129 Commits

Author SHA1 Message Date
mkanat%bugzilla.org
432a88165a Bug 670868: (CVE-2011-2978) [SECURITY] Account preferences page trusts user-modifiable field for obtaining current e-mail address
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262586 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 21:06:12 +00:00
mkanat%bugzilla.org
4f72d29310 Bug 553693: A new logincookie is created when changing the password or email address instead of reusing the existing one
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@260097 18797224-902f-48f8-a5cc-f745e15eee43
2010-03-29 21:47:39 +00:00
lpsolit%gmail.com
ee772fc40e Bug 534057: Auto-completion no longer works in email_in.pl - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@259526 18797224-902f-48f8-a5cc-f745e15eee43
2010-01-31 23:33:32 +00:00
lpsolit%gmail.com
c29dffd6c2 Bug 472362: [SECURITY] Malicious attachments can change your user settings (user + email prefs, shared searches) - Patch by Frédéric Buclin <LpSolit@gmail.com> r=wicked a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@256029 18797224-902f-48f8-a5cc-f745e15eee43
2009-02-02 19:26:35 +00:00
lpsolit%gmail.com
d85596dafd Bug 472549: Ignore undefined values when committing user pref changes - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@255755 18797224-902f-48f8-a5cc-f745e15eee43
2009-01-08 00:06:49 +00:00
lpsolit%gmail.com
3af770f143 Bug 399072: Remove the 'supportwatchers' parameter - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@255418 18797224-902f-48f8-a5cc-f745e15eee43
2008-12-10 18:26:56 +00:00
dkl%redhat.com
d2cc34e014 Bug 455584 - Use bz_crypt everywhere instead of the crypt() function
Patch by David Lawrence <dkl@redhat.com> = r/a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@254732 18797224-902f-48f8-a5cc-f745e15eee43
2008-10-22 21:54:59 +00:00
dkl%redhat.com
36109e6138 Bug 453767 - Passwords containing wide characters causes system error
Patch by David Lawrence <dkl@redhat.com> - a/r=mkanat


git-svn-id: svn://10.0.0.236/trunk@254181 18797224-902f-48f8-a5cc-f745e15eee43
2008-09-12 15:10:14 +00:00
mkanat%bugzilla.org
80501696b2 Bug 442016: Bugzilla::User::bless_groups should be returning Bugzilla::Group objects
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@253703 18797224-902f-48f8-a5cc-f745e15eee43
2008-08-19 21:32:40 +00:00
lpsolit%gmail.com
03b1e7c6dd Bug 405946: Some emails are not sent in the language chosen by the addressee - Patch by Frédéric Buclin <LpSolit@gmail.com> r=wurblzap a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@249006 18797224-902f-48f8-a5cc-f745e15eee43
2008-04-02 17:46:56 +00:00
timeless%mozdev.org
85ab544024 Bug 369062 prior should read "earlier" in edit groups
r=lpsolit a=lpsolit


git-svn-id: svn://10.0.0.236/trunk@241461 18797224-902f-48f8-a5cc-f745e15eee43
2007-12-16 10:32:54 +00:00
lpsolit%gmail.com
3e660f3c01 Bug 403824: Replace table locks in most Bugzilla files with transactions - Patch by Emmanuel Seyman <eseyman@linagora.com> r/a=mkanat
git-svn-id: svn://10.0.0.236/trunk@239400 18797224-902f-48f8-a5cc-f745e15eee43
2007-11-14 22:56:32 +00:00
mkanat%bugzilla.org
d7e641858a Bug 399954: Make Bugzilla able to hold its dependencies in a local directory
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/trunk@237891 18797224-902f-48f8-a5cc-f745e15eee43
2007-10-19 06:46:19 +00:00
lpsolit%gmail.com
11c75a4bd7 Bug 203309: "Users to watch" in email prefs doesn't support wildcard user matching - Patch by Frédéric Buclin <LpSolit@gmail.com> r=timeless a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@231052 18797224-902f-48f8-a5cc-f745e15eee43
2007-07-26 14:06:23 +00:00
lpsolit%gmail.com
246f3b0b21 Bug 365890: Searches shared by users with bless rights are in the footer by default, with no warning - Patch by Teemu Mannermaa <wicked@sci.fi> r/a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@230567 18797224-902f-48f8-a5cc-f745e15eee43
2007-07-21 11:00:59 +00:00
lpsolit%gmail.com
a2a0ee9f4b Bug 381738: SaveAccount() in userprefs.cgi doesn't check Bugzilla->user->authorizer->can_change_{password|email} - Patch by Tiago R. Mello <timello@gmail.com> r/a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@229929 18797224-902f-48f8-a5cc-f745e15eee43
2007-07-13 22:50:50 +00:00
lpsolit%gmail.com
6f9d144085 Bug 381732: Old tokens are not deleted on time when changing the email address - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=LpSolit
git-svn-id: svn://10.0.0.236/trunk@227050 18797224-902f-48f8-a5cc-f745e15eee43
2007-05-26 00:54:33 +00:00
timeless%mozdev.org
21b3d695bc Bug 365256 Period is on the wrong side of a bunch of other parentheses
r=lpsolit a=justdave


