2321 Commits

Author SHA1 Message Date
mkanat%bugzilla.org
19a66c4673 Bug 640756 - Make the documentation clearer that attachments created with Bug.add_attachment must by of type 'base64' when non-ASCII
.
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264470 18797224-902f-48f8-a5cc-f745e15eee43
2012-11-20 19:16:20 +00:00
mkanat%bugzilla.org
a2c550384f Bump version post-release
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264435 18797224-902f-48f8-a5cc-f745e15eee43
2012-11-13 23:31:18 +00:00
mkanat%bugzilla.org
00a140e827 Bump version to 4.0.9
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264429 18797224-902f-48f8-a5cc-f745e15eee43
2012-11-13 20:00:41 +00:00
mkanat%bugzilla.org
636fa6afe1 Bug 781850 (CVE-2012-4198): [SECURITY] Do not leak the existence of groups when using User.get()
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264425 18797224-902f-48f8-a5cc-f745e15eee43
2012-11-13 17:46:24 +00:00
mkanat%bugzilla.org
dd21d3d7d3 Bug 802204 (CVE-2012-4197): [SECURITY] Marking an attachment you cannot see as obsolete can disclose its description
r=gerv a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264424 18797224-902f-48f8-a5cc-f745e15eee43
2012-11-13 17:31:57 +00:00
mkanat%bugzilla.org
3fe95ece18 Fix typo
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264399 18797224-902f-48f8-a5cc-f745e15eee43
2012-11-02 13:03:22 +00:00
mkanat%bugzilla.org
d87638b2e2 Bug 807937: Fix POD
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264398 18797224-902f-48f8-a5cc-f745e15eee43
2012-11-02 13:02:41 +00:00
mkanat%bugzilla.org
ae0d2cb19e Fix typo
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264338 18797224-902f-48f8-a5cc-f745e15eee43
2012-10-13 21:31:56 +00:00
mkanat%bugzilla.org
8a1f56d99a Bumped version post-release
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264186 18797224-902f-48f8-a5cc-f745e15eee43
2012-08-30 20:32:17 +00:00
mkanat%bugzilla.org
ddca5da73e Bump version to 4.0.8
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264182 18797224-902f-48f8-a5cc-f745e15eee43
2012-08-30 19:16:21 +00:00
mkanat%bugzilla.org
6e111ef217 Bug 785470: (CVE-2012-3981) [SECURITY] Missing escaping of the username can lead to LDAP injection
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264179 18797224-902f-48f8-a5cc-f745e15eee43
2012-08-30 18:33:26 +00:00
mkanat%bugzilla.org
72066c1233 Bug 682317 - Bug.create is incorrectly documented as ignoring invalid fields; it should say it produces an error
r=dkl, a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264114 18797224-902f-48f8-a5cc-f745e15eee43
2012-08-03 17:01:30 +00:00
mkanat%bugzilla.org
752dc36b8f Bumped version post release
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264081 18797224-902f-48f8-a5cc-f745e15eee43
2012-07-26 23:01:15 +00:00
mkanat%bugzilla.org
2e174ba9dd Bump version to 4.0.7
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264077 18797224-902f-48f8-a5cc-f745e15eee43
2012-07-26 21:45:41 +00:00
mkanat%bugzilla.org
5902c5d0cb Bug 777586: (CVE-2012-1969) [SECURITY] The description of private attachments is still visible to unauthorized users when mentioned in a comment
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264073 18797224-902f-48f8-a5cc-f745e15eee43
2012-07-26 21:16:55 +00:00
mkanat%bugzilla.org
3869f341e1 Bug 776103 - Syntax error in Bugzilla::User::Setting API doc
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264065 18797224-902f-48f8-a5cc-f745e15eee43
2012-07-25 21:46:57 +00:00
mkanat%bugzilla.org
179912ff95 Bumping the version post-release
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263718 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-18 22:33:02 +00:00
mkanat%bugzilla.org
92ca787774 Bump version to 4.0.6
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263713 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-18 18:01:39 +00:00
mkanat%bugzilla.org
620b5cd8ec Bug 728639: (CVE-2012-0465) [SECURITY] User lockout policy can be bypassed by altering the X-FORWARDED-FOR header
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263711 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-18 17:06:52 +00:00
mkanat%bugzilla.org
4400d3c7bb Bug 746547: SMALLSERIAL is of type INT2, not INT1
r=timello a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263709 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-18 15:04:18 +00:00
mkanat%bugzilla.org
bb5b08cc57 Bug 733458: The "creator" argument is listed twice for the Bug.search WebService method
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263598 18797224-902f-48f8-a5cc-f745e15eee43
2012-03-22 19:02:53 +00:00
mkanat%bugzilla.org
6a9ee8dc21 Bug 731219: Fix XMLRPC breakage when content-type contains a charset
r=dkl, a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263500 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-29 05:03:15 +00:00
dlawrence%mozilla.com
8019024a98 Bumped version number post-release
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263472 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-22 18:23:23 +00:00
dlawrence%mozilla.com
7aacd6d91b Rolled back version bump for 4.0.5+
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263470 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-22 18:06:22 +00:00
mkanat%bugzilla.org
821166867d Bumped the version number post-release
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263467 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-22 15:46:57 +00:00
mkanat%bugzilla.org
c9dea496d4 Bumped version to 4.0.5
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263466 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-22 15:34:33 +00:00
mkanat%bugzilla.org
d568f97c43 Bug 725663 - (CVE-2012-0453) [SECURITY] CSRF vulnerability in the XML-RPC API when using mod_perl
