Bharat Mediratta
81073aeb5b
Merge branch 'master' of git@github.com:gallery/gallery3
2009-08-31 21:11:57 -07:00
Bharat Mediratta
c887170555
Stay on the same page when editing albums/movies/photos. Fixes ticket
2009-08-31 21:10:22 -07:00
Andy Staudacher
48050aca41
Add XSS check to ensure that html::js_string() is not preceded by a quote.
2009-08-31 19:53:53 -07:00
Andy Staudacher
8312eb116e
XSS review fixes (mostly adding missing html::mark_clean()) calls.
2009-08-31 02:12:01 -07:00
Andy Staudacher
26f6d8192f
Adding XSS test for href="javascript: and onclick="..."
2009-08-31 01:11:50 -07:00
Andy Staudacher
ddb84c84e1
Rename mark_safe() to mark_clean()
2009-08-31 00:42:18 -07:00
Andy Staudacher
6d26b0dd6e
Merge commit 'upstream/master'
2009-08-31 00:32:41 -07:00
Andy Staudacher
afb0111fe6
Updating golden XSS-test data file
2009-08-30 21:36:14 -07:00
Andy Staudacher
0a0c7a78e6
Check for href="<?= $foo ?>" (malicious "javascript:..." string)
2009-08-30 21:25:21 -07:00
Andy Staudacher
3aef420d48
Updating XSS golden file
2009-08-30 18:37:01 -07:00
Andy Staudacher
e7f5e0a9a3
Merge commit 'upstream/master'
...
Conflicts:
modules/gallery/views/l10n_client.html.php
modules/organize/views/organize_tree.html.php
modules/server_add/helpers/server_add_event.php
2009-08-30 18:27:40 -07:00
Andy Staudacher
df38a890a6
Tabs to spaces cleanup
2009-08-30 18:07:13 -07:00
Chad Kieffer
80ae2fe4bf
Finish this pass at the Admin Maintenance view. Re-introduce status icons, put Cancel All, Delete All buttons in the action heading cell.
2009-08-30 23:51:31 -06:00
Chad Kieffer
ce733e0f48
Merge branch 'master' of git@github.com:gallery/gallery3
2009-08-30 22:33:12 -06:00
Chad Kieffer
93b542ccd8
Apply hover effect to buttons in progress indicator dialog.
2009-08-30 22:32:23 -06:00
Andy Staudacher
00c73ec852
Updating uses of html::js_string and SafeString::for_js (value now contains string delimiters)
2009-08-30 15:34:46 -07:00
Andy Staudacher
beb711d6a0
Rename clean_js to js_string and have it return a complete JS string (with delimiters) instead of just the string contents.
...
Benefits: Using json_encode(), which is very robust. And as a user, it's clearer how to use this API compared to what it was before.
2009-08-30 15:21:02 -07:00
Bharat Mediratta
dee0abfab9
Use is_descendant() API inside move_to() for clarity.
2009-08-30 15:04:39 -07:00
Andy Staudacher
b5813f92c7
Improve no_tabs test to print out a complete list of files + line numbers + line snippet.
2009-08-30 07:42:37 -07:00
Andy Staudacher
22aa0b3092
Add $theme-> methods to Xss whitelist for HTML safety.
...
Updating XSS golden file.
2009-08-30 07:25:49 -07:00
Andy Staudacher
effccfd41d
Change all instances of SafeString::of_safe_html() to html::mark_safe() in views.
2009-08-30 07:00:56 -07:00
Andy Staudacher
52b542b253
Fixing typo
2009-08-30 06:55:24 -07:00
Andy Staudacher
d3b0302690
Minor cleanup
2009-08-29 23:15:28 -07:00
Andy Staudacher
b9bd1681a3
Update all code to use helper method html::clean(), html::purify(), ... instead of SafeString directly.
2009-08-29 22:54:20 -07:00
Andy Staudacher
952c885609
Adding html::clean(), ::purify(), etc.
2009-08-29 22:31:23 -07:00
Bharat Mediratta
878b9c91b2
Remove try/catch in resize() since that will swallow any exceptions
...
that we generate when resizing.
2009-08-29 16:38:53 -07:00
Andy Staudacher
b4b638be44
Undo url helper changes - url methods no longer return a SafeString.
...
Adding SafeString::of_safe_html() calls where urls are passed as parameters to t() and t2().
2009-08-29 16:28:30 -07:00
jhilden
a1ce2d3f0a
you can close the l10n client directly from its interface now, without going back to the languages admin page
2009-08-29 19:19:04 -04:00
Andy Staudacher
0204617b60
XSS fixes
2009-08-29 15:41:02 -07:00
Tim Almdal
0aceba6f48
Fix for ticket #628 :
...
