Commit Graph

4686 Commits

Author SHA1 Message Date
Bharat Mediratta
4bc7165dab Delete obsolete comment and tighten the code in site_menu(). 2009-08-29 16:42:33 -07:00
Bharat Mediratta
878b9c91b2 Remove try/catch in resize() since that will swallow any exceptions
that we generate when resizing.
2009-08-29 16:38:53 -07:00
Bharat Mediratta
a2258b2232 Merge branch 'master' of git@github.com:gallery/gallery3 2009-08-29 16:34:41 -07:00
Bharat Mediratta
483d8df91b Change the organize tree to expand/collapse. It doesn't properly open
up to the album that you're viewing, and if you move a photo to a
different album it'll reload the entire album tree.
2009-08-29 16:33:22 -07:00
Andy Staudacher
b4b638be44 Undo url helper changes - url methods no longer return a SafeString.
Adding SafeString::of_safe_html() calls where urls are passed as parameters to t() and t2().
2009-08-29 16:28:30 -07:00
jhilden
a1ce2d3f0a you can close the l10n client directly from its interface now, without going back to the languages admin page 2009-08-29 19:19:04 -04:00
Andy Staudacher
0204617b60 XSS fixes 2009-08-29 15:41:02 -07:00
Tim Almdal
0aceba6f48 Fix for ticket #628:
1) increased gallery module version to 11
2) added image_sharpened parameter to the gallery module
3) sharpen all resizes.
2009-08-29 15:20:27 -07:00
Tim Almdal
a5ddef021c Fix invalida syntax on trying to parse the progress bar percentage 2009-08-29 15:03:46 -07:00
Andy Staudacher
c4d5ecde66 L10n fixes for the admin_languages page, and JS/XSS cleanup of the organize views. 2009-08-29 14:38:47 -07:00
Andy Staudacher
f327b4ad38 Fix link in l10n UI (for SafeString changes) 2009-08-29 14:24:52 -07:00
Andy Staudacher
a5dfc81a8f Merge commit 'upstream/master'
Conflicts:

	modules/akismet/views/admin_akismet.html.php
	modules/comment/helpers/comment_rss.php
	modules/gallery/helpers/gallery_rss.php
	modules/gallery/libraries/I18n.php
	modules/gallery/views/permissions_browse.html.php
	modules/gallery/views/simple_uploader.html.php
	modules/info/views/info_block.html.php
	modules/organize/controllers/organize.php
	modules/organize/views/organize.html.php
	modules/organize/views/organize_album.html.php
	themes/default/views/album.html.php
	themes/default/views/movie.html.php
	themes/default/views/photo.html.php
2009-08-29 14:17:48 -07:00
Andy Staudacher
d5660d2d3e Fixing all detected XSS vectors in PHP->JS code.
Xss: Rename UNKNOWN back to DIRTY, JS_XSS to DIRTY_JS.
(using a different flag value to highlight potential XSS vectors in JS)
2009-08-29 13:41:18 -07:00
Chad Kieffer
a9fcec755a Merge branch 'master' of git@github.com:gallery/gallery3 2009-08-29 14:02:29 -06:00
Chad Kieffer
5db0b68a70 Update status message styles. Lighten backgrounds, don't show background on Admin Maintenance rows, and added gModuleStatus class. 2009-08-29 14:01:04 -06:00
Andy Staudacher
83344b9e7d Bugfix: Don't forget to copy the _is_purified_html flag when cloning a SafeString. 2009-08-29 12:50:20 -07:00
Andy Staudacher
c01ac42c46 Refactor all calls of p::clean() to SafeString::of() and p::purify() to SafeString::purify().
Removing any p::clean() calls for arguments to t() and t2() since their args are wrapped in a SafeString anyway.
2009-08-29 12:48:40 -07:00
Andy Staudacher
a10063ff68 Add more factory methods for convenience:
SafeString::purify() and SafeString::of_safe_html().

