184 Commits

Author SHA1 Message Date
mkanat%bugzilla.org
cfe160dd7e Bug 842038: (CVE-2013-0785) [SECURITY] XSS in show_bug.cgi when using an invalid page format
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264770 18797224-902f-48f8-a5cc-f745e15eee43
2013-02-19 17:33:12 +00:00
mkanat%bugzilla.org
f42ec136f8 Bug 830467: Don't call _wanted_languages() when only one is available
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264651 18797224-902f-48f8-a5cc-f745e15eee43
2013-01-17 12:15:47 +00:00
mkanat%bugzilla.org
7e3a06e5ab Bug 829939: Only build default_authorizer on request
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264643 18797224-902f-48f8-a5cc-f745e15eee43
2013-01-14 18:01:31 +00:00
mkanat%bugzilla.org
c5db81398d Bug 829709: Do not load CSS files from all skins by default
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264642 18797224-902f-48f8-a5cc-f745e15eee43
2013-01-14 18:00:47 +00:00
mkanat%bugzilla.org
4972341886 Bug 804343: Implement autolinkification for a list of comment ids
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264595 18797224-902f-48f8-a5cc-f745e15eee43
2012-12-29 19:45:41 +00:00
mkanat%bugzilla.org
1764f0df90 Bug 787668: Use |use parent| instead of |use base|
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264508 18797224-902f-48f8-a5cc-f745e15eee43
2012-12-01 01:31:00 +00:00
mkanat%bugzilla.org
f6af30d002 Bug 816747 - Add dummy POD for unPODded methods.
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264502 18797224-902f-48f8-a5cc-f745e15eee43
2012-11-30 14:45:59 +00:00
mkanat%bugzilla.org
b6f905fa00 Bug 811280: Adds a caching mechanism to Bugzilla::Object to avoid querying the database repeatedly for the same information
r=dkl,a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264478 18797224-902f-48f8-a5cc-f745e15eee43
2012-11-22 14:45:44 +00:00
mkanat%bugzilla.org
ca9fbfbf5b Bug 797636: Improve performance for buglists
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264452 18797224-902f-48f8-a5cc-f745e15eee43
2012-11-16 17:15:44 +00:00
mkanat%bugzilla.org
6c6e93ea81 Bug 213440: quoteUrls() should permit multiple bug numbers to be linkified in comments
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264335 18797224-902f-48f8-a5cc-f745e15eee43
2012-10-13 15:30:45 +00:00
mkanat%bugzilla.org
511e43b55e Bug 797883: Adds a Bugzilla->process_cache
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264301 18797224-902f-48f8-a5cc-f745e15eee43
2012-10-04 17:00:45 +00:00
mkanat%bugzilla.org
8e47ba629a Bug 787529: Use |use 5.10.1| everywhere
r=wicked a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264195 18797224-902f-48f8-a5cc-f745e15eee43
2012-09-01 21:45:59 +00:00
mkanat%bugzilla.org
2c83f44e36 Bug 778631: use a persistent Template::Provider to avoid recompiling templates between page loads on mod_perl
r=dkl, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264127 18797224-902f-48f8-a5cc-f745e15eee43
2012-08-08 14:15:47 +00:00
mkanat%bugzilla.org
f92c35ca22 Backing out Bug 778631 due to breakage
git-svn-id: svn://10.0.0.236/trunk@264123 18797224-902f-48f8-a5cc-f745e15eee43
2012-08-07 14:45:52 +00:00
mkanat%bugzilla.org
ac3efc7ece Bug 778631: use a persistent Template::Provider to avoid recompiling templates between page loads on mod_perl
r=dkl, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264121 18797224-902f-48f8-a5cc-f745e15eee43
2012-08-07 09:45:41 +00:00
mkanat%bugzilla.org
9fa3e8e91c Bug 777398: (CVE-2012-1968) [SECURITY] HTML bugmail exposes information about restricted bugs
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@264072 18797224-902f-48f8-a5cc-f745e15eee43
2012-07-26 21:15:42 +00:00
mkanat%bugzilla.org
2f2d3de62a Bug 752751: Perl modules that start with a protocol (eg HTTP::Header) are not escaped correctly in SAFE_URL_REGEXP
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263830 18797224-902f-48f8-a5cc-f745e15eee43
2012-05-17 13:30:47 +00:00
mkanat%bugzilla.org
4e5431f617 Bug 616191: Implement UI to easily tag bugs from the bug report directly (and get rid of the current form in the footer)
r=timello a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263790 18797224-902f-48f8-a5cc-f745e15eee43
2012-05-07 16:01:09 +00:00
mkanat%bugzilla.org
615c8fd9d1 Bug 731562: Cache the global/user.html.tmpl template for improved performance
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263511 18797224-902f-48f8-a5cc-f745e15eee43
2012-03-01 22:31:34 +00:00
mkanat%bugzilla.org
508d962c45 Bug 731175: Bugzilla::Field shouldn't assume that someone else already loaded required modules
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263504 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-29 16:31:33 +00:00
mkanat%bugzilla.org
d3a4c78fd7 Bug 727541 - Constants in Bugzilla::WebService::Constants should be available inside the templates similar to Bugzilla::Constants
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263431 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-16 21:31:21 +00:00
mkanat%bugzilla.org
3b5e8524aa Bug 680131: Replace the MPL 1.1 license by the MPL 2.0 one in all files, and add it to files which miss one
r=kiko r=mkanat r=mrbball a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@263258 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-11 22:48:45 +00:00
mkanat%bugzilla.org
94a88dc009 Bug 696256: global/variables.none.tmpl should be PRE_PROCESS'ed
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@263005 18797224-902f-48f8-a5cc-f745e15eee43
2011-10-23 11:17:16 +00:00
mkanat%bugzilla.org
acd4fb249d Bug 657158 - (CVE-2011-2381) [SECURITY] Request email headers for attachment containing newline are corrupt
[r=LpSolit a=LpSolit]


