| Age | Commit message (Collapse) | Author | |
|---|---|---|---|
| 2009-06-02 | make cleanm static | Tim Almdal | |
| 2009-06-02 | Fix for ticket #320 | Tim Almdal | |
| 2009-06-02 | Extend L10n client to provide UI for plural translation. | Andy Staudacher | |
| Ticket 148. | |||
| 2009-06-01 | Unescape %20 into " " also. | Bharat Mediratta | |
| 2009-06-01 | Security pass over all controller code. Mostly adding CSRF checking | Bharat Mediratta | |
| and verifying user permissions, but there are several above-the-bar changes: 1) Server add is now only available to admins. This is a hard requirement because we have to limit server access (eg: server_add::children) to a user subset and the current permission model doesn't include that. Easiest fix is to restrict to admins. Got rid of the server_add permission. 2) We now know check permissions at every level, which means in controllers AND in helpers. This "belt and suspenders" approach will give us defense in depth in case we overlook it in one area. 3) We now do CSRF checking in every controller method that changes the code, in addition to the Forge auto-check. Again, defense in depth and it makes scanning the code for security much simpler. 4) Moved Simple_Uploader_Controller::convert_filename_to_title to item:convert_filename_to_title 5) Fixed a bug in sending notification emails. 6) Fixed the Organize code to verify that you only have access to your own tasks. In general, added permission checks to organize which had pretty much no validation code. I did my best to verify every feature that I touched. | |||
| 2009-06-01 | Fix a place where I shouldn't have renamed "core" to "gallery", breaking ↵ | Bharat Mediratta | |
| maintenance mode. | |||
| 2009-06-01 | Normalize the random values used in the blocks_dashboard_xxx vars so | Bharat Mediratta | |
| that install.sql is more stable. | |||
| 2009-06-01 | Do a little cleanup and get rid of code left-over from when this | Bharat Mediratta | |
| controller rendered HTML. Also, catch all exceptions at the root level and restore the change in 84ce0cdefda162917c7b01722a7259ac52c4e30d which appears to have gotten lost in the shuffle. | |||
| 2009-05-31 | Merge branch 'master' of git@github.com:gallery/gallery3 | Tim Almdal | |
| 2009-05-31 | Move the sql packaging code from installer into the gallery module. It must ↵ | Tim Almdal | |
| be run from the command line and will throw a 404 if it is run as a web request. | |||
| 2009-05-31 | Don't let relative_path() try to update the database if the Item_Model | Bharat Mediratta | |
| is not loaded, else you get weird errors. | |||
| 2009-05-31 | Accidentally broke the AllowOverride info url in the migration from | Bharat Mediratta | |
| core -> modules/gallery. Fixed, and incidentally make the link appear in a new tab/window. | |||
| 2009-05-31 | Remove extra blank line | Bharat Mediratta | |
| 2009-06-01 | Convert %7E to ~ when proxying files to work around Firefox's overzealous ↵ | bharat | |
| security model. | |||
| 2009-05-31 | Update for changes to admin_users_group.html.php | Bharat Mediratta | |
| 2009-05-31 | Relax the regex we use to extract the movie size so that it works with | Bharat Mediratta | |
| the new version of ffmpeg that I have on my dev box (ffmpeg 0.5-svn17737+3:0.svn20090303-1) | |||
| 2009-05-31 | Switch to using html::specialchars() for cleaning. | Bharat Mediratta | |
| 2009-05-31 | Updated for renamed variable | Bharat Mediratta | |
| 2009-05-31 | Merge branch 'master' of git://github.com/gallery/gallery3 | Bharat Mediratta | |
| 2009-05-31 | Xss scanner golden file. Up to date. | Bharat Mediratta | |
| 2009-05-31 | Merge branch 'master' of git@github.com:gallery/gallery3 | Tim Almdal | |
| 2009-05-31 | Update the clean/dirty format, check all ffiles instead of just one (which ↵ | Bharat Mediratta | |
