Commit Graph
2216 Commits
Author SHA1 Message Date
Tim Almdal 1f9d45861d Merge branch 'master' into talmdal_dev
Conflicts:
	modules/gallery/helpers/gallery_block.php
	modules/gallery/helpers/gallery_theme.php
	modules/gallery/helpers/user.php
	modules/user/helpers/user_event.php
2009-10-13 12:53:33 -07:00
Tim Almdal 1c313e9d2d Continue to refactor locale and gallery3 ui from the user module to the gallery module 2009-10-13 12:46:27 -07:00
Tim Almdal f8eee90705 remove the unused private function user::_md5Salt() 2009-10-13 12:38:21 -07:00
Tim Almdal 2c711d8908 refactor locale related functionality out of the user module and into the gallery module. 2009-10-13 12:33:00 -07:00
Tim Almdal ab73a4092f Correct typo in method name 2009-10-13 12:03:55 -07:00
Tim Almdal d9720b77e9 Merge branch 'master' into talmdal_dev
Conflicts:
	modules/gallery/controllers/admin_users.php
	modules/gallery/controllers/password.php
	modules/gallery/helpers/group.php
	modules/gallery/helpers/user.php
	modules/notification/helpers/notification.php
2009-10-13 11:48:42 -07:00
Tim Almdal 53393a1446 Merge branch 'master' of git@github.com:gallery/gallery3 2009-10-09 01:28:17 -07:00
Bharat Mediratta 3fc1eb5842 Merge branch 'master' of git@github.com:gallery/gallery3 2009-10-13 10:39:25 -07:00
Bharat Mediratta 0a66ef9cc7 Don't allow users to change the file extension of photos/movies
If you can change the extension, then you can alter the way the server
handles the file, which is a security problem.  So for example, you
can change a .JPG to a .PHP and then if you put some malicious PHP
code in the EXIF data, you can get the server to execute
it. Vulnerability is low because only users who have edit permissions
could do this.

Fixes ticket #846
2009-10-13 10:36:50 -07:00
Bharat Mediratta b6c1ba7ea6 Use SQL_CALC_FOUND_ROWS instead of doing the search twice, for better performance.
Fixes ticket #835, thanks Joe7!
2009-10-11 11:22:41 -07:00
Bharat Mediratta bc63e4fcf9 Make the slug field required for all items.
Make the filename field required for photos/movies.
Fixes ticket #838
2009-10-11 11:16:07 -07:00
Tim Almdal 79b4b8bdc6 update the Access_Helper_Test to use the user::lookup_by_name API method. 2009-10-09 01:27:27 -07:00
Tim Almdal 1ee7d24766 Add support for the in filter to get_user_list and get_group_list. Convert the notifications to use user::get_user_list instead of accessing the table directly. 2009-10-09 01:27:26 -07:00
Tim Almdal 00ee91837f Convert direct lookups for the user table using ORM to using the user::lookup_by_name and user_lookup API methods.
Convert the Admin_User controller
Convert the login and password change controller
Change the item model to call user::lookup to get the owner.
On the log model, delete the relationship between the log and user table, and replace with a
call to user::lookup
(cherry picked from commit 194cc3b27a)
Create the get_user_list, lookup_by_name, lookup_by_hash and get_group_list api functions
2009-10-09 01:26:35 -07:00
Tim Almdal f67bfd0992 Change the users.php controller so its no longer restful. The problem with our approach to restfulness is that it assumes that the resource will be found in the gallery database. It may well be there, but in the case of using plugable drivers for users management, there are no guarantees that it is in our database or it could be in a ldap directory. So it was just easier to remove the restfulness and just call user::lookup instead.
(cherry picked from commit b3211cb2a8)
2009-10-08 23:22:07 -07:00
Tim Almdal 7ad203b97a Merge branch 'master' of git@github.com:gallery/gallery3 into talmdal_dev 2009-10-08 13:47:30 -07:00
Tim Almdal 6f315ad89c Part of the previous commit, forgot to save... again 2009-10-08 06:35:38 -07:00
Tim Almdal 052491e258 If the Identity backend is not writable don't display the "Forgot Your Password" link 2009-10-08 06:26:12 -07:00
Tim Almdal 3a0413901f Forgot to save these before the last commit 2009-10-07 21:46:26 -07:00
Tim Almdal 03d0311618 Implement a user::is_writable() API method and disable the user add, updates and display if the Identity driver does not support writes. This is set in the config.identity.php 2009-10-07 21:40:05 -07:00
Tim Almdal b3211cb2a8 Change the users.php controller so its no longer restful. The problem with our approach to restfulness is that it assumes that the resource will be found in the gallery database. It may well be there, but in the case of using plugable drivers from users, it could be in a ldap directory, it could be the gallery3 database, but the model could be wrapped in a control structure. So it was just easier to remove the restfulness and just call user::lookup instead. 2009-10-07 20:26:26 -07:00
Tim Almdal c787e46c2a Change the __set method on User_Definition to actually set the value as opposed to return it. 2009-10-07 20:14:51 -07:00
Tim Almdal fa2ec8825d Merge branch 'master' of git@github.com:gallery/gallery3 into talmdal_dev 2009-10-07 19:09:10 -07:00
Chad Kieffer 121fcab5c8 Replaced most clear fix hacks with generic class. 2009-10-07 00:46:02 -06:00
Chad Kieffer 617076e897 Merge branch 'master' of github.com:gallery/gallery3 2009-10-07 00:21:47 -06:00
Chad Kieffer 859f8dc558 Consolidated the rest of the base message styles into lib/gallery.common.css and applied updates to views. Moved over draggable/droppable styles. Use g-target consistently for drag/drop interactions. Minor re-ordering of selectors in gallery.common.css. Updates to css comments. 2009-10-07 00:21:23 -06:00
Bharat Mediratta 13fb033235 Remove debugging lines (thanks talmdal!) 2009-10-06 23:05:35 -07:00
Bharat Mediratta fcbce09fc4 Update gallery::find_file to look for subdirectories in lib, then fall
back to looking in just lib itself.  This is not consistent behavior
with the rest of our module structure, though so we should probably
make it more consistent.

