Chad Kieffer
7cdcb5179f
Merge branch 'master' of git@github.com:gallery/gallery3
2009-06-06 00:35:39 -06:00
Chad Kieffer
c5425f42a4
Remove album view icon link, added album link to info module. This and breadcrumb should suffice.
2009-06-06 00:35:30 -06:00
Andy Staudacher
329bd8caa1
Remove source code copy artefact
2009-06-05 18:31:15 -07:00
Bharat Mediratta
3275401f69
change the version to beta 1
2009-06-05 17:44:36 -07:00
Bharat Mediratta
275c25eb56
Add the exception message to the trace string when there's a graphics
...
failure.
Signed-off-by: Bharat Mediratta <bharat@menalto.com >
2009-06-06 08:39:07 +08:00
Andy Staudacher
4fcad78f54
Update golden file of Xss test
2009-06-05 16:10:08 -07:00
unostar
73a0df1b16
corrected misprint
...
Signed-off-by: Bharat Mediratta <bharat@menalto.com >
2009-06-06 01:26:42 +08:00
unostar
710d13aece
Correct locale and local translation
...
Signed-off-by: Bharat Mediratta <bharat@menalto.com >
2009-06-06 01:26:41 +08:00
Bharat Mediratta
62a63676d4
Add Belarusian to the language list.
...
Signed-off-by: Bharat Mediratta <bharat@menalto.com >
2009-06-06 01:26:24 +08:00
Bharat Mediratta
7612c8d404
Localize the 'Advanced' menu item
...
Signed-off-by: Bharat Mediratta <bharat@menalto.com >
2009-06-06 01:26:22 +08:00
Chad Kieffer
4d3cb760de
Move watch notification menu from the view menu to under the Options menu.
2009-06-05 01:14:09 -06:00
Bharat Mediratta
c7f49fd1ec
Skip over busted images when rebuilding. Change graphics::generate()
...
to return true/false on whether or not it could rebuild the image
properly, then track the broke images in the task and ignore them.
Fixes ticket #344 .
2009-06-04 23:20:54 -07:00
Bharat Mediratta
4f0a3fefa0
Fix a bug in Item_Model::get_position() where we incorrectly using the
...
grandparent id. Oops. This caused navigation from photo back up to
album to be broken.
Also update Photos_Controller to use the active sort order.. it was
still hardcoded to use the id. It's more efficient now, yay.
Fixes ticket #340 .
2009-06-04 22:11:08 -07:00
Bharat Mediratta
54927248b0
Updated for csrf in admin.html.php
2009-06-04 22:10:45 -07:00
Bharat Mediratta
66c6c3df0e
Convert single quotes to double quotes.
2009-06-04 21:43:21 -07:00
Bharat Mediratta
ac70a1b77a
Fix internationalization to use one long string and placeholders.
...
Removed the <br/> though since we're trying to avoid structural HTML
in internationalized strings.
2009-06-04 18:49:45 -07:00
Bharat Mediratta
2d7d55014a
Merge branch 'master' of git@github.com:gallery/gallery3
2009-06-04 18:41:41 -07:00
Bharat Mediratta
12ef4272ae
Work around a problem with the CGI sapi on urls that don't contain
...
index.php (ie, /gallery3 instead of /gallery3/index.php) that causes
is to mis-route.
2009-06-04 18:40:38 -07:00
jhilden
a156f1e9be
Merge branch 'master' of git@github.com:gallery/gallery3
2009-06-04 21:34:20 -04:00
jhilden
81d20c79b6
fixed another bug with the filesize unit and added a better error message
...
Merge branch 'master' of git@github.com:gallery/gallery3
Conflicts:
modules/gallery/views/simple_uploader.html.php
2009-06-04 21:32:45 -04:00
Bharat Mediratta
e5a0104769
Make sure the item is loaded in parse_url() before we use it.
2009-06-04 18:19:49 -07:00
jhilden
8933a19f1f
fixed stuff
2009-06-04 21:05:33 -04:00
Bharat Mediratta
5158a6f433
Add MY_num containing num::convert_to_bytes() which supports PHP's
...
size shorthand, and convert the simple_uploader code to use it.
2009-06-04 17:53:40 -07:00
Bharat Mediratta
59f3a84864
Merge branch 'master' of git@github.com:gallery/gallery3
2009-06-04 17:37:52 -07:00
Bharat Mediratta
8d9010cfe3
Let the Akismet module create the statistics menu, since it's the only
...
one that uses it. Perhaps this is not the best solution, but it's the
pragmatic one.
2009-06-04 17:36:37 -07:00
jhilden
9306c178a8
set filesize limit of swfupload to the same value as upload_max_filesize
...
* now users get an error when they try to upload too big files
* this should fix bug #337
* maybe it also needs to check for max_post_size
2009-06-04 18:29:31 -04:00
Bharat Mediratta
743b321154
Change "CLEAN" to an empty string to see if it's better visually.
...
Looks like it is.
