Commit Graph
537 Commits
Author SHA1 Message Date
Bharat Mediratta 81073aeb5b Merge branch 'master' of git@github.com:gallery/gallery3 2009-08-31 21:11:57 -07:00
Bharat Mediratta c887170555 Stay on the same page when editing albums/movies/photos. Fixes ticket 2009-08-31 21:10:22 -07:00
Andy Staudacher 48050aca41 Add XSS check to ensure that html::js_string() is not preceded by a quote. 2009-08-31 19:53:53 -07:00
Andy Staudacher 8312eb116e XSS review fixes (mostly adding missing html::mark_clean()) calls. 2009-08-31 02:12:01 -07:00
Andy Staudacher 26f6d8192f Adding XSS test for href="javascript: and onclick="..." 2009-08-31 01:11:50 -07:00
Andy Staudacher ddb84c84e1 Rename mark_safe() to mark_clean() 2009-08-31 00:42:18 -07:00
Andy Staudacher 6d26b0dd6e Merge commit 'upstream/master' 2009-08-31 00:32:41 -07:00
Andy Staudacher afb0111fe6 Updating golden XSS-test data file 2009-08-30 21:36:14 -07:00
Andy Staudacher 0a0c7a78e6 Check for href="<?= $foo ?>" (malicious "javascript:..." string) 2009-08-30 21:25:21 -07:00
Andy Staudacher 3aef420d48 Updating XSS golden file 2009-08-30 18:37:01 -07:00
Andy Staudacher e7f5e0a9a3 Merge commit 'upstream/master'
Conflicts:

	modules/gallery/views/l10n_client.html.php
	modules/organize/views/organize_tree.html.php
	modules/server_add/helpers/server_add_event.php
2009-08-30 18:27:40 -07:00
Andy Staudacher df38a890a6 Tabs to spaces cleanup 2009-08-30 18:07:13 -07:00
Chad Kieffer 80ae2fe4bf Finish this pass at the Admin Maintenance view. Re-introduce status icons, put Cancel All, Delete All buttons in the action heading cell. 2009-08-30 23:51:31 -06:00
Chad Kieffer ce733e0f48 Merge branch 'master' of git@github.com:gallery/gallery3 2009-08-30 22:33:12 -06:00
Chad Kieffer 93b542ccd8 Apply hover effect to buttons in progress indicator dialog. 2009-08-30 22:32:23 -06:00
Andy Staudacher 00c73ec852 Updating uses of html::js_string and SafeString::for_js (value now contains string delimiters) 2009-08-30 15:34:46 -07:00
Andy Staudacher beb711d6a0 Rename clean_js to js_string and have it return a complete JS string (with delimiters) instead of just the string contents.
Benefits: Using json_encode(), which is very robust. And as a user, it's clearer how to use this API compared to what it was before.
2009-08-30 15:21:02 -07:00
Bharat Mediratta dee0abfab9 Use is_descendant() API inside move_to() for clarity. 2009-08-30 15:04:39 -07:00
Andy Staudacher b5813f92c7 Improve no_tabs test to print out a complete list of files + line numbers + line snippet. 2009-08-30 07:42:37 -07:00
Andy Staudacher 22aa0b3092 Add $theme-> methods to Xss whitelist for HTML safety.
Updating XSS golden file.
2009-08-30 07:25:49 -07:00
Andy Staudacher effccfd41d Change all instances of SafeString::of_safe_html() to html::mark_safe() in views. 2009-08-30 07:00:56 -07:00
Andy Staudacher 52b542b253 Fixing typo 2009-08-30 06:55:24 -07:00
Andy Staudacher d3b0302690 Minor cleanup 2009-08-29 23:15:28 -07:00
Andy Staudacher b9bd1681a3 Update all code to use helper method html::clean(), html::purify(), ... instead of SafeString directly. 2009-08-29 22:54:20 -07:00
Andy Staudacher 952c885609 Adding html::clean(), ::purify(), etc. 2009-08-29 22:31:23 -07:00
Bharat Mediratta 878b9c91b2 Remove try/catch in resize() since that will swallow any exceptions
that we generate when resizing.
2009-08-29 16:38:53 -07:00
Andy Staudacher b4b638be44 Undo url helper changes - url methods no longer return a SafeString.
Adding SafeString::of_safe_html() calls where urls are passed as parameters to t() and t2().
2009-08-29 16:28:30 -07:00
jhilden a1ce2d3f0a you can close the l10n client directly from its interface now, without going back to the languages admin page 2009-08-29 19:19:04 -04:00
Andy Staudacher 0204617b60 XSS fixes 2009-08-29 15:41:02 -07:00
Tim Almdal 0aceba6f48 Fix for ticket #628:
1) increased gallery module version to 11
2) added image_sharpened parameter to the gallery module
3) sharpen all resizes.
2009-08-29 15:20:27 -07:00
Tim Almdal a5ddef021c Fix invalida syntax on trying to parse the progress bar percentage 2009-08-29 15:03:46 -07:00
Andy Staudacher c4d5ecde66 L10n fixes for the admin_languages page, and JS/XSS cleanup of the organize views. 2009-08-29 14:38:47 -07:00
Andy Staudacher f327b4ad38 Fix link in l10n UI (for SafeString changes) 2009-08-29 14:24:52 -07:00
Andy Staudacher a5dfc81a8f Merge commit 'upstream/master'
Conflicts:

	modules/akismet/views/admin_akismet.html.php
	modules/comment/helpers/comment_rss.php
	modules/gallery/helpers/gallery_rss.php
	modules/gallery/libraries/I18n.php
	modules/gallery/views/permissions_browse.html.php
	modules/gallery/views/simple_uploader.html.php
	modules/info/views/info_block.html.php
	modules/organize/controllers/organize.php
	modules/organize/views/organize.html.php
	modules/organize/views/organize_album.html.php
	themes/default/views/album.html.php
	themes/default/views/movie.html.php
	themes/default/views/photo.html.php
2009-08-29 14:17:48 -07:00
Andy Staudacher d5660d2d3e Fixing all detected XSS vectors in PHP->JS code.
Xss: Rename UNKNOWN back to DIRTY, JS_XSS to DIRTY_JS.
(using a different flag value to highlight potential XSS vectors in JS)
2009-08-29 13:41:18 -07:00
Chad Kieffer a9fcec755a Merge branch 'master' of git@github.com:gallery/gallery3 2009-08-29 14:02:29 -06:00
Chad Kieffer 5db0b68a70 Update status message styles. Lighten backgrounds, don't show background on Admin Maintenance rows, and added gModuleStatus class. 2009-08-29 14:01:04 -06:00
Andy Staudacher 83344b9e7d Bugfix: Don't forget to copy the _is_purified_html flag when cloning a SafeString. 2009-08-29 12:50:20 -07:00
Andy Staudacher c01ac42c46 Refactor all calls of p::clean() to SafeString::of() and p::purify() to SafeString::purify().
Removing any p::clean() calls for arguments to t() and t2() since their args are wrapped in a SafeString anyway.
2009-08-29 12:48:40 -07:00
Andy Staudacher a10063ff68 Add more factory methods for convenience:
SafeString::purify() and SafeString::of_safe_html().

Removing SafeString::mark_html_safe() since it's no longer needed.
2009-08-29 12:34:09 -07:00
Bharat Mediratta 6b633e8748 Merge branch 'talmdal_branch' of git@github.com:gallery/gallery3 2009-08-29 12:24:44 -07:00
Bharat Mediratta 0d16cc1c10 Clean up the test and get it working. 2009-08-29 12:12:53 -07:00
Andy Staudacher 7adb9ea2e3 Adding SafeString::for_html_attr() 2009-08-29 11:48:55 -07:00
Tim Almdal 38b2efc44c Fix for 641... extend viewable functionality to comments. Viewable unit test is not working. 2009-08-29 11:43:10 -07:00
Andy Staudacher 1d633457c4 Have url::site() and other methods return a SafeString, just as t() and t2().
Benefits:
 - url::site() is often used in views and we can ensure in the url class that returned strings are indeed safe for use in HTML. Makes the list of vars of unknown safety status shorter.
 - url::site() is often used as message parameter to t() and t2(). The parameter would be HTML-escaped if it wasn't marked as safe HTML already. Makes the usage simpler / shorter.
2009-08-29 11:31:00 -07:00
jhilden 22c7f44d0b Merge branch 'master' of git@github.com:gallery/gallery3 2009-08-29 14:29:54 -04:00
jhilden 746609b967 * created new generic "Add" dropdown in the site menu. this should take care of ticket #537
* removed start/stop translation menu items from the admin, since they are on the languags admin page now
2009-08-29 14:27:08 -04:00
Tim Almdal 27b81257fa Standardize the access to the create_random_item method 2009-08-29 11:24:12 -07:00
jhilden 8d256898c7 improved translation interface so that it now can be closed without going to the admin 2009-08-29 14:21:53 -04:00
Bharat Mediratta 1527f149a9 Merge branch 'master' of git@github.com:gallery/gallery3 2009-08-29 10:49:25 -07:00