Fix up the permission images to use gallery::find_file again.
2009-10-06 21:50:41 -07:00
Chad Kieffer 0c7e4581c9 Rename permissions icons to correspond to view states, move to lib/images. Fixed references to them in the edit permissions view. 2009-10-06 22:18:31 -06:00
Tim Almdal 7f38d6ff29 Change the focus of the user module from providing user/group management to providing the default Identity implementation.
* Remove the user_event callbacks and move them to the gallery_event callbacks. This will insure that the active user is always loaded (because the gallery callbacks are always called first) to its available to other gallery_ready handlers.  Moved the method set_request_locale to the locales helper as it is more related to locales.
* Move the user controllers and views into the gallery module.
* Move the theme and block processing out of the user module and into core.
2009-10-06 18:30:12 -07:00
Tim Almdal 6671bd8b85 Allow a groups property on the User implementation and load the Identity drivers early in the process so the session deserialization works. 2009-10-06 18:30:09 -07:00
Tim Almdal da84a46ccb Clean up extra single quotes from copy and paste 2009-10-06 18:30:09 -07:00
Tim Almdal b35051ff6f Move the graphics::rotate to gallery_graphics::rotate to be consistent with the other gallery graphics functions. 2009-10-06 18:30:08 -07:00
Tim Almdal dc0d344b4a Move the graphics::rotate to gallery_graphics::rotate to be consistent with the other gallery graphics functions. 2009-10-06 12:58:53 -07:00
Tim Almdal c068384504 Encapsulate the user and group model in Gallery_User and Gallery_Group classes which extend the User_Definition and Group_Definition classes defined in the Identity API 2009-10-06 11:20:51 -07:00
Tim Almdal 6e59de2fb5 Change the notification handler to use the Identity API to lookup subscribers
for event notifications.  This drove out some issues in the user::users and
group::groups API backend.
2009-10-06 07:55:31 -07:00
Tim Almdal 8285cd58e2 Handle the filters on Identity/Gallery::list_users and Identity/Gallery::list_groups 2009-10-05 18:10:39 -07:00
Tim Almdal ca17727478 Access the form validation rules via the API for groups and users 2009-10-05 17:08:27 -07:00
Tim Almdal 194cc3b27a First pass on converting calls to the Identity interface. Will worry about writes and saves later.
Convert the Admin_User controller
Convert the login and password change controller
Change the item model to call user::lookup to get the owner.
On the log model, delete the relationship between the log and user table, and replace with a
call to user::lookup
2009-10-05 16:28:16 -07:00
Tim Almdal 08c01fec6c The initial commit of refactoring the user/group adminsitration into a driver.
Create an Identity library that defines the interface the Gallery3 expects
Move the user and group helpers into the gallery module to provide the familiar
interface into the Identity library.
Create a Gallery Identity back-end that is supplied by the user module.

The vision here is that all user and group code that is gallery or ui specific
is contained within the core product.  Anything that relates to manipulating a
user or group is contained in the back end code that can be replaced.
2009-10-05 16:27:52 -07:00
Chad Kieffer d581bbbd1e Renamed more CSS selectors from gName to g-name. 2009-10-04 15:53:00 -06:00
Chad Kieffer 048e540a98 Fixed previous over zealous find and replace. 2009-10-04 15:44:24 -06:00
Chad Kieffer 4be3210f1d Fixed previous over zealous find and replace. 2009-10-04 15:30:05 -06:00
Tim Almdal 2634a683b3 Revert "Create a gallery::plugin_path which returns the appropriate path to the module or theme. This checks for the existence of an application/modules or application/themes first."
This reverts commit e1e1461a77caf5bff457927f098366497de6ffff.
2009-10-04 10:12:22 -07:00
Tim Almdal aa0529d557 Create a gallery::plugin_path which returns the appropriate path to the module or theme. This checks for the existence of an application/modules or application/themes first. 2009-10-04 10:12:21 -07:00
Chad Kieffer 3e6ba7acc3 Renamed most, if not all css selectors from gName to g-name. Moved a few shared images from wind to lib. Deleted unused images in the admin_wind. This will likely break a few ajax features. 2009-10-04 00:27:22 -06:00
Chad Kieffer 9145331fd4 Renamed and moved gOdd/gEven CSS classes. 2009-10-03 12:33:53 -06:00
Bharat Mediratta 7236208655 Log the stack trace when non-admins get the error. 2009-10-02 13:20:44 -07:00
Tim Almdal b2a9bf43af Change gallery::find_file to not assume that the absolute path is relative to the document root. Instead ignore all th path parts until one of application, modules, themes, or libs is found. Fixes ticket #827 2009-10-01 12:44:18 -07:00
Tim Almdal 3ceb2775f8 adjust whitespace 2009-10-01 10:59:45 -07:00