• last updated 4 hours ago
Constraints
Constraints: committers
 
Constraints: files
Constraints: dates
bootstrap installer:

- added csp policy to the files upgradeable via apm

- bumped version number to 5.9.1d5

    • -1
    • +1
    /openacs-4/www/SYSTEM/csp-collector.tcl
file csp-collector.tcl was initially added on branch oacs-5-9.

Removed dangerous catch idiom

Removed leftover count_query argument from template::paginator::create

- set link variables always.

- adjust topline for wiki menu

- remove remaining onclick handlers in templates

- add font-src directive for bootstrap

- do not prevent default behavior

- reduce verbosity

- change onclick handler into event listener

- template::head::add_style: don't add identical entries multiple times

- make sure to load bootstrap after jquery

- fix js function name

- save dirty buffer

- replace on-click handler by event listener

- add CSP directives

- use subst instead of doublequotes

- replace "javascript:*" urls with event listeners

remove javascript urls and onclick handlers from xowiki menubar (yui and bootstrap)

- add nonce attribute to javascript created via tdom

- add HTML IDs to menu items

- add ability to add listener (list with 2 elements: type (such as

"click") and script (body of a function to be executed).

    • -1
    • +1
    /openacs-4/packages/xowiki/tcl/folder-procs.tcl
    • -11
    • +48
    /openacs-4/packages/xowiki/tcl/yui-procs.tcl
- replace onclick handle by event listener

- remove onlick handler be event listener

- avoid event bubbling for click listener

- add nonce to inline javascript

- use "-force" flag for CSP "script-src 'unsafe-inline'" for ckeditor4

- update version dependency to acs-tcl

- bump version number to 0.7

- use "-force" flag for CSP "script-src 'unsafe-inline'" for ckeditor4

- update version dependency to acs-tcl

- bump version number to 5.9.1d13

    • -3
    • +3
    /openacs-4/packages/xowiki/xowiki.info
- adding "-force" parameter to security::csp::require

- bump version number to 5.9.1d12

    • -2
    • +2
    /openacs-4/packages/acs-tcl/acs-tcl.info
- add conditional name normalization to simple_item_ref

    • -1
    • +4
    /openacs-4/packages/xowiki/tcl/package-procs.tcl
- use "www-" prefix

-- handle ie 11 (uses a different header field for CSP)

- move CSP generation to the end

- update security settings

- use maxcdn rather than netdna CDN

    • -2
    • +2
    /openacs-4/packages/dotlrn/install.xml