98 Commits

Author SHA1 Message Date
mkanat%bugzilla.org
388ddeef0f Bug 824399: (CVE-2013-0786) [SECURITY] build_subselect() leaks the existence of products and components you cannot access
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264769 18797224-902f-48f8-a5cc-f745e15eee43
2013-02-19 17:32:38 +00:00
mkanat%bugzilla.org
7da4afeb09 Bug 826678: Disable warnings about the deprecated Return::Value module when loading Email::Send
r=wicked a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@264623 18797224-902f-48f8-a5cc-f745e15eee43
2013-01-05 23:31:21 +00:00
mkanat%bugzilla.org
620b5cd8ec Bug 728639: (CVE-2012-0465) [SECURITY] User lockout policy can be bypassed by altering the X-FORWARDED-FOR header
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263711 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-18 17:06:52 +00:00
mkanat%bugzilla.org
2f50aaf522 Bug 685552 - Email auto-completion causes server to thrash
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@263012 18797224-902f-48f8-a5cc-f745e15eee43
2011-10-24 22:19:56 +00:00
mkanat%bugzilla.org
219ce259e5 Fix missing documentation. r=mkanat.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@261847 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-27 12:05:21 +00:00
mkanat%bugzilla.org
e23ce78a9b Bug 611979: Undefined subroutine &Bugzilla::Config::Advanced::check_multi when enabling strict_transport_security
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@261563 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-14 19:04:13 +00:00
mkanat%bugzilla.org
b4cde6aa8f Bug 600475 - Support the 'includeSubDomains' flag as an option for the 'Strict-Transport-Security' advanced option in order to protect subdomains.
[r=glob a=mkanat]


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@261301 18797224-902f-48f8-a5cc-f745e15eee43
2010-09-29 19:03:27 +00:00
mkanat%bugzilla.org
4657e20014 Bug 594990: Make the Strict-Transport-Security HTTP header only be sent
if a particular parameter is enabled.
r=glob, a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-4_0-BRANCH@261293 18797224-902f-48f8-a5cc-f745e15eee43
2010-09-28 03:39:43 +00:00
mkanat%bugzilla.org
1228ba5d93 Bug 486292: Change the default workflow to UNCONFIRMED, CONFIRMED,
IN_PROGRESS, RESOLVED, VERIFIED.
r=LpSolit, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260637 18797224-902f-48f8-a5cc-f745e15eee43
2010-07-06 00:47:25 +00:00
mkanat%bugzilla.org
a3d7656f23 Bug 556422: Move the existing bug-moving functionality into an extension
called OldBugMove.
r=dkl, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260491 18797224-902f-48f8-a5cc-f745e15eee43
2010-06-18 21:16:53 +00:00
mkanat%bugzilla.org
33a07dae31 Bug 450301: What Simplify searching UI, initial improvements to the advanced search ui.
r=mkanat, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260429 18797224-902f-48f8-a5cc-f745e15eee43
2010-06-06 08:46:26 +00:00
mkanat%bugzilla.org
42aa99ed27 Bug 561362: Remove the 'sendmailnow' parameter
r=justdave a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@260222 18797224-902f-48f8-a5cc-f745e15eee43
2010-04-23 16:16:31 +00:00
mkanat%bugzilla.org
f7e990146a Bug 560009: Use firstidx from List::MoreUtils instead of lsearch
r=timello, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260217 18797224-902f-48f8-a5cc-f745e15eee43
2010-04-22 18:16:55 +00:00
mkanat%bugzilla.org
2992c0b59d Bug 557806: When setting the upgrade_notification parameter, an error should be thrown if you don't have all the required Perl modules installed
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@260165 18797224-902f-48f8-a5cc-f745e15eee43
2010-04-07 14:47:54 +00:00
mkanat%bugzilla.org
a68210b184 Bug 372979: Make voting into an extension
r=mkanat, a=mkanat, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@259709 18797224-902f-48f8-a5cc-f745e15eee43
2010-02-15 23:32:10 +00:00
mkanat%bugzilla.org
e936808e85 Bug 537846 - "Disable the "Reset" checkbox for the maintainer parameter" [r=mkanat a=mkanat]
git-svn-id: svn://10.0.0.236/trunk@259669 18797224-902f-48f8-a5cc-f745e15eee43
2010-02-10 04:17:29 +00:00
mkanat%bugzilla.org
0cc827bc54 Bug 527586: Use X-Forwarded-For instead of REMOTE_ADDR for trusted proxies
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=dkl, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@259326 18797224-902f-48f8-a5cc-f745e15eee43
2009-12-31 12:53:21 +00:00
mkanat%bugzilla.org
b2323c2ef3 Bug 519858 - Move uncommonly used parameters out of the "Required" section and into a "General" and "Advanced" section
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@259324 18797224-902f-48f8-a5cc-f745e15eee43
2009-12-31 12:37:51 +00:00
mkanat%bugzilla.org
6a86535026 Bug 527387: Make Parameter section sortkeys numeric and leave space between the numbers
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@259209 18797224-902f-48f8-a5cc-f745e15eee43
2009-12-13 20:49:08 +00:00
mkanat%bugzilla.org
15546c7c25 Bug 355283: Lock out a user account on a particular IP for 30 minutes if they fail to log in 5 times from that IP.
