31 Commits

Author SHA1 Message Date
justdave%bugzilla.org
bca966aff7 [SECURITY] Bug 263780: Exporting a bug to XML exposes user comments and attachment summaries which are marked as private to users who are not members of the group allowed to see private comments and attachments. XML export is not exposed in the user interface, but is available to anyone who knows the correct URL to invoke it. This only affects sites that use the 'insidergroup' feature.
Patch by Joel Peshkin <bugreport@peshkin.net>
r=vladd,justdave, a=justdave


git-svn-id: svn://10.0.0.236/trunk@164337 18797224-902f-48f8-a5cc-f745e15eee43
2004-10-25 07:26:57 +00:00
timeless%mozdev.org
b37a798e99 Bug 259452 Add bonsai style &mark support to showbug for bug comments
r=kiko a=justdave


git-svn-id: svn://10.0.0.236/trunk@162618 18797224-902f-48f8-a5cc-f745e15eee43
2004-09-21 19:56:19 +00:00
jocuri%softhome.net
35e0719e5b Patch for bug 87770: make attachment.cgi work with no parameters; patch by GavinS <bugzilla@chimpychompy.org>; r=kiko; a=myk.
git-svn-id: svn://10.0.0.236/trunk@154676 18797224-902f-48f8-a5cc-f745e15eee43
2004-04-10 15:08:21 +00:00
kiko%async.com.br
4382f2bf77 Fix for bug 238868: remove %FORM and %COOKIE from show_bug.cgi. Does
that, swapping them for calls to cgi->param/cookie. r=vladd,justdave; a=justdave.


git-svn-id: svn://10.0.0.236/trunk@154447 18797224-902f-48f8-a5cc-f745e15eee43
2004-04-01 23:46:11 +00:00
kiko%async.com.br
319f68a68e Fix for bug 234175: Remove deprecated ConnectToDatabase() and
quietly_check_login()/confirm_login() calls.  Cleans up callsites
(consisting of most of our CGIs), swapping (where appropriate) for calls
to Bugzilla->login. Patch by Teemu Mannermaa <wicked@etlicon.fi>.
r=bbaetz, kiko. a=justdave.


git-svn-id: svn://10.0.0.236/trunk@154331 18797224-902f-48f8-a5cc-f745e15eee43
2004-03-27 03:51:44 +00:00
justdave%syndicomm.com
e099454c93 Bug 192516: Moving the loose .pm files into the Bugzilla directory, where they belong. These files pre-date the Bugzilla directory, and would have gone there had it existed at the time. The four files in question were copied on the CVS server to preserve CVS history in the files. This checkin deletes them from the old location and modifies everything else to know where they are now.
r= myk, gerv
a= justdave


git-svn-id: svn://10.0.0.236/trunk@154078 18797224-902f-48f8-a5cc-f745e15eee43
2004-03-18 03:57:05 +00:00
jkeiser%netscape.com
1b7dc26697 Check for PatchReader as a part of the installation and disable the "Diff"
links if it is not there (bug 215268)


git-svn-id: svn://10.0.0.236/trunk@146209 18797224-902f-48f8-a5cc-f745e15eee43
2003-08-20 00:45:43 +00:00
bbaetz%acm.org
9e1d7096ea Bug 201816 - use CGI.pm for header output
r=joel, a=justdave


git-svn-id: svn://10.0.0.236/trunk@142113 18797224-902f-48f8-a5cc-f745e15eee43
2003-05-05 01:15:38 +00:00
jake%bugzilla.org
c3994d7057 Bug 196433 - Bugzilla now uses /usr/bin/perl as the shebang line
r=justdave
a=justdave


git-svn-id: svn://10.0.0.236/trunk@140364 18797224-902f-48f8-a5cc-f745e15eee43
2003-03-27 00:07:02 +00:00
gerv%gerv.net
7de031b9ce Bug 136603 - show_bug.cgi's XML retrieval needs a summary mode. Patch by gerv; r=bbaetz, a=justdave.
git-svn-id: svn://10.0.0.236/trunk@136359 18797224-902f-48f8-a5cc-f745e15eee43
2003-01-15 07:59:53 +00:00
bbaetz%student.usyd.edu.au
f60e59ef75 Bug 158499 - Templatise XML bug output
r=gerv, justdave
a=justdave


git-svn-id: svn://10.0.0.236/trunk@135318 18797224-902f-48f8-a5cc-f745e15eee43
2002-12-15 09:24:08 +00:00
bbaetz%student.usyd.edu.au
4dd0d47760 Bug 171493 - make show_bug use Bug.pm and remove bug_form.pl
r=justdave, joel
a=justdave


git-svn-id: svn://10.0.0.236/trunk@134567 18797224-902f-48f8-a5cc-f745e15eee43
2002-11-28 10:49:58 +00:00
bbaetz%student.usyd.edu.au
71381b40ed Bug 76923 - Don't |use diagnostics| (its really expensive at startup time)
r=joel x2


git-svn-id: svn://10.0.0.236/trunk@128080 18797224-902f-48f8-a5cc-f745e15eee43
2002-08-26 06:17:26 +00:00
gerv%gerv.net
6c6b37abf0 Bug 110012 - show_bug templatisation. r=bbaetz, afranke.
git-svn-id: svn://10.0.0.236/trunk@117328 18797224-902f-48f8-a5cc-f745e15eee43
2002-03-23 17:58:41 +00:00
justdave%syndicomm.com
c148fadef8 Fix for bug 108982: enable taint mode for all user-facing CGI files.
Patch by Brad Baetz <bbaetz@student.usyd.edu.au>
r= jake, justdave


