454 Commits

Author SHA1 Message Date
mkanat%bugzilla.org
0a81634be5 Bug 824399: (CVE-2013-0786) [SECURITY] build_subselect() leaks the existence of products and components you cannot access
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264768 18797224-902f-48f8-a5cc-f745e15eee43
2013-02-19 17:15:41 +00:00
mkanat%bugzilla.org
e15ca127bd Bug 819432: Execute queries in two steps to improve performance
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264650 18797224-902f-48f8-a5cc-f745e15eee43
2013-01-16 18:15:42 +00:00
mkanat%bugzilla.org
d7fb30d846 Bug 413851 - add CSV output option to request lists. r=LpSolit.
git-svn-id: svn://10.0.0.236/trunk@264615 18797224-902f-48f8-a5cc-f745e15eee43
2013-01-02 17:16:27 +00:00
mkanat%bugzilla.org
4eb193ff89 Bug 718289: The deadline field should be visible by non-members of the timetracking group
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264484 18797224-902f-48f8-a5cc-f745e15eee43
2012-11-26 19:31:38 +00:00
mkanat%bugzilla.org
57ce848077 Bug 761046: Don't redirect when hitting buglist.cgi directly to avoid duplicate cgi->header calls
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264219 18797224-902f-48f8-a5cc-f745e15eee43
2012-09-17 14:30:45 +00:00
mkanat%bugzilla.org
8e47ba629a Bug 787529: Use |use 5.10.1| everywhere
r=wicked a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264195 18797224-902f-48f8-a5cc-f745e15eee43
2012-09-01 21:45:59 +00:00
mkanat%bugzilla.org
116a14ddfd Bug 786310: Remove tokens when saving the default query
r= LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264169 18797224-902f-48f8-a5cc-f745e15eee43
2012-08-29 06:00:43 +00:00
mkanat%bugzilla.org
3d7d902c40 Bug 772953: Remove the token from buglist urls
r=dkl, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264163 18797224-902f-48f8-a5cc-f745e15eee43
2012-08-28 15:30:47 +00:00
mkanat%bugzilla.org
ed9c84f10c Bug 698068: The "There is no saved search named ..." page has a "forget" link
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264154 18797224-902f-48f8-a5cc-f745e15eee43
2012-08-20 09:15:46 +00:00
mkanat%bugzilla.org
b3ff509cbf Bug 768870: The "Un-forget the search" link has no token
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263995 18797224-902f-48f8-a5cc-f745e15eee43
2012-06-27 16:16:21 +00:00
mkanat%bugzilla.org
0715897a0d Bug 760978: Remove support for Internet Explorer 5 on Mac
r=timello a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263913 18797224-902f-48f8-a5cc-f745e15eee43
2012-06-07 21:45:44 +00:00
mkanat%bugzilla.org
fca185824d Bug 297553: Enable serverpush for Opera
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263896 18797224-902f-48f8-a5cc-f745e15eee43
2012-06-03 13:15:42 +00:00
mkanat%bugzilla.org
938397e25f Bug 754672 - CSRF vulnerability in buglist.cgi allows possible unauthorized setting of default search options
[r=LpSolit a=LpSolit]


