summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2009-08-31Fix XSS vectors in HTML attributes (mostly t() calls)Andy Staudacher
2009-08-31Fix typo in descriptionAndy Staudacher
2009-08-31Add XSS check for HTML attributesAndy Staudacher
2009-08-31Add XSS check to ensure that html::js_string() is not preceded by a quote.Andy Staudacher
2009-08-31XSS review fixes (mostly adding missing html::mark_clean()) calls.Andy Staudacher
2009-08-31Adding XSS test for href="javascript: and onclick="..."Andy Staudacher
2009-08-31Rename mark_safe() to mark_clean()Andy Staudacher
2009-08-31Merge commit 'upstream/master'Andy Staudacher
2009-08-30Fix double -> single quotes (::js_string returns a double-quotes delimited ↵Andy Staudacher
string)
2009-08-30Updating golden XSS-test data fileAndy Staudacher
2009-08-30(mostly harmless) XSS fix in server addAndy Staudacher
2009-08-30XSS fixes in admin_comments.html.phpAndy Staudacher
2009-08-30Check for href="<?= $foo ?>" (malicious "javascript:..." string)Andy Staudacher
2009-08-30Updating XSS golden fileAndy Staudacher
2009-08-30Merge commit 'upstream/master'Andy Staudacher
Conflicts: modules/gallery/views/l10n_client.html.php modules/organize/views/organize_tree.html.php modules/server_add/helpers/server_add_event.php
2009-08-30Tabs to spaces cleanupAndy Staudacher
2009-08-30Merge branch 'master' of git@github.com:/gallery/gallery3Bharat Mediratta
2009-08-30Finish this pass at the Admin Maintenance view. Re-introduce status icons, ↵Chad Kieffer
put Cancel All, Delete All buttons in the action heading cell.
2009-08-30Oops, fix up the show argument that I "fixed" in the last change.Bharat Mediratta
2009-08-30Use $theme->item() instead of $item.Bharat Mediratta
2009-08-30Merge branch 'master' of git@github.com:/gallery/gallery3Bharat Mediratta
2009-08-30Move header and footer into page.html.php since they're not included in any ↵Chad Kieffer
other view template.
2009-08-30Added comments, formatted CSS, added status message styles.Chad Kieffer
2009-08-30Merge branch 'master' of git@github.com:gallery/gallery3Chad Kieffer
2009-08-30Apply hover effect to buttons in progress indicator dialog.Chad Kieffer
2009-08-30Remove jquery.dropshadow. It's only used in one place, not worth keeping.Chad Kieffer
2009-08-30Minor refactoring.Bharat Mediratta
2009-08-30Merge branch 'master' of git@github.com:/gallery/gallery3Bharat Mediratta
2009-08-30Add back mysql_fetch_object() call that I accidentally removed in myBharat Mediratta
rush to catch a plane.
2009-08-30Don't mark colors !important.Bharat Mediratta
2009-08-30Make comments consistent.Bharat Mediratta
2009-08-30Remove extra padding lineBharat Mediratta
2009-08-30Get rid of as much jitter as possible in the organize tree.Bharat Mediratta
2009-08-30Tighten up a class attr.Bharat Mediratta
2009-08-30Make the lasso more prominent and the colors consistent.Bharat Mediratta
2009-08-30Change the higlight/selection behavior so that we don't use opacity toBharat Mediratta
indicate selection state. It's too difficult to tell opacity differences on light colored photos. This approach models what WinXP does.
2009-08-30Simplify over-targetted CSS.Bharat Mediratta
2009-08-30Updating uses of html::js_string and SafeString::for_js (value now contains ↵Andy Staudacher
string delimiters)
2009-08-30Rename clean_js to js_string and have it return a complete JS string (with ↵Andy Staudacher
delimiters) instead of just the string contents. Benefits: Using json_encode(), which is very robust. And as a user, it's clearer how to use this API compared to what it was before.
2009-08-30Remove unnecessary cleverness in stripping off the hyphen for mysqlBharat Mediratta
version checks that was causing problems in the case where there's no hyphen. version_compare handles hypens fine.
2009-08-30Don't try to move an item into its own descendant hierarchy. Just leave it ↵Bharat Mediratta
out of the move for now.
2009-08-30Use is_descendant() API inside move_to() for clarity.Bharat Mediratta
2009-08-30CSS rename: gMicroThumbXxx -> gOrganizeMicroThumbXxx to make it clearBharat Mediratta
that this is organize only.
2009-08-30Rename gAlbumText to gOrganizeAlbumText for consistency since this isBharat Mediratta
an organize-only construct.
2009-08-30remove unused #gOrganizeDialogBharat Mediratta
2009-08-30Manage the selection so we don't automatically select an albumBharat Mediratta
whenever we expand a tree.
2009-08-30Precalculate the organize tree based on the selected album and renderBharat Mediratta
it right away while still allowing incremental tree loading.
2009-08-30Print out the version of MySQL that we found along with our errorBharat Mediratta
message, which should resolve http://gallery.menalto.com/node/90646
2009-08-30Change the processing time for search_task and exif_task to start theBharat Mediratta
1.5 second counter only after we've done any expensive queries. This guarantees at least some time to do work. Fixes ticket #693.
2009-08-30Merge branch 'master' of git@github.com:gallery/gallery3Bharat Mediratta