213753 Commits

Author SHA1 Message Date
mkanat%bugzilla.org
1874eef40e Bug 633422: Fix the documentation for User.get's include_disabled parameter
and make User.get check that its required parameters are passed.
r=LpSolit, a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261932 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-14 07:51:04 +00:00
mkanat%bugzilla.org
8e847fa809 Bug 630750: Don't let "." and "lib" get into @INC when running under
mod_perl
r=dkl, a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261891 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-03 21:49:37 +00:00
mkanat%bugzilla.org
87201dfd68 Bug 629007: Example in quicksearch priority shortcut is incorrect
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261879 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-31 23:05:07 +00:00
mkanat%bugzilla.org
bc19b49de9 Add missing documentation. r=mkanat.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261848 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-27 12:06:49 +00:00
mkanat%bugzilla.org
96096b8378 The "simple format" of the duplicates table was broken by an improper backport
using the "mtime" filter, which doesn't exist in 3.6.


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261831 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-25 05:31:41 +00:00
mkanat%bugzilla.org
e35b6ce4fd Bug 621597: Make mod_perl.pl automatically include the lib/ directory and
all the architecture-specific directories underneath it.
r=dkl, a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261829 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-25 02:31:54 +00:00
mkanat%bugzilla.org
2835c33f35 Bump the version number post-release.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261828 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-25 02:06:03 +00:00
mkanat%bugzilla.org
0aa5df3a3e Bump the version number for 3.6.4.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261820 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 23:45:11 +00:00
mkanat%bugzilla.org
cc59d868e7 Bug 619594: (CVE-2010-4568) [SECURITY] Improve the randomness of
generate_random_password, to protect against an account compromise issue
and other critical vulnerabilities.
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261817 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 22:07:59 +00:00
mkanat%bugzilla.org
2d76acd475 Bug 621105 - [SECURITY] Voting lacks CSRF protection
r=mkanat,a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261814 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 19:53:26 +00:00
mkanat%bugzilla.org
72a8e0036b Bug 619588: (CVE-2010-4567) [SECURITY] Safety checks that disallow clicking for javascript: or data: URLs in the URL field can be evaded with prefixed whitespace
and

Bug 628034: (CVE-2011-0048) [SECURITY] For not-logged-in users, the URL field doesn't safeguard against javascript: or data: URLs

r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261813 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 18:53:58 +00:00
mkanat%bugzilla.org
80a65875dd Bug 621572: (CVE-2010-4572) [SECURITY] chart.cgi vulnerable to header-injection due to use of |print "Location:"| instead of $cgi->redirect
[r=mkanat a=LpSolit]


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261812 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 18:31:15 +00:00
mkanat%bugzilla.org
7445e5472f Bug 621110: [SECURITY] Quips (adding/approving/deleting) lacks CSRF protection
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261806 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 17:38:25 +00:00
mkanat%bugzilla.org
58e7e4bff8 Bug 621108: [SECURITY] Creating/editing charts lacks CSRF protection
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261805 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 17:27:06 +00:00
mkanat%bugzilla.org
448e567c1e Bug 627923 - Release Notes for Bugzilla 3.6.4
r=reed


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261799 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 04:23:23 +00:00
mkanat%bugzilla.org
6f7a3988b9 Bug 627854: Add 'form' hook to create-guided.html.tmpl similar to create.html.tmpl
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261785 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-21 21:50:19 +00:00
mkanat%bugzilla.org
3894d17d04 Bug 591165: (CVE-2010-4411) [SECURITY] Bump minimum required version of CGI.pm to v3.51 in order to address header injection vulnerability.
[r=mkanat a=mkanat]


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261784 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-21 21:22:55 +00:00
mkanat%bugzilla.org
e4db7a5241 Bug 623608 - Add intro/outro extension hooks to footer.html.tmpl
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261780 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-21 05:19:52 +00:00
mkanat%bugzilla.org
524773f812 Bug 255524: The duplicates table inherits no CSS classes when viewed in simple format
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261728 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-07 12:50:04 +00:00
mkanat%bugzilla.org
8c3d044ee9 Bug 622822 - add additional_links hook to front page. r,a=mkanat.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261707 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-05 10:50:18 +00:00
mkanat%bugzilla.org
c8d557f459 Bug 622105 - Misspelling in setting_info_invalid error message
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261703 18797224-902f-48f8-a5cc-f745e15eee43
2010-12-30 17:03:17 +00:00
mkanat%bugzilla.org
383bca84ad Bug 588013: Fix typo
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261692 18797224-902f-48f8-a5cc-f745e15eee43
2010-12-27 22:05:20 +00:00
mkanat%bugzilla.org
c02570a325 Bug 617684: Values starting with a dot or an underscore are no longer hidden in reports
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261636 18797224-902f-48f8-a5cc-f745e15eee43
2010-12-08 20:19:55 +00:00
mkanat%bugzilla.org
3263338f74 Bug 416784: In PostgreSQL 8.1 and newer, createuser takes the argument -R instead of -A
r=manu a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261600 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-27 21:22:33 +00:00
mkanat%bugzilla.org
2783edc189 Bug 610217: config.cgi?ctype=rdf should include product.allows_unconfirmed
r=mkanat a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261566 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-14 19:24:51 +00:00
mkanat%bugzilla.org
dae96dea7a Bug 611974: collectstats.pl --regenerate fails with PostgreSQL 8.4.x (sql_from_days() doesn't accept integers as argument)
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261564 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-14 19:23:27 +00:00
mkanat%bugzilla.org
1eea0565f5 Bug 611623: The alias is not filtered in QuickSearch when passed to show_bug.cgi
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261561 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-13 00:20:10 +00:00
mkanat%bugzilla.org
b382f2321b Bug 591165: (CVE-2010-2761) [SECURITY] Bump minimum required version of CGI.pm to v3.50 in order to address header injection vulnerability.
[r=mkanat a=mkanat]


