summaryrefslogtreecommitdiff
path: root/modules/gallery
AgeCommit message (Collapse)Author
2009-06-04Skip over busted images when rebuilding. Change graphics::generate()Bharat Mediratta
to return true/false on whether or not it could rebuild the image properly, then track the broke images in the task and ignore them. Fixes ticket #344.
2009-06-04Fix a bug in Item_Model::get_position() where we incorrectly using theBharat Mediratta
grandparent id. Oops. This caused navigation from photo back up to album to be broken. Also update Photos_Controller to use the active sort order.. it was still hardcoded to use the id. It's more efficient now, yay. Fixes ticket #340.
2009-06-04Updated for csrf in admin.html.phpBharat Mediratta
2009-06-04Convert single quotes to double quotes.Bharat Mediratta
2009-06-04Fix internationalization to use one long string and placeholders.Bharat Mediratta
Removed the <br/> though since we're trying to avoid structural HTML in internationalized strings.
2009-06-04Merge branch 'master' of git@github.com:gallery/gallery3Bharat Mediratta
2009-06-04Work around a problem with the CGI sapi on urls that don't containBharat Mediratta
index.php (ie, /gallery3 instead of /gallery3/index.php) that causes is to mis-route.
2009-06-04Merge branch 'master' of git@github.com:gallery/gallery3jhilden
2009-06-04fixed another bug with the filesize unit and added a better error messagejhilden
Merge branch 'master' of git@github.com:gallery/gallery3 Conflicts: modules/gallery/views/simple_uploader.html.php
2009-06-04Make sure the item is loaded in parse_url() before we use it.Bharat Mediratta
2009-06-04fixed stuffjhilden
2009-06-04Add MY_num containing num::convert_to_bytes() which supports PHP'sBharat Mediratta
size shorthand, and convert the simple_uploader code to use it.
2009-06-04Merge branch 'master' of git@github.com:gallery/gallery3Bharat Mediratta
2009-06-04Let the Akismet module create the statistics menu, since it's the onlyBharat Mediratta
one that uses it. Perhaps this is not the best solution, but it's the pragmatic one.
2009-06-04set filesize limit of swfupload to the same value as upload_max_filesizejhilden
* now users get an error when they try to upload too big files * this should fix bug #337 * maybe it also needs to check for max_post_size
2009-06-04Change "CLEAN" to an empty string to see if it's better visually.Bharat Mediratta
Looks like it is.
2009-06-04Update xss clean listBharat Mediratta
2009-06-03Sanitize all data we return via json_encode() to guard against XSS andBharat Mediratta
other data leaks.
2009-06-02made "Add photos" its own site menu itemjhilden
* open for suggestions on the submenu item labels * @bharat: not sure about the add photos menu item id in the dropdown case
2009-06-02Merge branch 'master' of git@github.com:gallery/gallery3Bharat Mediratta
2009-06-02Have server_add turn the "Add Photo" menu option into a dropdown andBharat Mediratta
make "Add from Server" a 2nd option there. This requires adding the Menu::remove() API function.
2009-06-02Improve test isolation so that Albums_Controller_Test doesn't fail when run ↵Tim Almdal
with Photos_Controller_Test
2009-06-02Restore "view" permissions on the root album in teardown.Bharat Mediratta
2009-06-02fix the xss_security_test in regards to the renaming of thumb_tag, ↵Tim Almdal
resize_tag and move_tag.
2009-06-02make cleanm staticTim Almdal
2009-06-02Fix for ticket #320Tim Almdal
2009-06-02Extend L10n client to provide UI for plural translation.Andy Staudacher
Ticket 148.
2009-06-01Unescape %20 into " " also.Bharat Mediratta
2009-06-01Security pass over all controller code. Mostly adding CSRF checkingBharat Mediratta
and verifying user permissions, but there are several above-the-bar changes: 1) Server add is now only available to admins. This is a hard requirement because we have to limit server access (eg: server_add::children) to a user subset and the current permission model doesn't include that. Easiest fix is to restrict to admins. Got rid of the server_add permission. 2) We now know check permissions at every level, which means in controllers AND in helpers. This "belt and suspenders" approach will give us defense in depth in case we overlook it in one area. 3) We now do CSRF checking in every controller method that changes the code, in addition to the Forge auto-check. Again, defense in depth and it makes scanning the code for security much simpler. 4) Moved Simple_Uploader_Controller::convert_filename_to_title to item:convert_filename_to_title 5) Fixed a bug in sending notification emails. 6) Fixed the Organize code to verify that you only have access to your own tasks. In general, added permission checks to organize which had pretty much no validation code. I did my best to verify every feature that I touched.
2009-06-01Fix a place where I shouldn't have renamed "core" to "gallery", breaking ↵Bharat Mediratta
maintenance mode.
2009-06-01Normalize the random values used in the blocks_dashboard_xxx vars soBharat Mediratta
that install.sql is more stable.
2009-06-01Do a little cleanup and get rid of code left-over from when thisBharat Mediratta
controller rendered HTML. Also, catch all exceptions at the root level and restore the change in 84ce0cdefda162917c7b01722a7259ac52c4e30d which appears to have gotten lost in the shuffle.
2009-05-31Merge branch 'master' of git@github.com:gallery/gallery3Tim Almdal
2009-05-31Move the sql packaging code from installer into the gallery module. It must ↵Tim Almdal
be run from the command line and will throw a 404 if it is run as a web request.
2009-05-31Don't let relative_path() try to update the database if the Item_ModelBharat Mediratta
is not loaded, else you get weird errors.
2009-05-31Accidentally broke the AllowOverride info url in the migration fromBharat Mediratta
core -> modules/gallery. Fixed, and incidentally make the link appear in a new tab/window.
2009-05-31Remove extra blank lineBharat Mediratta
2009-06-01Convert %7E to ~ when proxying files to work around Firefox's overzealous ↵bharat
security model.
2009-05-31Update for changes to admin_users_group.html.phpBharat Mediratta
2009-05-31Relax the regex we use to extract the movie size so that it works withBharat Mediratta
the new version of ffmpeg that I have on my dev box (ffmpeg 0.5-svn17737+3:0.svn20090303-1)
2009-05-31Switch to using html::specialchars() for cleaning.Bharat Mediratta
2009-05-31Updated for renamed variableBharat Mediratta
2009-05-31Merge branch 'master' of git://github.com/gallery/gallery3Bharat Mediratta
2009-05-31Xss scanner golden file. Up to date.Bharat Mediratta
2009-05-31Merge branch 'master' of git@github.com:gallery/gallery3Tim Almdal
2009-05-31Update the clean/dirty format, check all ffiles instead of just one (which ↵Bharat Mediratta
was for debugging)
2009-05-31Run p::clean() on any variables that contain data entered by users.Bharat Mediratta
2009-05-31First pass at an XSS security test, along with the "p" helper whichBharat Mediratta
can clean HTML output.
2009-05-31Remove the test images from the gallery module and move it to the developer ↵Tim Almdal
module in -contrib
2009-05-30Add transparency for overlay in IE 7 and 8Chad Kieffer