summaryrefslogtreecommitdiff
path: root/modules/gallery/controllers/simple_uploader.php
AgeCommit message (Collapse)Author
2009-09-15CSRF / auth fixes, golden data file checkpointAndy Staudacher
2009-08-27Properly deal with invalid images. This fixes ticket #611 which showsBharat Mediratta
a BMP masquerading as a .jpg causing us to be unable to rebuild resizes and thumbnails. Now if that happens, we discard the file, log it and move on.
2009-07-16Remove spurious blank line at the top of the file introduced in ↵Bharat Mediratta
09c9b1a75561881a40ada71f02710355923602e2
2009-07-11Fix a bug where we're referring to $photo when we just uploaded aBharat Mediratta
$movie, that causes the simpler uploader to throw an error for all movies.
2009-07-10Added the upload::required validation in order to insure that failed uploadsTim Almdal
are not treated as successful. Log any exceptions to the Kohana log and return the error message
2009-06-29If the argument to app() is not an album id, switch to the item parent.Bharat Mediratta
Fixes ticket #489.
2009-06-16Add support for uploading .jpeg files (in addition to .jpg)Bharat Mediratta
Fix for ticket #428
2009-06-01Security pass over all controller code. Mostly adding CSRF checkingBharat Mediratta
and verifying user permissions, but there are several above-the-bar changes: 1) Server add is now only available to admins. This is a hard requirement because we have to limit server access (eg: server_add::children) to a user subset and the current permission model doesn't include that. Easiest fix is to restrict to admins. Got rid of the server_add permission. 2) We now know check permissions at every level, which means in controllers AND in helpers. This "belt and suspenders" approach will give us defense in depth in case we overlook it in one area. 3) We now do CSRF checking in every controller method that changes the code, in addition to the Forge auto-check. Again, defense in depth and it makes scanning the code for security much simpler. 4) Moved Simple_Uploader_Controller::convert_filename_to_title to item:convert_filename_to_title 5) Fixed a bug in sending notification emails. 6) Fixed the Organize code to verify that you only have access to your own tasks. In general, added permission checks to organize which had pretty much no validation code. I did my best to verify every feature that I touched.
2009-05-29Require "add" permission to show the add form.Bharat Mediratta
2009-05-27Restructure things so that the application is now just another module.Bharat Mediratta
Kohana makes this type of transition fairly straightforward in that all controllers/helpers/etc are still located in the cascading filesystem without any extra effort, except that I've temporarily added a hack to force modules/gallery into the module path. Rename what's left of "core" to be "application" so that it conforms more closely to the Kohana standard (basically, just application/config/config.php which is the minimal thing that you need in the application directory) There's still considerable work left to be done here.