git-svn-id: svn://10.0.0.236/trunk@263871 18797224-902f-48f8-a5cc-f745e15eee43
2012-05-29 15:30:45 +00:00
mkanat%bugzilla.org
4e5431f617 Bug 616191: Implement UI to easily tag bugs from the bug report directly (and get rid of the current form in the footer)
r=timello a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263790 18797224-902f-48f8-a5cc-f745e15eee43
2012-05-07 16:01:09 +00:00
mkanat%bugzilla.org
8eeb112f53 Bug 745751: Remove support for microsummaries
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263749 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-24 21:32:17 +00:00
mkanat%bugzilla.org
dae90e7dc8 Bug 745397: (CVE-2012-0466) [SECURITY] The JS template for buglists permits attackers to access all bugs that the victim can see
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263712 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-18 17:08:02 +00:00
mkanat%bugzilla.org
29308480db Bug 745320: Shared queries do not work when tags are part of the query
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263698 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-17 18:46:28 +00:00
mkanat%bugzilla.org
9c5fb4ec82 Bug 732440: Add SQL execution timings to buglist.cgi's debug output
r=LpSolit, r=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263597 18797224-902f-48f8-a5cc-f745e15eee43
2012-03-22 06:31:26 +00:00
mkanat%bugzilla.org
3e4f37dad9 Bug 730670: Do not redirect in buglist.cgi to improve performance
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263490 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-27 14:02:13 +00:00
mkanat%bugzilla.org
3b5e8524aa Bug 680131: Replace the MPL 1.1 license by the MPL 2.0 one in all files, and add it to files which miss one
r=kiko r=mkanat r=mrbball a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263258 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-11 22:48:45 +00:00
mkanat%bugzilla.org
3eaa22ad33 Bug 644281: When the sort order of a buglist is modified, the "Show next bug in my list" user pref still uses the original sort order to decide which bug to display next
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263147 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-08 23:32:33 +00:00
mkanat%bugzilla.org
62dd0eae57 Bug 297382: Move sort order validation from buglist.cgi to Bugzilla::Search
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@263117 18797224-902f-48f8-a5cc-f745e15eee43
2011-11-30 09:46:20 +00:00
mkanat%bugzilla.org
ef209bdb4b Bug 255606: Do not let buglist.cgi return all bugs by default
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@263104 18797224-902f-48f8-a5cc-f745e15eee43
2011-11-26 13:01:37 +00:00
mkanat%bugzilla.org
5b32a30304 Bug 678357: Fix 'limit' parameter in the saved searches results
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@262674 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-16 23:05:34 +00:00
mkanat%bugzilla.org
ba97af1e21 Bug 678970: Use $user and $cgi instead of Bugzilla->user and Bugzilla->cgi
r=timello a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@262672 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-16 23:02:57 +00:00
mkanat%bugzilla.org
a7d5a2e186 Bug 647649: Change the old "Boolean Charts" UI into the new AND/OR
"Custom Search" UI.
r=timello, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@262354 18797224-902f-48f8-a5cc-f745e15eee43
2011-05-31 16:32:47 +00:00
mkanat%bugzilla.org
7a6be4d48a Bug 632718: Only return 500 search results unless the user specifically
requests to see more.
r=dkl, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261989 18797224-902f-48f8-a5cc-f745e15eee43
2011-03-02 08:50:28 +00:00
mkanat%bugzilla.org
0c25b7ebcc Bug 480044: Use dashes instead of colons to separate bug IDs in the BUGLIST cookie, because colons are HTML-escaped, making the cookie bigger than the 4k limit
r=mkanat a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261941 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-14 22:04:53 +00:00
mkanat%bugzilla.org
04b6a7dde3 Bug 417551: Make it possible for CSV headers to be the field description
instead of the field name, and have the buglist.cgi link give you CSV like
this by default.
r=mkanat, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261933 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-14 20:02:10 +00:00
mkanat%bugzilla.org
8febf24400 Bug 535571: Allow Search.pm to accept "limit" and "offset" as parameters.
r=mkanat, a=mkanat (module owner)


git-svn-id: svn://10.0.0.236/trunk@261925 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-12 02:16:46 +00:00
mkanat%bugzilla.org
b3b24b3c1c Bug 616185: Move tags (aka lists of bugs) to their own DB tables
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261875 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-30 12:16:48 +00:00
mkanat%bugzilla.org
f1b0586ba6 Bug 621090 - [SECURITY] Adding saved searches lacks CSRF protection
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261726 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-07 04:16:49 +00:00
mkanat%bugzilla.org
46d29e85bf Bug 615574: Make every search done by buglist.cgi create a list_id, so that
even Saved Searches get "last list" support.
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261694 18797224-902f-48f8-a5cc-f745e15eee43
2010-12-27 22:21:47 +00:00
mkanat%bugzilla.org
569ca875c0 Bug 77193 - Add the ability to retire (disable) old versions, components and milestones
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261153 18797224-902f-48f8-a5cc-f745e15eee43
2010-08-31 04:32:08 +00:00
mkanat%bugzilla.org
4a086c29fb Bug 581622: When a quicksearch includes the "content" field, it is limited to 200 bugs
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260934 18797224-902f-48f8-a5cc-f745e15eee43
2010-08-01 23:37:32 +00:00
mkanat%bugzilla.org
c634e6e71e Bug 398308: Make Search.pm take a hashref for its "params" argument
instead of taking a CGI object.
r=mkanat, a=mkanat (module owner)