git-svn-id: svn://10.0.0.236/trunk@112490 18797224-902f-48f8-a5cc-f745e15eee43
2002-01-20 01:44:52 +00:00
gerv%gerv.net
86fd0a166e Make Bugzilla support <link> tag for buglists. Bug 87818. r=jake, caillon.
git-svn-id: svn://10.0.0.236/trunk@102665 18797224-902f-48f8-a5cc-f745e15eee43
2001-09-10 21:26:05 +00:00
tara%tequilarista.org
cbb24b9172 Landing Myk's patch for bug #71767
git-svn-id: svn://10.0.0.236/trunk@96243 18797224-902f-48f8-a5cc-f745e15eee43
2001-06-02 22:02:02 +00:00
endico%mozilla.org
575073abd0 Checking in Jake's <jake@acutex.net> interim patches from bug 30694. Bugzilla was showing bug summaries to everyone, even if they didn't have permission to view the bug. Jake's quick solution is to not display the bug at all if it is in a group no matter who is viewing it. The correct solution would be display the summary if the viewer had the proper permissions.
git-svn-id: svn://10.0.0.236/trunk@89378 18797224-902f-48f8-a5cc-f745e15eee43
2001-03-12 22:35:51 +00:00
endico%mozilla.org
bbccc02b1e Patch from Jake <jake@acutex.net> for bugs 22041 and 25693 which had the same problem. HTML meta characters in the summary were not being quoted before being printed to html.
git-svn-id: svn://10.0.0.236/trunk@89043 18797224-902f-48f8-a5cc-f745e15eee43
2001-03-09 01:49:42 +00:00
dave%intrec.com
79201226b9 Fix for bug 22041: Bug page title now includes bug summary. Patch by st.n@gmx.net (Stephan Niemz (faniz))
git-svn-id: svn://10.0.0.236/trunk@86047 18797224-902f-48f8-a5cc-f745e15eee43
2001-02-02 03:44:47 +00:00
terry%mozilla.org
b541dc2d83 Patch by Ramon Felciano <felciano@ingenuity.com>, with many tweaks by
me.  Added a footer to every page.  Add some options to do things like
display checkboxes instead of scrolling lists, and a new formatting
for email diffs, and show list items capitalized instead of all upper
case.


git-svn-id: svn://10.0.0.236/trunk@57846 18797224-902f-48f8-a5cc-f745e15eee43
2000-01-14 22:35:49 +00:00
dmose%mozilla.org
03ec794132 updated license boilerplate
git-svn-id: svn://10.0.0.236/trunk@52443 18797224-902f-48f8-a5cc-f745e15eee43
1999-11-01 23:33:56 +00:00
terry%mozilla.org
d8dc2f6fd7 Patch by holger@holger.om.org (Holger Schurig) -- more fixups to put proper header on pages.
git-svn-id: svn://10.0.0.236/trunk@48990 18797224-902f-48f8-a5cc-f745e15eee43
1999-09-24 19:15:51 +00:00
bryce-mozilla%nextbus.com
68a4a1e8e1 Fix several browsers, Lynx and Opera at least. HTML syntax errors here
and there were fixed, and serverpush was restricted only to the versions
of Mozilla known to support it.


git-svn-id: svn://10.0.0.236/trunk@35348 18797224-902f-48f8-a5cc-f745e15eee43
1999-06-15 04:25:29 +00:00
terry%mozilla.org
ff2440150e Do some sanity checking on the entered bug number.
git-svn-id: svn://10.0.0.236/trunk@31015 18797224-902f-48f8-a5cc-f745e15eee43
1999-05-10 22:52:43 +00:00
terry%mozilla.org
b3ab03301f Give better error messages when we can't display a bug.
git-svn-id: svn://10.0.0.236/trunk@30987 18797224-902f-48f8-a5cc-f745e15eee43
1999-05-10 22:08:58 +00:00
terry%netscape.com
f5e4efb177 Added three new fields (which appear in the UI only if params are
turned on): target_milestone, qa_contact, and status_whiteboard.


git-svn-id: svn://10.0.0.236/trunk@18817 18797224-902f-48f8-a5cc-f745e15eee43
1999-01-27 21:17:10 +00:00
terry%netscape.com
1d5e9c99f5 Backed out Andrew's patch -- turns out it was doing quoting sublty wrong.
git-svn-id: svn://10.0.0.236/trunk@15034 18797224-902f-48f8-a5cc-f745e15eee43
1998-11-20 19:18:37 +00:00
terry%netscape.com
d96970ce3c Patch by Andrew Anderson <andrew@redhat.com>. Many minor bugfixes and cleanup.
git-svn-id: svn://10.0.0.236/trunk@14745 18797224-902f-48f8-a5cc-f745e15eee43
1998-11-16 19:43:50 +00:00
terry%netscape.com
763d43f255 Everything has been ported to now run under Perl.
git-svn-id: svn://10.0.0.236/trunk@10080 18797224-902f-48f8-a5cc-f745e15eee43
1998-09-15 21:49:26 +00:00
terry%netscape.com
502157a1c3 Bugzilla source.
git-svn-id: svn://10.0.0.236/trunk@8494 18797224-902f-48f8-a5cc-f745e15eee43
1998-08-26 06:14:20 +00:00