Andy Staudacher
dcddc68f58
Never assign a SafeString instance to a Model member (or hell will break loose).
2010-02-15 13:12:38 -08:00
Tim Almdal
a597b57210
return the absolute url not the relative for the full size, resize and thumb images.
2010-02-15 12:29:49 -08:00
Andy Staudacher
4091219425
Fix for ticket #491 : Make user and group names translatable.
...
Also fixed a UI bug: No longer showing the edit user buttons to admins in the profile view (to be consistent with the requirements in the controller).
2010-02-14 19:26:34 -08:00
Andy Staudacher
667d65aea4
Fix for ticket 901: Wrap Gallery version string into bdo tag to override the BiDi algorithm. Also, properly marking the "Powere by" string for translation.
...
See: http://www.w3.org/International/tutorials/bidi-xhtml/#Slide0420
2010-02-14 18:33:38 -08:00
Andy Staudacher
30dcaaa236
Need to allow access to ::change_provider for CLI, to make packager work.
2010-02-14 18:33:10 -08:00
Andy Staudacher
0eb9b43a33
Enable session expiration. Currently, it's set to expire sessions after 7 days of inactivity.
2010-02-14 17:26:57 -08:00
Andy Staudacher
74471df777
Minor security tightening of IdentityProvider::change_provider().
2010-02-14 16:12:18 -08:00
Tim Almdal
141595e709
Create an items REST collection requests that accepts a list of resource urls and returns the items associated with them.
2010-02-14 07:35:03 -08:00
Tim Almdal
897215689c
Remove the dirty flags from the information returned from the rest request for an item. In addition, add links to the images.
2010-02-14 07:32:35 -08:00
Andy Staudacher and Tim Almdal
0f66db51ef
Change JavaScript reauthentication check to check via XHR.
...
Benefit: Getting the real deadline this way, not interfering with an ongoing maintenance task.
2010-02-14 07:15:59 -08:00
Andy Staudacher and Tim Almdal
1a951cb7f6
HTML validation fix (<script>)
2010-02-14 07:15:58 -08:00
Andy Staudacher and Tim Almdal
2dad1d7cd1
Some HTML validation fixes (don't render empty <ul> lists, empty id attributes, use & not &)
2010-02-14 07:15:57 -08:00
Andy Staudacher and Tim Almdal
8412aeb133
For consistency, use straight Kohana_404_Exception instead of the event system.
2010-02-14 07:15:57 -08:00
Bharat Mediratta
e88e976fc4
Tighten up the text.
2010-02-12 13:49:14 -08:00
Andy Staudacher
d53f6d0e05
Fix for tickets 1009 and 603: Show a themed error page to guests / registered users (not to admins though). And show a login form to guests for 404 (incl. insufficient view permissions) errors.
2010-02-12 16:40:44 -08:00
Bharat Mediratta
ce71ea6aa7
Revert "1) Add a depth parameter to retrieving an item thru the rest api"
...
This reverts commit 3439671bcf .
2010-02-12 04:53:26 -08:00
Tim Almdal
3439671bcf
1) Add a depth parameter to retrieving an item thru the rest api
...
2) Standardize the structure of members so that client programs can consistently
parse the return information.
3) Added a summary parameter so that client programs can easily determine if the
information returned is summary (item type, item title) or the full meal deal
2010-02-12 09:52:57 -08:00
Andy Staudacher
6353a7c2de
Security: Fix leaking of album / photo names. Reject previous fix for ticket 1009.
...
Side effect: Renaming auth::required_login() to login_page().
2010-02-11 14:28:32 -08:00
Bharat Mediratta
1ada27916f
Use the admin/users/edit_user_form version of the user editing form
...
right after initial install so that we're not requiring the user to
re-enter the auto-generated password to change their password and
email.
Fixes ticket #1007
2010-02-11 05:24:16 -08:00
Tim Almdal
8ef08d2088
Refactor the code to display the login page if the user does not have view
...
permission into the common auth::require_login() method.
2010-02-10 08:53:39 -08:00
Tim Almdal
17f0a1b10f
If the user does not have permission to view the album, photo or movie, redirect
...
to a logon page to allow the user to login. Pass the target url as a session
variable to allow the user to be redirected where they want to go if the login
was successful. Fixes ticket #1009 .
2010-02-10 08:45:14 -08:00
Tim Almdal
f6c615c379
Use the helper ulr:current instead of manually creating the continue url.
2010-02-10 08:32:30 -08:00
Bharat Mediratta
09d3f48323
Merge branch 'master' of github.com:gallery/gallery3
2010-02-09 15:50:30 -08:00
Chad Kieffer
92c2dd61ff
Formated upgrader for RTL languages. Closes ticket #883
2010-02-09 21:57:04 -07:00
Bharat Mediratta
8a8d8b4bc4
Rename item name and slug if necessary to avoid a conflict when we
...
move photos. Fixes ticket #957 .
2010-02-09 15:49:43 -08:00
Bharat Mediratta
86721ce280
Whitespace.
