Dandelion is a fair source project. View the code on Github
Commits on Oct 11, 2025
| d11feea |
🔒️ (rack_attack_throttle.rb): replace hard-coded path list with regex patterns to block bots on any org's /events |
| 9550890 |
🔒️ (rack_attack_throttle.rb): block bots that use q parameter on protected paths
|
| 53997b6 |
➕ Add rack-attack gem to Gemfile for rate-limiting protection |
| 3a87790 |
➕ Add rack-attack gem for request throttling |
| a14bd7f |
♻️ Replace custom RackUserAgentThrottler with Rack::Attack The bespoke middleware only supported per-agent path throttling and kept state in memory. Rack::Attack gives us a standard, flexible rules engine and a Mongo-backed cache store for distributed rate limits. |
| 2115176 |
🔥 Remove referrer-based search resubmission checks
|
| bd5783f |
💬 Clarify payment-processor warning to “add details for at least one payment processor” |
| fa43e21 |
🐛 Fix ticket button to open external purchase URL in new tab |
| 26e9d97 |
🐛 Fix autocomplete selection in header search bar |
| c7d6f06 |
🐛 Fix free-mailgun check to exclude current pmail |
| 582049f |
📝 (build.erb): update GoCardless setup instructions to include access token creation step |
| c667ae2 |
🐛 (pmails): move delayed_jobs.destroy_all before conditional to ensure jobs are always cleared
|
| 6544a38 |
🐛 (pmails/_header): hide “Send later” UI for Event mails and when no Mailgun key
|
| bc2a4a5 |
🐛 (pmails.erb): hide search form when organisation has no pmails to avoid empty UI
|
| 7ad174d |
🐛 Fix free Mailgun check to also exclude future scheduled mails |
| 6a99d6f |
🐛 Fix organisation counters not being initialised on create Set subscribed_accounts_count and followers_count to 0 for new records to prevent nil values that could break downstream calculations. |
| 163f0fc |
✨ Add gift checkbox to Pmail model |
| 0b77f13 |
🐛 Fix typo in organisation variable name |
| 5a21c56 |
✨ Add gift flag to Pmail model |
| 85964c5 |
🐛 Fix typo in organisation variable name |