7690 Commits

Author SHA1 Message Date
mkanat%bugzilla.org
6b568442fe Typo :(
git-svn-id: svn://10.0.0.236/trunk@261877 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-30 13:04:24 +00:00
mkanat%bugzilla.org
a0f6efb2ee Fix bustage for bug 616185: commas are encoded as %2C in Bugzilla 3.x, but not in 2.22
git-svn-id: svn://10.0.0.236/trunk@261876 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-30 13:02:17 +00:00
mkanat%bugzilla.org
b3b24b3c1c Bug 616185: Move tags (aka lists of bugs) to their own DB tables
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261875 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-30 12:16:48 +00:00
mkanat%bugzilla.org
23c0346f8c Bug 622080 - Change group which can moderate quips
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261859 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-28 16:32:17 +00:00
mkanat%bugzilla.org
8b3f242213 Bug 622679 - Autocomplete suggests inactive/disabled accounts as matches
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261853 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-27 22:03:41 +00:00
mkanat%bugzilla.org
41c0903a59 Allow extensions to alter quicksearch terms and search format. r=mkanat.
git-svn-id: svn://10.0.0.236/trunk@261850 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-27 13:03:40 +00:00
mkanat%bugzilla.org
781c552e6f Allow jobqueue.pl to run once and then exit. r=mkanat.
git-svn-id: svn://10.0.0.236/trunk@261849 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-27 12:47:20 +00:00
mkanat%bugzilla.org
f9b207f5ea Add missing documentation. r=mkanat.
git-svn-id: svn://10.0.0.236/trunk@261848 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-27 12:06:49 +00:00
mkanat%bugzilla.org
22645a9b06 Allow addition/removal of descriptions of statuses and resolutions. r=mkanat.
git-svn-id: svn://10.0.0.236/trunk@261846 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-27 12:02:02 +00:00
mkanat%bugzilla.org
4ab6094f28 Fix bustage; diffs is an arrayref in 4.0, an array on trunk.
git-svn-id: svn://10.0.0.236/trunk@261845 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-27 11:16:42 +00:00
mkanat%bugzilla.org
59fef3e9d7 Update default column list to something more sensible. r=mkanat, lpsolit, wurblzap.
git-svn-id: svn://10.0.0.236/trunk@261844 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-27 10:50:25 +00:00
mkanat%bugzilla.org
fc8ea6b68c Add diffs parameter to bugmail_recipients hook. r=mkanat.
git-svn-id: svn://10.0.0.236/trunk@261843 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-27 10:50:24 +00:00
mkanat%bugzilla.org
0804bbf13f Make param pages without a sortkey sort to the end. r=dkl, a=lpsolit.
git-svn-id: svn://10.0.0.236/trunk@261834 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-25 17:31:44 +00:00
mkanat%bugzilla.org
1455271c76 Bug 619594: (CVE-2010-4568) [SECURITY] Improve the randomness of
generate_random_password, to protect against an account compromise issue
and other critical vulnerabilities.
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261817 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 22:07:59 +00:00
mkanat%bugzilla.org
192acb445e Bug 621105 - [SECURITY] Voting lacks CSRF protection
r=mkanat,a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261814 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 19:53:26 +00:00
mkanat%bugzilla.org
3c1eb91b87 Bug 619588: (CVE-2010-4567) [SECURITY] Safety checks that disallow clicking for javascript: or data: URLs in the URL field can be evaded with prefixed whitespace
and

Bug 628034: (CVE-2011-0048) [SECURITY] For not-logged-in users, the URL field doesn't safeguard against javascript: or data: URLs

r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261813 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 18:53:58 +00:00
mkanat%bugzilla.org
037b511533 Bug 621572: (CVE-2010-4572) [SECURITY] chart.cgi vulnerable to header-injection due to use of |print "Location:"| instead of $cgi->redirect
[r=mkanat a=LpSolit]


git-svn-id: svn://10.0.0.236/trunk@261809 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 18:21:35 +00:00
mkanat%bugzilla.org
e31c7274dd Bug 619648: (CVE-2010-4570) [SECURITY] XSS via summary in "possible duplicates" table due to lack of encoding by YUI
[r=mkanat a=LpSolit]


git-svn-id: svn://10.0.0.236/trunk@261808 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 18:19:32 +00:00
mkanat%bugzilla.org
0de7873107 Bug 619637: (CVE-2010-4569) [SECURITY] XSS in user autocomplete due to lack of encoding by YUI
[r=mkanat r=dkl a=LpSolit]


git-svn-id: svn://10.0.0.236/trunk@261807 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 18:17:27 +00:00
mkanat%bugzilla.org
63e0fe631d Bug 621110: [SECURITY] Quips (adding/approving/deleting) lacks CSRF protection
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261806 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 17:38:25 +00:00
mkanat%bugzilla.org
5591cfca76 Bug 621108: [SECURITY] Creating/editing charts lacks CSRF protection
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261805 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 17:27:06 +00:00
mkanat%bugzilla.org
ad969a4c73 Bug 621107: [SECURITY] Sanity checking lacks CSRF protection
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261804 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 17:20:55 +00:00
mkanat%bugzilla.org
27435d5247 An optional module was accidentally listed in the "required" section of the
release notes.