git-svn-id: svn://10.0.0.236/trunk@217941 18797224-902f-48f8-a5cc-f745e15eee43
2007-01-07 23:58:22 +00:00
lpsolit%gmail.com
9ee874607f Bug 365407: Reorder tabs in userprefs.cgi - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=justdave
git-svn-id: svn://10.0.0.236/trunk@217568 18797224-902f-48f8-a5cc-f745e15eee43
2006-12-30 19:53:52 +00:00
reed%reedloden.com
6eb41c6e0e Bug 364920 - "Watcher list should be sorted alphabetically" [p=reed r=LpSolit a=justdave]
git-svn-id: svn://10.0.0.236/trunk@217424 18797224-902f-48f8-a5cc-f745e15eee43
2006-12-26 16:46:04 +00:00
lpsolit%gmail.com
21b303adf4 Bug 189627: Implement per-product privileges - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=myk
git-svn-id: svn://10.0.0.236/trunk@215097 18797224-902f-48f8-a5cc-f745e15eee43
2006-11-10 16:51:30 +00:00
mkanat%bugzilla.org
e3263b4efe Bug 352403: Create an object for saved searches, and have Bugzilla::User use it
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=myk


git-svn-id: svn://10.0.0.236/trunk@214674 18797224-902f-48f8-a5cc-f745e15eee43
2006-11-03 23:16:47 +00:00
wurblzap%gmail.com
534cc8b074 Bug 340538: Insecure dependency in exec while running with -T switch at /usr/lib/perl5/site_perl/5.8.6/Mail/Mailer/sendmail.pm line 16.
Patch by Marc Schumann <wurblzap@gmail.com>,
r=LpSolit, a=myk


git-svn-id: svn://10.0.0.236/trunk@213922 18797224-902f-48f8-a5cc-f745e15eee43
2006-10-20 18:52:24 +00:00
lpsolit%gmail.com
1396aea32e Bug 355833: Groups are out of order when sharing queries - Patch by Frédéric Buclin <LpSolit@gmail.com> r=wurblzap a=justdave
git-svn-id: svn://10.0.0.236/trunk@213292 18797224-902f-48f8-a5cc-f745e15eee43
2006-10-07 17:51:43 +00:00
lpsolit%gmail.com
b735434f6f Bug 87795: Creating an account should send token and wait for confirmation (prevent user account abuse) - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat r=bkor a=myk
git-svn-id: svn://10.0.0.236/trunk@207935 18797224-902f-48f8-a5cc-f745e15eee43
2006-08-19 18:12:00 +00:00
mozilla%colinogilvie.co.uk
1962186e8b Bug 320197: Watcher editing in userprefs should use a list box instead of text entry
Patch by Colin Ogilvie <colin.ogilvie@gmail.com>; r=wicked; a=myk


git-svn-id: svn://10.0.0.236/trunk@207617 18797224-902f-48f8-a5cc-f745e15eee43
2006-08-16 19:01:24 +00:00
wurblzap%gmail.com
adc3fc4f09 Bug 69000: Permit a stored query to be marked "shared" and accessible by other users.
Patch by Marc Schumann <wurblzap@gmail.com>,
r=vladd, a=myk