git-svn-id: svn://10.0.0.236/trunk@260794 18797224-902f-48f8-a5cc-f745e15eee43
2010-07-16 03:01:42 +00:00
mkanat%bugzilla.org
c8197e8456 Bug 577800: Finish the cleanup of Search.pm's "init" function by removing
it and having its work be done by a new "sql" accessor instead. Also adds
some comments, moves functions around into sections, and creates a new
_user accessor.
r=mkanat, a=mkanat (module owner)


git-svn-id: svn://10.0.0.236/trunk@260784 18797224-902f-48f8-a5cc-f745e15eee43
2010-07-15 11:24:27 +00:00
mkanat%bugzilla.org
6add188323 Bug 24896: Make the First/Last/Prev/Next navigation on bugs work with
multiple buglists at once
r=glob, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260472 18797224-902f-48f8-a5cc-f745e15eee43
2010-06-16 01:46:23 +00:00
mkanat%bugzilla.org
ecf0f13ce8 Bug 565879: Merge ThrowCodeError("action_unrecognized"), ThrowUserError("no_valid_action") and ThrowCodeError("unknown_action")
r=ghendricks a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@260347 18797224-902f-48f8-a5cc-f745e15eee43
2010-05-20 15:46:29 +00:00
mkanat%bugzilla.org
36e3953f83 Bug 486050: Bugzilla should prefill quicksearch box when showing search results from a quicksearch
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260287 18797224-902f-48f8-a5cc-f745e15eee43
2010-05-12 17:16:22 +00:00
mkanat%bugzilla.org
f7e990146a Bug 560009: Use firstidx from List::MoreUtils instead of lsearch
r=timello, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260217 18797224-902f-48f8-a5cc-f745e15eee43
2010-04-22 18:16:55 +00:00
mkanat%bugzilla.org
c608951232 Bug 513989 - large search query causing internal server error (500) but valid redirect 302 returned
r=mkanat, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@259873 18797224-902f-48f8-a5cc-f745e15eee43
2010-03-03 22:16:23 +00:00
mkanat%bugzilla.org
d848003a60 Bug 286041 - Allow people to undo "forget search"
r=mkanat, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@259860 18797224-902f-48f8-a5cc-f745e15eee43
2010-03-01 23:31:30 +00:00
mkanat%bugzilla.org
495517b96c Bug 537834 - "Buglist results using atom ctype do not display users with empty real names"
[r=LpSolit a=LpSolit]


git-svn-id: svn://10.0.0.236/trunk@259830 18797224-902f-48f8-a5cc-f745e15eee43
2010-02-28 20:22:57 +00:00
mkanat%bugzilla.org
a68210b184 Bug 372979: Make voting into an extension
r=mkanat, a=mkanat, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@259709 18797224-902f-48f8-a5cc-f745e15eee43
2010-02-15 23:32:10 +00:00
lpsolit%gmail.com
71147b9b71 Bug 535675: Typing +foo in the QuickSearch box throws an "uninitialized value" warning (missing 'order' parameter) - Patch by Frédéric Buclin <LpSolit@gmail.com> r=wicked a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@259343 18797224-902f-48f8-a5cc-f745e15eee43
2010-01-06 15:00:47 +00:00
lpsolit%gmail.com
e23819934e Bug 505039: Use $user->is_timetracker instead of $user->in_group(Bugzilla->params->{'timetrackinggroup'}) - Patch by XqueZme <xquezme@gmail.com> r/a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@258957 18797224-902f-48f8-a5cc-f745e15eee43
2009-11-10 16:31:51 +00:00
lpsolit%gmail.com
241dbe4bfb Bug 526271: Uninitialized value in can_enter_product() due to a missing argument - Patch by Frédéric Buclin <LpSolit@gmail.com> r=ghendricks a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@258858 18797224-902f-48f8-a5cc-f745e15eee43
2009-11-03 19:46:15 +00:00
mkanat%bugzilla.org
ccb8bd9945 Bug 524234: When there are no search results, include helpful links
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=dkl, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@258818 18797224-902f-48f8-a5cc-f745e15eee43
2009-10-29 04:46:17 +00:00
lpsolit%gmail.com
c496f78667 Bug 524395: Boolean charts And, Or, "add another chart" buttons do no work with JS turned off - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@258785 18797224-902f-48f8-a5cc-f745e15eee43
2009-10-26 00:12:23 +00:00