1) increased gallery module version to 11
2) added image_sharpened parameter to the gallery module
3) sharpen all resizes.
2009-08-29 15:20:27 -07:00
Tim Almdal
a5ddef021c
Fix invalida syntax on trying to parse the progress bar percentage
2009-08-29 15:03:46 -07:00
Andy Staudacher
c4d5ecde66
L10n fixes for the admin_languages page, and JS/XSS cleanup of the organize views.
2009-08-29 14:38:47 -07:00
Andy Staudacher
f327b4ad38
Fix link in l10n UI (for SafeString changes)
2009-08-29 14:24:52 -07:00
Andy Staudacher
a5dfc81a8f
Merge commit 'upstream/master'
...
Conflicts:
modules/akismet/views/admin_akismet.html.php
modules/comment/helpers/comment_rss.php
modules/gallery/helpers/gallery_rss.php
modules/gallery/libraries/I18n.php
modules/gallery/views/permissions_browse.html.php
modules/gallery/views/simple_uploader.html.php
modules/info/views/info_block.html.php
modules/organize/controllers/organize.php
modules/organize/views/organize.html.php
modules/organize/views/organize_album.html.php
themes/default/views/album.html.php
themes/default/views/movie.html.php
themes/default/views/photo.html.php
2009-08-29 14:17:48 -07:00
Andy Staudacher
d5660d2d3e
Fixing all detected XSS vectors in PHP->JS code.
...
Xss: Rename UNKNOWN back to DIRTY, JS_XSS to DIRTY_JS.
(using a different flag value to highlight potential XSS vectors in JS)
2009-08-29 13:41:18 -07:00
Chad Kieffer
a9fcec755a
Merge branch 'master' of git@github.com:gallery/gallery3
2009-08-29 14:02:29 -06:00
Chad Kieffer
5db0b68a70
Update status message styles. Lighten backgrounds, don't show background on Admin Maintenance rows, and added gModuleStatus class.
2009-08-29 14:01:04 -06:00
Andy Staudacher
83344b9e7d
Bugfix: Don't forget to copy the _is_purified_html flag when cloning a SafeString.
2009-08-29 12:50:20 -07:00
Andy Staudacher
c01ac42c46
Refactor all calls of p::clean() to SafeString::of() and p::purify() to SafeString::purify().
...
Removing any p::clean() calls for arguments to t() and t2() since their args are wrapped in a SafeString anyway.
2009-08-29 12:48:40 -07:00
Andy Staudacher
a10063ff68
Add more factory methods for convenience:
...
SafeString::purify() and SafeString::of_safe_html().
Removing SafeString::mark_html_safe() since it's no longer needed.
2009-08-29 12:34:09 -07:00
Bharat Mediratta
6b633e8748
Merge branch 'talmdal_branch' of git@github.com:gallery/gallery3
2009-08-29 12:24:44 -07:00
Bharat Mediratta
0d16cc1c10
Clean up the test and get it working.
2009-08-29 12:12:53 -07:00
Andy Staudacher
7adb9ea2e3
Adding SafeString::for_html_attr()
2009-08-29 11:48:55 -07:00
Tim Almdal
38b2efc44c
Fix for 641... extend viewable functionality to comments. Viewable unit test is not working.
2009-08-29 11:43:10 -07:00
Andy Staudacher
1d633457c4
Have url::site() and other methods return a SafeString, just as t() and t2().
...
Benefits:
- url::site() is often used in views and we can ensure in the url class that returned strings are indeed safe for use in HTML. Makes the list of vars of unknown safety status shorter.
- url::site() is often used as message parameter to t() and t2(). The parameter would be HTML-escaped if it wasn't marked as safe HTML already. Makes the usage simpler / shorter.
2009-08-29 11:31:00 -07:00
jhilden
22c7f44d0b
Merge branch 'master' of git@github.com:gallery/gallery3
2009-08-29 14:29:54 -04:00
jhilden
746609b967
* created new generic "Add" dropdown in the site menu. this should take care of ticket #537
...
* removed start/stop translation menu items from the admin, since they are on the languags admin page now
2009-08-29 14:27:08 -04:00
Tim Almdal
27b81257fa
Standardize the access to the create_random_item method
2009-08-29 11:24:12 -07:00
jhilden
8d256898c7
improved translation interface so that it now can be closed without going to the admin
2009-08-29 14:21:53 -04:00
Bharat Mediratta
1527f149a9
Merge branch 'master' of git@github.com:gallery/gallery3
2009-08-29 10:49:25 -07:00