| Age | Commit message (Collapse) | Author | 
|---|
|  | other data leaks. | 
|  |  | 
|  | and verifying user permissions, but there are several above-the-bar
changes:
1) Server add is now only available to admins.  This is a hard
   requirement because we have to limit server access (eg:
   server_add::children) to a user subset and the current permission
   model doesn't include that.  Easiest fix is to restrict to admins.
   Got rid of the server_add permission.
2) We now know check permissions at every level, which means in
   controllers AND in helpers.  This "belt and suspenders" approach will
   give us defense in depth in case we overlook it in one area.
3) We now do CSRF checking in every controller method that changes the
   code, in addition to the Forge auto-check.  Again, defense in depth
   and it makes scanning the code for security much simpler.
4) Moved Simple_Uploader_Controller::convert_filename_to_title to
   item:convert_filename_to_title
5) Fixed a bug in sending notification emails.
6) Fixed the Organize code to verify that you only have access to your
   own tasks.  In general, added permission checks to organize which had
   pretty much no validation code.
I did my best to verify every feature that I touched. | 
|  |  | 
|  | gallery module.  This type of mass update is prone to some small bugs. | 
|  | rewritten by beta2, pull all of its "tenticles" back into itself and
out of core or tags module. | 
|  | Install: <module>_installer::install() is called, any necessary tables
are created.
Activate: <module>_installer::activate() is called.  Module
controllers are routable, helpers are accessible, etc.  The module is
in use.
Deactivate: <module>_installer::deactivate() is called.  Module code
is not accessible or routable.  Module is *not* in use, but its tables
are still around.
Uninstall: <module>_installer::uninstall() is called.  Module is
completely removed from the database.
Admin > Modules will install and activate modules, but will only
deactivate (will NOT uninstall modules). | 
|  |  | 
|  | the draggable functionality to be activated | 
|  | I've missed any spots let me know. | 
|  | organize feature.
2) Remove the tag functionality at this point
3) Added a callback to handle validating conflicting names (only used
by organize at this point.
4) Closes #231 | 
|  | can't edit, but we are getting closer :-).
This change sets up a framework for modules to contribute edit panels
to the organize drawer. Currently implemented General (albums and
photos), Sort Order (albums only) and Manage Tags | 
|  |  | 
|  |  | 
|  | drawer | 
|  | 2) And a 1em left margin to provide more spacing, so the lasso is less inclusive | 
|  | doesn't have to be selected first | 
|  | 2) Drawer closes if no images or albums are selected | 
|  | make_album_cover() functions into it. | 
|  | into the core helper.  Clean up interactions so that when we remove an
album cover we pick a new one, or clean out the old album cover if
there are no other choices. | 
|  | feature its provided for. | 
|  |  | 
|  |  | 
|  |  | 
|  |  | 
|  | when the drawer opens.  This way the drawer is never scrolled. | 
|  |  | 
|  | make_album_cover and remove_album_cover methods in Item_Model.
Usage: $photo->make_album_cover()  $album->remove_album_cover() | 
|  |  | 
|  |  | 
|  | request types.
2) Enable/Disable the drawer handle buttons depending on the number of
items selcted
3) Image rotation works. | 
|  | Rearrange the layout as per discussion with thumb, start the drawer
functionality. Still to do... 
1) Add the processing behind the buttons on the drawer handle
2) Enable the drawer buttons when something is selected
3) Create a copy of the thumbs for the drawer
4) Add the bulk editting functionality to the drawer | 
|  | 2) Provide status and error messages back to the user | 
|  | can be cancelled. | 
|  | 2) Fix where the microthumb was removed even if the move was cancelled | 
|  | Refactored the javascript to minimize duplication. | 
|  | 2) Add the album name to the task name | 
|  |  | 
|  |  | 
|  |  | 
|  | 2) Improved drop location determination
3) Add a revert if dropped on an invalid target
4) Add a popup dialog to display ajax errors
Still to do progress bar, pause/continue and status messages | 
|  |  | 
|  |  | 
|  | objects into variables) | 
|  | - Make sure the thumbgrid will utoscroll when dragging
- And an ordinal attribute to the thumbnail when generated, based on the
current sort order of the album. | 
|  | handle the edge cases where the draggable is dropped on the micro
thumbnail panel | 
|  |  | 
|  | this point you can select microthumbs, by clicking on them, ctrl-click
will add to the selection.  You can select by drawing a lasso around
images. Holding the ctrl will add the lassoed thumbs to the selection.
Once slected, thumbs can be dragged and dropped within the current
At this point no background processing takes place | 
|  |  | 
|  | drag and drop to work.  And to get it to layout properly.  Any
thoughts would be appreciated. |