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261557 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-11 02:20:43 +00:00
mkanat%bugzilla.org
4502635fa9 Bug 611129: Quicksearch fails in 3.6.3 if List::MoreUtils is not installed
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261547 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-10 23:46:49 +00:00
mkanat%bugzilla.org
2324bbecc4 Bug 596611: Add a hook to email_in.pl
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261527 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-04 17:23:45 +00:00
mkanat%bugzilla.org
5c5dcff6b1 Bug 474766: The [details] string is duplicated when replying to a comment containing a link to an attachment
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261524 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-04 17:09:26 +00:00
mkanat%bugzilla.org
d190424c2f Fix the 3.6 release notes to accurately describe the "form field longdesclength"
fix.


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261519 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-03 02:46:39 +00:00
mkanat%bugzilla.org
e2d2059f0b Bump the version number post-release.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261518 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-03 01:50:41 +00:00
mkanat%bugzilla.org
8e6cfd6750 Bump the version number for 3.6.3.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261511 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-03 00:46:04 +00:00
mkanat%bugzilla.org
f8bb64c9e4 Bug 600464: (CVE-2010-3172) [SECURITY] Content/Header injection due to non-random multipart/x-mixed-replace boundary
r=mkanat a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261506 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-02 23:37:45 +00:00
mkanat%bugzilla.org
8fa11a377c Bug 419014: (CVE-2010-3764) [SECURITY] Old charts are not project specific, and product names are viewable in graphs/
r=wurblzap a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261505 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-02 23:23:21 +00:00
mkanat%bugzilla.org
851f8aa427 Bug 608188 - Release Notes for Bugzilla 3.6.3
r=LpSolit, a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261498 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-31 23:31:59 +00:00
mkanat%bugzilla.org
b3f1fb0e3b Bug 607966: Use of qw(...) as parentheses is deprecated since Perl 5.13.5
r=gerv a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261490 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-28 15:35:02 +00:00
mkanat%bugzilla.org
49d68e27fd Bug 607083: Improve the error message that install-module.pl prints when
you specify an invalid CPAN module.
r=mkanat, a=mkanat (module owner)


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261462 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-26 21:21:24 +00:00
mkanat%bugzilla.org
b8b9b4fbbb Bug 607361: Creating an attachment without a "comment" param in the URL causes an internal error
a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261461 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-26 18:35:08 +00:00
mkanat%bugzilla.org
b7d54710a7 Bug 413648: Attachment mime type handling should strip leading and trailing spaces
a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261444 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-22 13:05:03 +00:00
mkanat%bugzilla.org
8ab6d52c1a Bug 605425: Non-english templates are no longer precompiled by checksetup
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261436 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-20 23:17:10 +00:00
mkanat%bugzilla.org
d4caf8a025 Bug 605693: Make config.cgi?ctype=rdf faster
r=timello a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261433 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-20 12:19:08 +00:00
mkanat%bugzilla.org
cbebd9c86b Bug 553266: config.cgi?ctype=rdf spends most of its time loading flagtypes from the database (partial backport)
a=LpSolit (module owner)


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261431 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-20 00:50:28 +00:00
mkanat%bugzilla.org
846ce027dd Bug 339270: When editing a simple search, the bug status is lost
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261423 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-18 09:49:49 +00:00
mkanat%bugzilla.org
d5cba4863c Bug 604107: The link to delete the value 0 of custom fields is broken
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261405 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-15 01:20:24 +00:00
mkanat%bugzilla.org
c205068eae Bug 604522: t/012throwables.t doesn't catch new user errors correctly
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261404 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-15 00:21:59 +00:00
mkanat%bugzilla.org
4c82713caa Bug 575947: Users with passwords length less than 6 characters can't login after migration from 3.4.x or older to 3.6 or newer
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261395 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-14 00:53:22 +00:00
mkanat%bugzilla.org
db9f7c0e00 Bug 599953: Editing an advanced search doesn't remember values passed to discrete custom fields added by extensions
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261384 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-13 22:50:00 +00:00
mkanat%bugzilla.org
85264956ad s/Extensionn/Extension/ (no bug).
[r=mkanat a=mkanat@IRC]


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261344 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-05 04:35:36 +00:00