471 Commits

Author SHA1 Message Date
bzrmirror%bugzilla.org
a4191be170 Bug 1075578: [SECURITY] Improper filtering of CGI arguments
r=dkl,a=sgreen


git-svn-id: svn://10.0.0.236/trunk@265601 18797224-902f-48f8-a5cc-f745e15eee43
2014-10-06 14:45:58 +00:00
bzrmirror%bugzilla.org
300ea0eab3 Bug 1071033: Variable "$user" will not stay shared at buglist.cgi
r=dkl a=sgreen


git-svn-id: svn://10.0.0.236/trunk@265588 18797224-902f-48f8-a5cc-f745e15eee43
2014-09-25 22:15:46 +00:00
bzrmirror%bugzilla.org
ac150fb997 Bug 1065444: Several columns are not legal when displaying queries
r=dkl a=sgreen


git-svn-id: svn://10.0.0.236/trunk@265583 18797224-902f-48f8-a5cc-f745e15eee43
2014-09-22 23:30:49 +00:00
bzrmirror%bugzilla.org
d1e41111d4 Bug 281791 - Add ability to change flags in "change several bugs at once"
r=glob, a=sgreen


git-svn-id: svn://10.0.0.236/trunk@265545 18797224-902f-48f8-a5cc-f745e15eee43
2014-09-02 00:45:50 +00:00
bzrmirror%bugzilla.org
84c5be6eb5 Bug 996893: Perl 5.18 and newer throw tons of warnings about deprecated modules
r=dkl a=sgreen


git-svn-id: svn://10.0.0.236/trunk@265490 18797224-902f-48f8-a5cc-f745e15eee43
2014-08-13 11:01:07 +00:00
bzrmirror%bugzilla.org
7d52bf34b5 Bug 1008764: Add a web service to create and update Flag types
r=glob, a=justdave


git-svn-id: svn://10.0.0.236/trunk@265408 18797224-902f-48f8-a5cc-f745e15eee43
2014-05-21 23:30:48 +00:00
bzrmirror%bugzilla.org
89770e5763 Bug 318715 - iCalendar Buglist doesn't include deadline
r=dkl,a=justdave


git-svn-id: svn://10.0.0.236/trunk@265276 18797224-902f-48f8-a5cc-f745e15eee43
2014-03-08 21:15:50 +00:00
bzrmirror%bugzilla.org
2c2c454b38 Bug 977030 - Remove the useless buglist_joined variable in buglist.cgi
r=dkl,a=justdave


git-svn-id: svn://10.0.0.236/trunk@265266 18797224-902f-48f8-a5cc-f745e15eee43
2014-03-04 20:00:49 +00:00
bzrmirror%bugzilla.org
a3d4ea4500 Bug 947823: Replace gender-specific pronouns with gender-neutral pronouns
r=gerv a=justdave


git-svn-id: svn://10.0.0.236/trunk@265260 18797224-902f-48f8-a5cc-f745e15eee43
2014-02-27 09:00:54 +00:00
bzrmirror%bugzilla.org
41a21e2898 Bug 956233: enable USE_MEMCACHE on most objects
r=dkl, a=glob


git-svn-id: svn://10.0.0.236/trunk@265222 18797224-902f-48f8-a5cc-f745e15eee43
2014-01-31 07:30:50 +00:00
bzrmirror%bugzilla.org
71bc0fd474 Bug 543432: [PostgreSQL] Crash when typing a string in combination with a numeric field
r=dkl a=sgreen


git-svn-id: svn://10.0.0.236/trunk@265162 18797224-902f-48f8-a5cc-f745e15eee43
2014-01-02 23:15:43 +00:00
bzrmirror%bugzilla.org
f9f7952fc6 Bug 890165 - Buglist for single component should offer "File a new bug in the XYZ component" instead of "File a new bug in the XYZ product"
r=glob, a=glob


git-svn-id: svn://10.0.0.236/trunk@265100 18797224-902f-48f8-a5cc-f745e15eee43
2013-11-05 00:01:00 +00:00
bzrmirror%bugzilla.org
91aabd7d29 Bug 621216 - Don't call GetQuip() if the user doesn't want quips
r=simon, a=simon


git-svn-id: svn://10.0.0.236/trunk@265032 18797224-902f-48f8-a5cc-f745e15eee43
2013-09-26 02:18:21 +00:00
bzrmirror%bugzilla.org
9ccc31d214 Bug 914262: KHTML-based browsers such as Konqueror do not support the Server-Push technology
r=dkl a=sgreen


