Age | Commit message (Collapse) | Author |
|
|
|
This reverts commit c80d2da0a95a63b76f5a4c835f1a0e1022ec2f53.
Conflicts:
modules/gallery/models/item.php
|
|
This reverts commit 809e52d80cbf3beb75b238fddb0da3951fb9a8e7.
|
|
Revert "Changed access::user_can to force the owner of an item to have"
This reverts commit 0b97cfd6f098be08be5f3cf1dbca1cce580ae330.
|
|
Revert "It helps to save before committing :-)"
This reverts commit 0d76d6fd77f53e9e92a9a013cd112c69217f3ceb.
|
|
|
|
|
|
|
|
view permission on the parent. Added a whitelist of allowable
owner permissions.
If the requested permission is view and the user requesting access
is the owner, check that they have view permission to the parent.
|
|
1) Change access_Core::user_can to return true for all permissions if the
owner is the specified user.
2) Change Item_Model::viewable to set the owner_id is the first view_restriction
This allowed simplification of the generating the where clause to a single
$this->orwhere instead of a where and an orwhere.
|
|
the album.
|
|
was updated via the admin panel.
|
|
|
|
|
|
|
|
|
|
This required putting a wrapper view around the forms and passing
this view as the parameter to the item_edit_form event. The view
contains a $script variable that the modules can add script to be
included in the form html when rendered as part of the ajax response.
|
|
on the tag add form in the tag sidebar block. Updated the xss golden file as well. Still to do figure out how toget it into the edit popup dialog
|
|
|
|
|
|
in global data." check in the Input library.
|
|
|
|
|
|
|
|
Conflicts:
modules/gallery/helpers/access.php
|
|
|
|
user_add_form_admin admin adding a user
user_edit_form_admin admin editing a user
user_add_form_admin_completed successfully added a user (admin)
user_edit_form user editing their own settings
user_edit_form_completed successfully edited a user (admin and user editing own settings)
|
|
attribute to contain the url of the tag cloud controller.
|
|
made in dbeadc1407293d0c7af36723db6fe5699890b845
|
|
|
|
commas or semi-colons as separators
|
|
|
|
Related to 719c59e0402464a0e2b14915f6d10218ff5d4729
(cherry picked from commit 831bf63c236fe88624470d2906729e035e9dbfc8)
|
|
(cherry picked from commit c9017ae2f21ff8f5d745f296a636b80a30add6a1)
|
|
- DENY = false
- ALLOW = true
- UNKNOW = null (for intent only)
- INHERIT = null (for cache)
Upgrade is not included for now.
(cherry picked from commit 719c59e0402464a0e2b14915f6d10218ff5d4729)
|
|
|
|
|
|
1) Specifically catch Kohana_404_Exception and let other exceptions pass, the
test framework will report them as errors
2) Simplify some testing idioms
3) Change malicious address to a legal addr
|
|
This patch allows users with only view permission to request fullsize
prints using Digibug. There is now a Digibug config file that contains
the IP ranges of the Digibug servers. Any request for the full size
image via the print proxy must come from within the ranges in the config
file.
The reason for the "if (!Test_Mode) {..." is that the print proxy makes a
call to Kohana::close_buffers, which closes all the output buffers and then
we see the image download on the console which messes up the test output.
|
|
|
|
|
|
|
|
theme. Because the theme comes first, this means that themes can
override any module resources, at the cost that we no longer have
namespacing for JS and CSS files.
The only file getting used outside of this model is
themes/default/screen.css which is used in the admin theme. I fixed
that by copying screen.css into admin_default and renaming its
screen.css to admin_screen.css. I also copied over all the images
that it was referencing.
Fixes tickets #48 and #539.
Theme API changes:
- theme_script(), theme_url() and theme_css() are no longer needed
- script(), url() and css() now refer to the first matching asset in
the module load path, where gallery3/lib is at the end of the path
|
|
|
|
have "view" access to the item the notification is being generated for.
Fix for ticket: #538.
|
|
|
|
groups from the session
|
|
Related to 719c59e0402464a0e2b14915f6d10218ff5d4729
|
|
|
|
specified permission to the item. Changed can to delegate to this method
passing in the active user.
|