summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2009-08-31Hold the banner's height when header text is set or the logo's yanked.Chad Kieffer
2009-08-31Don't include Make this the album's cover in context menu's for albums. #705Chad Kieffer
2009-08-31Update XSS test golden fileAndy Staudacher
2009-08-31Merge branch 'master' of git@github.com:gallery/gallery3Chad Kieffer
2009-08-31Merge commit 'upstream/master'Andy Staudacher
2009-08-31Fix XSS vectors in HTML attributes (mostly t() calls)Andy Staudacher
2009-08-31Add icons to context menu for albums. I'm open to other options, if folks ↵Chad Kieffer
think there's something better in the jQuery UI themeroller set.
2009-08-31Escape single quotes in the password so that we don't break our configBharat Mediratta
syntax. Related to (but unclear that it fixes) ticket #650.
2009-08-31Fix typo in descriptionAndy Staudacher
2009-08-31Suppress errors to mysql_connect(). We had this before, but itBharat Mediratta
appears to have been accidentally removed in 177a854d
2009-08-31Add XSS check for HTML attributesAndy Staudacher
2009-08-31Merge branch 'master' of git@github.com:gallery/gallery3Bharat Mediratta
2009-08-31Stay on the same page when editing albums/movies/photos. Fixes ticketBharat Mediratta
2009-08-31Add 'organize album' to the context menu.Bharat Mediratta
2009-08-31Add XSS check to ensure that html::js_string() is not preceded by a quote.Andy Staudacher
2009-08-31XSS review fixes (mostly adding missing html::mark_clean()) calls.Andy Staudacher
2009-08-31Adding XSS test for href="javascript: and onclick="..."Andy Staudacher
2009-08-31Rename mark_safe() to mark_clean()Andy Staudacher
2009-08-31Merge commit 'upstream/master'Andy Staudacher
2009-08-30Fix double -> single quotes (::js_string returns a double-quotes delimited ↵Andy Staudacher
string)
2009-08-30Updating golden XSS-test data fileAndy Staudacher
2009-08-30(mostly harmless) XSS fix in server addAndy Staudacher
2009-08-30XSS fixes in admin_comments.html.phpAndy Staudacher
2009-08-30Check for href="<?= $foo ?>" (malicious "javascript:..." string)Andy Staudacher
2009-08-30Updating XSS golden fileAndy Staudacher
2009-08-30Merge commit 'upstream/master'Andy Staudacher
Conflicts: modules/gallery/views/l10n_client.html.php modules/organize/views/organize_tree.html.php modules/server_add/helpers/server_add_event.php
2009-08-30Tabs to spaces cleanupAndy Staudacher
2009-08-30Merge branch 'master' of git@github.com:/gallery/gallery3Bharat Mediratta
2009-08-30Finish this pass at the Admin Maintenance view. Re-introduce status icons, ↵Chad Kieffer
put Cancel All, Delete All buttons in the action heading cell.
2009-08-30Oops, fix up the show argument that I "fixed" in the last change.Bharat Mediratta
2009-08-30Use $theme->item() instead of $item.Bharat Mediratta
2009-08-30Merge branch 'master' of git@github.com:/gallery/gallery3Bharat Mediratta
2009-08-30Move header and footer into page.html.php since they're not included in any ↵Chad Kieffer
other view template.
2009-08-30Added comments, formatted CSS, added status message styles.Chad Kieffer
2009-08-30Merge branch 'master' of git@github.com:gallery/gallery3Chad Kieffer
2009-08-30Apply hover effect to buttons in progress indicator dialog.Chad Kieffer
2009-08-30Remove jquery.dropshadow. It's only used in one place, not worth keeping.Chad Kieffer
2009-08-30Minor refactoring.Bharat Mediratta
2009-08-30Merge branch 'master' of git@github.com:/gallery/gallery3Bharat Mediratta
2009-08-30Add back mysql_fetch_object() call that I accidentally removed in myBharat Mediratta
rush to catch a plane.
2009-08-30Don't mark colors !important.Bharat Mediratta
2009-08-30Make comments consistent.Bharat Mediratta
2009-08-30Remove extra padding lineBharat Mediratta
2009-08-30Get rid of as much jitter as possible in the organize tree.Bharat Mediratta
2009-08-30Tighten up a class attr.Bharat Mediratta
2009-08-30Make the lasso more prominent and the colors consistent.Bharat Mediratta
2009-08-30Change the higlight/selection behavior so that we don't use opacity toBharat Mediratta
indicate selection state. It's too difficult to tell opacity differences on light colored photos. This approach models what WinXP does.
2009-08-30Simplify over-targetted CSS.Bharat Mediratta
2009-08-30Updating uses of html::js_string and SafeString::for_js (value now contains ↵Andy Staudacher
string delimiters)
2009-08-30Rename clean_js to js_string and have it return a complete JS string (with ↵Andy Staudacher
delimiters) instead of just the string contents. Benefits: Using json_encode(), which is very robust. And as a user, it's clearer how to use this API compared to what it was before.