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263465 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-22 15:32:12 +00:00
mkanat%bugzilla.org
26e2568713 Bug 727240: The POD for Bug.attachments is wrong about the format of the returned data
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263407 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-14 22:24:30 +00:00
mkanat%bugzilla.org
6885029fd3 Bump the version number post-release
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263354 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-01 00:04:54 +00:00
mkanat%bugzilla.org
36ebe12ba3 Bumped to version 4.0.4
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263344 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-31 16:47:04 +00:00
mkanat%bugzilla.org
d21ff6ea40 Bug 718319: (CVE-2012-0440) [SECURITY] JSON-RPC permits to bypass token checks and can lead to CSRF (no victim's action required)
r=mkanat a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263341 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-31 16:16:56 +00:00
mkanat%bugzilla.org
ebeabba5e8 Bug 714472: (CVE-2012-0448) [SECURITY] utf8 homoglyphs are allowed in email addresses, which could allow an attacker to be CC'ed to private bugs by accident
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263337 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-31 15:48:18 +00:00
mkanat%bugzilla.org
fcedb45128 Bug 706753: Bugzilla will not work with newest version of JSON::RPC 1.01 due to non-backward compatibility
r=dkl r=mkanat a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263226 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-05 01:02:37 +00:00
mkanat%bugzilla.org
c6ee7aa266 Bump the version number post-release
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263216 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-29 18:03:54 +00:00
mkanat%bugzilla.org
b109733298 Bump version for 4.0.3
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263207 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-28 23:16:24 +00:00
mkanat%bugzilla.org
118c8d3319 Bug 711714: (CVE-2011-3667) [SECURITY] The User.offer_account_by_email WebService method lets you create new user accounts independently of the value of Bugzilla::Auth::Verify::*::user_can_create_account
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263205 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-28 22:21:31 +00:00
mkanat%bugzilla.org
f3cb64b4d1 Bug 697699 - (CVE-2011-3657) [SECURITY] XSS when viewing new charts or tabular and graphical reports in debug mode
r=gerv, a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263202 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-28 22:03:37 +00:00
mkanat%bugzilla.org
5700ff9ce4 Bug 644281: When the sort order of a buglist is modified, the "Show next bug in my list" user pref still uses the original sort order to decide which bug to display next
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263147 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-08 23:32:33 +00:00
mkanat%bugzilla.org
de0268f582 Bug 657290: Bug.add_attachment() stores truncated timestamps in the DB (seconds are missing)
r=dkl a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263137 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-06 12:05:31 +00:00
mkanat%bugzilla.org
6df13f362e Bug 550299: User fields are left blank in buglists and whines when local user accounts are used (i.e. they have no @company.com suffix)
r=mkanat a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263136 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-06 12:04:13 +00:00
mkanat%bugzilla.org
0b85a2884f Bug 692354: Incorrect parameter type in WebServices documentation for Bug.add_comment
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263135 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-05 21:35:28 +00:00
mkanat%bugzilla.org
2e4cca9c0c Bug 707594: Fix broken account lockout notifications
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263130 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-05 16:48:52 +00:00
mkanat%bugzilla.org
c6d56a2e9e Bug 701350: Oracle crashes if the 'maxattachmentsize' parameter is set to a too small value
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263129 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-05 16:17:32 +00:00
mkanat%bugzilla.org
2f50aaf522 Bug 685552 - Email auto-completion causes server to thrash
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263012 18797224-902f-48f8-a5cc-f745e15eee43
2011-10-24 22:19:56 +00:00
mkanat%bugzilla.org
1144f41a1a Bug 686860: Correctly calculate Hours Worked in buglists
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@262992 18797224-902f-48f8-a5cc-f745e15eee43
2011-10-18 21:46:29 +00:00
mkanat%bugzilla.org
a644285360 Bug 691243: Fix typo
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@262987 18797224-902f-48f8-a5cc-f745e15eee43
2011-10-15 13:35:13 +00:00
mkanat%bugzilla.org
d784f25d96 $user->is_mover no longer exists, see bug 556422
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@262956 18797224-902f-48f8-a5cc-f745e15eee43
2011-10-04 21:47:29 +00:00
mkanat%bugzilla.org
325e07d936 Bug 682203 - migrate.pl fails at requirements check.
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@262779 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-31 13:32:51 +00:00
mkanat%bugzilla.org
ceed5cb286 Bug 678772: version.pm 0.92 and newer forbids negative values, making checksetup.pl to fail
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@262663 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-16 01:49:56 +00:00
mkanat%bugzilla.org
a0ab02e077 Bug 654496: Duplicate bug detection doesn't work when using Oracle
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@262662 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-16 01:48:50 +00:00