| Age | Commit message (Collapse) | Author | |
|---|---|---|---|
| 2009-06-04 | Change "CLEAN" to an empty string to see if it's better visually. | Bharat Mediratta | |
| Looks like it is. | |||
| 2009-06-04 | Update xss clean list | Bharat Mediratta | |
| 2009-06-04 | Only request the server_add js if the user is an admin | Bharat Mediratta | |
| 2009-06-05 | Rewrite the server_add to have the server format the selection when a branch ↵ | Tim Almdal | |
| is opened. Sub trees re only retrieved when the branch is opened. Changed the start task processing to fill in any subtrees that are selected, but were never expanded on the client. Added the loading icon. Signed-off-by: Bharat Mediratta <bharat@menalto.com> | |||
| 2009-06-05 | Create a gDialogLargeLoading class for use with dialogs when running ↵ | Tim Almdal | |
| something that will take a little longer. If the standard gLoadingLarge is used with a dialog then the ui-dialog-content class will override the background and the loading icon will not be seen. Signed-off-by: Bharat Mediratta <bharat@menalto.com> | |||
| 2009-06-04 | Remove console.log() calls, they break some browsers | Bharat Mediratta | |
| 2009-06-04 | Properly internationalize the "Add some" photos link. | Bharat Mediratta | |
| 2009-06-04 | Merge branch 'master' of git@github.com:gallery/gallery3 | Bharat Mediratta | |
| 2009-06-04 | Update notify/watch eyeglasses icon with bullhorn icon. Rename css/image ↵ | Chad Kieffer | |
| names from watch to notify. | |||
| 2009-06-03 | Show an "add photos" message on empty albums for those who can. | Chad Kieffer | |
| 2009-06-03 | Merge branch 'master' of git@github.com:gallery/gallery3 | Chad Kieffer | |
| 2009-06-03 | Sanitize all data we return via json_encode() to guard against XSS and | Bharat Mediratta | |
| other data leaks. | |||
| 2009-06-03 | Guard against pages with no items. | Bharat Mediratta | |
| 2009-06-03 | Merge branch 'master' of git@github.com:gallery/gallery3 | Chad Kieffer | |
| 2009-06-03 | Minor tweaks to the way that we turn the add photos item into a menu | Bharat Mediratta | |
| to make it a little more robust. | |||
| 2009-06-02 | Merge branch 'master' of git@github.com:gallery/gallery3 | Chad Kieffer | |
| 2009-06-02 | made "Add photos" its own site menu item | jhilden | |
| * open for suggestions on the submenu item labels * @bharat: not sure about the add photos menu item id in the dropdown case | |||
| 2009-06-02 | Merge branch 'master' of git@github.com:gallery/gallery3 | Bharat Mediratta | |
| 2009-06-02 | Have server_add turn the "Add Photo" menu option into a dropdown and | Bharat Mediratta | |
| make "Add from Server" a 2nd option there. This requires adding the Menu::remove() API function. | |||
| 2009-06-02 | Improve test isolation so that Albums_Controller_Test doesn't fail when run ↵ | Tim Almdal | |
| with Photos_Controller_Test | |||
| 2009-06-02 | Restore "view" permissions on the root album in teardown. | Bharat Mediratta | |
| 2009-06-02 | Merge branch 'master' of git@github.com:gallery/gallery3 | Bharat Mediratta | |
| 2009-06-02 | fix the xss_security_test in regards to the renaming of thumb_tag, ↵ | Tim Almdal | |
| resize_tag and move_tag. | |||
| 2009-06-02 | make cleanm static | Tim Almdal | |
| 2009-06-02 | fix preamble so file structure test passes | Tim Almdal | |
| 2009-06-02 | Fix for ticket #320 | Tim Almdal | |
| 2009-06-02 | Update for beta 1 | Bharat Mediratta | |
| 2009-06-02 | Extend L10n client to provide UI for plural translation. | Andy Staudacher | |
| Ticket 148. | |||
| 2009-06-01 | Move recaptcha widget into a view for clarity. Also, wrap it in a | Bharat Mediratta | |
| setTimeout() call so that on subsequent reloads (which happen when you fail to validate the form) it has time to rebuild the DOM before calling the JS which tries to inject the Recaptcha HTML. Fixes ticket #327 | |||