Removing SafeString::mark_html_safe() since it's no longer needed.
2009-08-29 12:34:09 -07:00
Bharat Mediratta
6b633e8748 Merge branch 'talmdal_branch' of git@github.com:gallery/gallery3 2009-08-29 12:24:44 -07:00
Bharat Mediratta
cd1fd4989f Add a test for Comment_Model::viewable(). 2009-08-29 12:22:00 -07:00
Bharat Mediratta
50c624ed1b Fix active() to not use user::guest() as the fallback for our Session::get() call. 2009-08-29 12:20:03 -07:00
Bharat Mediratta
0d16cc1c10 Clean up the test and get it working. 2009-08-29 12:12:53 -07:00
Andy Staudacher
7adb9ea2e3 Adding SafeString::for_html_attr() 2009-08-29 11:48:55 -07:00
Bharat Mediratta
d85a8b20bb Rename $comment_model to $comments. 2009-08-29 11:48:49 -07:00
Tim Almdal
38b2efc44c Fix for 641... extend viewable functionality to comments. Viewable unit test is not working. 2009-08-29 11:43:10 -07:00
Bharat Mediratta
35f83ff31d Merge branch 'master' of git@github.com:gallery/gallery3 2009-08-29 11:33:29 -07:00
Andy Staudacher
1d633457c4 Have url::site() and other methods return a SafeString, just as t() and t2().
Benefits:
 - url::site() is often used in views and we can ensure in the url class that returned strings are indeed safe for use in HTML. Makes the list of vars of unknown safety status shorter.
 - url::site() is often used as message parameter to t() and t2(). The parameter would be HTML-escaped if it wasn't marked as safe HTML already. Makes the usage simpler / shorter.
2009-08-29 11:31:00 -07:00
jhilden
22c7f44d0b Merge branch 'master' of git@github.com:gallery/gallery3 2009-08-29 14:29:54 -04:00
Bharat Mediratta
775987dff9 Fix a bug where organize doesn't properly generate the tree at the root album. 2009-08-29 11:29:38 -07:00
jhilden
746609b967 * created new generic "Add" dropdown in the site menu. this should take care of ticket #537
* removed start/stop translation menu items from the admin, since they are on the languags admin page now
2009-08-29 14:27:08 -04:00
Tim Almdal
27b81257fa Standardize the access to the create_random_item method 2009-08-29 11:24:12 -07:00
Tim Almdal
08d7fda7f8 Merge branch 'master' of git://github.com/gallery/gallery3 2009-08-29 11:22:19 -07:00
jhilden
8d256898c7 improved translation interface so that it now can be closed without going to the admin 2009-08-29 14:21:53 -04:00
Tim Almdal
6de10a54dd Fix typo in the parameter list 2009-08-29 11:21:30 -07:00
Bharat Mediratta
4408ed0684 Remove stray blank line. 2009-08-29 10:56:35 -07:00
Bharat Mediratta
1527f149a9 Merge branch 'master' of git@github.com:gallery/gallery3 2009-08-29 10:49:25 -07:00
Bharat Mediratta
b833cb6073 Get rid of the task infrastructure. The multiple requests greatly
slow down simple operations.  We may run into problems with more
complex operations, but let's only add tasks into the mix when it's
clear that we need them.
2009-08-29 10:48:23 -07:00
Andy Staudacher
020281d932 Adding SafeString which is going to replace p::clean() and p::purify().
Refactoring of Xss_Security_Test.
t() and t2() return a SafeString instance.

TODO:
 - Update all code to use SafeString where appropriate.
 - Update golden fole of Xss_Security_Test
 - Stop reporting CLEAN vars in Xss_Security_Test
2009-08-29 10:45:47 -07:00
Andy Staudacher
a2e2a2178b Using SafeString in album controller / view 2009-08-29 10:40:34 -07:00
Bharat Mediratta
f257cd3d69 Major refactor of organize:
* Clean up naming conventions for variables in the controller
  so that we specifically refer to albums with $album_id, etc.

* Move complexity for drawing tree out of the controller and into
  the view.

* Simplify task definitions to get rid of extraneous text

* Change __PLACEHOLDERS__ to clearly define which is the album
  and which is the item that we're moving before/after

* Remove as many CSS ids as we can from the tree view to keep
  things simple
2009-08-29 10:00:47 -07:00
Bharat Mediratta
acce8cbafd Log the actual exception details, before swallowing the exception. 2009-08-29 08:47:44 -07:00
jhilden
c234f9fd39 improved translations admin interface 2009-08-28 20:53:06 -04:00
Bharat Mediratta
cb2171d082 Display the sort order in the Organize dialog, and allow users to
change the sort order on the fly.
2009-08-28 14:27:37 -07:00
Tim Almdal
31d63a0d0a Merge branch 'master' of git://github.com/gallery/gallery3 2009-08-28 13:47:36 -07:00
Tim Almdal
1d5262f9c3 Fix ticket #591: reCaptcha always on the page.
1) move creating the "Add a comment" button into the comments.html.php
2) use $.get() to retrieve the comment add form
2009-08-28 13:44:01 -07:00
jhilden
1855642bd1 improved UI for the languages admin
this should take care of bug #329
2009-08-28 16:19:41 -04:00
Bharat Mediratta
6dcfdb6432 Fix a bug in notification where were using get() instead of current()
to get the first item in an ORM result set.
2009-08-28 12:42:37 -07:00
Bharat Mediratta
dcead39dfb Merge branch 'talmdal_branch' of git@github.com:gallery/gallery3 2009-08-28 12:37:01 -07:00
Bharat Mediratta
e24d23bf14 Merge branch 'master' of git@github.com:talmdal/gallery3 into talmdal_branch 2009-08-28 12:33:47 -07:00
Bharat Mediratta
36d1a8c4f2 Rename sort columns:
* Order Added => Manual
  * Capture Date => Date captured
  * Creation Date => Date uploaded
  * Updated Date => Date modified

Set the default sort order to "created" which mimics what we had
before, expt that it is not manual.
2009-08-28 12:08:21 -07:00