42 Commits

Author SHA1 Message Date
cls%seawood.org
bc1a57ed0f Do not allow access to CVSROOT.
Bug #204126 r=timeless


git-svn-id: svn://10.0.0.236/trunk@166034 18797224-902f-48f8-a5cc-f745e15eee43
2004-12-01 08:40:33 +00:00
cls%seawood.org
c6516a20c7 Quote all values to be used in urls or in html output.
Bug #261616 r=timeless


git-svn-id: svn://10.0.0.236/trunk@166011 18797224-902f-48f8-a5cc-f745e15eee43
2004-12-01 04:46:35 +00:00
cls%seawood.org
91c6f7e8ba Use : instead of + as file separator to avoid + being converted to a space.
Bug #261616 r=timeless


git-svn-id: svn://10.0.0.236/trunk@165994 18797224-902f-48f8-a5cc-f745e15eee43
2004-12-01 01:11:37 +00:00
cls%seawood.org
768abf5478 Verify that the given cvsroot is actually in our repository list.
Bug #261616 r=timeless


git-svn-id: svn://10.0.0.236/trunk@165983 18797224-902f-48f8-a5cc-f745e15eee43
2004-12-01 00:22:53 +00:00
cls%seawood.org
636e1ae296 Add check routines to sanitize user input.
Rename sanitize_revision to SanitizeRevision and move it to globals.pl.
Bug #261616 r=timeless


git-svn-id: svn://10.0.0.236/trunk@165975 18797224-902f-48f8-a5cc-f745e15eee43
2004-11-30 23:56:13 +00:00
cls%seawood.org
f68cba64c9 Remove 'use diagnostics' calls to speed up scripts.
Bug #204463 r=justdave


git-svn-id: svn://10.0.0.236/trunk@162516 18797224-902f-48f8-a5cc-f745e15eee43
2004-09-18 05:02:17 +00:00
cls%seawood.org
1eba50dbcc Fix security issue related to unsanitized rcs version strings:
* Added sanitize_revision()
* Do not install SourceChecker.*
* Add ~ & ` to shell_escape()
Bug #39284 r=timeless


git-svn-id: svn://10.0.0.236/trunk@162420 18797224-902f-48f8-a5cc-f745e15eee43
2004-09-15 22:44:55 +00:00
cls%seawood.org
8255c8501d Misc cleanup to better handle files with spaces & special chars:
* Do not encode / in url_quote
* Do not install old/unused perl scripts
* Update README
* Replace system(rm/mkdir) calls with standard perl modules
* Use url_quote to quote filenames when passing files between cgis
* Use shell_escape on filenames that are passed to system calls via open()

Bug #44642 r=timeless


git-svn-id: svn://10.0.0.236/trunk@162364 18797224-902f-48f8-a5cc-f745e15eee43
2004-09-15 15:48:18 +00:00
cls%seawood.org
46874d60a8 Escape special chars in filenames when calling rlog.
Fix minor 'used once' warnings.
Bug #258668 r=timeless


git-svn-id: svn://10.0.0.236/trunk@162251 18797224-902f-48f8-a5cc-f745e15eee43
2004-09-13 21:41:22 +00:00
timeless%mozdev.org
3b75ecc692 Bug 253010 bonsai diffs looks doublespaced (extra newlines)
css per dbaron, r=vladd
also changed cvsblame per mvl


git-svn-id: svn://10.0.0.236/trunk@160194 18797224-902f-48f8-a5cc-f745e15eee43
2004-08-01 19:59:46 +00:00
timeless%mozdev.org
a9a32f383d Bug 233967 Bonsai showing stale pages
r=kiko


git-svn-id: svn://10.0.0.236/trunk@152917 18797224-902f-48f8-a5cc-f745e15eee43
2004-02-19 06:53:19 +00:00
timeless%mozdev.org
a906a9556d Bug 176316 Add Last-Modified support to bonsai
Adds optional path parameter to parse_rcs_file
Adds required http header call to do_directory
patch by rperrot@debian.org r=justdave


git-svn-id: svn://10.0.0.236/trunk@142609 18797224-902f-48f8-a5cc-f745e15eee43
2003-05-19 12:58:45 +00:00
tara%tequilarista.org
680c1966eb Checking in a fix for bug #187239--preventing fully qualified paths from being displayed.
git-svn-id: svn://10.0.0.236/trunk@140559 18797224-902f-48f8-a5cc-f745e15eee43
2003-04-02 05:42:22 +00:00
timeless%mozdev.org
237360ee79 Bug 181566 cvsview2.cgi fails if $0 has no path
patch by not_erik@dasbistro.com r=timeless


