Branch: refs/heads/release_16.07 Home: https://github.com/galaxyproject/galaxy Commit: 93a8bfc7cb5e9c3395c5057910ec39d68ad787b4 https://github.com/galaxyproject/galaxy/commit/93a8bfc7cb5e9c3395c5057910ec3... Author: Nate Coraor <nate@bx.psu.edu> Date: 2017-10-19 (Thu, 19 Oct 2017) Changed paths: M config/galaxy.ini.sample M lib/galaxy/config.py M lib/galaxy/managers/folders.py M lib/galaxy/managers/libraries.py M lib/galaxy/tools/parameters/grouping.py M lib/galaxy/util/__init__.py A lib/galaxy/util/path/__init__.py A lib/galaxy/util/path/ntpath.py A lib/galaxy/util/path/posixpath.py M lib/galaxy/webapps/galaxy/api/lda_datasets.py M lib/galaxy/webapps/galaxy/api/remote_files.py M lib/galaxy/webapps/galaxy/controllers/library.py M lib/galaxy/webapps/galaxy/controllers/library_common.py M lib/galaxy/webapps/galaxy/controllers/user.py M lib/tool_shed/managers/groups.py Log Message: ----------- Security: Fix issues with path handling in libraries and in general. Commit: 0e698813a96f1ad61d797255686f69cf5e6b1280 https://github.com/galaxyproject/galaxy/commit/0e698813a96f1ad61d797255686f6... Author: Nate Coraor <nate@bx.psu.edu> Date: 2017-10-19 (Thu, 19 Oct 2017) Changed paths: M tools/data_source/data_source.py Log Message: ----------- [GX-2017-0003]: Fix for the reported issue, only allow http, https, and ftp schemes in the data_source tool. Compare: https://github.com/galaxyproject/galaxy/compare/8e199a33cf25...0e698813a96f