]>
git.mjollnir.org Git - s9y.git/log
garvinhicking [Fri, 10 Jun 2005 08:27:45 +0000 (08:27 +0000)]
fix parse error
garvinhicking [Fri, 10 Jun 2005 08:14:24 +0000 (08:14 +0000)]
missing function, thanks to Karotte
garvinhicking [Thu, 9 Jun 2005 09:24:43 +0000 (09:24 +0000)]
fix type to length 200 so that the index key is not > 500.
Since only two users ever reported problems I'm not creating a new version stepping only for this.
omidmottaghi [Tue, 7 Jun 2005 21:34:49 +0000 (21:34 +0000)]
updated
capriskye [Tue, 7 Jun 2005 17:46:03 +0000 (17:46 +0000)]
updated language for chinese traditional
capriskye [Tue, 7 Jun 2005 17:40:35 +0000 (17:40 +0000)]
updated language for chinese traditional
capriskye [Tue, 7 Jun 2005 17:31:09 +0000 (17:31 +0000)]
elf2000 [Tue, 7 Jun 2005 15:31:32 +0000 (15:31 +0000)]
o translation updated.
garvinhicking [Tue, 7 Jun 2005 12:52:12 +0000 (12:52 +0000)]
Updated dutch language, thanks to Bryan Alibaks!
capriskye [Tue, 7 Jun 2005 04:42:25 +0000 (04:42 +0000)]
chinese traditional language
elf2000 [Tue, 7 Jun 2005 02:43:38 +0000 (02:43 +0000)]
o translation updated.
garvinhicking [Mon, 6 Jun 2005 13:26:19 +0000 (13:26 +0000)]
use "-" instead of "_"
garvinhicking [Mon, 6 Jun 2005 13:11:22 +0000 (13:11 +0000)]
Fix broken installer, add groups upon installation.
garvinhicking [Mon, 6 Jun 2005 11:45:20 +0000 (11:45 +0000)]
fix wrong permission check
garvinhicking [Mon, 6 Jun 2005 07:45:00 +0000 (07:45 +0000)]
Change of behavior: If a user does not have a certain privilege, he should not be able to set that privilege for others / other groups
capriskye [Mon, 6 Jun 2005 00:49:14 +0000 (00:49 +0000)]
event_bbcode Chinese Traditional UTF-8 language
garvinhicking [Sun, 5 Jun 2005 20:39:34 +0000 (20:39 +0000)]
ACL group permission setup for Serendipity.
Very experimental. I tested it until my head went into flames.
Testers very much appreciated. There's a little notice in the docs/NEWs
file for future TODOs.
I need QA guys who check if the system is exploitable; please read
more on the mailinglist.
garvinhicking [Sun, 5 Jun 2005 18:40:27 +0000 (18:40 +0000)]
Fix a Feed Category RSS bug. Thanks to hanno :)
garvinhicking [Sun, 5 Jun 2005 17:53:31 +0000 (17:53 +0000)]
Make bblog importer recognize trackbacks. Thanks to hanno!
garvinhicking [Fri, 3 Jun 2005 10:26:28 +0000 (10:26 +0000)]
lang updates (the new constants for my pending usergroups patch slipped through)
garvinhicking [Tue, 31 May 2005 13:55:20 +0000 (13:55 +0000)]
Remove Cache-restricting headers to allow caching of the CSS
garvinhicking [Mon, 30 May 2005 08:51:51 +0000 (08:51 +0000)]
Fix spartacus problems with dependant plugins in the same path
garvinhicking [Mon, 30 May 2005 08:13:34 +0000 (08:13 +0000)]
Add div.serendipity_section_(comments|trackbacks|commentform) containers
for CSS styling. Solves RFE #
1210889
garvinhicking [Mon, 30 May 2005 08:05:17 +0000 (08:05 +0000)]
Solve RFE #
1210676 : Assign DIV-Containers for CSS-styling the search results
garvinhicking [Mon, 30 May 2005 07:53:12 +0000 (07:53 +0000)]
PGSql patch to properly detect isdraft state
elf2000 [Mon, 30 May 2005 02:45:58 +0000 (02:45 +0000)]
o updated translation.
