Bharat Mediratta
dd854379c2
Sanitize all data we return via json_encode() to guard against XSS and
...
other data leaks.
2009-06-03 17:08:23 -07:00
jhilden
dde5fb96ee
made "Add photos" its own site menu item
...
* open for suggestions on the submenu item labels
* @bharat: not sure about the add photos menu item id in the dropdown case
2009-06-02 19:31:11 -04:00
Bharat Mediratta
01c5774794
Merge branch 'master' of git@github.com:gallery/gallery3
2009-06-02 15:47:04 -07:00
Bharat Mediratta
e834c4ca24
Have server_add turn the "Add Photo" menu option into a dropdown and
...
make "Add from Server" a 2nd option there.
This requires adding the Menu::remove() API function.
2009-06-02 15:46:05 -07:00
Tim Almdal
dbeceb333b
Improve test isolation so that Albums_Controller_Test doesn't fail when run with Photos_Controller_Test
2009-06-02 14:19:03 -07:00
Bharat Mediratta
ffb3abdcac
Restore "view" permissions on the root album in teardown.
2009-06-02 13:37:19 -07:00
Tim Almdal
4f50357a38
fix the xss_security_test in regards to the renaming of thumb_tag, resize_tag and move_tag.
2009-06-02 12:56:36 -07:00
Tim Almdal
d8eca7682d
make cleanm static
2009-06-02 12:41:59 -07:00
Tim Almdal
0f987880e6
Fix for ticket #320
2009-06-02 12:08:47 -07:00
Andy Staudacher
1cfed1fac1
Extend L10n client to provide UI for plural translation.
...
Ticket 148.
2009-06-02 00:43:04 -07:00
Bharat Mediratta
3b6567f38c
Unescape %20 into " " also.
2009-06-01 23:20:36 -07:00
Bharat Mediratta
43abcd9386
Security pass over all controller code. Mostly adding CSRF checking
...
and verifying user permissions, but there are several above-the-bar
changes:
1) Server add is now only available to admins. This is a hard
requirement because we have to limit server access (eg:
server_add::children) to a user subset and the current permission
model doesn't include that. Easiest fix is to restrict to admins.
Got rid of the server_add permission.
2) We now know check permissions at every level, which means in
controllers AND in helpers. This "belt and suspenders" approach will
give us defense in depth in case we overlook it in one area.
3) We now do CSRF checking in every controller method that changes the
code, in addition to the Forge auto-check. Again, defense in depth
and it makes scanning the code for security much simpler.
4) Moved Simple_Uploader_Controller::convert_filename_to_title to
item:convert_filename_to_title
5) Fixed a bug in sending notification emails.
6) Fixed the Organize code to verify that you only have access to your
own tasks. In general, added permission checks to organize which had
pretty much no validation code.
I did my best to verify every feature that I touched.
2009-06-01 22:40:22 -07:00
Bharat Mediratta
1145b846ba
Fix a place where I shouldn't have renamed "core" to "gallery", breaking maintenance mode.
2009-06-01 21:07:24 -07:00
Bharat Mediratta
c94c11eb3e
Normalize the random values used in the blocks_dashboard_xxx vars so
...
that install.sql is more stable.
2009-06-01 00:22:30 -07:00
Bharat Mediratta
e4f4c8b2e8
Do a little cleanup and get rid of code left-over from when this
...
controller rendered HTML. Also, catch all exceptions at the root
level and restore the change in
84ce0cdefd which appears to have gotten
lost in the shuffle.
2009-06-01 00:11:09 -07:00
Tim Almdal
3c24d94766
Merge branch 'master' of git@github.com:gallery/gallery3
2009-05-31 23:28:42 -07:00
Tim Almdal
463b3454ae
Move the sql packaging code from installer into the gallery module. It must be run from the command line and will throw a 404 if it is run as a web request.
2009-05-31 23:28:27 -07:00
Bharat Mediratta
9a7e642cd6
Don't let relative_path() try to update the database if the Item_Model
...
is not loaded, else you get weird errors.
2009-05-31 22:30:48 -07:00
Bharat Mediratta
33df7de391
Accidentally broke the AllowOverride info url in the migration from
...
core -> modules/gallery. Fixed, and incidentally make the link appear
in a new tab/window.
2009-05-31 22:25:53 -07:00
Bharat Mediratta
54ae9fac88
Remove extra blank line
2009-05-31 22:12:14 -07:00
bharat
297fb737ac
Convert %7E to ~ when proxying files to work around Firefox's overzealous security model.