| 2009-06-01 | Merge branch 'master' of git@github.com:gallery/gallery3 | andyst | |
| 2009-06-01 | Unescape %20 into " " also. | Bharat Mediratta | |
| 2009-06-01 | Workaround for parse_ini_file issue: There's no way to escape a double-quote ↵ | Andy | |
| in a value that's read with parse_ini_file. Using single quotes instead, even if that's not the best style in English. | |||
| 2009-06-01 | Don't throw an error if there are no visible tags. | Bharat Mediratta | |
| 2009-06-01 | Security pass over all controller code. Mostly adding CSRF checking | Bharat Mediratta | |
| and verifying user permissions, but there are several above-the-bar changes: 1) Server add is now only available to admins. This is a hard requirement because we have to limit server access (eg: server_add::children) to a user subset and the current permission model doesn't include that. Easiest fix is to restrict to admins. Got rid of the server_add permission. 2) We now know check permissions at every level, which means in controllers AND in helpers. This "belt and suspenders" approach will give us defense in depth in case we overlook it in one area. 3) We now do CSRF checking in every controller method that changes the code, in addition to the Forge auto-check. Again, defense in depth and it makes scanning the code for security much simpler. 4) Moved Simple_Uploader_Controller::convert_filename_to_title to item:convert_filename_to_title 5) Fixed a bug in sending notification emails. 6) Fixed the Organize code to verify that you only have access to your own tasks. In general, added permission checks to organize which had pretty much no validation code. I did my best to verify every feature that I touched. | |||
| 2009-06-01 | Switch the default login page to non-ajax mode. It looks awful, but better ↵ | Bharat Mediratta | |
| than before. | |||
| 2009-06-01 | Fix a place where I shouldn't have renamed "core" to "gallery", breaking ↵ | Bharat Mediratta | |
| maintenance mode. | |||
| 2009-06-01 | use PHP_SAPI instead of php_sapi_name() | Bharat Mediratta | |
| 2009-06-01 | Don't bomb if there are no exif_records for the given item. | Bharat Mediratta | |
| 2009-06-01 | Normalize the random values used in the blocks_dashboard_xxx vars so | Bharat Mediratta | |
| that install.sql is more stable. | |||
| 2009-06-01 | Do a little cleanup and get rid of code left-over from when this | Bharat Mediratta | |
| controller rendered HTML. Also, catch all exceptions at the root level and restore the change in 84ce0cdefda162917c7b01722a7259ac52c4e30d which appears to have gotten lost in the shuffle. | |||
| 2009-05-31 | Merge branch 'master' of git@github.com:gallery/gallery3 | Tim Almdal | |
| 2009-05-31 | Move the sql packaging code from installer into the gallery module. It must ↵ | Tim Almdal | |
| be run from the command line and will throw a 404 if it is run as a web request. | |||
| 2009-05-31 | Forgot these in last commit | Chad Kieffer | |
| 2009-05-31 | Update notify/watch eyeglasses icon with bullhorn icon. Rename css/image ↵ | Chad Kieffer | |
| names from watch to notify. | |||
| 2009-05-31 | Clear the site status message on deactivate, not on uninstall. | Bharat Mediratta | |
| 2009-05-31 | Don't let relative_path() try to update the database if the Item_Model | Bharat Mediratta | |
| is not loaded, else you get weird errors. | |||
| 2009-05-31 | Accidentally broke the AllowOverride info url in the migration from | Bharat Mediratta | |
| core -> modules/gallery. Fixed, and incidentally make the link appear in a new tab/window. | |||
| 2009-05-31 | Remove extra blank line | Bharat Mediratta | |
| 2009-06-01 | Merge branch 'master' of git@github.com:gallery/gallery3 | Bharat Mediratta | |
| 2009-06-01 | Convert %7E to ~ when proxying files to work around Firefox's overzealous ↵ | bharat | |
| security model. | |||