git-svn-id: svn://10.0.0.236/trunk@262579 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 19:32:30 +00:00
mkanat%bugzilla.org
05f72fb8d2 Bug 634812: Having a very large number of custom fields can make displaying show_bug.cgi slow
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@262562 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-01 08:48:47 +00:00
mkanat%bugzilla.org
0315e1dc2d Bug 652663 - When using bug_format_comment hook some replacements can happen more than once causing broken links
r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@262521 18797224-902f-48f8-a5cc-f745e15eee43
2011-07-25 05:32:46 +00:00
mkanat%bugzilla.org
bdf8ba3fe8 Bug 670169 - Escape '>' in js filter
[r=LpSolit a=LpSolit]


git-svn-id: svn://10.0.0.236/trunk@262478 18797224-902f-48f8-a5cc-f745e15eee43
2011-07-08 18:16:22 +00:00
mkanat%bugzilla.org
ea9684e90d Bug 659185: html_quote() escapes @ causing mailto links to not be processed
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@262340 18797224-902f-48f8-a5cc-f745e15eee43
2011-05-24 07:05:38 +00:00
mkanat%bugzilla.org
d811d0f3ac Bug 423612 - Allow editing extern_id for users from the admin interface
r=mkanat, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@262246 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-27 22:32:21 +00:00
mkanat%bugzilla.org
ea58399fd8 Bug 650593: Bugzilla crashes when the database is gone, even when shutdownhtml is set
r=justdave a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@262203 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-21 01:33:37 +00:00
mkanat%bugzilla.org
3c1eb91b87 Bug 619588: (CVE-2010-4567) [SECURITY] Safety checks that disallow clicking for javascript: or data: URLs in the URL field can be evaded with prefixed whitespace
and

Bug 628034: (CVE-2011-0048) [SECURITY] For not-logged-in users, the URL field doesn't safeguard against javascript: or data: URLs