git-svn-id: svn://10.0.0.236/trunk@202073 18797224-902f-48f8-a5cc-f745e15eee43
2006-07-13 20:08:00 +00:00
mkanat%bugzilla.org
680d743be8 Bug 173629: Clean up "my" variable scoping issues for mod_perl
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=myk


git-svn-id: svn://10.0.0.236/trunk@201662 18797224-902f-48f8-a5cc-f745e15eee43
2006-07-06 06:12:05 +00:00
mkanat%bugzilla.org
520fe42625 Bug 338375: Use Bugzilla->params everywhere instead of Param().
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=justdave


git-svn-id: svn://10.0.0.236/trunk@201503 18797224-902f-48f8-a5cc-f745e15eee43
2006-07-03 21:42:47 +00:00
mkanat%bugzilla.org
8323e09c40 Bug 342869: Use Bugzilla->params everywhere except templates
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=justdave


git-svn-id: svn://10.0.0.236/trunk@201499 18797224-902f-48f8-a5cc-f745e15eee43
2006-07-03 21:26:22 +00:00
lpsolit%gmail.com
a698e74659 Bug 282121: Remove globals.pl from scripts that no longer use it - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=myk
git-svn-id: svn://10.0.0.236/trunk@200489 18797224-902f-48f8-a5cc-f745e15eee43
2006-06-21 00:44:48 +00:00
lpsolit%gmail.com
f952ed05cf Bug 304601: Bugzilla::Config's :locations exports need to be in their own module - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat for the main patch, r=myk for the patch about CGI.pm a=justdave
Bug 328637: Remove all legal_* versioncache arrays - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=justdave

Bug 110503 - Eliminate versioncache


git-svn-id: svn://10.0.0.236/trunk@200347 18797224-902f-48f8-a5cc-f745e15eee43
2006-06-19 20:15:18 +00:00
mkanat%bugzilla.org
caee2e9858 Bug 300410: Bugzilla::Auth needs to be restructured to not require a BEGIN block
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=myk


git-svn-id: svn://10.0.0.236/trunk@196368 18797224-902f-48f8-a5cc-f745e15eee43
2006-05-12 02:41:22 +00:00
lpsolit%gmail.com
c9a524756a Bug 332598: Move ValidatePassword() and DBNameToIdAndCheck() from globals.pl into User.pm - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=myk
git-svn-id: svn://10.0.0.236/trunk@196144 18797224-902f-48f8-a5cc-f745e15eee43
2006-05-07 20:13:49 +00:00
lpsolit%gmail.com
d574ffedbf Bug 287741: changing password from 'password' to 'password' should not invalidate login cookies - Patch by Marc Schumann <wurblzap@gmail.com> r=LpSolit a=justdave
git-svn-id: svn://10.0.0.236/trunk@186338 18797224-902f-48f8-a5cc-f745e15eee43
2005-12-20 22:25:57 +00:00
lpsolit%gmail.com
c861863af0 Bug 320866: Watching the same address twice produces software error - Patch by Frédéric Buclin <LpSolit@gmail.com> r=kevin r=bkor a=justdave
git-svn-id: svn://10.0.0.236/trunk@186335 18797224-902f-48f8-a5cc-f745e15eee43
2005-12-20 21:49:26 +00:00
karl%kornel.name
c24e7e6db3 Bug 313679: Changing email address in sudo mode logs user in as
impersonated user - Patch by A. Karl Kornel <karl@kornel.name>
r=wurblzap a=justdave


