| Age | Commit message (Collapse) | Author | |
|---|---|---|---|
| 2010-01-30 | Protect REST login controller from brute force attacks too. | Andy Staudacher | |
| And make the REST auth token less predictable by using a better source for randomness. | |||
| 2010-01-30 | Update install.sql -- gallery version jumps from 23 to 25 due to a mistake | Bharat Mediratta | |
| in the version 24 upgrade code. Update packager to serialize files so that we can serialize the new .htaccess files Update init_var.php to include the newly serialized .htaccess files. Fixes ticket #587. | |||
| 2010-01-30 | Lock down web access to var/uploads, var/tmp and var/logs using .htaccess | Bharat Mediratta | |
| Fixes ticket #587. | |||
| 2010-01-30 | Don't override the password in the database if it's empty in the form. | Bharat Mediratta | |
| Fixes ticket #995. | |||
| 2010-01-30 | Prevent brute force login attacks by reducing login attempts to 1 per | Bharat Mediratta | |
| minute after there have been 5 consecutive failed login attempts. Fix for ticket #589. | |||
| 2010-01-30 | Make url::merge() function use the same exact definition as url_Core::merge() | Bharat Mediratta | |
| 2010-01-30 | Fix the valid_admin code -- it was considering all non-admins invalid. | Bharat Mediratta | |
| Fixes ticket #997 (highest prime under 1000!) | |||
| 2010-01-30 | Dump out validation errors so that we have some extra information in the logs. | Bharat Mediratta | |
| 2010-01-30 | Fix #992: Digibug pops up a blank page and doesn't allow printing | Bharat Mediratta | |
| form::hidden() changed in K24 breaking this. Also fixed the spelling of "$order_params" | |||
| 2010-01-30 | Remap parent_id and album_cover_item_id to and from RESTful urls. | Bharat Mediratta | |
| 2010-01-30 | The user must have some edit permission somewhere to create a tag | Bharat Mediratta | |
| 2010-01-30 | Make the error page more robust in the case where there's a failure | Bharat Mediratta | |
| early on in the framework code before we can load Gallery_I18n.php | |||
| 2010-01-29 | Use ? or & as appropriate when appending output=html. | Bharat Mediratta | |
| 2010-01-29 | Add missing permission checks. | Bharat Mediratta | |
| Make the tag relationship an associative array. | |||
| 2010-01-29 | Use var_export instead of print_r for better clarity. | Bharat Mediratta | |
| 2010-01-29 | Don't forget to flush the relative_url_cache when updating the slug. | Bharat Mediratta | |
| 2010-01-29 | Go through all slugs and make them legal values. | Bharat Mediratta | |
| Upgrade gallery3 module to version 23 | |||
| 2010-01-29 | Oops, forgot to bump the version to 2 in install(). | Bharat Mediratta | |
| 2010-01-29 | Merge branch 'master' of git@github.com:gallery/gallery3 | Bharat Mediratta | |
| 2010-01-29 | Oops, somebody (me?) forgot to update the gallery module version | Bharat Mediratta | |
| number in gallery_installer::install() so the install.sql was out of sync. | |||
| 2010-01-29 | Strongly type the argument list to the model::validate method. | Tim Almdal | |
| 2010-01-29 | Merge branch 'master' of git@github.com:gallery/gallery3 | Tim Almdal | |
| Conflicts: modules/gallery/views/in_place_edit.html.php | |||
| 2010-01-29 | Replace <?= form::close() ?> with </form>. Also add a call to ↵ | Tim Almdal | |
| access::csrf_form_field in the form template. Fixes ticket #996. | |||
| 2010-01-29 | Work around a weirdness where empty() doesn't work on input values. | Bharat Mediratta | |
| 2010-01-29 | Clean up form validation code. | Bharat Mediratta | |
| 2010-01-29 | Clean up form validation code. | Bharat Mediratta | |
| 2010-01-29 | Stop using obsolete form::close() | Bharat Mediratta | |
| Update the way we include the hidden CSRF field for InPlaceEdit. | |||
| 2010-01-28 | Add page_type to the rotate and delete context menu items so that the | Bharat Mediratta | |
| quick menu knows where to send you after the action is done. | |||
| 2010-01-28 | Add @todo. | Bharat Mediratta | |
| 2010-01-28 | Use identity::set_active_user() instead of auth::login() when we | Bharat Mediratta | |
| change providers otherwise the user_installer code is going to be calling auth::login() which causes all kinds of unexpected weirdness, like it triggers the handler in gallery_event which detects graphics toolkits, and that's only supposed to run on the first admin login. | |||
| 2010-01-28 | In auth::login() make the user active before trying to save it, else | Bharat Mediratta | |
| the validation code fails because it expects there to be an active user. | |||
| 2010-01-28 | Use auth::login() when we initially log in the admin user. | Bharat Mediratta | |
| 2010-01-28 | Localize edit form error messages. | Bharat Mediratta | |
| 2010-01-28 | Cast the SafeString $task->status to (string) so that it doesn't come | Bharat Mediratta | |
| down to the JS as an object. | |||
| 2010-01-28 | Merge branch 'master' of git@github.com:gallery/gallery3 | Bharat Mediratta | |
| 2010-01-28 | cast $task->done to bool so that it doesn't show up as "0" to the JS, | Bharat Mediratta | |
| which will interpret that as a true value, when it's not. | |||
| 2010-01-28 | Fix language preference block / language cookie reading. | Andy Staudacher | |
| The preference block must have been broken by a jquery update, and the cookie reading by a Kohana update. | |||
| 2010-01-28 | Make the return button work in chrome, FF, IE, safari and opera. | Tim Almdal | |
| 2010-01-28 | Merge branch 'master' of git@github.com:gallery/gallery3 | Tim Almdal | |
| 2010-01-28 | Found another broken link for what should have been the user profile | Tim Almdal | |
| 2010-01-28 | Reviewed DIRTY_ATTR | Bharat Mediratta | |
| 2010-01-28 | Rename $class to $css_class for clarity. | Bharat Mediratta | |
| 2010-01-28 | Reviewed all DIRTY_JS entries | Bharat Mediratta | |
| 2010-01-28 | Secure the t("Completed") call. | Bharat Mediratta | |
| 2010-01-28 | Secure the t("Continue") strings in javascript. | Bharat Mediratta | |
| 2010-01-28 | Make the varible for the profile name more descriptive and clean the label | Tim Almdal | |
| 2010-01-28 | Update the xss golden file for user profile changes. | Tim Almdal | |
| 2010-01-28 | Don't show a link to the user profile for the guest user | Tim Almdal | |
| 2010-01-28 | Do all the html::clean|purify calls in the views and not the controller. ↵ | Tim Almdal | |
| Also clean the subject line and email message body of the contact user email. | |||
| 2010-01-27 | Localize validation messages. | Bharat Mediratta | |
