213780 Commits

Author SHA1 Message Date
mkanat%bugzilla.org
a158c71df8 Bug 591610: Custom field doc doesn't include 'Bug ID' type
r=timello a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263128 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-02 16:50:47 +00:00
mkanat%bugzilla.org
4d19b12121 Bug 531257: Wrong error codes in WebServices documentation
r=gerv a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263076 18797224-902f-48f8-a5cc-f745e15eee43
2011-11-16 17:02:28 +00:00
mkanat%bugzilla.org
16f2744e63 Bug 691243: Fix typo
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262987 18797224-902f-48f8-a5cc-f745e15eee43
2011-10-15 13:35:13 +00:00
mkanat%bugzilla.org
018c63a1c8 Bug 620694: MySQL is not 'required' RDBMS for Bugzilla
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262981 18797224-902f-48f8-a5cc-f745e15eee43
2011-10-15 12:50:10 +00:00
mkanat%bugzilla.org
d8c3ead78b Bug 445804: Suggested crontab configuration opens security hole
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262979 18797224-902f-48f8-a5cc-f745e15eee43
2011-10-15 12:35:24 +00:00
mkanat%bugzilla.org
e0f7f71b31 Bump the version number post-release.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262610 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-06 00:19:39 +00:00
mkanat%bugzilla.org
997061796a Bump version number for 3.6.6.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262593 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-05 00:18:47 +00:00
mkanat%bugzilla.org
432a88165a Bug 670868: (CVE-2011-2978) [SECURITY] Account preferences page trusts user-modifiable field for obtaining current e-mail address
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262586 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 21:06:12 +00:00
mkanat%bugzilla.org
9ed06e7b6e Bug 637981: (CVE-2011-2379) [SECURITY] "Raw Unified" patch diffs can cause XSS on this domain in IE 6-8 and Safari
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262585 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 20:49:57 +00:00
mkanat%bugzilla.org
79ac518c92 Bug 660502: (CVE-2011-2977) [SECURITY] Temporary files for uploaded attachments are not deleted on Windows
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262584 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 20:33:34 +00:00
mkanat%bugzilla.org
a4c8ab1653 Bug 653477: (CVE-2011-2380) [SECURITY] Group names can be guessed when creating or editing a bug
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262583 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 20:20:54 +00:00
mkanat%bugzilla.org
91d4f8b7b2 Bug 657158 - (CVE-2011-2381) [SECURITY] Request email headers for attachment containing newline are corrupt
[r=glob a=LpSolit]


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262580 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 19:34:39 +00:00
mkanat%bugzilla.org
7a38fe66c0 Bug 675752: Release notes for Bugzilla 3.6.6
r=mkanat a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262564 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-02 23:01:21 +00:00
mkanat%bugzilla.org
3b0e00fd3c Bug 653406: fix escaping of url vars in error messages
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262270 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-29 05:49:35 +00:00
mkanat%bugzilla.org
b77fa6e570 Bump the version number post-release.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262263 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-28 04:06:09 +00:00
mkanat%bugzilla.org
19fdf4332b Bump version number for 3.6.5.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262259 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-28 02:20:06 +00:00
mkanat%bugzilla.org
4fca133da2 Bug 653274 - Release Notes for Bugzilla 3.6.5
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262251 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-28 00:29:58 +00:00
mkanat%bugzilla.org
e4f4fed7d3 Bug 646578: Make Math::Random::Secure fail to install if its dependencies
don't install properly, when using install-module.pl.
r=glob, a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262244 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-27 22:22:46 +00:00
mkanat%bugzilla.org
5235c0a72e Fix typo in POD
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262218 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-22 15:50:50 +00:00
mkanat%bugzilla.org
74ce1ca6ae Bug 311392 - Typos and proper name of Red Hat's stuff
author=Matt Selksy <selsky_at_columbia_dot_edu>, r=dkl, a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262089 18797224-902f-48f8-a5cc-f745e15eee43
2011-03-22 20:21:02 +00:00
mkanat%bugzilla.org
a604083c17 Bug 586011 - Change references to 'DarwinPorts' to 'MacPorts' (proper project name)
author=Matt Selsky <selsky_at_columbia_dot_edu>, r=dkl,a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262069 18797224-902f-48f8-a5cc-f745e15eee43
2011-03-18 21:04:46 +00:00
mkanat%bugzilla.org
cb351b6e88 Restore the missing link due to bug 490322 (thanks Selenium!)
r=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261948 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-15 19:01:41 +00:00
mkanat%bugzilla.org
aff8064de6 Bug 490322: Make "allwords" work with the keywords field, again.
r=glob, a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261942 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-15 05:48:11 +00:00
mkanat%bugzilla.org
535075a875 Bug 480044: Use dashes instead of colons to separate bug IDs in the BUGLIST cookie, because colons are HTML-escaped, making the cookie bigger than the 4k limit
r=mkanat a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261941 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-14 22:04:53 +00:00
mkanat%bugzilla.org
3eb5521896 Remove tabs and fix some formatting in Bugzilla::DB::Pg.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261940 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-14 20:36:14 +00:00
mkanat%bugzilla.org
e9009e86e3 Bug 633055: Make Bug.legal_values explicitly throw an error if you pass "undef"
for the "field" parameter
r=dkl, a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261939 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-14 20:31:54 +00:00
mkanat%bugzilla.org
9f3d5702d4 Bug 616981: Make whine.pl work with PostgreSQL 8.4+ by fixing sql_string_until
r=mkanat, a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261938 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-14 20:27:00 +00:00
mkanat%bugzilla.org
1874eef40e Bug 633422: Fix the documentation for User.get's include_disabled parameter
and make User.get check that its required parameters are passed.
r=LpSolit, a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261932 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-14 07:51:04 +00:00
mkanat%bugzilla.org
8e847fa809 Bug 630750: Don't let "." and "lib" get into @INC when running under
mod_perl
r=dkl, a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261891 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-03 21:49:37 +00:00
mkanat%bugzilla.org
87201dfd68 Bug 629007: Example in quicksearch priority shortcut is incorrect
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261879 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-31 23:05:07 +00:00
mkanat%bugzilla.org
bc19b49de9 Add missing documentation. r=mkanat.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261848 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-27 12:06:49 +00:00
mkanat%bugzilla.org
96096b8378 The "simple format" of the duplicates table was broken by an improper backport
using the "mtime" filter, which doesn't exist in 3.6.


