Commit Graph
411 Commits
Author SHA1 Message Date
Bharat Mediratta b3b308f369 Add a missing colon. 2008-12-20 02:08:15 +00:00
Bharat Mediratta a5a9a79fa6 Internationalize. 2008-12-20 02:08:03 +00:00
Bharat Mediratta 0f10f37c16 Replace placeholders with real data 2008-12-20 02:06:14 +00:00
Bharat Mediratta e4bace4c74 Collapse Admin_Dashboard_Controller down into a single theme call, since now
all dashboard blocks are stored in modules.
2008-12-20 01:42:18 +00:00
Bharat Mediratta b933d1a170 Move Recent Comments into its own block. 2008-12-20 01:25:03 +00:00
Bharat Mediratta 9afd9d05ae Move log entries into its own block 2008-12-20 01:20:19 +00:00
Bharat Mediratta 16a3e43b45 Move the "Photo Stream" section into its own block 2008-12-20 01:16:46 +00:00
Bharat Mediratta e12a4f2ae3 Move the "status messages" section into its own block. 2008-12-20 01:13:57 +00:00
Bharat Mediratta 68e9dcf027 Move Platform and Project News admin sidebar blocks into the new
modular structure.
2008-12-20 01:08:39 +00:00
Bharat Mediratta ac4bb34cf2 Add admin sidebar blocks, and move the stats block into that pattern. 2008-12-20 01:00:52 +00:00
Bharat Mediratta aee3efe972 Create a pattern for admin dashboard blocks and make the "welcome"
block.
2008-12-20 00:52:20 +00:00
Bharat Mediratta 99f131d9ae Create module::load_themes() to load the correct theme after we do
routing and know whether we're going to an /admin page or a regular
one.
2008-12-20 00:50:37 +00:00
Bharat Mediratta 9d2d824336 Fix a bug in admin delegation. 2008-12-19 22:14:14 +00:00
Bharat Mediratta 17c0b01444 Add access::forbidden() 2008-12-19 22:13:33 +00:00
Bharat Mediratta 855a5928ce Create a new pattern for Site Admin controllers:
1) They must all start with "admin_".  This pattern is not directly
   routable.

2) Their urls must be /admin/xxx.

3) The Admin_Controller will take the xxx and look for Admin_Xxx_Controller
   and will delegate to that admin controller, after doing security checks.

Moved the users and dashboard views into individual modules for now.
2008-12-19 09:47:13 +00:00
Bharat Mediratta 2438dba396 Delete the var/thumbs .htaccess files, too. 2008-12-19 07:16:38 +00:00
Bharat Mediratta 8b3e244578 We always have at least 1 page in an album. 2008-12-19 01:26:49 +00:00
Bharat Mediratta c00dc21ba8 Add session based CSRF protection to all forms 2008-12-19 01:24:27 +00:00
Bharat Mediratta 5ca17fd273 Allow server-side adding of images to other albums than the root 2008-12-19 00:48:45 +00:00
Bharat Mediratta a74537ad59 Don't wrap hidden inputs in <li/> 2008-12-18 22:29:49 +00:00
Bharat Mediratta c67234974d Refactor site admin menu into a theme function and build the menus in
the various modules.  In the process, rename xxx_menu::site_navigation() to just
xxx_menu::site().  And add xxx_menu::admin().

The menus are the same as before, but I changed the HTML to be
consistent with the way that we do it in the regular site, and this
broke the superfish styles.  I don't know how to fix this.. help me
Chad!
2008-12-18 07:32:34 +00:00
Chad Kieffer aed68bfa9f I'm tired of clicking. Here are a few Selenium IDE tests. 2008-12-18 07:00:47 +00:00
Bharat Mediratta b37047ff55 Add Item_Model::viewable() which we can use to restrict any query to
just items viewable by the active user.  Ie:

  ORM::factory("item")
    ->where("name", "foo")
    ->find_all()

Would get all items with the name "foo".

  ORM::factory("item")
    ->viewable()
    ->where("name", "foo")
    ->find_all()

