summaryrefslogtreecommitdiff
path: root/modules/gallery/views/simple_uploader.html.php
AgeCommit message (Collapse)Author
2009-08-31Fix XSS vectors in HTML attributes (mostly t() calls)Andy Staudacher
2009-08-30Updating uses of html::js_string and SafeString::for_js (value now contains ↵Andy Staudacher
string delimiters)
2009-08-30Fixing typoAndy Staudacher
2009-08-29Minor cleanupAndy Staudacher
2009-08-29Update all code to use helper method html::clean(), html::purify(), ... ↵Andy Staudacher
instead of SafeString directly.
2009-08-29Merge commit 'upstream/master'Andy Staudacher
Conflicts: modules/akismet/views/admin_akismet.html.php modules/comment/helpers/comment_rss.php modules/gallery/helpers/gallery_rss.php modules/gallery/libraries/I18n.php modules/gallery/views/permissions_browse.html.php modules/gallery/views/simple_uploader.html.php modules/info/views/info_block.html.php modules/organize/controllers/organize.php modules/organize/views/organize.html.php modules/organize/views/organize_album.html.php themes/default/views/album.html.php themes/default/views/movie.html.php themes/default/views/photo.html.php
2009-08-29Fixing all detected XSS vectors in PHP->JS code.Andy Staudacher
Xss: Rename UNKNOWN back to DIRTY, JS_XSS to DIRTY_JS. (using a different flag value to highlight potential XSS vectors in JS)
2009-08-29Refactor all calls of p::clean() to SafeString::of() and p::purify() to ↵Andy Staudacher
SafeString::purify(). Removing any p::clean() calls for arguments to t() and t2() since their args are wrapped in a SafeString anyway.
2009-08-27Properly deal with invalid images. This fixes ticket #611 which showsBharat Mediratta
a BMP masquerading as a .jpg causing us to be unable to rebuild resizes and thumbnails. Now if that happens, we discard the file, log it and move on.
2009-07-143rd attempt to fix localization messages. Last time around I didn'tBharat Mediratta
dig deep enough, but now we form the complete message using t() style semantics to replace % placeholders with __ style JS placeholders. Also, stop appending the (completed) text to existing messages.. roll it together.
2009-07-11Fix a typo in the last commit. I left off a closing paren.Bharat Mediratta
2009-07-11Change 'completed' status message to be a full sentence with javascript ↵Bharat Mediratta
placeholders.
2009-07-12Fixed indentation of commit 2760e119bbfc3e2d436c404de194dbeea738a735Shai Ben-Naphtali
Signed-off-by: Tim Almdal <tnalmdal@shaw.ca>
2009-07-12This fixes ticket #513Shai Ben-Naphtali
Signed-off-by: Tim Almdal <tnalmdal@shaw.ca>
2009-07-10Change the word "Done" to "Close" to make translations easierTim Almdal
2009-07-03Split the clean method into two clean and purify. clean is a light weightTim Almdal
approach using html::specialchars and purify uses HTMLPurifier to intelligently cleanse the output fields. Use purifier for text and title fields where it is likely that a user would enter html to format their data.
2009-06-29Merge branch 'master' of git@github.com:gallery/gallery3jhilden
2009-06-29added textual description of upload progressjhilden
moved the cancel link to above the upload queue (where the textual upload progress also is)
2009-06-28use jquery.scrollTo to scroll the active upload into view.Bharat Mediratta
2009-06-09Add string to localizerunostar
Signed-off-by: Bharat Mediratta <bharat@menalto.com>
2009-06-04Fix internationalization to use one long string and placeholders.Bharat Mediratta
Removed the <br/> though since we're trying to avoid structural HTML in internationalized strings.
2009-06-04fixed another bug with the filesize unit and added a better error messagejhilden
Merge branch 'master' of git@github.com:gallery/gallery3 Conflicts: modules/gallery/views/simple_uploader.html.php
2009-06-04fixed stuffjhilden
2009-06-04Add MY_num containing num::convert_to_bytes() which supports PHP'sBharat Mediratta
size shorthand, and convert the simple_uploader code to use it.
2009-06-04set filesize limit of swfupload to the same value as upload_max_filesizejhilden
* now users get an error when they try to upload too big files * this should fix bug #337 * maybe it also needs to check for max_post_size
2009-06-01Security pass over all controller code. Mostly adding CSRF checkingBharat Mediratta
and verifying user permissions, but there are several above-the-bar changes: 1) Server add is now only available to admins. This is a hard requirement because we have to limit server access (eg: server_add::children) to a user subset and the current permission model doesn't include that. Easiest fix is to restrict to admins. Got rid of the server_add permission. 2) We now know check permissions at every level, which means in controllers AND in helpers. This "belt and suspenders" approach will give us defense in depth in case we overlook it in one area. 3) We now do CSRF checking in every controller method that changes the code, in addition to the Forge auto-check. Again, defense in depth and it makes scanning the code for security much simpler. 4) Moved Simple_Uploader_Controller::convert_filename_to_title to item:convert_filename_to_title 5) Fixed a bug in sending notification emails. 6) Fixed the Organize code to verify that you only have access to your own tasks. In general, added permission checks to organize which had pretty much no validation code. I did my best to verify every feature that I touched.
2009-05-31Run p::clean() on any variables that contain data entered by users.Bharat Mediratta
2009-05-27Restructure things so that the application is now just another module.Bharat Mediratta
Kohana makes this type of transition fairly straightforward in that all controllers/helpers/etc are still located in the cascading filesystem without any extra effort, except that I've temporarily added a hack to force modules/gallery into the module path. Rename what's left of "core" to be "application" so that it conforms more closely to the Kohana standard (basically, just application/config/config.php which is the minimal thing that you need in the application directory) There's still considerable work left to be done here.