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@259208 18797224-902f-48f8-a5cc-f745e15eee43
2009-12-13 20:46:28 +00:00
mkanat%bugzilla.org
bc7313feed Bug 520948: Use Bugzilla->feature and feature_enabled everywhere instead of checking if modules are installed
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@258771 18797224-902f-48f8-a5cc-f745e15eee43
2009-10-24 05:21:11 +00:00
lpsolit%gmail.com
c89b589751 Bug 399073: Remove the 'loginnetmask' parameter - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@258717 18797224-902f-48f8-a5cc-f745e15eee43
2009-10-18 23:35:01 +00:00
mkanat%bugzilla.org
c70c2cf9ff Bug 514913: Eliminate ssl="authenticated sessions"
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=dkl, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@258645 18797224-902f-48f8-a5cc-f745e15eee43
2009-10-09 04:31:13 +00:00
mkanat%bugzilla.org
c4f99cc559 Bug 224588: Unify ($^O =~ /MSWin/) checks (always use ON_WINDOWS)
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@258321 18797224-902f-48f8-a5cc-f745e15eee43
2009-09-04 21:08:52 +00:00
lpsolit%gmail.com
2b4f829545 Bug 480986: The BMP -> PNG conversion tool for new attachments should be an extension - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@258106 18797224-902f-48f8-a5cc-f745e15eee43
2009-08-13 21:32:27 +00:00
mkanat%bugzilla.org
72f7ffea5f Bug 314364: Make QuickSearch use "matches" for comment searches instead of "substring"
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=wicked, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@257727 18797224-902f-48f8-a5cc-f745e15eee43
2009-07-20 04:10:57 +00:00
mkanat%bugzilla.org
10288809cf Bug 482584: Add a parameter to hide the "See Also" field
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, r=dkl, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@256956 18797224-902f-48f8-a5cc-f745e15eee43
2009-04-17 22:30:33 +00:00
lpsolit%gmail.com
f4803560fd Bug 399089: Remove the 'usermatchmode' parameter - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@256772 18797224-902f-48f8-a5cc-f745e15eee43
2009-03-31 19:24:34 +00:00
lpsolit%gmail.com
bfda31bbd9 Bug 478972: Remove the 'useentrygroupdefault' parameter - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@256770 18797224-902f-48f8-a5cc-f745e15eee43
2009-03-31 19:17:03 +00:00
mkanat%bugzilla.org
28915b7f1f Bug 480001: MySQL 5.1.31 throws an error when you try to SET SESSION max_allowed_packet (and previous versions of MySQL were just ignoring the SET SESSION), so just warn people if their max_allowed_packet is too small
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@256380 18797224-902f-48f8-a5cc-f745e15eee43
2009-03-02 01:23:17 +00:00
lpsolit%gmail.com
054bb4fdd3 Bug 472206: [SECURITY] Bugzilla should optionally not allow the user to view possibly harmful attachments - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat r=justdave a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@256027 18797224-902f-48f8-a5cc-f745e15eee43
2009-02-02 19:12:26 +00:00
lpsolit%gmail.com
0c29cf31b2 Bug 38862: [SECURITY] attachments should be at a different hostname - Patch by Byron Jones <bugzilla@glob.com.au> and Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@256018 18797224-902f-48f8-a5cc-f745e15eee43
2009-02-02 18:26:26 +00:00
mkanat%bugzilla.org
b35fd1b839 Bug 474516: specific_search_allow_empty_words should default to on
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@255929 18797224-902f-48f8-a5cc-f745e15eee43
2009-01-26 22:05:59 +00:00
mkanat%bugzilla.org
3ef17d8edf Bug 284184: Allow Bugzilla to use an asynchronous job queue for sending mail.