git-svn-id: svn://10.0.0.236/trunk@261798 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 04:21:54 +00:00
mkanat%bugzilla.org
a44779d06f Bug 627910: Update Release Notes for Bugzilla 4.0rc2
r=reed


git-svn-id: svn://10.0.0.236/trunk@261797 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 04:20:14 +00:00
mkanat%bugzilla.org
f7e2d54be7 Bug 625741: Need a hook in update_fielddefs_definition to enable adding columns to fielddefs
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261796 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-23 12:16:55 +00:00
mkanat%bugzilla.org
54c445dd98 Bug 621128 - Remove trailing whitespace from '<div id="view_disabled" >'
[r=reed a=LpSolit]


git-svn-id: svn://10.0.0.236/trunk@261795 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-22 21:33:53 +00:00
mkanat%bugzilla.org
4e9207cb2c Bug 624696: We need a template hook to add a description to parameters added by extensions
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261793 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-22 18:01:52 +00:00
mkanat%bugzilla.org
0a7675f82f Bug 621109: Column changing lacks CSRF protection
r=dkl a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261792 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-22 17:33:23 +00:00
mkanat%bugzilla.org
4309161c54 Bug 627854: Add 'form' hook to create-guided.html.tmpl similar to create.html.tmpl
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261785 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-21 21:50:19 +00:00
mkanat%bugzilla.org
c2043384eb Bug 591165: (CVE-2010-4411) [SECURITY] Bump minimum required version of CGI.pm to v3.51 in order to address header injection vulnerability.
[r=mkanat a=mkanat]


git-svn-id: svn://10.0.0.236/trunk@261784 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-21 21:22:55 +00:00
mkanat%bugzilla.org
dfc275d0b7 Bug 627660 - Rename "Send" button on final create account page to "Create", as nothing is actually sent.
[r=mkanat a=mkanat]


git-svn-id: svn://10.0.0.236/trunk@261783 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-21 21:03:23 +00:00
mkanat%bugzilla.org
003008ba3f Bug 626292: "Make description private" checkbox should set bz_private class on the comment box
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261781 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-21 06:46:43 +00:00
mkanat%bugzilla.org
cdf700462f Bug 623608 - Add intro/outro extension hooks to footer.html.tmpl
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261780 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-21 05:19:52 +00:00
mkanat%bugzilla.org
96c9f97ed2 Bug 626658 - Add (take) link to bug edit page to allow quick assigning to the current user
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261779 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-21 05:01:51 +00:00
mkanat%bugzilla.org
821d3d9bf9 Bug 625190: Typo and Missing FK in Bugzilla::DB::Schema
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261748 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-15 00:19:58 +00:00
mkanat%bugzilla.org
e32f9a5b84 Bug 623408: Message-ID is gone in bugmail for new bugs
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261747 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-15 00:16:48 +00:00
mkanat%bugzilla.org
4dce4e16c6 Bug 624349: Let the config_modify_panels hook add new parameters to existing panels
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261735 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-10 23:16:43 +00:00
mkanat%bugzilla.org
46957ef7fa Bug 618841: Bare word "bug" in release notes
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261732 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-09 14:36:48 +00:00
mkanat%bugzilla.org
d16127037b Bug 622204: Bugzilla::Migrate crashes trying to create bugs with resolutions
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261731 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-09 14:35:14 +00:00
mkanat%bugzilla.org
683c9861bf Bug 558803: Add a parameter to specify the password complexity for new passwords
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261729 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-07 14:31:50 +00:00
mkanat%bugzilla.org
19167fa159 Bug 255524: The duplicates table inherits no CSS classes when viewed in simple format
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261728 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-07 12:50:04 +00:00
mkanat%bugzilla.org
2803e4edc8 Provide user objects to bugmail_recipients hook. r,a=mkanat.
git-svn-id: svn://10.0.0.236/trunk@261727 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-07 11:16:39 +00:00
mkanat%bugzilla.org
f1b0586ba6 Bug 621090 - [SECURITY] Adding saved searches lacks CSRF protection
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261726 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-07 04:16:49 +00:00
mkanat%bugzilla.org
20b28b8e61 Document how to add user settings. r,a=mkanat.
git-svn-id: svn://10.0.0.236/trunk@261709 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-05 17:03:49 +00:00
mkanat%bugzilla.org
7090d28190 Allow extensions to add new Jobs. r,a=mkanat.
git-svn-id: svn://10.0.0.236/trunk@261708 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-05 12:01:59 +00:00
mkanat%bugzilla.org
7224a52f7a Bug 622822 - add additional_links hook to front page. r,a=mkanat.
git-svn-id: svn://10.0.0.236/trunk@261707 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-05 10:50:18 +00:00
mkanat%bugzilla.org
160ef05099 Bug 595410: Make it faster to display a bug that has a lot of dependencies.
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261706 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-04 02:16:57 +00:00
mkanat%bugzilla.org
9454fcae9f Bug 622437: Remove 'colchange_columns' hook from the Example extension
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261705 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-02 20:04:09 +00:00
mkanat%bugzilla.org
6baae2406b Bug 622105 - Misspelling in setting_info_invalid error message
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261702 18797224-902f-48f8-a5cc-f745e15eee43
2010-12-30 16:46:44 +00:00
mkanat%bugzilla.org
5b37e09217 Bug 621597: Make mod_perl.pl do the INC configuration itself, instead of
requiring it to be in httpd.conf.
r=dkl, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261700 18797224-902f-48f8-a5cc-f745e15eee43
2010-12-28 23:04:08 +00:00