rename rules for clarity and remove redundant comments |
| 5d30a10 |
♻️ Extract bot/protected-path checks into lambdas Reuse the same logic in blocklist and throttle rules |
| c9aeae9 |
🔒️ (rack_attack_throttle.rb): replace deprecated request.is_crawler? with explicit bot pattern check to fix deprecation warning |
| caf6cb5 |
♻️ Rename Rack::Attack rules for clarity and consistency |
| 7df5174 |
♻️ (app.rb): move Rack::Attack after Rack::CrawlerDetect so bot detection works correctly
|
| bfd60eb |
🔒️ (rack_attack_throttle.rb): add .ics endpoints to protected paths to prevent bot abuse |
| 6fc3f29 |
🐛 (rack_attack_throttle.rb): expand bot user-agent patterns to catch more crawlers |