Commit Graph

140 Commits

Author SHA1 Message Date
steinm
cad78d5304 - new files to manage and use attributes 2012-10-09 09:44:58 +00:00
steinm
c15d62fe73 - check for settings also 2012-10-08 09:47:25 +00:00
steinm
bd09ba32eb - out.RemoveVersion.php is also visible if access right is M_READWRITE 2012-10-08 09:46:30 +00:00
steinm
fc96b169b3 - check for missing document content 2012-10-05 19:59:22 +00:00
steinm
7f93fe51d5 - added some explaination where things are search for 2012-10-05 19:58:33 +00:00
steinm
216b15d26a - use new api of indexer 2012-10-05 19:57:36 +00:00
steinm
35db7831fc - fixed password text 2012-10-05 19:57:10 +00:00
steinm
e217b456fb - some more xss prevention 2012-10-05 19:56:37 +00:00
steinm
b882d38dfb - ask current password 2012-10-05 19:56:18 +00:00
steinm
781f494005 - new config options 2012-10-05 19:54:16 +00:00
steinm
4a17ff44e1 - better check for reasonable operations 2012-10-05 19:53:58 +00:00
steinm
c0b77febf9 - omit duplicate entries in document lists 2012-10-05 19:51:57 +00:00
steinm
c3de676329 - output list of documents 2012-10-05 19:50:47 +00:00
steinm
145bdb7768 -check if version maybe deleted 2012-10-05 19:50:21 +00:00
steinm
1b5017cf38 - fixed filtering by stopwords 2012-09-13 13:58:12 +00:00
steinm
4a67f259bf - added form key 2012-09-11 13:15:59 +00:00
steinm
81c0bd8a7e - output name and login of user in lists 2012-09-11 13:00:43 +00:00
steinm
9412479354 - output name and login in all user lists 2012-09-11 12:57:13 +00:00
steinm
14755b838a - prevent xss attack
- no need to decodeString() in javascript anymore
2012-09-11 12:55:29 +00:00
steinm
52fbc5bc29 - fixed more xss security holes 2012-09-11 12:51:46 +00:00
steinm
5e11a14c42 - fixed possible xss security holes 2012-09-05 21:00:14 +00:00
steinm
f14c15ee50 - fixed security hole 2012-08-31 07:44:25 +00:00
steinm
452221fe2b - lots of fixes to prevent CSRF attacks 2012-08-29 20:37:22 +00:00
steinm
ce2843ef6e - handle new settings for password strength, expiration
- prevent some XSS attacs
2012-08-28 07:24:32 +00:00
steinm
7d4c363e5a - output password expiration 2012-08-28 07:22:25 +00:00
steinm
a9d8f415ae - prevent XSS attac 2012-08-28 07:21:56 +00:00
steinm
f4489d6a73 - some minor code formating
- added copyright notice
2012-08-28 07:21:15 +00:00
steinm
a3a42bb451 - some initial coding for auto completion 2012-08-28 07:20:41 +00:00
steinm
75c2adcfc6 - prevent XSS attacs 2012-08-28 07:18:00 +00:00
steinm
4bb7c9307f - check password strength
- allow password change only if current password is entered
2012-08-28 07:09:23 +00:00
steinm
a68a78ceab - check for password strength
- ask for current password before setting a new one
2012-08-28 07:00:19 +00:00
steinm
1b29ae6bd8 - Script for which is called when the login process detects a to old password 2012-08-28 06:37:58 +00:00
steinm
36dc571aa5 - added more configuration settings for password handling, stopwords file
and user listing
2012-08-28 06:34:21 +00:00
steinm
020165de17 - do not list groups/users for which an entry in the acl already exists 2012-05-08 08:10:08 +00:00
steinm
1e06a235da - output file converters for creation of index 2012-02-14 12:54:22 +00:00
steinm
8c6b19f38a - changed line endings from dos to unix 2012-02-13 08:29:10 +00:00
steinm
229b79edad - changed line endings from dos to unix 2012-02-13 08:28:34 +00:00
steinm
5a39bffd73 - replace more <?= by <?php 2012-02-07 10:31:31 +00:00
steinm
f3b2cbe950 - run mimetype through htmlspecialchars() 2012-01-12 17:00:31 +00:00
steinm
8e87e1cd97 - run mimetype through htmlspecialchars() 2012-01-12 16:59:35 +00:00
steinm
95c0a4deee - call htmlspecialchars() on comment 2011-12-06 12:30:18 +00:00
steinm
a731ac5ea0 - call htmlspecialchars() on email 2011-12-06 12:29:39 +00:00
steinm
4e8ba69ba8 - replace html in email address 2011-12-06 12:29:09 +00:00
steinm
2538851beb - do not decode string anymore 2011-12-05 16:45:05 +00:00
steinm
d2a4147de3 - just replace ' by \' in javascript code, do not use htmlspecialchars() 2011-12-05 16:44:09 +00:00
steinm
7c5805badb - call htmlspeciachars() before output of comment 2011-12-05 13:21:09 +00:00
steinm
73f4c8d90d - use htmlspecialchars() whenever data from the database is output
(this does currently break the output, because data was already
	encoded when saved)
2011-12-02 16:23:36 +00:00
steinm
b4d4317e89 - set unix line endings 2011-12-02 08:03:01 +00:00
steinm
9fdcd9ab1f - get rid of function sanitizeString() 2011-12-01 14:11:07 +00:00
steinm
f51a97b4b2 - run repair function for documents
- nicer output
2011-11-29 09:02:55 +00:00