Andy Staudacher
f93528ffab
Last partial fix for ticket 585: Compartmentalize the admin area and require active authentication every 20 minutes to access the admin area.
...
Also renaming auth::validate_too_many_failed_password_changes to validate_too_many_failed_auth_attempts since it's used in this generalized way in 3 places now.
2010-02-07 15:37:32 -08:00
Andy Staudacher
18b0096751
Merge commit 'upstream/master'
2010-02-07 15:06:14 -08:00
Andy Staudacher
370e0e2f32
Fix installer code for version 27, and introduce new module variable in version 28 as a preparation for admin area compartmentalization.
2010-02-07 15:02:41 -08:00
Tim Almdal
6783de2457
Remove the redundant reference to ["force_rtl".
2010-02-07 14:17:58 -08:00
Tim Almdal
a54a81f9c7
Merge branch 'master' of git@github.com:gallery/gallery3
2010-02-07 13:59:59 -08:00
Tim Almdal
b6c0d3a48c
Refactor the is_rtl() helper into the Gallery_I18n class. This allows checking
...
for a config value "force_rtl" which will layout the gallery pages in rtl mode
without having to change to an language that is no longer understandable to the
developer.
Adding the line "$config['force_rtl'] = true;" to the config/locales.php file
will make it happen.
2010-02-07 13:55:17 -08:00
Bharat Mediratta
eda6e3af06
Rename user_authenticate_xxx events to user_auth_xxx for brevity.
2010-02-07 08:49:37 -08:00
Bharat Mediratta
aff5d1cef4
Create the concept of a "failed authentication" as semantically
...
separate from a successful or failed login.
1) Rename user_login_failed event to user_authenticate_failed
2) Rename failed_logins table to failed_auth (bump Gallery module to
v27 to rename the table)
3) auth::too_many_failed_logins -> auth::too_many_failures
4) auth::record_failed_auth_attempts -> auth::record_failed_attempts
auth::clear_failed_auth_attempts -> auth::clear_failed_attempts
2010-02-07 08:45:10 -08:00
Bharat Mediratta
adac97b537
Add prefix support for the target of RENAME TABLE.
2010-02-07 08:28:32 -08:00
Andy Staudacher
2c3c126aaf
Fix ticket 930: Use the first frame as video thumbnail if the video is shorter than 3 seconds. And fall back to the default thumbnail if that operation fails.
...
Thanks to lsowen for providing a patch!
2010-02-06 20:07:58 -08:00
Andy Staudacher
163391ee39
Partial fix for ticket 585: Require current password when changing an account's email address.
...
Still leaving the user/group admin page wide open though.
2010-02-06 17:43:33 -08:00
Andy Staudacher
7099fc71f1
Fix for ticket 1004: Replace all uses of split with explode (none actually required regular expressions). Thanks to Brian Hartsock for providing a patch!
2010-02-06 13:05:44 -08:00
Andy Staudacher
5c0c33782d
Fix for ticket 892: Avoid double escaping of HTML entities, instead use Unicode in the source code for the locale names (as we do in other places already).
...
Note: Also fixing the localized name of Ukrainian. For some reason it was garbled before.
2010-02-06 12:19:55 -08:00
Andy Staudacher
4977c00db1
Merge commit 'upstream/master'
2010-02-06 11:32:53 -08:00
Tim Almdal
1f51d663a0
Correct missing function name.
2010-02-03 08:18:53 -08:00
Bharat Mediratta
99a7f470b9
Protect password changes against brute force attacks.
2010-02-02 21:48:01 -08:00
Bharat Mediratta
6e1b761b12
Require the current password to change your password.
...
Fixes ticket #585 .
Separate out the password change form from the regular edit user form.
Require the old password to enter a new one. While I'm at it, roll
the password strength javascript into a Form_Script element so that we
can get rid of the old view (which incidentally fixes a bug where the
password strength meter would go away on form errors).
2010-02-02 21:36:01 -08:00
Bharat Mediratta
225fe81ce0
Add an upgrade path to prevent the item title field from being empty.
2010-02-02 20:50:34 -08:00
Bharat Mediratta
08f3f71ad9
Merge branch 'master' of git@github.com:gallery/gallery3
2010-02-02 19:04:20 -08:00
Tim Almdal
9ac3eca477
Merge branch 'master' into talmdal_dev
2010-02-02 15:01:13 -08:00
Tim Almdal
1c0e5eaa0d
use html::purify to cleans the additional content on the admin maintence page.
2010-02-02 15:00:05 -08:00
Tim Almdal
f69493d138
Update the xss golden file to reflect the changes to the admin screen.
2010-02-02 14:51:06 -08:00
Tim Almdal
19fee6b5e4
Refactor the admin maintenance screen so that events are used to pupluate the action buttons and other content such as the list of scheduled tasks.