2010-02-09 15:21:40 -08:00
Bharat Mediratta
e1c0877646
Add unit tests for item::move() in preparation for renaming when there
...
are conflicts (see ticket #957 )
2010-02-09 08:53:27 -08:00
Andy Staudacher
992d305e19
Merge commit 'upstream/master'
2010-02-08 22:16:30 -08:00
Andy Staudacher
13cfe2d61d
Change admin area timeout from 20 to 90 minutes
2010-02-08 22:15:38 -08:00
Bharat Mediratta
9ca521c710
Merge branch 'master' of github.com:gallery/gallery3
2010-02-08 15:38:59 -08:00
Bharat Mediratta
6dfab72922
Override Input::clean_input_keys() to sanitize malicious values out of
...
strings instead of dying. This at least gives us graceful degradation.
Fixes ticket #764 , patch thanks to djnz.
2010-02-08 15:37:11 -08:00
Andy Staudacher
f9377bcbd3
Suppress errors when checking for readability of /proc/loadavg. Often this file will be protected by openbasedir, and is_readable will trigger an open basedir warning.
2010-02-08 13:05:18 -08:00
Andy Staudacher
f9d00aa742
Fix for ticket 1008: Redirect to destination after re-auth.
2010-02-08 00:30:36 -08:00
Andy Staudacher
d0f6839c25
Fix Arabic language name. Thanks shaibn for reporting the issue. Verified with CLDR data.
2010-02-08 00:05:17 -08:00
Tim Almdal
b8047db539
Revert "Add the scheduler component to the admin maintenance screen."
...
This reverts commit 48cb5021c6 .
2010-02-07 21:40:34 -08:00
Tim Almdal
316b0583b3
Revert "Refactor the admin maintenance screen so that events are used to
...
populate the action buttons and other content such as the list of scheduled
tasks."
Leaving this api out of RC1.
This reverts commit 19fee6b5e4 .
Conflicts:
modules/gallery/views/admin_maintenance.html.php
2010-02-07 21:38:51 -08:00
Andy Staudacher
9695041a86
Change welcome message dialog to link to the user_profile page instead of the change user dialog.
...
a) the edit user form doesn't include the password anymore
b) the new admin would probably also like to change the email, so directing him to the profile page with options to change the pw / email.
Ideally, we'd have a special purpose edit profile page for the install experience, without prompting for the randomly generated password. But that's something for another task.
2010-02-07 16:56:19 -08:00
Andy Staudacher
8fc346e9b6
Addendum for ticket 585: Handle case C), redirect the admin to a non-admin page when the admin area session expires, before the admin has a chance to send an XHR admin request, for which we wouldn't have a good answer.
2010-02-07 16:44:07 -08:00
Andy Staudacher
f93528ffab
Last partial fix for ticket 585: Compartmentalize the admin area and require active authentication every 20 minutes to access the admin area.
...
Also renaming auth::validate_too_many_failed_password_changes to validate_too_many_failed_auth_attempts since it's used in this generalized way in 3 places now.
2010-02-07 15:37:32 -08:00
Andy Staudacher
18b0096751
Merge commit 'upstream/master'
2010-02-07 15:06:14 -08:00
Andy Staudacher
370e0e2f32
Fix installer code for version 27, and introduce new module variable in version 28 as a preparation for admin area compartmentalization.
2010-02-07 15:02:41 -08:00
Tim Almdal
6783de2457
Remove the redundant reference to ["force_rtl".
2010-02-07 14:17:58 -08:00
Tim Almdal
a54a81f9c7
Merge branch 'master' of git@github.com:gallery/gallery3
2010-02-07 13:59:59 -08:00
Tim Almdal
b6c0d3a48c
Refactor the is_rtl() helper into the Gallery_I18n class. This allows checking
...
for a config value "force_rtl" which will layout the gallery pages in rtl mode
without having to change to an language that is no longer understandable to the
developer.
Adding the line "$config['force_rtl'] = true;" to the config/locales.php file
will make it happen.
2010-02-07 13:55:17 -08:00
Bharat Mediratta
eda6e3af06
Rename user_authenticate_xxx events to user_auth_xxx for brevity.
2010-02-07 08:49:37 -08:00
Bharat Mediratta
aff5d1cef4
Create the concept of a "failed authentication" as semantically
...
separate from a successful or failed login.
1) Rename user_login_failed event to user_authenticate_failed
2) Rename failed_logins table to failed_auth (bump Gallery module to
v27 to rename the table)
3) auth::too_many_failed_logins -> auth::too_many_failures
4) auth::record_failed_auth_attempts -> auth::record_failed_attempts
auth::clear_failed_auth_attempts -> auth::clear_failed_attempts
2010-02-07 08:45:10 -08:00
Bharat Mediratta
adac97b537
Add prefix support for the target of RENAME TABLE.
2010-02-07 08:28:32 -08:00
Andy Staudacher
2c3c126aaf
Fix ticket 930: Use the first frame as video thumbnail if the video is shorter than 3 seconds. And fall back to the default thumbnail if that operation fails.
...
Thanks to lsowen for providing a patch!
2010-02-06 20:07:58 -08:00
Andy Staudacher
163391ee39
Partial fix for ticket 585: Require current password when changing an account's email address.
...
Still leaving the user/group admin page wide open though.
2010-02-06 17:43:33 -08:00
Andy Staudacher
7099fc71f1
Fix for ticket 1004: Replace all uses of split with explode (none actually required regular expressions). Thanks to Brian Hartsock for providing a patch!
2010-02-06 13:05:44 -08:00