Skip to content
Snippets Groups Projects
  1. Mar 17, 2015
  2. Mar 16, 2015
  3. Mar 13, 2015
  4. Mar 12, 2015
  5. Mar 11, 2015
  6. Mar 03, 2015
    • Andreas Gohr's avatar
      send JavaScript with correct mimetype · 138a9500
      Andreas Gohr authored
      While Browsers (IE of course) still fail to accept the correct
      application/javascript mimetype in the type attribute of the script
      element, we should serve the scripts with the correct Content-Type
      header at least. This is especially important as the default
      configuration of mod_deflate expects application/javascript and will not
      compress text/javascript.
      138a9500
    • Sascha Klopp's avatar
      Two new authldap config options: 'userkey' denotes the LDAP · 6619ddf4
      Sascha Klopp authored
      attribute holding the username, 'modPass' allows to disable
      password changing by the user.
      6619ddf4
  7. Feb 25, 2015
  8. Feb 24, 2015
    • Schplurtz le Déboulonné's avatar
      translation update · 6401de3d
      Schplurtz le Déboulonné authored
      6401de3d
    • Andreas Gohr's avatar
      check permissions in ACL plugin's RPC API component. #1056 · 9cbf80e6
      Andreas Gohr authored
      Security Fix
      
      Severity: Medium
      Type:     Remote Priviledge Escalation
      Remote:   yes
      
      Vulnerability Details:
      
      This fixes a security hole in the ACL plugins remote API component. The
      plugin failed to check for superuser permissions before executing ACL
      addition or deletion. This means everybody with permissions to call the
      XMLRPC API also had permissions to set up their own ACL rules and thus
      circumventing any existing rules.
      
      Risk Assessment:
      
      The XMLRPC API in DokuWiki is marked experimental and off by default. It
      also implements an additional safeguard by giving access to a configured
      circle of users and groups only. So only a minor number of DokuWiki
      installations will be affected at all.
      For affected installations the risk is high if users with access to the
      API are not to be trusted.
      Thus the overall severity of medium.
      
      Resolution:
      
      Installations applying this commit are safe. A hotfix is about to be
      released. Meanwhile users are advised to disable the XMLRPC API in the
      config manager.
      9cbf80e6
    • Andreas Gohr's avatar
      simple fix for pageID clash with sidebar in mobile view · 757f6dda
      Andreas Gohr authored
      Since the pageid is no longer positioned absolute it clashed with the
      sidebar since #1027. this introduces a very simplisitc fix.
      757f6dda
    • Andreas Gohr's avatar
      Merge pull request #1027 from splitbrain/issue-1011 · 809448f5
      Andreas Gohr authored
      avoid messages pushing down page tools. fixes #1011
      809448f5
    • Andreas Gohr's avatar
      fixed the margin for the sidebar · 30c46635
      Andreas Gohr authored
      30c46635
    • Andreas Gohr's avatar
      15a61525
  9. Feb 23, 2015
  10. Feb 19, 2015
  11. Feb 18, 2015
  12. Feb 17, 2015
  13. Feb 16, 2015
  14. Feb 13, 2015
Loading