summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2009-08-30(mostly harmless) XSS fix in server addAndy Staudacher
2009-08-30XSS fixes in admin_comments.html.phpAndy Staudacher
2009-08-30Check for href="<?= $foo ?>" (malicious "javascript:..." string)Andy Staudacher
2009-08-30Updating XSS golden fileAndy Staudacher
2009-08-30Merge commit 'upstream/master'Andy Staudacher
Conflicts: modules/gallery/views/l10n_client.html.php modules/organize/views/organize_tree.html.php modules/server_add/helpers/server_add_event.php
2009-08-30Tabs to spaces cleanupAndy Staudacher
2009-08-30Updating uses of html::js_string and SafeString::for_js (value now contains ↵Andy Staudacher
string delimiters)
2009-08-30Rename clean_js to js_string and have it return a complete JS string (with ↵Andy Staudacher
delimiters) instead of just the string contents. Benefits: Using json_encode(), which is very robust. And as a user, it's clearer how to use this API compared to what it was before.
2009-08-30Remove unnecessary cleverness in stripping off the hyphen for mysqlBharat Mediratta
version checks that was causing problems in the case where there's no hyphen. version_compare handles hypens fine.
2009-08-30Don't try to move an item into its own descendant hierarchy. Just leave it ↵Bharat Mediratta
out of the move for now.
2009-08-30Use is_descendant() API inside move_to() for clarity.Bharat Mediratta
2009-08-30CSS rename: gMicroThumbXxx -> gOrganizeMicroThumbXxx to make it clearBharat Mediratta
that this is organize only.
2009-08-30Rename gAlbumText to gOrganizeAlbumText for consistency since this isBharat Mediratta
an organize-only construct.
2009-08-30remove unused #gOrganizeDialogBharat Mediratta
2009-08-30Manage the selection so we don't automatically select an albumBharat Mediratta
whenever we expand a tree.
2009-08-30Precalculate the organize tree based on the selected album and renderBharat Mediratta
it right away while still allowing incremental tree loading.
2009-08-30Print out the version of MySQL that we found along with our errorBharat Mediratta
message, which should resolve http://gallery.menalto.com/node/90646
2009-08-30Change the processing time for search_task and exif_task to start theBharat Mediratta
1.5 second counter only after we've done any expensive queries. This guarantees at least some time to do work. Fixes ticket #693.
2009-08-30Merge branch 'master' of git@github.com:gallery/gallery3Bharat Mediratta
2009-08-30Improve no_tabs test to print out a complete list of files + line numbers + ↵Andy Staudacher
line snippet.
2009-08-30Add $theme-> methods to Xss whitelist for HTML safety.Andy Staudacher
Updating XSS golden file.
2009-08-30Change all instances of SafeString::of_safe_html() to html::mark_safe() in ↵Andy Staudacher
views.
2009-08-30Fixing typoAndy Staudacher
2009-08-29Minor cleanupAndy Staudacher
2009-08-29Update all code to use helper method html::clean(), html::purify(), ... ↵Andy Staudacher
instead of SafeString directly.
2009-08-29Adding html::clean(), ::purify(), etc.Andy Staudacher
2009-08-29Delete obsolete comment and tighten the code in site_menu().Bharat Mediratta
2009-08-29Remove try/catch in resize() since that will swallow any exceptionsBharat Mediratta
that we generate when resizing.
2009-08-29Merge branch 'master' of git@github.com:gallery/gallery3Bharat Mediratta
2009-08-29Merge branch 'master' of git@github.com:gallery/gallery3Chad Kieffer
2009-08-29Change the organize tree to expand/collapse. It doesn't properly openBharat Mediratta
up to the album that you're viewing, and if you move a photo to a different album it'll reload the entire album tree.
2009-08-29Apply hover effect to dialog buttons.Chad Kieffer
2009-08-29Undo url helper changes - url methods no longer return a SafeString.Andy Staudacher
Adding SafeString::of_safe_html() calls where urls are passed as parameters to t() and t2().
2009-08-29you can close the l10n client directly from its interface now, without going ↵jhilden
back to the languages admin page
2009-08-29Merge branch 'master' of git@github.com:gallery/gallery3jhilden
2009-08-29initial version of the the file with common CSS styles that should be reused ↵jhilden
if possible
2009-08-29Fix error text color.Chad Kieffer
2009-08-29XSS fixesAndy Staudacher
2009-08-29Fix for ticket #628:Tim Almdal
1) increased gallery module version to 11 2) added image_sharpened parameter to the gallery module 3) sharpen all resizes.
2009-08-29Fix invalida syntax on trying to parse the progress bar percentageTim Almdal
2009-08-29L10n fixes for the admin_languages page, and JS/XSS cleanup of the organize ↵Andy Staudacher
views.
2009-08-29Fix link in l10n UI (for SafeString changes)Andy Staudacher
2009-08-29Merge commit 'upstream/master'Andy Staudacher
Conflicts: modules/akismet/views/admin_akismet.html.php modules/comment/helpers/comment_rss.php modules/gallery/helpers/gallery_rss.php modules/gallery/libraries/I18n.php modules/gallery/views/permissions_browse.html.php modules/gallery/views/simple_uploader.html.php modules/info/views/info_block.html.php modules/organize/controllers/organize.php modules/organize/views/organize.html.php modules/organize/views/organize_album.html.php themes/default/views/album.html.php themes/default/views/movie.html.php themes/default/views/photo.html.php
2009-08-29Fixing all detected XSS vectors in PHP->JS code.Andy Staudacher
Xss: Rename UNKNOWN back to DIRTY, JS_XSS to DIRTY_JS. (using a different flag value to highlight potential XSS vectors in JS)
2009-08-29Merge branch 'master' of git@github.com:gallery/gallery3Chad Kieffer
2009-08-29Update status message styles. Lighten backgrounds, don't show background on ↵Chad Kieffer
Admin Maintenance rows, and added gModuleStatus class.
2009-08-29Bugfix: Don't forget to copy the _is_purified_html flag when cloning a ↵Andy Staudacher
SafeString.
2009-08-29Refactor all calls of p::clean() to SafeString::of() and p::purify() to ↵Andy Staudacher
SafeString::purify(). Removing any p::clean() calls for arguments to t() and t2() since their args are wrapped in a SafeString anyway.
2009-08-29Add more factory methods for convenience:Andy Staudacher
SafeString::purify() and SafeString::of_safe_html(). Removing SafeString::mark_html_safe() since it's no longer needed.
2009-08-29Merge branch 'talmdal_branch' of git@github.com:gallery/gallery3Bharat Mediratta