summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2009-06-05Rewrite the server_add to have the server format the selection when a branch ↵Tim Almdal
is opened. Sub trees re only retrieved when the branch is opened. Changed the start task processing to fill in any subtrees that are selected, but were never expanded on the client. Added the loading icon. Signed-off-by: Bharat Mediratta <bharat@menalto.com>
2009-06-05Create a gDialogLargeLoading class for use with dialogs when running ↵Tim Almdal
something that will take a little longer. If the standard gLoadingLarge is used with a dialog then the ui-dialog-content class will override the background and the loading icon will not be seen. Signed-off-by: Bharat Mediratta <bharat@menalto.com>
2009-06-04Remove console.log() calls, they break some browsersBharat Mediratta
2009-06-04Properly internationalize the "Add some" photos link.Bharat Mediratta
2009-06-04Merge branch 'master' of git@github.com:gallery/gallery3Bharat Mediratta
2009-06-04Update notify/watch eyeglasses icon with bullhorn icon. Rename css/image ↵Chad Kieffer
names from watch to notify.
2009-06-03Show an "add photos" message on empty albums for those who can.Chad Kieffer
2009-06-03Merge branch 'master' of git@github.com:gallery/gallery3Chad Kieffer
2009-06-03Sanitize all data we return via json_encode() to guard against XSS andBharat Mediratta
other data leaks.
2009-06-03Guard against pages with no items.Bharat Mediratta
2009-06-03Merge branch 'master' of git@github.com:gallery/gallery3Chad Kieffer
2009-06-03Minor tweaks to the way that we turn the add photos item into a menuBharat Mediratta
to make it a little more robust.
2009-06-02Merge branch 'master' of git@github.com:gallery/gallery3Chad Kieffer
2009-06-02made "Add photos" its own site menu itemjhilden
* open for suggestions on the submenu item labels * @bharat: not sure about the add photos menu item id in the dropdown case
2009-06-02Merge branch 'master' of git@github.com:gallery/gallery3Bharat Mediratta
2009-06-02Have server_add turn the "Add Photo" menu option into a dropdown andBharat Mediratta
make "Add from Server" a 2nd option there. This requires adding the Menu::remove() API function.
2009-06-02Improve test isolation so that Albums_Controller_Test doesn't fail when run ↵Tim Almdal
with Photos_Controller_Test
2009-06-02Restore "view" permissions on the root album in teardown.Bharat Mediratta
2009-06-02Merge branch 'master' of git@github.com:gallery/gallery3Bharat Mediratta
2009-06-02fix the xss_security_test in regards to the renaming of thumb_tag, ↵Tim Almdal
resize_tag and move_tag.
2009-06-02make cleanm staticTim Almdal
2009-06-02fix preamble so file structure test passesTim Almdal
2009-06-02Fix for ticket #320Tim Almdal
2009-06-02Update for beta 1Bharat Mediratta
2009-06-02Extend L10n client to provide UI for plural translation.Andy Staudacher
Ticket 148.
2009-06-01Move recaptcha widget into a view for clarity. Also, wrap it in aBharat Mediratta
setTimeout() call so that on subsequent reloads (which happen when you fail to validate the form) it has time to rebuild the DOM before calling the JS which tries to inject the Recaptcha HTML. Fixes ticket #327
2009-06-01Merge branch 'master' of git@github.com:gallery/gallery3andyst
2009-06-01Unescape %20 into " " also.Bharat Mediratta
2009-06-01Workaround for parse_ini_file issue: There's no way to escape a double-quote ↵Andy
in a value that's read with parse_ini_file. Using single quotes instead, even if that's not the best style in English.
2009-06-01Don't throw an error if there are no visible tags.Bharat Mediratta
2009-06-01Security pass over all controller code. Mostly adding CSRF checkingBharat Mediratta
and verifying user permissions, but there are several above-the-bar changes: 1) Server add is now only available to admins. This is a hard requirement because we have to limit server access (eg: server_add::children) to a user subset and the current permission model doesn't include that. Easiest fix is to restrict to admins. Got rid of the server_add permission. 2) We now know check permissions at every level, which means in controllers AND in helpers. This "belt and suspenders" approach will give us defense in depth in case we overlook it in one area. 3) We now do CSRF checking in every controller method that changes the code, in addition to the Forge auto-check. Again, defense in depth and it makes scanning the code for security much simpler. 4) Moved Simple_Uploader_Controller::convert_filename_to_title to item:convert_filename_to_title 5) Fixed a bug in sending notification emails. 6) Fixed the Organize code to verify that you only have access to your own tasks. In general, added permission checks to organize which had pretty much no validation code. I did my best to verify every feature that I touched.
2009-06-01Switch the default login page to non-ajax mode. It looks awful, but better ↵Bharat Mediratta
than before.
2009-06-01Fix a place where I shouldn't have renamed "core" to "gallery", breaking ↵Bharat Mediratta
maintenance mode.
2009-06-01use PHP_SAPI instead of php_sapi_name()Bharat Mediratta
2009-06-01Don't bomb if there are no exif_records for the given item.Bharat Mediratta
2009-06-01Normalize the random values used in the blocks_dashboard_xxx vars soBharat Mediratta
that install.sql is more stable.
2009-06-01Do a little cleanup and get rid of code left-over from when thisBharat Mediratta
controller rendered HTML. Also, catch all exceptions at the root level and restore the change in 84ce0cdefda162917c7b01722a7259ac52c4e30d which appears to have gotten lost in the shuffle.
2009-05-31Merge branch 'master' of git@github.com:gallery/gallery3Tim Almdal
2009-05-31Move the sql packaging code from installer into the gallery module. It must ↵Tim Almdal
be run from the command line and will throw a 404 if it is run as a web request.
2009-05-31Forgot these in last commitChad Kieffer
2009-05-31Update notify/watch eyeglasses icon with bullhorn icon. Rename css/image ↵Chad Kieffer
names from watch to notify.
2009-05-31Clear the site status message on deactivate, not on uninstall.Bharat Mediratta
2009-05-31Don't let relative_path() try to update the database if the Item_ModelBharat Mediratta
is not loaded, else you get weird errors.
2009-05-31Accidentally broke the AllowOverride info url in the migration fromBharat Mediratta
core -> modules/gallery. Fixed, and incidentally make the link appear in a new tab/window.
2009-05-31Remove extra blank lineBharat Mediratta
2009-06-01Merge branch 'master' of git@github.com:gallery/gallery3Bharat Mediratta
2009-06-01Convert %7E to ~ when proxying files to work around Firefox's overzealous ↵bharat
security model.
2009-05-31Merge branch 'master' of git://github.com/gallery/gallery3Bharat Mediratta
2009-05-31Properly call user::login when we automatically login the admin userBharat Mediratta
immediately after install. Fixes ticket #323.
2009-06-01Fix a warningbharat