git-svn-id: svn://10.0.0.236/trunk@138959 18797224-902f-48f8-a5cc-f745e15eee43
2003-03-05 17:06:11 +00:00
timeless%mozdev.org
9a466e3c5e Bug 176316 Add Last-Modified support to bonsai
r=tara


git-svn-id: svn://10.0.0.236/trunk@138955 18797224-902f-48f8-a5cc-f745e15eee43
2003-03-05 14:49:20 +00:00
tara%tequilarista.org
98e33a62b2 Partial fix for bug 104313, making the default behavior of the diff page be correct, at least
git-svn-id: svn://10.0.0.236/trunk@132466 18797224-902f-48f8-a5cc-f745e15eee43
2002-10-24 17:53:38 +00:00
jake%acutex.net
4afe8caa98 Bug 122663 - Eliminate some undefined value warnings in cvsview2.cgi and cvsqueryform.cgi
Patch by Jody McIntyre <jodym@oeone.com>
r=jake


git-svn-id: svn://10.0.0.236/trunk@117648 18797224-902f-48f8-a5cc-f745e15eee43
2002-03-27 14:52:04 +00:00
jake%acutex.net
7dbccc55a3 Bug 121105 - type="application/x-javascript" confuses IE, so we should use the new $::script_type variable added in bug 123339.
r= kiko


git-svn-id: svn://10.0.0.236/trunk@114390 18797224-902f-48f8-a5cc-f745e15eee43
2002-02-13 14:19:07 +00:00
jake%acutex.net
7efb764af7 Bug 121636 - Provide support for cvsgraph (requires the cvsgraph binary, see bug 121636 for more information).
r= kiko


git-svn-id: svn://10.0.0.236/trunk@113417 18797224-902f-48f8-a5cc-f745e15eee43
2002-02-01 14:32:55 +00:00
timeless%mac.com
1fbabf4c79 Bug 27506 The Bonsai pages contain SCRIPTs which are not enclosed in
<!-- -->, greatly confusing some HTML parsers.
r=kiko


git-svn-id: svn://10.0.0.236/trunk@105179 18797224-902f-48f8-a5cc-f745e15eee43
2001-10-11 18:44:14 +00:00
endico%mozilla.org
fa24fcf482 Lets be consistant. Switch back to #!/usr/bonsaitools/bin/perl -w
git-svn-id: svn://10.0.0.236/trunk@90364 18797224-902f-48f8-a5cc-f745e15eee43
2001-03-25 08:59:55 +00:00
dave%intrec.com
2f9356d728 Fix for bug 54690: security holes in cvsview2.cgi by lax validation of the http query string. Fixed by retrieving parms via CGI.pm instead of trying to dynamically parse them from the query string. Patch by Adam Spiers <adam@spiers.net>
git-svn-id: svn://10.0.0.236/trunk@88318 18797224-902f-48f8-a5cc-f745e15eee43
2001-03-01 22:18:55 +00:00
tara%tequilarista.org
c8019b562f Landing Adam Spiers' contributions for security and small functional issues
git-svn-id: svn://10.0.0.236/trunk@74752 18797224-902f-48f8-a5cc-f745e15eee43
2000-07-25 18:58:54 +00:00
dmose%mozilla.org
3032b29df4 Security check needs to happen after the eval, so that it's matching
variable side-effects don't hurt us.