garvinhicking [Sun, 29 May 2005 00:23:03 +0000 (00:23 +0000)]
make kubrick emit both sidebars on one,even though it only supports the right bar
garvinhicking [Fri, 27 May 2005 11:53:23 +0000 (11:53 +0000)]
Fix bug #
1209706 - uploading image error for Opera+IE
garvinhicking [Fri, 27 May 2005 11:08:42 +0000 (11:08 +0000)]
fix bug #
1204576 : Wrong accesskey, thanks to Brett PRofitt!
garvinhicking [Fri, 27 May 2005 10:43:29 +0000 (10:43 +0000)]
fa should use en as WYSIWYG language
garvinhicking [Fri, 27 May 2005 09:40:04 +0000 (09:40 +0000)]
swedish update
garvinhicking [Fri, 27 May 2005 09:37:16 +0000 (09:37 +0000)]
* Fix deleting categories when having privileges but not being
administrator (Patch #
1205347 , many thanks to Penny Leach)
garvinhicking [Fri, 27 May 2005 09:18:20 +0000 (09:18 +0000)]
Increase spartacus output
garvinhicking [Fri, 27 May 2005 09:09:52 +0000 (09:09 +0000)]
Japanese update for htmlarea, by Tadashi Jokagi
garvinhicking [Fri, 27 May 2005 09:01:35 +0000 (09:01 +0000)]
patch xml-rpc, thanks to tim Putnam
(http://www.fracsoft.com/serendipity/archives/12-More-Serendipity-xml-rpc-patching.html)
garvinhicking [Fri, 27 May 2005 08:25:56 +0000 (08:25 +0000)]
Translate unlocalized "Reply"
garvinhicking [Fri, 27 May 2005 08:16:07 +0000 (08:16 +0000)]
patch by swiesinger: When using shortcut admin URL, use https:// when specified by user
mgroeninger [Wed, 25 May 2005 02:22:30 +0000 (02:22 +0000)]
Changes to serendipity_displayImageList to allow passing of argument to restrict folder.
Change to serendipity_displayImageList to use absolute path for images so that function can be used in permalink pages below main directory level.
omidmottaghi [Tue, 24 May 2005 15:19:07 +0000 (15:19 +0000)]
some changes
omidmottaghi [Tue, 24 May 2005 10:02:01 +0000 (10:02 +0000)]
some changes
omidmottaghi [Tue, 24 May 2005 10:01:40 +0000 (10:01 +0000)]
some updates
garvinhicking [Tue, 24 May 2005 06:42:34 +0000 (06:42 +0000)]
fix XHTML compliance
garvinhicking [Mon, 23 May 2005 19:37:52 +0000 (19:37 +0000)]
fix a parse error
garvinhicking [Mon, 23 May 2005 19:36:11 +0000 (19:36 +0000)]
Added swedish, hungarian and portuguese european languages.
Thanks to all translators!
garvinhicking [Mon, 23 May 2005 19:24:56 +0000 (19:24 +0000)]
Jalalil and future other calendars support
garvinhicking [Mon, 23 May 2005 12:00:41 +0000 (12:00 +0000)]
* New personal configuration item: "Forbid creating entries" to
allow authors to be logged in, but not create any entries. Meant
to be used in conjunction with serendipity_plugin_adduser for
user self-registration where you want to allow posting comments
to registered users only. (garvinhicking)
garvinhicking [Sun, 22 May 2005 15:37:11 +0000 (15:37 +0000)]
Major update, commit custom permalink patch and some DB updates.
Please report any updates, as from now "alpha" means "alpha". :)
garvinhicking [Thu, 19 May 2005 16:55:24 +0000 (16:55 +0000)]
propper fix
garvinhicking [Thu, 19 May 2005 14:39:21 +0000 (14:39 +0000)]
fix some evil error that cause x additional SQL query per page per plugin.
That sucks, we'll need to release 0.8.2 soon then.
garvinhicking [Thu, 19 May 2005 09:48:58 +0000 (09:48 +0000)]
since w equery those constants, and undefined constants evaluate to true we need to explicitly set the constants to false now that we are no longer using a $CONST array.
garvinhicking [Thu, 19 May 2005 08:40:00 +0000 (08:40 +0000)]
Drop our $CONST method and use $smarty.const. in a BC-compatible way instead.