2009-06-01 01:07:05 -04:00
Bharat Mediratta
0ec3f1b830
Update for changes to admin_users_group.html.php
2009-05-31 19:32:13 -07:00
Bharat Mediratta
181c97ef4b
Relax the regex we use to extract the movie size so that it works with
...
the new version of ffmpeg that I have on my dev box (ffmpeg
0.5-svn17737+3:0.svn20090303-1)
2009-05-31 12:53:03 -07:00
Bharat Mediratta
f9a741782d
Switch to using html::specialchars() for cleaning.
2009-05-31 12:33:10 -07:00
Bharat Mediratta
897ca2806d
Updated for renamed variable
2009-05-31 01:22:48 -07:00
Bharat Mediratta
e30b45be07
Merge branch 'master' of git://github.com/gallery/gallery3
2009-05-31 01:15:11 -07:00
Bharat Mediratta
af0031e029
Xss scanner golden file. Up to date.
2009-05-31 01:10:52 -07:00
Tim Almdal
0a5ca7a766
Merge branch 'master' of git@github.com:gallery/gallery3
2009-05-31 00:28:51 -07:00
Bharat Mediratta
a049de28ac
Update the clean/dirty format, check all ffiles instead of just one (which was for debugging)
2009-05-31 00:13:28 -07:00
Bharat Mediratta
708f27f483
Run p::clean() on any variables that contain data entered by users.
2009-05-31 00:11:48 -07:00
Bharat Mediratta
ad81861c33
First pass at an XSS security test, along with the "p" helper which
...
can clean HTML output.
2009-05-31 00:11:02 -07:00
Tim Almdal
45d58c8680
Remove the test images from the gallery module and move it to the developer module in -contrib
2009-05-31 00:10:04 -07:00
Chad Kieffer
8482f51e15
Add transparency for overlay in IE 7 and 8
2009-05-30 23:01:48 -06:00
Bharat Mediratta
a5670d8d70
gate $can_edit and $can_add on whether or not we have an $item at all
...
(fixes a bug where search doesn't render because it has no item).
2009-05-30 17:14:17 -07:00
Chad Kieffer
ef14f0faf5
White space fixes
2009-05-30 15:25:24 -06:00
tim almdal
f0104ee43b
remove scaffolding code
2009-05-29 21:53:49 -07:00
Bharat Mediratta
ce285b8feb
Use the relative_path_cache to look up items which should be a faster
...
query than using the level + the components.
2009-05-29 21:23:08 -07:00
Bharat Mediratta
cbec883d8a
Don't show "edit permissions" for non-albums.
2009-05-29 20:59:34 -07:00
Bharat Mediratta
60d1bbc2d6
Move credits message into a variable, which can be changed in Admin >
...
Settings > Advanced. It's stored in the variable as an
internationalized string and localized at output time.
2009-05-29 20:24:42 -07:00
Bharat Mediratta
2925a1c797
Require "add" permission to show the add form.
2009-05-29 17:54:20 -07:00
Bharat Mediratta
381dd0574a
Don't show the add photo/album options to users who don't have the
...
permission. This isn't a security hole, since they can't actually add
stuff.. but they can try and fail which is a bad user experience.
Also fix it up so that we show the option menu only if there's stuff
to show, and cache some of the permissions for performance (which I'm
guessing at-- didn't benchmark it).
2009-05-29 17:53:33 -07:00
Bharat Mediratta
055e0a7dc5
Remove a completed @todo
2009-05-29 17:42:31 -07:00
Bharat Mediratta
34da188e81
Revert test code inserted in 88a3d43ba9
...
which showed stack traces to non-admins.
2009-05-29 17:40:23 -07:00
Bharat Mediratta
356bac0db0
Restore calls to module::load_modules() after install/activate/deactivate/uninstall events.
2009-05-28 21:18:46 -07:00
Bharat Mediratta
d088a41747
Load the gallery module in load_modules(), but put it at the end of
...
the module list (to match its location in the cascading filesystem)
2009-05-28 21:00:06 -07:00
Bharat Mediratta
7fd6fcaf9b
Force modules/gallery to be at the end of the module load path, so
...
that all other modules can override the core code.
2009-05-28 17:46:17 -07:00
Bharat Mediratta
1a095fffe5
Prepend all code files we copy from Gallery2 and put into var with our
...
code preamble for security.
Update File_Structure_Test::code_files_start_with_preamble_test to
check all the php files in var, too.
2009-05-28 02:19:53 -07:00
Bharat Mediratta
c8aa9ed440
Update tests to reflect cache-buster param on thumbnail urls.
2009-05-28 01:58:41 -07:00
Bharat Mediratta
534b8525ce
Rename Core_Installer_Test -> Gallery_Installer_Test to match the
...
change from application -> modules/gallery.
2009-05-28 01:55:42 -07:00
Bharat Mediratta
8d2782ad1d
Flush the model cache as appropriate every time we call ORM::save().
...
Fixes ticket #301
2009-05-28 00:45:00 -07:00