- Apr 01, 2015
-
-
Christopher Smith authored
-
Christopher Smith authored
-
- Mar 31, 2015
-
-
Romulo Pereira authored
-
- Mar 30, 2015
-
-
Alejandro Nunez authored
-
- Mar 28, 2015
-
-
Jaroslav Lichtblau authored
-
- Mar 27, 2015
-
-
Myeongjin authored
-
- Mar 21, 2015
-
-
chang-zhao authored
When the picker button is near the border of the screen, then an opening panel of picker buttons can go over the screen edge. That's not convenient. So we should add a check in a `function pickerToggle()` and shift picker buttons position if needed.
-
- Mar 18, 2015
-
-
Andreas Gohr authored
The user properties (login, real name, etc) where not properly escaped in the user manager's edit form. This allowed a XSS attack on the superuser by registered users. Thanks to Filippo Cavallarin from www.segment.technology for discovering this bug.
-
- Mar 17, 2015
-
-
Jacob Palm authored
-
Christoph Dwertmann authored
-
- Mar 16, 2015
-
-
Sascha Klopp authored
-
- Mar 13, 2015
-
-
Sascha Klopp authored
-
- Mar 12, 2015
-
-
Michael Große authored
-
Michael Große authored
-
Michael Große authored
-
Michael Große authored
Since we cannot effectively filter for groups and have to work with incremental prefetching, the ``last`` button is mostly broken/buggy. Hence it is disabled in this usecase.
-
Michael Große authored
-
Michael Große authored
-
- Mar 11, 2015
-
-
Michael Große authored
-
- Mar 03, 2015
-
-
Andreas Gohr authored
While Browsers (IE of course) still fail to accept the correct application/javascript mimetype in the type attribute of the script element, we should serve the scripts with the correct Content-Type header at least. This is especially important as the default configuration of mod_deflate expects application/javascript and will not compress text/javascript.
-
Sascha Klopp authored
attribute holding the username, 'modPass' allows to disable password changing by the user.
-
- Feb 25, 2015
-
-
Andreas Gohr authored
-
- Feb 24, 2015
-
-
Schplurtz le Déboulonné authored
-
Andreas Gohr authored
Security Fix Severity: Medium Type: Remote Priviledge Escalation Remote: yes Vulnerability Details: This fixes a security hole in the ACL plugins remote API component. The plugin failed to check for superuser permissions before executing ACL addition or deletion. This means everybody with permissions to call the XMLRPC API also had permissions to set up their own ACL rules and thus circumventing any existing rules. Risk Assessment: The XMLRPC API in DokuWiki is marked experimental and off by default. It also implements an additional safeguard by giving access to a configured circle of users and groups only. So only a minor number of DokuWiki installations will be affected at all. For affected installations the risk is high if users with access to the API are not to be trusted. Thus the overall severity of medium. Resolution: Installations applying this commit are safe. A hotfix is about to be released. Meanwhile users are advised to disable the XMLRPC API in the config manager.
-
Andreas Gohr authored
Since the pageid is no longer positioned absolute it clashed with the sidebar since #1027. this introduces a very simplisitc fix.
-
Andreas Gohr authored
-
Andreas Gohr authored
-
- Feb 17, 2015
-
- Feb 13, 2015
-
-
Álvaro Iradier authored
-
- Feb 12, 2015
- Feb 09, 2015
-
-
Andreas Gohr authored
This moves the message area into content div. The pageid is now aligned by floating instead of absolute positioning.
-
Andreas Gohr authored
-
Andreas Gohr authored
-
- Feb 04, 2015
-
-
Christoph Dwertmann authored
I'm running this dokuwiki docker container: https://registry.hub.docker.com/u/mprasil/dokuwiki/ It uses lighttpd and fastcgi. For some reason, the ignore_user_abort() feature where the browser should close the connection after the GIF has been received is not working on lighty. The browser keeps loading the page until the indexer run is complete, which leads to extremely slow load times with a larger page index. Adding ob_flush() to sendGIF fixes the issue.
-
- Jan 28, 2015
-
-
Davor Turkalj authored
-
- Jan 25, 2015
-
-
Aleksandr Selivanov authored
-
- Jan 15, 2015
-
-
Andreas Gohr authored
-
- Jan 14, 2015
-
-
KeenRivals authored
-
- Jan 12, 2015
-
-
Rainbow Spike authored
1 little fix
-