Feels faster. ;)
garvinhicking [Wed, 18 May 2005 14:56:23 +0000 (14:56 +0000)]
fix iframe preview bug
garvinhicking [Fri, 13 May 2005 17:19:00 +0000 (17:19 +0000)]
one more htmlspecialchar()ing neccessary
nohn [Fri, 13 May 2005 14:43:13 +0000 (14:43 +0000)]
i've actually not seen anyone doing this but that does not me some webhosters don't do it
garvinhicking [Fri, 13 May 2005 12:30:55 +0000 (12:30 +0000)]
Fix PDF thumbnail creation.
garvinhicking [Fri, 13 May 2005 11:04:42 +0000 (11:04 +0000)]
This should fix the image upload bug for good. Uses basename() and upload verification before any checks are done.
Also admins can no longer upload active content files.
Tricking the upload by making the directory "evil.ph" and the filename "p" does not work because trailing slashes are appended to directory names.
garvinhicking [Fri, 13 May 2005 10:04:11 +0000 (10:04 +0000)]
french update by Andre San-Martin
garvinhicking [Thu, 12 May 2005 18:19:28 +0000 (18:19 +0000)]
Now this is one funny XSS discovered by Rasmus:
You could send HTTP Cookie HTML which does not get htmlspecialchar()ed and then exploit the page for yourself only, and no other viewers.
Rare case of a XSS and low-impact, but still not nice when advanced form redirection takes place and you want to XSS exploit a single user :-)
Please test, if anybody is reading this :-D
garvinhicking [Thu, 12 May 2005 10:58:05 +0000 (10:58 +0000)]
update french language
garvinhicking [Thu, 12 May 2005 10:49:41 +0000 (10:49 +0000)]
If someone is linking the additional_plugins into his installation,
the list of plugins grows too large and load_plugin() on 90 plugins consumes
more than 8MB.
Thus we need pagination for the plugins panel.
The one flaw my patch has is that it can not sort the list of all plugins alphabetically and apply pagination on that, since only loading the plugin shows the real name, and this is what we cannot do.
Any suggestions? Somehow we might need to pre-cache the names of all plugins somewhere...
nohn [Thu, 12 May 2005 10:45:22 +0000 (10:45 +0000)]
be compliant (and yes, I really found a browser where this did not work)
garvinhicking [Wed, 11 May 2005 13:37:34 +0000 (13:37 +0000)]
wrong array key index
garvinhicking [Wed, 11 May 2005 09:56:00 +0000 (09:56 +0000)]
Actually this makes more sense, also backport the dotfile patch from trunk to branch
garvinhicking [Wed, 11 May 2005 09:40:58 +0000 (09:40 +0000)]
Try to catch more "evil" opportunities.
GUYS: We need some volunteers to check if uploads still work as expected and our latest changes don't break stuff. And of course that it's no longer exploitable.
garvinhicking [Tue, 10 May 2005 16:35:31 +0000 (16:35 +0000)]
Also look for "convert.exe", satisfying windows users.
Thanks to pattyjj from IRC!
nohn [Tue, 10 May 2005 14:53:48 +0000 (14:53 +0000)]
zero-tolerance
garvinhicking [Tue, 10 May 2005 10:34:05 +0000 (10:34 +0000)]
update icelandic
garvinhicking [Tue, 10 May 2005 10:11:05 +0000 (10:11 +0000)]
This should be a better fix to not pass any bad characters into the $url.
Anyone care to check? :)
garvinhicking [Mon, 9 May 2005 13:46:01 +0000 (13:46 +0000)]
Let's make it sound less nasty ;)
nohn [Mon, 9 May 2005 13:24:57 +0000 (13:24 +0000)]
document
garvinhicking [Mon, 9 May 2005 13:03:20 +0000 (13:03 +0000)]
possible xss for shoutbox/templatedropdown,
fix author pagination
nohn [Mon, 9 May 2005 09:25:13 +0000 (09:25 +0000)]
killing null-bytes
nohn [Mon, 9 May 2005 08:33:50 +0000 (08:33 +0000)]
NO ONE should be able to upload dot-files
garvinhicking [Mon, 9 May 2005 08:10:25 +0000 (08:10 +0000)]
disallow "." files like .htaccess.
