summaryrefslogtreecommitdiff
path: root/modules
AgeCommit message (Expand)Author
2009-08-30(mostly harmless) XSS fix in server addAndy Staudacher
2009-08-30XSS fixes in admin_comments.html.phpAndy Staudacher
2009-08-30Check for href="<?= $foo ?>" (malicious "javascript:..." string)Andy Staudacher
2009-08-30Updating XSS golden fileAndy Staudacher
2009-08-30Merge commit 'upstream/master'Andy Staudacher
2009-08-30Tabs to spaces cleanupAndy Staudacher
2009-08-30Updating uses of html::js_string and SafeString::for_js (value now contains s...Andy Staudacher
2009-08-30Rename clean_js to js_string and have it return a complete JS string (with de...Andy Staudacher
2009-08-30Don't try to move an item into its own descendant hierarchy. Just leave it o...Bharat Mediratta
2009-08-30Use is_descendant() API inside move_to() for clarity.Bharat Mediratta
2009-08-30CSS rename: gMicroThumbXxx -> gOrganizeMicroThumbXxx to make it clearBharat Mediratta
2009-08-30Rename gAlbumText to gOrganizeAlbumText for consistency since this isBharat Mediratta
2009-08-30remove unused #gOrganizeDialogBharat Mediratta
2009-08-30Manage the selection so we don't automatically select an albumBharat Mediratta
2009-08-30Precalculate the organize tree based on the selected album and renderBharat Mediratta
2009-08-30Change the processing time for search_task and exif_task to start theBharat Mediratta
2009-08-30Improve no_tabs test to print out a complete list of files + line numbers + l...Andy Staudacher
2009-08-30Add $theme-> methods to Xss whitelist for HTML safety.Andy Staudacher
2009-08-30Change all instances of SafeString::of_safe_html() to html::mark_safe() in vi...Andy Staudacher
2009-08-30Fixing typoAndy Staudacher
2009-08-29Minor cleanupAndy Staudacher
2009-08-29Update all code to use helper method html::clean(), html::purify(), ... inste...Andy Staudacher
2009-08-29Adding html::clean(), ::purify(), etc.Andy Staudacher
2009-08-29Delete obsolete comment and tighten the code in site_menu().Bharat Mediratta
2009-08-29Remove try/catch in resize() since that will swallow any exceptionsBharat Mediratta
2009-08-29Merge branch 'master' of git@github.com:gallery/gallery3Bharat Mediratta
2009-08-29Change the organize tree to expand/collapse. It doesn't properly openBharat Mediratta
2009-08-29Undo url helper changes - url methods no longer return a SafeString.Andy Staudacher
2009-08-29you can close the l10n client directly from its interface now, without going ...jhilden
2009-08-29XSS fixesAndy Staudacher
2009-08-29Fix for ticket #628:Tim Almdal
2009-08-29Fix invalida syntax on trying to parse the progress bar percentageTim Almdal
2009-08-29L10n fixes for the admin_languages page, and JS/XSS cleanup of the organize v...Andy Staudacher
2009-08-29Fix link in l10n UI (for SafeString changes)Andy Staudacher
2009-08-29Merge commit 'upstream/master'Andy Staudacher
2009-08-29Fixing all detected XSS vectors in PHP->JS code.Andy Staudacher
2009-08-29Merge branch 'master' of git@github.com:gallery/gallery3Chad Kieffer
2009-08-29Update status message styles. Lighten backgrounds, don't show background on A...Chad Kieffer
2009-08-29Bugfix: Don't forget to copy the _is_purified_html flag when cloning a SafeSt...Andy Staudacher
2009-08-29Refactor all calls of p::clean() to SafeString::of() and p::purify() to SafeS...Andy Staudacher
2009-08-29Add more factory methods for convenience:Andy Staudacher
2009-08-29Merge branch 'talmdal_branch' of git@github.com:gallery/gallery3Bharat Mediratta
2009-08-29Add a test for Comment_Model::viewable().Bharat Mediratta
2009-08-29Fix active() to not use user::guest() as the fallback for our Session::get() ...Bharat Mediratta
2009-08-29Clean up the test and get it working.Bharat Mediratta
2009-08-29Adding SafeString::for_html_attr()Andy Staudacher
2009-08-29Rename $comment_model to $comments.Bharat Mediratta
2009-08-29Fix for 641... extend viewable functionality to comments. Viewable unit test ...Tim Almdal
2009-08-29Merge branch 'master' of git@github.com:gallery/gallery3Bharat Mediratta
2009-08-29Have url::site() and other methods return a SafeString, just as t() and t2().Andy Staudacher