Commit Graph
59 Commits
Author SHA1 Message Date
Bharat Mediratta dd854379c2 Sanitize all data we return via json_encode() to guard against XSS and
other data leaks.
2009-06-03 17:08:23 -07:00
jhilden dde5fb96ee made "Add photos" its own site menu item
* open for suggestions on the submenu item labels
* @bharat: not sure about the add photos menu item id in the dropdown case
2009-06-02 19:31:11 -04:00
Bharat Mediratta 01c5774794 Merge branch 'master' of git@github.com:gallery/gallery3 2009-06-02 15:47:04 -07:00
Bharat Mediratta e834c4ca24 Have server_add turn the "Add Photo" menu option into a dropdown and
make "Add from Server" a 2nd option there.

This requires adding the Menu::remove() API function.
2009-06-02 15:46:05 -07:00
Tim Almdal dbeceb333b Improve test isolation so that Albums_Controller_Test doesn't fail when run with Photos_Controller_Test 2009-06-02 14:19:03 -07:00
Bharat Mediratta ffb3abdcac Restore "view" permissions on the root album in teardown. 2009-06-02 13:37:19 -07:00
Tim Almdal 4f50357a38 fix the xss_security_test in regards to the renaming of thumb_tag, resize_tag and move_tag. 2009-06-02 12:56:36 -07:00
Tim Almdal d8eca7682d make cleanm static 2009-06-02 12:41:59 -07:00
Tim Almdal 0f987880e6 Fix for ticket #320 2009-06-02 12:08:47 -07:00
Andy Staudacher 1cfed1fac1 Extend L10n client to provide UI for plural translation.
Ticket 148.
2009-06-02 00:43:04 -07:00
Bharat Mediratta 3b6567f38c Unescape %20 into " " also. 2009-06-01 23:20:36 -07:00
Bharat Mediratta 43abcd9386 Security pass over all controller code. Mostly adding CSRF checking
and verifying user permissions, but there are several above-the-bar
changes:

1) Server add is now only available to admins.  This is a hard
   requirement because we have to limit server access (eg:
   server_add::children) to a user subset and the current permission
   model doesn't include that.  Easiest fix is to restrict to admins.
   Got rid of the server_add permission.

2) We now know check permissions at every level, which means in
   controllers AND in helpers.  This "belt and suspenders" approach will
   give us defense in depth in case we overlook it in one area.

3) We now do CSRF checking in every controller method that changes the
   code, in addition to the Forge auto-check.  Again, defense in depth
   and it makes scanning the code for security much simpler.

4) Moved Simple_Uploader_Controller::convert_filename_to_title to
   item:convert_filename_to_title

5) Fixed a bug in sending notification emails.

6) Fixed the Organize code to verify that you only have access to your
   own tasks.  In general, added permission checks to organize which had
   pretty much no validation code.