2010-02-02 14:34:50 -08:00
Andy Staudacher
31aaf7555f
Merge commit 'upstream/master'
2010-02-02 13:41:50 -08:00
Bharat Mediratta
aa65bb0048
Merge branch 'master' of git@github.com:gallery/gallery3
2010-02-02 13:08:27 -08:00
Tim Almdal
3c3671cff2
Remove the test-transform:uppercase from the l10n css as it was causing problems with other text fields in IE and it violates our case standards. Fixes ticket #912
2010-02-02 12:30:23 -08:00
Tim Almdal
fe11e34cea
Change the view to display 'empty' when the variable value is a null string(""). Fixes ticket #987 .
2010-02-02 11:42:13 -08:00
Tim Almdal
370faf5f26
Display the error message for the in place edit. Also improve the double click guard. Fixes ticket #1000 .
2010-02-02 10:55:22 -08:00
Bharat Mediratta
469111d36a
Merge branch 'master' of git@github.com:gallery/gallery3
2010-02-01 21:44:58 -08:00
Bharat Mediratta
81a1df4a50
Localize the name "conflict" validation error when creating a new album.
2010-02-01 21:41:16 -08:00
Tim Almdal
5ded9e8ac5
Refactor starting a task into the task helper so we can call it multiple times.
2010-02-01 16:31:24 -08:00
Tim Almdal
48cb5021c6
Add the scheduler component to the admin maintenance screen.
2010-02-01 16:28:52 -08:00
Tim Almdal
43985ea2fb
Update the description to reflect we are only removing "expired" files.
2010-02-01 08:35:23 -08:00
Tim Almdal
64e014203c
Correct the internationalization of the status message.
2010-02-01 08:15:49 -08:00
Bharat Mediratta
c050acf30a
Fix lots of warnings that pop up when we're in E_STRICT mode. They're
...
mostly issues around uninitialized variables, calling non-static
functions in a static context, calling Session functions directly
instead of on its singleton, passing non-variables by reference, and
subclasses not using the same interface as the parent class.
2010-01-31 16:07:41 -08:00
Bharat Mediratta
c6676dd455
Remove obsolete call to _force_block_adder() which has been broken for over a year.
2010-01-31 15:23:37 -08:00
Andy Staudacher
be5f38adea
Minir l10n message cleanup. Avoid <br/> in messages since the server normalizes them to <br />, i.e. leading to a mismatch.
2010-01-31 14:03:32 -08:00
Bharat Mediratta
c5471a76a2
htaccess_works() can't use var/tmp anymore because that's locked down.
...
So just create var/security_test and delete it when we're done.
2010-01-31 13:27:05 -08:00
Bharat Mediratta
ee35b0a9fe
Elide data that isn't useful from the REST array.
2010-01-31 13:10:34 -08:00
Bharat Mediratta
4cd5c4cebb
Second attempt to fix the timezone issue. If the timezone is not set
...
in phpinfo(), then force it to America/Los_Angeles for now.
2010-01-31 11:27:54 -08:00
Bharat Mediratta
dad537effe
Update the timezone field to match the setting in
...
system/config/locale.php. This fixes the "date_default_timezone_set()
[function.date-default-timezone-set]: Timezone ID '' is invalid" error.
2010-01-31 11:24:00 -08:00
Bharat Mediratta
a79d20a361
Use Item_Model::as_restful_array() to simplify tests.
2010-01-30 23:36:41 -08:00
Bharat Mediratta
d29028c4ea
Add Item_Model::as_restful_array() for convenience.
2010-01-30 23:36:11 -08:00
Bharat Mediratta
6963695569
Verified
2010-01-30 23:22:53 -08:00
Bharat Mediratta
d92ee7954e
Refactory auth::too_many_failed_logins() out of
...
auth::validate_too_many_failed_logins() to conceptually separate the
two.
2010-01-30 23:15:18 -08:00
Andy Staudacher
1470b99d1f
Protect REST login controller from brute force attacks too.
...
And make the REST auth token less predictable by using a better source for randomness.
2010-01-30 21:42:57 -08:00
Bharat Mediratta
cb92e58d40
Update install.sql -- gallery version jumps from 23 to 25 due to a mistake
...
in the version 24 upgrade code.
Update packager to serialize files so that we can serialize the new
.htaccess files
Update init_var.php to include the newly serialized .htaccess files.
Fixes ticket #587 .
2010-01-30 21:16:47 -08:00
Bharat Mediratta
c2a7a6a4e7
Lock down web access to var/uploads, var/tmp and var/logs using .htaccess
...
Fixes ticket #587 .
2010-01-30 21:07:03 -08:00
Bharat Mediratta
2bfcec9620
Prevent brute force login attacks by reducing login attempts to 1 per
...
minute after there have been 5 consecutive failed login attempts.
Fix for ticket #589 .
2010-01-30 19:48:57 -08:00
Bharat Mediratta
86fd81ef26
Make url::merge() function use the same exact definition as url_Core::merge()
2010-01-30 17:41:48 -08:00