git-svn-id: svn://10.0.0.236/trunk@265006 18797224-902f-48f8-a5cc-f745e15eee43
2013-09-10 21:15:44 +00:00
bzrmirror%bugzilla.org
7538504a69 Bug 902515: Internet Explorer 11 receives multipart/x-mixed-replace content from buglist.cgi
r=dkl a=justdave


git-svn-id: svn://10.0.0.236/trunk@264966 18797224-902f-48f8-a5cc-f745e15eee43
2013-08-13 18:57:12 +00:00
bzrmirror%bugzilla.org
c9f2d293ab Bug 868330 - Password creation directions incomplete
r=sgreen, a=sgreen


git-svn-id: svn://10.0.0.236/trunk@264957 18797224-902f-48f8-a5cc-f745e15eee43
2013-08-13 18:47:50 +00:00
bzrmirror%bugzilla.org
8b67949f5e Bug 902515: Internet Explorer 11 receives multipart/x-mixed-replace content from buglist.cgi
r=dkl a=justdave


git-svn-id: svn://10.0.0.236/trunk@264955 18797224-902f-48f8-a5cc-f745e15eee43
2013-08-13 18:45:11 +00:00
mkanat%bugzilla.org
0a81634be5 Bug 824399: (CVE-2013-0786) [SECURITY] build_subselect() leaks the existence of products and components you cannot access
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264768 18797224-902f-48f8-a5cc-f745e15eee43
2013-02-19 17:15:41 +00:00
mkanat%bugzilla.org
e15ca127bd Bug 819432: Execute queries in two steps to improve performance
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264650 18797224-902f-48f8-a5cc-f745e15eee43
2013-01-16 18:15:42 +00:00
mkanat%bugzilla.org
d7fb30d846 Bug 413851 - add CSV output option to request lists. r=LpSolit.
git-svn-id: svn://10.0.0.236/trunk@264615 18797224-902f-48f8-a5cc-f745e15eee43
2013-01-02 17:16:27 +00:00
mkanat%bugzilla.org
4eb193ff89 Bug 718289: The deadline field should be visible by non-members of the timetracking group
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264484 18797224-902f-48f8-a5cc-f745e15eee43
2012-11-26 19:31:38 +00:00
mkanat%bugzilla.org
57ce848077 Bug 761046: Don't redirect when hitting buglist.cgi directly to avoid duplicate cgi->header calls
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264219 18797224-902f-48f8-a5cc-f745e15eee43
2012-09-17 14:30:45 +00:00
mkanat%bugzilla.org
8e47ba629a Bug 787529: Use |use 5.10.1| everywhere
r=wicked a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264195 18797224-902f-48f8-a5cc-f745e15eee43
2012-09-01 21:45:59 +00:00
mkanat%bugzilla.org
116a14ddfd Bug 786310: Remove tokens when saving the default query
r= LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264169 18797224-902f-48f8-a5cc-f745e15eee43
2012-08-29 06:00:43 +00:00
mkanat%bugzilla.org
3d7d902c40 Bug 772953: Remove the token from buglist urls
r=dkl, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264163 18797224-902f-48f8-a5cc-f745e15eee43
2012-08-28 15:30:47 +00:00
mkanat%bugzilla.org
ed9c84f10c Bug 698068: The "There is no saved search named ..." page has a "forget" link
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264154 18797224-902f-48f8-a5cc-f745e15eee43
2012-08-20 09:15:46 +00:00
mkanat%bugzilla.org
b3ff509cbf Bug 768870: The "Un-forget the search" link has no token
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263995 18797224-902f-48f8-a5cc-f745e15eee43
2012-06-27 16:16:21 +00:00
mkanat%bugzilla.org
0715897a0d Bug 760978: Remove support for Internet Explorer 5 on Mac
r=timello a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263913 18797224-902f-48f8-a5cc-f745e15eee43
2012-06-07 21:45:44 +00:00
mkanat%bugzilla.org
fca185824d Bug 297553: Enable serverpush for Opera
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263896 18797224-902f-48f8-a5cc-f745e15eee43
2012-06-03 13:15:42 +00:00
mkanat%bugzilla.org
938397e25f Bug 754672 - CSRF vulnerability in buglist.cgi allows possible unauthorized setting of default search options
[r=LpSolit a=LpSolit]


