• last updated 9 hours ago
Constraints
Constraints: committers
 
Constraints: files
Constraints: dates
file edit.adp was initially added on branch oacs-5-9.

    • -0
    • +0
    /openacs-4/packages/xowiki/resources/templates/edit.adp
file view-book-no-ajax.tcl was initially added on branch oacs-5-9.

file view-book-no-ajax.adp was initially added on branch oacs-5-9.

file revisions.adp was initially added on branch oacs-5-9.

file oacs-view3.adp was initially added on branch oacs-5-9.

file oacs-view3-bootstrap.adp was initially added on branch oacs-5-9.

file oacs-view2.adp was initially added on branch oacs-5-9.

file oacs-view.adp was initially added on branch oacs-5-9.

file error-template.adp was initially added on branch oacs-5-9.

file view-plain.adp was initially added on branch oacs-5-9.

file view-page.tcl was initially added on branch oacs-5-9.

file view-page.adp was initially added on branch oacs-5-9.

file view-modal-content.adp was initially added on branch oacs-5-9.

file view-mobile.adp was initially added on branch oacs-5-9.

    • -0
    • +0
    /openacs-4/packages/xowiki/resources/templates/view-mobile.adp
file view-links.adp was initially added on branch oacs-5-9.

file view-default.adp was initially added on branch oacs-5-9.

    • -0
    • +0
    /openacs-4/packages/xowiki/resources/templates/view-default.adp
file view-book.tcl was initially added on branch oacs-5-9.

- fix stupid cut&paste bug

- simplify script

- improve error handling of closed connections

- add csrf protection (bulk-delete, save operations in FormPages)

- add input checking for optional query-parameter "master"

- bump version number to 5.9.1d8

    • -3
    • +3
    /openacs-4/packages/xowiki/xowiki.info
    • -1
    • +1
    /openacs-4/packages/xowiki/tcl/folder-procs.tcl
- added tdom command "::html::CSRFToken" similar to html::div etc. for easy generation of csrf token in tdom contexts

- output more detail for errors

- only subst value, when it was provided explicitely in the "- -export" list. (see also change in www/register/user-new.tcl in http://cvs.openacs.org/changelog/OpenACS?cs=oacs-5-9%3Agustafn%3A20160525130725)

- protect against certain characters in return_url (the real solution is probably a fix in ad_form, which could cause some collateral damage)

- protect against manipulated hidden input fields

- hardening page contracts (invalid values for color_filter_value could cause postgres errors; example color_filter_value=1%00%c0%a7%c0%a2%252527%252522)

- improve page contracts on demo pages

- add errorCode to reported context information

- protect against too large bug numbers (causes pg errors)

- don't access @patch.patch_id@ for displayed_object_id, if it does

not exist (view mode)

- don't perform message key subsitution in user contributed bug description

- add csrf protection for search