| was for debugging) | |||
| 2009-05-31 | Run p::clean() on any variables that contain data entered by users. | Bharat Mediratta | |
| 2009-05-31 | First pass at an XSS security test, along with the "p" helper which | Bharat Mediratta | |
| can clean HTML output. | |||
| 2009-05-31 | Remove the test images from the gallery module and move it to the developer ↵ | Tim Almdal | |
| module in -contrib | |||
| 2009-05-30 | Add transparency for overlay in IE 7 and 8 | Chad Kieffer | |
| 2009-05-30 | gate $can_edit and $can_add on whether or not we have an $item at all | Bharat Mediratta | |
| (fixes a bug where search doesn't render because it has no item). | |||
| 2009-05-30 | White space fixes | Chad Kieffer | |
| 2009-05-29 | remove scaffolding code | tim almdal | |
| 2009-05-29 | Use the relative_path_cache to look up items which should be a faster | Bharat Mediratta | |
| query than using the level + the components. | |||
| 2009-05-29 | Don't show "edit permissions" for non-albums. | Bharat Mediratta | |
| 2009-05-29 | Move credits message into a variable, which can be changed in Admin > | Bharat Mediratta | |
| Settings > Advanced. It's stored in the variable as an internationalized string and localized at output time. | |||
| 2009-05-29 | Require "add" permission to show the add form. | Bharat Mediratta | |
| 2009-05-29 | Don't show the add photo/album options to users who don't have the | Bharat Mediratta | |
| permission. This isn't a security hole, since they can't actually add stuff.. but they can try and fail which is a bad user experience. Also fix it up so that we show the option menu only if there's stuff to show, and cache some of the permissions for performance (which I'm guessing at-- didn't benchmark it). | |||
| 2009-05-29 | Remove a completed @todo | Bharat Mediratta | |
| 2009-05-29 | Revert test code inserted in 88a3d43ba9b9377ba6bbe21a4547220ae3a37276 | Bharat Mediratta | |
| which showed stack traces to non-admins. | |||
| 2009-05-28 | Restore calls to module::load_modules() after ↵ | Bharat Mediratta | |
| install/activate/deactivate/uninstall events. | |||
| 2009-05-28 | Load the gallery module in load_modules(), but put it at the end of | Bharat Mediratta | |
| the module list (to match its location in the cascading filesystem) | |||
| 2009-05-28 | Force modules/gallery to be at the end of the module load path, so | Bharat Mediratta | |
| that all other modules can override the core code. | |||
| 2009-05-28 | Prepend all code files we copy from Gallery2 and put into var with our | Bharat Mediratta | |
| code preamble for security. Update File_Structure_Test::code_files_start_with_preamble_test to check all the php files in var, too. | |||
| 2009-05-28 | Update tests to reflect cache-buster param on thumbnail urls. | Bharat Mediratta | |
| 2009-05-28 | Rename Core_Installer_Test -> Gallery_Installer_Test to match the | Bharat Mediratta | |
| change from application -> modules/gallery. | |||
| 2009-05-28 | Flush the model cache as appropriate every time we call ORM::save(). | Bharat Mediratta | |
| Fixes ticket #301 | |||
| 2009-05-28 | Fix broken html::script() and url::file() references to the newly | Bharat Mediratta | |
| moved gallery module. | |||
| 2009-05-28 | Remove unnecessary (and broken) <form/> | Bharat Mediratta | |
| 2009-05-27 | Fix up another place where we were incorrectly referencing the gallery module. | Bharat Mediratta | |
| 2009-05-27 | Normalize root update time in the installer | Bharat Mediratta | |
| Rebuild install.sql | |||
| 2009-05-27 | Fix a typo in the class name | Bharat Mediratta | |
| 2009-05-27 | Convert a few more references of APPPATH to MODPATH/gallery | Bharat Mediratta | |
| 2009-05-27 | Show the scaffolding link if the controller is around. | Bharat Mediratta | |