git-svn-id: svn://10.0.0.236/trunk@69422 18797224-902f-48f8-a5cc-f745e15eee43
2000-05-12 17:51:00 +00:00
dmose%mozilla.org
0e8610b91d Fix the fix; it was slightly overzealous.
git-svn-id: svn://10.0.0.236/trunk@69421 18797224-902f-48f8-a5cc-f745e15eee43
2000-05-12 17:39:40 +00:00
dmose%mozilla.org
c87ba932cb Fix security hole.
git-svn-id: svn://10.0.0.236/trunk@69420 18797224-902f-48f8-a5cc-f745e15eee43
2000-05-12 17:27:57 +00:00
terry%mozilla.org
666ab60fac Patch by Adam Spiers <adam@spiers.net> -- fixed some poor HTML.
git-svn-id: svn://10.0.0.236/trunk@57854 18797224-902f-48f8-a5cc-f745e15eee43
2000-01-14 23:56:55 +00:00
dmose%mozilla.org
03ec794132 updated license boilerplate
git-svn-id: svn://10.0.0.236/trunk@52443 18797224-902f-48f8-a5cc-f745e15eee43
1999-11-01 23:33:56 +00:00
terry%mozilla.org
4d41190cf3 This was using complicated perl features I don't understand, so I simplified it and it works now...
git-svn-id: svn://10.0.0.236/trunk@51141 18797224-902f-48f8-a5cc-f745e15eee43
1999-10-19 16:24:48 +00:00
terry%mozilla.org
c51e515d06 Fix perl warnings.
git-svn-id: svn://10.0.0.236/trunk@51139 18797224-902f-48f8-a5cc-f745e15eee43
1999-10-19 15:05:16 +00:00
terry%mozilla.org
877a31dd8a Fix potential security hole (and I think some perl warnings.)
git-svn-id: svn://10.0.0.236/trunk@51080 18797224-902f-48f8-a5cc-f745e15eee43
1999-10-19 00:17:54 +00:00
terry%mozilla.org
2249323ac8 Fixed perl warnings -- this module no longer defines its own "die" routine.
git-svn-id: svn://10.0.0.236/trunk@51078 18797224-902f-48f8-a5cc-f745e15eee43
1999-10-19 00:07:23 +00:00
terry%mozilla.org
93cd29ad2b Massive spank to put "use strict" in all Bonsai code.
git-svn-id: svn://10.0.0.236/trunk@51050 18797224-902f-48f8-a5cc-f745e15eee43
1999-10-18 22:55:01 +00:00
slamm%netscape.com
4f206234cd Avoid tall lines (too many newlines)
git-svn-id: svn://10.0.0.236/trunk@43020 18797224-902f-48f8-a5cc-f745e15eee43
1999-08-10 21:19:27 +00:00
slamm%netscape.com
684f48c90b -mAvoid breaking the line in the middle of an entity.
git-svn-id: svn://10.0.0.236/trunk@43017 18797224-902f-48f8-a5cc-f745e15eee43
1999-08-10 21:07:06 +00:00
terry%mozilla.org
486b4dc3fc Massive patch (mostly from Dieter Weber <dieter@Compatible.COM>) -- ported all TCL code to Perl.
git-svn-id: svn://10.0.0.236/trunk@40909 18797224-902f-48f8-a5cc-f745e15eee43
1999-07-23 18:39:31 +00:00
slamm%netscape.com
b651be006c Pull netscape-specific hack.
git-svn-id: svn://10.0.0.236/trunk@9654 18797224-902f-48f8-a5cc-f745e15eee43
1998-09-09 20:00:33 +00:00
slamm%netscape.com
c669313675 Get the 'Change Log' link right. Set 'LANGUAGE=JavaScript' for the SCRIPT tag
git-svn-id: svn://10.0.0.236/trunk@9653 18797224-902f-48f8-a5cc-f745e15eee43
1998-09-09 19:29:00 +00:00
slamm%netscape.com
710729e972 Fix the 'Change Log' like to pass along the branch and the root. Trim the email addresses of netscape folks (i.e. slamm%netscape.com becomes slamm).
git-svn-id: svn://10.0.0.236/trunk@9630 18797224-902f-48f8-a5cc-f745e15eee43
1998-09-09 17:37:12 +00:00
terry
ac1101d225 Patches by Matthew Wilson <msw@gimp.org> -- added much of the missing configuration ability.
git-svn-id: svn://10.0.0.236/trunk@4666 18797224-902f-48f8-a5cc-f745e15eee43
1998-06-29 16:21:41 +00:00
terry
507ecde94d Implement CheckHidden(), so that we can have some semblance of security.
git-svn-id: svn://10.0.0.236/trunk@4068 18797224-902f-48f8-a5cc-f745e15eee43
1998-06-18 16:47:00 +00:00
terry
0d01ac7bc3 Bonsai and Tinderbox have been freed.
git-svn-id: svn://10.0.0.236/trunk@3931 18797224-902f-48f8-a5cc-f745e15eee43
1998-06-16 21:43:24 +00:00