2009-06-04 12:23:12 -07:00
Bharat Mediratta
1acc64add7
Update xss clean list
2009-06-04 12:22:41 -07:00
Bharat Mediratta
7e5a363ffc
Only request the server_add js if the user is an admin
2009-06-04 12:21:51 -07:00
Tim Almdal
e1ce3196f4
Rewrite the server_add to have the server format the selection when a branch is opened. Sub trees re only retrieved when the branch is opened. Changed the
...
start task processing to fill in any subtrees that are selected, but were never expanded on the client. Added the loading icon.
Signed-off-by: Bharat Mediratta <bharat@menalto.com >
2009-06-05 03:13:14 +08:00
Chad Kieffer
bc38505251
Update notify/watch eyeglasses icon with bullhorn icon. Rename css/image names from watch to notify.
2009-06-04 11:55:18 -07:00
Bharat Mediratta
dd854379c2
Sanitize all data we return via json_encode() to guard against XSS and
...
other data leaks.
2009-06-03 17:08:23 -07:00
Bharat Mediratta
05d18da390
Guard against pages with no items.
2009-06-03 17:01:33 -07:00
Bharat Mediratta
bec2fdf7c4
Minor tweaks to the way that we turn the add photos item into a menu
...
to make it a little more robust.
2009-06-03 16:39:08 -07:00
jhilden
dde5fb96ee
made "Add photos" its own site menu item
...
* open for suggestions on the submenu item labels
* @bharat: not sure about the add photos menu item id in the dropdown case
2009-06-02 19:31:11 -04:00
Bharat Mediratta
01c5774794
Merge branch 'master' of git@github.com:gallery/gallery3
2009-06-02 15:47:04 -07:00
Bharat Mediratta
e834c4ca24
Have server_add turn the "Add Photo" menu option into a dropdown and
...
make "Add from Server" a 2nd option there.
This requires adding the Menu::remove() API function.
2009-06-02 15:46:05 -07:00
Tim Almdal
dbeceb333b
Improve test isolation so that Albums_Controller_Test doesn't fail when run with Photos_Controller_Test
2009-06-02 14:19:03 -07:00
Bharat Mediratta
ffb3abdcac
Restore "view" permissions on the root album in teardown.
2009-06-02 13:37:19 -07:00
Tim Almdal
4f50357a38
fix the xss_security_test in regards to the renaming of thumb_tag, resize_tag and move_tag.
2009-06-02 12:56:36 -07:00
Tim Almdal
d8eca7682d
make cleanm static
2009-06-02 12:41:59 -07:00
Tim Almdal
9f51395151
fix preamble so file structure test passes
2009-06-02 12:31:27 -07:00
Tim Almdal
0f987880e6
Fix for ticket #320
2009-06-02 12:08:47 -07:00
Andy Staudacher
1cfed1fac1
Extend L10n client to provide UI for plural translation.
...
Ticket 148.
2009-06-02 00:43:04 -07:00
Bharat Mediratta
f039598410
Move recaptcha widget into a view for clarity. Also, wrap it in a
...
setTimeout() call so that on subsequent reloads (which happen when you
fail to validate the form) it has time to rebuild the DOM before
calling the JS which tries to inject the Recaptcha HTML.
Fixes ticket #327
2009-06-01 23:58:49 -07:00
andyst
02a840c84c
Merge branch 'master' of git@github.com:gallery/gallery3
2009-06-01 23:45:37 -07:00
Bharat Mediratta
3b6567f38c
Unescape %20 into " " also.
2009-06-01 23:20:36 -07:00
Andy
d0845aadc6
Workaround for parse_ini_file issue: There's no way to escape a double-quote in a value that's read with
...
parse_ini_file. Using single quotes instead, even if that's not the best style in English.
2009-06-01 23:08:13 -07:00
Bharat Mediratta
91c7eb1200
Don't throw an error if there are no visible tags.
2009-06-01 23:00:10 -07:00
Bharat Mediratta
43abcd9386
Security pass over all controller code. Mostly adding CSRF checking
...
and verifying user permissions, but there are several above-the-bar
changes:
1) Server add is now only available to admins. This is a hard
requirement because we have to limit server access (eg:
server_add::children) to a user subset and the current permission
model doesn't include that. Easiest fix is to restrict to admins.
Got rid of the server_add permission.
2) We now know check permissions at every level, which means in
controllers AND in helpers. This "belt and suspenders" approach will
give us defense in depth in case we overlook it in one area.
3) We now do CSRF checking in every controller method that changes the
code, in addition to the Forge auto-check. Again, defense in depth
and it makes scanning the code for security much simpler.
4) Moved Simple_Uploader_Controller::convert_filename_to_title to
item:convert_filename_to_title
5) Fixed a bug in sending notification emails.
6) Fixed the Organize code to verify that you only have access to your
own tasks. In general, added permission checks to organize which had
pretty much no validation code.
I did my best to verify every feature that I touched.
2009-06-01 22:40:22 -07:00