r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261813 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 18:53:58 +00:00
mkanat%bugzilla.org
160ef05099 Bug 595410: Make it faster to display a bug that has a lot of dependencies.
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@261706 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-04 02:16:57 +00:00
mkanat%bugzilla.org
91dced6bf2 Bug 474766: The [details] string is duplicated when replying to a comment containing a link to an attachment
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261524 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-04 17:09:26 +00:00
mkanat%bugzilla.org
30577b05ca Bug 605425: Non-english templates are no longer precompiled by checksetup
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261435 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-20 23:03:45 +00:00
mkanat%bugzilla.org
aefe414e6d Bug 602418: Add "template_cache" to bz_locations(), a way of specifying that
cached templates should be stored somewhere else than the data directory.
r=LpSolit, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261392 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-13 23:52:22 +00:00
mkanat%bugzilla.org
3f349d63e1 Bug 65477: Send HTML bugmail
r=mkanat, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261329 18797224-902f-48f8-a5cc-f745e15eee43
2010-10-03 21:02:54 +00:00
mkanat%bugzilla.org
31942c63dd Bug 595380: Add a ?mtime string to all of the manually-inserted
<script src> and <link href> tags in Bugzilla
r=glob, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261290 18797224-902f-48f8-a5cc-f745e15eee43
2010-09-28 03:34:25 +00:00
mkanat%bugzilla.org
048a4fa74a Bug 586244: Make mod_headers and mod_expires optional
r=glob, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261239 18797224-902f-48f8-a5cc-f745e15eee43
2010-09-18 23:40:15 +00:00
mkanat%bugzilla.org
02b9a9a904 Bug 585490: Instead of hardcoding <i> for UNCONFIRMED bug links, use
a CSS class.
r=mkanat, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@261010 18797224-902f-48f8-a5cc-f745e15eee43
2010-08-10 03:46:38 +00:00
mkanat%bugzilla.org
cb0d08e43d Bug 466968: Remove hardcoded strings from BugMail.pm, and refactor it so that bugmails are 100% localizable
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260996 18797224-902f-48f8-a5cc-f745e15eee43
2010-08-06 10:46:40 +00:00
mkanat%bugzilla.org
fd470cc2f7 Bug 583690: (CVE-2010-2759) [SECURITY][PostgreSQL] Bugzilla crashes when viewing a bug if a comment contains 'bug <num>' or 'attachment <num>' where <num> is greater than the max allowed integer
r=mkanat a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@260976 18797224-902f-48f8-a5cc-f745e15eee43
2010-08-04 22:22:01 +00:00
mkanat%bugzilla.org
10a748cb5c Bug 584021: FILTER txt should also remove &nbsp;
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260962 18797224-902f-48f8-a5cc-f745e15eee43
2010-08-04 00:31:36 +00:00
mkanat%bugzilla.org
679581987b Bug 398701: Replace |FILTER url_quote| by |FILTER uri|
r/a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260844 18797224-902f-48f8-a5cc-f745e15eee43
2010-07-22 23:01:57 +00:00
mkanat%bugzilla.org
f98a0d8a34 Bug 428313: Properly expire the browser's CSS and JS cache when there
are new versions of those files. This also eliminates single-file skins
and should also allow Extensions to have skins.
r=glob, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260830 18797224-902f-48f8-a5cc-f745e15eee43
2010-07-21 03:48:22 +00:00
mkanat%bugzilla.org
0b5e02b469 Bug 576670: Optimize Search.pm's "init" method for being called many times
in a loop
r=glob, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260692 18797224-902f-48f8-a5cc-f745e15eee43
2010-07-09 02:16:39 +00:00
mkanat%bugzilla.org
a90851bdd3 Bug 554964 - Show if a user is a "Default CC" under the Product Responsibilities section of editusers.cgi.
[r=mkanat a=mkanat]


git-svn-id: svn://10.0.0.236/trunk@260638 18797224-902f-48f8-a5cc-f745e15eee43
2010-07-06 00:49:13 +00:00
mkanat%bugzilla.org
44cb9bfaec Bug 455810 - Add autocomplete support to the keywords field
* Special thanks to Guy Pyrzak for the original patch
[r=mkanat a=mkanat]


git-svn-id: svn://10.0.0.236/trunk@260625 18797224-902f-48f8-a5cc-f745e15eee43
2010-07-05 07:46:50 +00:00
mkanat%bugzilla.org
9a13bbe14d Bug 545766: Figure out what columns can be reported on from the database,
instead of from a static list
r=glob, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260612 18797224-902f-48f8-a5cc-f745e15eee43
2010-07-01 21:18:12 +00:00
mkanat%bugzilla.org
6add188323 Bug 24896: Make the First/Last/Prev/Next navigation on bugs work with
multiple buglists at once
r=glob, a=mkanat


git-svn-id: svn://10.0.0.236/trunk@260472 18797224-902f-48f8-a5cc-f745e15eee43
2010-06-16 01:46:23 +00:00
mkanat%bugzilla.org
265b1534e0 Bug 565899: Make the html_linebreak filter safe by having it first call the
"html" filter
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@260339 18797224-902f-48f8-a5cc-f745e15eee43
2010-05-19 17:33:03 +00:00