- Mar 27, 2015
-
-
furun authored
Done: Cleanup of the mail text signature. The signature is deleted from the txt files and moved in to lang.php Mailer.class.php updated to insert the signature Fix: - Cleaner text - no more "-- " "--" "---" "----" problems. - mailwrap.html is not needed anymore an can be deleted (?) Changed files in all languages: lang.php mailtext.txt password.txt registermail.txt subscr_digest.txt subscr_list.txt subscr_single.txt uploadmail.txt pwconfirm.txt showrev.txt delete?: mailwrap.html
-
- Mar 25, 2015
-
-
Andreas Gohr authored
Update toolbar.js
-
- Mar 24, 2015
-
-
Andreas Gohr authored
Translation update (ne)
-
सरोज ढकाल authored
-
- Mar 21, 2015
-
-
chang-zhao authored
When the picker button is near the border of the screen, then an opening panel of picker buttons can go over the screen edge. That's not convenient. So we should add a check in a `function pickerToggle()` and shift picker buttons position if needed.
-
chang-zhao authored
Test
-
- Mar 19, 2015
-
-
Andreas Gohr authored
indexer.php: slow page loads on lighttpd due to missing ob_flush()
-
- Mar 18, 2015
-
-
Andreas Gohr authored
it seems that different zlib versions behave different with corrupted files. Some return false, some return whatever they still can read from the file. the file now should no longer be readable by any version.
-
Andreas Gohr authored
The user properties (login, real name, etc) where not properly escaped in the user manager's edit form. This allowed a XSS attack on the superuser by registered users. Thanks to Filippo Cavallarin from www.segment.technology for discovering this bug.
-
Andreas Gohr authored
This also reverses the order of crypto protocols tried again. Using TLS first again. related to #915
-
Andreas Gohr authored
The code reading .bz2 compressed files did not correctly check for possible read errors. In case of a corrupted file this could have led to an infinite loop. Thanks to Filippo Cavallarin from www.segment.technology for dicovering this bug.
-
Andreas Gohr authored
Translation update (he)
-
itsho authored
-
Andreas Gohr authored
-
- Mar 17, 2015
-
-
Andreas Gohr authored
Translation update (da)
-
Jacob Palm authored
-
Christoph Dwertmann authored
-
- Mar 16, 2015
-
-
Andreas Gohr authored
-
Andreas Gohr authored
Add two config options to authldap
-
Sascha Klopp authored
-
Andreas Gohr authored
Get total number of users in ad, needed for paging
-
- Mar 13, 2015
-
-
Sascha Klopp authored
-
- Mar 12, 2015
-
-
Michael Große authored
-
Michael Große authored
-
Michael Große authored
-
Michael Große authored
Since we cannot effectively filter for groups and have to work with incremental prefetching, the ``last`` button is mostly broken/buggy. Hence it is disabled in this usecase.
-
Michael Große authored
-
Michael Große authored
-
- Mar 11, 2015
-
-
Michael Große authored
-
- Mar 03, 2015
-
-
Andreas Gohr authored
While Browsers (IE of course) still fail to accept the correct application/javascript mimetype in the type attribute of the script element, we should serve the scripts with the correct Content-Type header at least. This is especially important as the default configuration of mod_deflate expects application/javascript and will not compress text/javascript.
-
Sascha Klopp authored
attribute holding the username, 'modPass' allows to disable password changing by the user.
-
- Feb 25, 2015
-
-
Andreas Gohr authored
simple fix for pageID clash with sidebar in mobile view
-
Andreas Gohr authored
-
Andreas Gohr authored
Translation update (fr)
-
- Feb 24, 2015
-
-
Schplurtz le Déboulonné authored
-
Andreas Gohr authored
Security Fix Severity: Medium Type: Remote Priviledge Escalation Remote: yes Vulnerability Details: This fixes a security hole in the ACL plugins remote API component. The plugin failed to check for superuser permissions before executing ACL addition or deletion. This means everybody with permissions to call the XMLRPC API also had permissions to set up their own ACL rules and thus circumventing any existing rules. Risk Assessment: The XMLRPC API in DokuWiki is marked experimental and off by default. It also implements an additional safeguard by giving access to a configured circle of users and groups only. So only a minor number of DokuWiki installations will be affected at all. For affected installations the risk is high if users with access to the API are not to be trusted. Thus the overall severity of medium. Resolution: Installations applying this commit are safe. A hotfix is about to be released. Meanwhile users are advised to disable the XMLRPC API in the config manager.
-
Andreas Gohr authored
Since the pageid is no longer positioned absolute it clashed with the sidebar since #1027. this introduces a very simplisitc fix.
-
Andreas Gohr authored
avoid messages pushing down page tools. fixes #1011
-
Andreas Gohr authored
-
Andreas Gohr authored
-