git-svn-id: svn://10.0.0.236/trunk@186009 18797224-902f-48f8-a5cc-f745e15eee43
2005-12-13 20:03:13 +00:00
lpsolit%gmail.com
7c3f38ad5d Bug 301062: [PostgreSQL] whine.pl fails when using PostgreSQL 8.0.x - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat r=manu a=justdave
git-svn-id: svn://10.0.0.236/trunk@184543 18797224-902f-48f8-a5cc-f745e15eee43
2005-11-13 17:36:21 +00:00
lpsolit%gmail.com
64f1a95f02 Bug 304075: Eliminate use of $::userid from Bugzilla - Patch by Frédéric Buclin <LpSolit@gmail.com> r=wicked a=justdave
git-svn-id: svn://10.0.0.236/trunk@183259 18797224-902f-48f8-a5cc-f745e15eee43
2005-10-30 21:31:29 +00:00
lpsolit%gmail.com
743c9a1707 Bug 308340: General Preferences tab is empty except for submit button when no user prefences are enabled - Patch by Frédéric Buclin <LpSolit@gmail.com> r=GavinS a=justdave
git-svn-id: svn://10.0.0.236/trunk@183179 18797224-902f-48f8-a5cc-f745e15eee43
2005-10-28 09:56:54 +00:00
lpsolit%gmail.com
e334b85a95 Bug 312157: Remove $::template and $::vars from globals.pl - Patch by Olav Vitters <bugzilla-mozilla@bkor.dhs.org> r=LpSolit a=justdave
git-svn-id: svn://10.0.0.236/trunk@182927 18797224-902f-48f8-a5cc-f745e15eee43
2005-10-24 23:11:56 +00:00
lpsolit%gmail.com
c8bd8ab3fb Bug 303699: Eliminate deprecated Bugzilla::DB routines from userprefs.cgi - Patch by Teemu Mannermaa <wicked@etlicon.fi> r=LpSolit a=justdave
git-svn-id: svn://10.0.0.236/trunk@182049 18797224-902f-48f8-a5cc-f745e15eee43
2005-10-12 01:21:16 +00:00
bugreport%peshkin.net
205c3f3402 Bug 304583: Remove all remaining need to rederive inherited groups
Patch by Joel Peshkin <bugreport@peshkin.net>
r=mkanat, a=justdave


git-svn-id: svn://10.0.0.236/trunk@178200 18797224-902f-48f8-a5cc-f745e15eee43
2005-08-18 20:09:37 +00:00
lpsolit%gmail.com
88c468dba1 Bug 304653: remove 'use Bugzilla::Error' from Util.pm - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=myk
git-svn-id: svn://10.0.0.236/trunk@177759 18797224-902f-48f8-a5cc-f745e15eee43
2005-08-15 17:43:38 +00:00
lpsolit%gmail.com
ae7abb5289 Bug 304044: Missing scalar() for some parameters - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=justdave
git-svn-id: svn://10.0.0.236/trunk@177696 18797224-902f-48f8-a5cc-f745e15eee43
2005-08-13 12:35:12 +00:00
mkanat%kerio.com
0cbbdcfee7 Bug 303669: Bugzilla mis-uses perl subroutine prototypes
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=justdave


git-svn-id: svn://10.0.0.236/trunk@177695 18797224-902f-48f8-a5cc-f745e15eee43
2005-08-13 12:27:04 +00:00
lpsolit%gmail.com
b4d7cca746 Bug 301508: Remove CGI.pl - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat,wicked a=justdave
git-svn-id: svn://10.0.0.236/trunk@177475 18797224-902f-48f8-a5cc-f745e15eee43
2005-08-10 01:30:41 +00:00
bugreport%peshkin.net
9778732be8 Backout of bug 303669 which broke AppendComment and possibly a number
of other items.


git-svn-id: svn://10.0.0.236/trunk@177419 18797224-902f-48f8-a5cc-f745e15eee43
2005-08-09 11:23:43 +00:00
mkanat%kerio.com
7bbde62ad3 Bug 303669: Bugzilla mis-uses perl subroutine prototypes
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=justdave


git-svn-id: svn://10.0.0.236/trunk@177413 18797224-902f-48f8-a5cc-f745e15eee43
2005-08-09 05:59:02 +00:00
lpsolit%gmail.com
c047143952 Bug 303061: userprefs.cgi should call ThrowUserError for old_password_required - Patch by Marc Schumann <wurblzap@gmail.com> r=LpSolit a=justdave
git-svn-id: svn://10.0.0.236/trunk@177041 18797224-902f-48f8-a5cc-f745e15eee43
2005-08-03 00:10:08 +00:00