I did my best to verify every feature that I touched.
2009-06-01 22:40:22 -07:00
Bharat Mediratta 1145b846ba Fix a place where I shouldn't have renamed "core" to "gallery", breaking maintenance mode. 2009-06-01 21:07:24 -07:00
Bharat Mediratta c94c11eb3e Normalize the random values used in the blocks_dashboard_xxx vars so
that install.sql is more stable.
2009-06-01 00:22:30 -07:00
Bharat Mediratta e4f4c8b2e8 Do a little cleanup and get rid of code left-over from when this
controller rendered HTML.  Also, catch all exceptions at the root
level and restore the change in
84ce0cdefd which appears to have gotten
lost in the shuffle.
2009-06-01 00:11:09 -07:00
Tim Almdal 3c24d94766 Merge branch 'master' of git@github.com:gallery/gallery3 2009-05-31 23:28:42 -07:00
Tim Almdal 463b3454ae Move the sql packaging code from installer into the gallery module. It must be run from the command line and will throw a 404 if it is run as a web request. 2009-05-31 23:28:27 -07:00
Bharat Mediratta 9a7e642cd6 Don't let relative_path() try to update the database if the Item_Model
is not loaded, else you get weird errors.
2009-05-31 22:30:48 -07:00
Bharat Mediratta 33df7de391 Accidentally broke the AllowOverride info url in the migration from
core -> modules/gallery.  Fixed, and incidentally make the link appear
in a new tab/window.
2009-05-31 22:25:53 -07:00
Bharat Mediratta 54ae9fac88 Remove extra blank line 2009-05-31 22:12:14 -07:00
bharat 297fb737ac Convert %7E to ~ when proxying files to work around Firefox's overzealous security model. 2009-06-01 01:07:05 -04:00
Bharat Mediratta 0ec3f1b830 Update for changes to admin_users_group.html.php 2009-05-31 19:32:13 -07:00
Bharat Mediratta 181c97ef4b Relax the regex we use to extract the movie size so that it works with
the new version of ffmpeg that I have on my dev box (ffmpeg
0.5-svn17737+3:0.svn20090303-1)
2009-05-31 12:53:03 -07:00
Bharat Mediratta f9a741782d Switch to using html::specialchars() for cleaning. 2009-05-31 12:33:10 -07:00
Bharat Mediratta 897ca2806d Updated for renamed variable 2009-05-31 01:22:48 -07:00
Bharat Mediratta e30b45be07 Merge branch 'master' of git://github.com/gallery/gallery3 2009-05-31 01:15:11 -07:00
Bharat Mediratta af0031e029 Xss scanner golden file. Up to date. 2009-05-31 01:10:52 -07:00
Tim Almdal 0a5ca7a766 Merge branch 'master' of git@github.com:gallery/gallery3 2009-05-31 00:28:51 -07:00
Bharat Mediratta a049de28ac Update the clean/dirty format, check all ffiles instead of just one (which was for debugging) 2009-05-31 00:13:28 -07:00
Bharat Mediratta 708f27f483 Run p::clean() on any variables that contain data entered by users. 2009-05-31 00:11:48 -07:00
Bharat Mediratta ad81861c33 First pass at an XSS security test, along with the "p" helper which
can clean HTML output.
2009-05-31 00:11:02 -07:00
Tim Almdal 45d58c8680 Remove the test images from the gallery module and move it to the developer module in -contrib 2009-05-31 00:10:04 -07:00
Chad Kieffer 8482f51e15 Add transparency for overlay in IE 7 and 8 2009-05-30 23:01:48 -06:00
Bharat Mediratta a5670d8d70 gate $can_edit and $can_add on whether or not we have an $item at all
(fixes a bug where search doesn't render because it has no item).
2009-05-30 17:14:17 -07:00
Chad Kieffer ef14f0faf5 White space fixes 2009-05-30 15:25:24 -06:00
tim almdal f0104ee43b remove scaffolding code 2009-05-29 21:53:49 -07:00
Bharat Mediratta ce285b8feb Use the relative_path_cache to look up items which should be a faster
query than using the level + the components.
2009-05-29 21:23:08 -07:00
Bharat Mediratta cbec883d8a Don't show "edit permissions" for non-albums. 2009-05-29 20:59:34 -07:00
Bharat Mediratta 60d1bbc2d6 Move credits message into a variable, which can be changed in Admin >
Settings > Advanced.  It's stored in the variable as an
internationalized string and localized at output time.
2009-05-29 20:24:42 -07:00
Bharat Mediratta 2925a1c797 Require "add" permission to show the add form. 2009-05-29 17:54:20 -07:00
Bharat Mediratta 381dd0574a Don't show the add photo/album options to users who don't have the
permission.  This isn't a security hole, since they can't actually add
stuff.. but they can try and fail which is a bad user experience.

Also fix it up so that we show the option menu only if there's stuff
to show, and cache some of the permissions for performance (which I'm
guessing at-- didn't benchmark it).
2009-05-29 17:53:33 -07:00
Bharat Mediratta 055e0a7dc5 Remove a completed @todo 2009-05-29 17:42:31 -07:00
Bharat Mediratta 34da188e81 Revert test code inserted in 88a3d43ba9
which showed stack traces to non-admins.
2009-05-29 17:40:23 -07:00
Bharat Mediratta 356bac0db0 Restore calls to module::load_modules() after install/activate/deactivate/uninstall events. 2009-05-28 21:18:46 -07:00
Bharat Mediratta d088a41747 Load the gallery module in load_modules(), but put it at the end of
the module list (to match its location in the cascading filesystem)
2009-05-28 21:00:06 -07:00
Bharat Mediratta 7fd6fcaf9b Force modules/gallery to be at the end of the module load path, so
that all other modules can override the core code.
2009-05-28 17:46:17 -07:00
Bharat Mediratta 1a095fffe5 Prepend all code files we copy from Gallery2 and put into var with our
code preamble for security.

Update File_Structure_Test::code_files_start_with_preamble_test to
check all the php files in var, too.
2009-05-28 02:19:53 -07:00
Bharat Mediratta c8aa9ed440 Update tests to reflect cache-buster param on thumbnail urls. 2009-05-28 01:58:41 -07:00
Bharat Mediratta 534b8525ce Rename Core_Installer_Test -> Gallery_Installer_Test to match the
change from application -> modules/gallery.
2009-05-28 01:55:42 -07:00
Bharat Mediratta 8d2782ad1d Flush the model cache as appropriate every time we call ORM::save().
Fixes ticket #301
2009-05-28 00:45:00 -07:00