Restricts it to just the set of items that the user is allowed to see.
2008-12-17 22:39:33 +00:00
Bharat Mediratta 9b6ccfc7f3 Fix some lint errors 2008-12-17 19:06:39 +00:00
Bharat Mediratta 26f0b4e44d Clear out module list in load_modules() before trying any db operations 2008-12-17 19:04:20 +00:00
Bharat Mediratta fa5a8fde4a Switch from cookie sessions to database sessions. We can't use cookie
sessions; it encodes all the value into the cookie which means
little/no security, transfer costs, and storage limits.
2008-12-17 18:32:08 +00:00
Bharat Mediratta 130e26983a Add initialization to the user module to put the user and group_ids
into the session, for easy access.  This cuts down the number of
queries when we're loading images through file_proxy.php
2008-12-17 17:40:45 +00:00
Bharat Mediratta 78cd00312e Improve performance by finding the item without walking the tree.
Instead, use the level and the name to get a short list of candidates,
and check each one of those.  In most cases, this query should give us
the right result the first time.
2008-12-17 05:53:05 +00:00
Bharat Mediratta 8630d61051 Change the album thumbnail/resize from _album.jpg to .album.pjg
because the leading underscore confuses the Kohana router.
2008-12-17 04:55:49 +00:00
Bharat Mediratta fc7b78492b Separate thumbnails out into var/thumbs. This clears up some ambiguity in Item_Model and simplifies
file_proxy.  It also means we can stop munging file names in the var/resizes hierarchy.

In the process, rename "thumbnail" to "thumb" everywhere in honor of
Chad (well, ok because it's shorter)..
2008-12-17 04:45:35 +00:00
Bharat Mediratta f4c6a20149 Remove error checking; if this fails let it fail noisily for now so that we can find problems faster. 2008-12-16 23:59:33 +00:00
Bharat Mediratta af32e5708d Remove all caching from ORM_MPTT. This was premature optimization: it
wasn't benefitting us, and it will get in the way when we want to add
implicit view protection to our queries.
2008-12-16 23:36:56 +00:00
Bharat Mediratta 8c7d0a76e5 Add file_proxy. This is controller gets triggered by .htaccess
protection on var/albums and var/resizes and only displays files to
the user if they have "view" permission on the base ite.
2008-12-16 23:07:33 +00:00
Tim Almdal 04441e11cc 1) Remove the load watermark from the scaffolding... use the menu option
2) The set watermark dialog is now sizing properly.  @todo is recenter in the window
2008-12-16 17:30:18 +00:00
Bharat Mediratta e2544da5b0 Alphabetize field names to make it easier to find 'em. 2008-12-16 08:27:06 +00:00
Bharat Mediratta 3e219aab6b Change htaccess rules to use mod_rewrite 2008-12-16 08:17:00 +00:00
Bharat Mediratta 8bd7afeb5b TEST_MODE always exists now, so check its value, don't rely on its existence to know that we're in test mode. 2008-12-16 05:13:04 +00:00
Bharat Mediratta 83363172b1 Don't use model_cache for get_version and set_version; that breaks the installer. 2008-12-16 05:04:42 +00:00
Bharat Mediratta 3273984582 Use model_cache::get() to reduce duplicate queries 2008-12-16 04:56:51 +00:00
Bharat Mediratta 65a340efd8 Fix a bug where we were using module::set_var() instead of module::get_var() resulting in
loading all photos in an album on a single page and updating the var on every page load.
2008-12-16 04:52:16 +00:00
Bharat Mediratta e82b08db20 Make the profiler output more legible by adding some padding to the table. 2008-12-16 04:45:52 +00:00
Bharat Mediratta d9e02a5d0c Various optimizations:
o Add model_cache::get() which caches models avoiding duplicate lookups
o Stop using ORM relationships for Item_Model::owner so that we can use caching
o For Item_Model::xxx_edit fields, don't make them editable for guests
o Other minor stuff.

These optimizations reduce the number of queries for a 9-photos page from ~200
to ~45.  Still way too many!
2008-12-16 04:29:00 +00:00
Bharat Mediratta dc08917345 Fix a bug where we were not deleting the .htaccess file on access::reset() 2008-12-16 02:31:13 +00:00
Bharat Mediratta 61618af0db Create and delete .htaccess files based on the view permissions for
the group::everybody() user.
2008-12-16 01:04:19 +00:00
Bharat Mediratta 898d001330 Fix capitalization. 2008-12-16 00:50:51 +00:00
Bharat Mediratta eecf7bd518 phpdoc cleanup 2008-12-16 00:31:50 +00:00
Bharat Mediratta 3d2fc86604 Permission only function on albums. 2008-12-16 00:30:05 +00:00
Bharat Mediratta 2f8b4df0f5 Protect menus and blocks against the fact that we don't have an item
on tag pages.
2008-12-15 21:23:00 +00:00
Bharat Mediratta b6363bcb03 Update to reflect changes in Kohana ORM relationship code.
Now you must call ORM::save() after ORM::add() and ORM::remove().
2008-12-15 20:49:05 +00:00
Tim Almdal 1d3e1484a7 The admin high level menu is shown if the active user is not a guest. Other sub menus depend on the appropriate level of access 2008-12-15 19:51:49 +00:00