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> and Mark Smith <mark@plogs.net> r=glob, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@255634 18797224-902f-48f8-a5cc-f745e15eee43
2008-12-24 03:43:49 +00:00
mkanat%bugzilla.org
3329d84b3c Bug 468728: The 'allowemailchange' parameter should default to 1
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@255542 18797224-902f-48f8-a5cc-f745e15eee43
2008-12-16 21:22:02 +00:00
lpsolit%gmail.com
5a590adea0 Bug 399079: Remove the 'showallproducts' parameter - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@255423 18797224-902f-48f8-a5cc-f745e15eee43
2008-12-10 18:43:36 +00:00
lpsolit%gmail.com
898879cb3d Bug 399076: Remove the 'commentonreassignbycomponent' parameter - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@255421 18797224-902f-48f8-a5cc-f745e15eee43
2008-12-10 18:40:02 +00:00
lpsolit%gmail.com
fb38686377 Bug 399075: Remove the 'commentonclearresolution' parameter - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@255420 18797224-902f-48f8-a5cc-f745e15eee43
2008-12-10 18:36:02 +00:00
lpsolit%gmail.com
839bd078af Bug 399074: Remove the 'maxpatchsize' parameter - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@255419 18797224-902f-48f8-a5cc-f745e15eee43
2008-12-10 18:32:30 +00:00
lpsolit%gmail.com
3af770f143 Bug 399072: Remove the 'supportwatchers' parameter - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@255418 18797224-902f-48f8-a5cc-f745e15eee43
2008-12-10 18:26:56 +00:00
lpsolit%gmail.com
225cd8cd05 Bug 399070: Remove the 'timezone' parameter - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@253910 18797224-902f-48f8-a5cc-f745e15eee43
2008-08-27 23:26:26 +00:00
mkanat%bugzilla.org
fd276d6f66 Bug 438435: Need code hooks for authentication
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@253408 18797224-902f-48f8-a5cc-f745e15eee43
2008-08-06 23:38:31 +00:00
lpsolit%gmail.com
3068ac33df Bug 182975: Bugzilla directory structure to be adopted to l10n needs - Patch by A.A. Shimono (himorin) <shimono@mozilla.gr.jp> r=LpSolit r=mkanat a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@249049 18797224-902f-48f8-a5cc-f745e15eee43
2008-04-03 19:05:51 +00:00
lpsolit%gmail.com
e77bc8e4a9 Bug 358588: The sslbase's port is harcoded, but shouldn't (allow the port to be specified with the parameter) - Patch by Frédéric Buclin <LpSolit@gmail.com> r=glob a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@248628 18797224-902f-48f8-a5cc-f745e15eee43
2008-03-27 00:23:41 +00:00
lpsolit%gmail.com
9228a2db7b Bug 304005: Implement SMTP authentication support for email notifications - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@247785 18797224-902f-48f8-a5cc-f745e15eee43
2008-03-14 00:05:37 +00:00
lpsolit%gmail.com
b1f4826502 Bug 387672: Move BUG_STATE_OPEN and is_open_state() into Status.pm - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@237447 18797224-902f-48f8-a5cc-f745e15eee43
2007-10-09 10:35:01 +00:00
lpsolit%gmail.com
ecf43ca735 Bug 394959: Turn votes off by default - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@235479 18797224-902f-48f8-a5cc-f745e15eee43
2007-09-10 22:57:00 +00:00
wurblzap%gmail.com
60184b20e6 Bug 365378 – The 'languages' parameter is not necessary.
Patch by Marc Schumann <wurblzap@gmail.com>;
r=LpSolit; a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@232473 18797224-902f-48f8-a5cc-f745e15eee43
2007-08-21 20:47:56 +00:00
lpsolit%gmail.com
4fd36feed5 Bug 335354: editparams.cgi crashes when editing the 'languages' and 'defaultlanguage' parameters - Patch by Frédéric Buclin <LpSolit@gmail.com> r=wurblzap, mkanat a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@232411 18797224-902f-48f8-a5cc-f745e15eee43
2007-08-20 21:05:45 +00:00
wurblzap%gmail.com
2ae6da445f Bug 380187 – Bugzilla should support RADIUS authentication.
Patch by Marc Schumann <wurblzap@gmail.com>;
r=mkanat, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@231372 18797224-902f-48f8-a5cc-f745e15eee43
2007-08-02 22:38:53 +00:00