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261831 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-25 05:31:41 +00:00
mkanat%bugzilla.org
e35b6ce4fd Bug 621597: Make mod_perl.pl automatically include the lib/ directory and
all the architecture-specific directories underneath it.
r=dkl, a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261829 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-25 02:31:54 +00:00
mkanat%bugzilla.org
2835c33f35 Bump the version number post-release.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261828 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-25 02:06:03 +00:00
mkanat%bugzilla.org
0aa5df3a3e Bump the version number for 3.6.4.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261820 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 23:45:11 +00:00
mkanat%bugzilla.org
cc59d868e7 Bug 619594: (CVE-2010-4568) [SECURITY] Improve the randomness of
generate_random_password, to protect against an account compromise issue
and other critical vulnerabilities.
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261817 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 22:07:59 +00:00
mkanat%bugzilla.org
2d76acd475 Bug 621105 - [SECURITY] Voting lacks CSRF protection
r=mkanat,a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261814 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 19:53:26 +00:00
mkanat%bugzilla.org
72a8e0036b Bug 619588: (CVE-2010-4567) [SECURITY] Safety checks that disallow clicking for javascript: or data: URLs in the URL field can be evaded with prefixed whitespace
and

Bug 628034: (CVE-2011-0048) [SECURITY] For not-logged-in users, the URL field doesn't safeguard against javascript: or data: URLs

r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261813 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 18:53:58 +00:00
mkanat%bugzilla.org
80a65875dd Bug 621572: (CVE-2010-4572) [SECURITY] chart.cgi vulnerable to header-injection due to use of |print "Location:"| instead of $cgi->redirect
[r=mkanat a=LpSolit]


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261812 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 18:31:15 +00:00
mkanat%bugzilla.org
7445e5472f Bug 621110: [SECURITY] Quips (adding/approving/deleting) lacks CSRF protection
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261806 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 17:38:25 +00:00
mkanat%bugzilla.org
58e7e4bff8 Bug 621108: [SECURITY] Creating/editing charts lacks CSRF protection
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261805 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 17:27:06 +00:00
mkanat%bugzilla.org
448e567c1e Bug 627923 - Release Notes for Bugzilla 3.6.4
r=reed


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261799 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 04:23:23 +00:00
mkanat%bugzilla.org
6f7a3988b9 Bug 627854: Add 'form' hook to create-guided.html.tmpl similar to create.html.tmpl
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261785 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-21 21:50:19 +00:00
mkanat%bugzilla.org
3894d17d04 Bug 591165: (CVE-2010-4411) [SECURITY] Bump minimum required version of CGI.pm to v3.51 in order to address header injection vulnerability.
[r=mkanat a=mkanat]


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261784 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-21 21:22:55 +00:00
mkanat%bugzilla.org
e4db7a5241 Bug 623608 - Add intro/outro extension hooks to footer.html.tmpl
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261780 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-21 05:19:52 +00:00
mkanat%bugzilla.org
524773f812 Bug 255524: The duplicates table inherits no CSS classes when viewed in simple format
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261728 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-07 12:50:04 +00:00
mkanat%bugzilla.org
8c3d044ee9 Bug 622822 - add additional_links hook to front page. r,a=mkanat.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261707 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-05 10:50:18 +00:00
mkanat%bugzilla.org
c8d557f459 Bug 622105 - Misspelling in setting_info_invalid error message
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261703 18797224-902f-48f8-a5cc-f745e15eee43
2010-12-30 17:03:17 +00:00
mkanat%bugzilla.org
383bca84ad Bug 588013: Fix typo
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261692 18797224-902f-48f8-a5cc-f745e15eee43
2010-12-27 22:05:20 +00:00
mkanat%bugzilla.org
c02570a325 Bug 617684: Values starting with a dot or an underscore are no longer hidden in reports
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@261636 18797224-902f-48f8-a5cc-f745e15eee43
2010-12-08 20:19:55 +00:00