git-svn-id: svn://10.0.0.236/trunk@263871 18797224-902f-48f8-a5cc-f745e15eee43
2012-05-29 15:30:45 +00:00
mkanat%bugzilla.org
4e5431f617 Bug 616191: Implement UI to easily tag bugs from the bug report directly (and get rid of the current form in the footer)
r=timello a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263790 18797224-902f-48f8-a5cc-f745e15eee43
2012-05-07 16:01:09 +00:00
mkanat%bugzilla.org
8eeb112f53 Bug 745751: Remove support for microsummaries
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263749 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-24 21:32:17 +00:00
mkanat%bugzilla.org
dae90e7dc8 Bug 745397: (CVE-2012-0466) [SECURITY] The JS template for buglists permits attackers to access all bugs that the victim can see
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263712 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-18 17:08:02 +00:00
mkanat%bugzilla.org
29308480db Bug 745320: Shared queries do not work when tags are part of the query
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263698 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-17 18:46:28 +00:00
mkanat%bugzilla.org
9c5fb4ec82 Bug 732440: Add SQL execution timings to buglist.cgi's debug output
r=LpSolit, r=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263597 18797224-902f-48f8-a5cc-f745e15eee43
2012-03-22 06:31:26 +00:00
mkanat%bugzilla.org
3e4f37dad9 Bug 730670: Do not redirect in buglist.cgi to improve performance
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263490 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-27 14:02:13 +00:00
mkanat%bugzilla.org
3b5e8524aa Bug 680131: Replace the MPL 1.1 license by the MPL 2.0 one in all files, and add it to files which miss one
r=kiko r=mkanat r=mrbball a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263258 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-11 22:48:45 +00:00
mkanat%bugzilla.org
3eaa22ad33 Bug 644281: When the sort order of a buglist is modified, the "Show next bug in my list" user pref still uses the original sort order to decide which bug to display next
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263147 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-08 23:32:33 +00:00
mkanat%bugzilla.org
62dd0eae57 Bug 297382: Move sort order validation from buglist.cgi to Bugzilla::Search
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@263117 18797224-902f-48f8-a5cc-f745e15eee43
2011-11-30 09:46:20 +00:00
mkanat%bugzilla.org
ef209bdb4b Bug 255606: Do not let buglist.cgi return all bugs by default
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@263104 18797224-902f-48f8-a5cc-f745e15eee43
2011-11-26 13:01:37 +00:00
mkanat%bugzilla.org
5b32a30304 Bug 678357: Fix 'limit' parameter in the saved searches results
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@262674 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-16 23:05:34 +00:00
mkanat%bugzilla.org
ba97af1e21 Bug 678970: Use $user and $cgi instead of Bugzilla->user and Bugzilla->cgi
r=timello a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@262672 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-16 23:02:57 +00:00
mkanat%bugzilla.org
a7d5a2e186 Bug 647649: Change the old "Boolean Charts" UI into the new AND/OR
"Custom Search" UI.
r=timello, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@262354 18797224-902f-48f8-a5cc-f745e15eee43
2011-05-31 16:32:47 +00:00
mkanat%bugzilla.org
7a6be4d48a Bug 632718: Only return 500 search results unless the user specifically
requests to see more.
r=dkl, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261989 18797224-902f-48f8-a5cc-f745e15eee43
2011-03-02 08:50:28 +00:00
mkanat%bugzilla.org
0c25b7ebcc Bug 480044: Use dashes instead of colons to separate bug IDs in the BUGLIST cookie, because colons are HTML-escaped, making the cookie bigger than the 4k limit
r=mkanat a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261941 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-14 22:04:53 +00:00
mkanat%bugzilla.org
04b6a7dde3 Bug 417551: Make it possible for CSV headers to be the field description
instead of the field name, and have the buglist.cgi link give you CSV like
this by default.
r=mkanat, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261933 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-14 20:02:10 +00:00
mkanat%bugzilla.org
8febf24400 Bug 535571: Allow Search.pm to accept "limit" and "offset" as parameters.
r=mkanat, a=mkanat (module owner)


git-svn-id: svn://10.0.0.236/trunk@261925 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-12 02:16:46 +00:00
mkanat%bugzilla.org
b3b24b3c1c Bug 616185: Move tags (aka lists of bugs) to their own DB tables
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261875 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-30 12:16:48 +00:00
mkanat%bugzilla.org
f1b0586ba6 Bug 621090 - [SECURITY] Adding saved searches lacks CSRF protection
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261726 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-07 04:16:49 +00:00
mkanat%bugzilla.org
46d29e85bf Bug 615574: Make every search done by buglist.cgi create a list_id, so that
even Saved Searches get "last list" support.
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261694 18797224-902f-48f8-a5cc-f745e15eee43
2010-12-27 22:21:47 +00:00