Sebastian, Tom - see my mail about this issue.
garvinhicking [Wed, 4 May 2005 16:37:54 +0000 (16:37 +0000)]
* fix missing rss1.0 namespace
* fix autodetection using ports if not :80.
garvinhicking [Wed, 4 May 2005 10:19:13 +0000 (10:19 +0000)]
use strftime wrapper
garvinhicking [Tue, 3 May 2005 07:40:35 +0000 (07:40 +0000)]
only show WYSIWYG config option when installing. Later on it will
be configured in Personal Configuration only.
garvinhicking [Tue, 3 May 2005 07:39:06 +0000 (07:39 +0000)]
fix paths for people
garvinhicking [Mon, 2 May 2005 12:31:41 +0000 (12:31 +0000)]
allow plugins to send trackbacks despite missing RDF metadata
nohn [Mon, 2 May 2005 08:49:40 +0000 (08:49 +0000)]
deppen leer zeichen
garvinhicking [Sat, 30 Apr 2005 10:41:02 +0000 (10:41 +0000)]
Allow to view and fetch multiple categories. Categories plugin
can allow viewers to select multiple categories to view.
Multiple categories are separated by ";" inside the URL. Values are still
turned to (int)s later on.
nohn [Sat, 30 Apr 2005 09:44:27 +0000 (09:44 +0000)]
adding missing constant
garvinhicking [Fri, 29 Apr 2005 14:37:34 +0000 (14:37 +0000)]
Image selector hook support
garvinhicking [Fri, 29 Apr 2005 13:05:53 +0000 (13:05 +0000)]
allow to sort categories by custom fields
garvinhicking [Fri, 29 Apr 2005 09:19:08 +0000 (09:19 +0000)]
missing HTML code
garvinhicking [Thu, 28 Apr 2005 12:23:58 +0000 (12:23 +0000)]
added missing files from migration
garvinhicking [Thu, 28 Apr 2005 12:15:31 +0000 (12:15 +0000)]
gzip encoding is making too many problems, set it off as default:
Warning: (null)() [ref.outcontrol]: output handler 'ob_gzhandler' cannot be
used twice in Unknown on line 0
or
Warning: ob_start(): output handler 'ob_gzhandler' cannot be used
after 'URL-Rewriter' in /include/functions.inc.php on line 28
Tom, do you know more about it, can you fix it properly? It seems the
ob_functions need to be called before our session_start, but ob_* may also
not interfer with our BC-compatibility $raw_data stuff or the
simplecache plugin.
I also firmly believe gzip compression is a webserver matter and IMHO should
not be touched in application level?
garvinhicking [Thu, 28 Apr 2005 12:10:16 +0000 (12:10 +0000)]
we need full URL for redirection
garvinhicking [Wed, 27 Apr 2005 13:04:49 +0000 (13:04 +0000)]
typo
garvinhicking [Wed, 27 Apr 2005 12:52:33 +0000 (12:52 +0000)]
add new config option for nugget plugin
garvinhicking [Wed, 27 Apr 2005 11:57:08 +0000 (11:57 +0000)]
updated french
garvinhicking [Wed, 27 Apr 2005 07:48:18 +0000 (07:48 +0000)]
entryproperties option: Hide from frontpage
garvinhicking [Tue, 26 Apr 2005 10:00:36 +0000 (10:00 +0000)]
PHP < 4.3 has bugs with version_compare
garvinhicking [Mon, 25 Apr 2005 16:50:43 +0000 (16:50 +0000)]
Fix importers when not on the same DB
garvinhicking [Mon, 25 Apr 2005 16:32:14 +0000 (16:32 +0000)]
fix remaining JS issues, hopefully.
garvinhicking [Mon, 25 Apr 2005 10:15:28 +0000 (10:15 +0000)]
fix trackbacks with "#" in it
garvinhicking [Mon, 25 Apr 2005 09:55:16 +0000 (09:55 +0000)]
allow "=" in urls. :-(
garvinhicking [Mon, 25 Apr 2005 09:40:08 +0000 (09:40 +0000)]
also send trackback with event_trackback plugin if not at least one link
was inserted
garvinhicking [Mon, 25 Apr 2005 08:41:26 +0000 (08:41 +0000)]
no sidebar titles if not set
garvinhicking [Mon, 25 Apr 2005 08:35:55 +0000 (08:35 +0000)]
Fix PHP error which comes because session_start() is called before the obgzhandler ob_start and if session.use_trans_sid is activated.
Currently this is more a hotfix - it effectively disables gzcompression on servers with use_trans_sid. We would need to move serendipity_gzCompression before session_start, but I don't dare touch this beast I have no knowledge of. Tom?