Commit Graph

689 Commits

Author SHA1 Message Date
steinm
c15d62fe73 - check for settings also 2012-10-08 09:47:25 +00:00
steinm
bd09ba32eb - out.RemoveVersion.php is also visible if access right is M_READWRITE 2012-10-08 09:46:30 +00:00
steinm
fc96b169b3 - check for missing document content 2012-10-05 19:59:22 +00:00
steinm
7f93fe51d5 - added some explaination where things are search for 2012-10-05 19:58:33 +00:00
steinm
216b15d26a - use new api of indexer 2012-10-05 19:57:36 +00:00
steinm
35db7831fc - fixed password text 2012-10-05 19:57:10 +00:00
steinm
e217b456fb - some more xss prevention 2012-10-05 19:56:37 +00:00
steinm
b882d38dfb - ask current password 2012-10-05 19:56:18 +00:00
steinm
781f494005 - new config options 2012-10-05 19:54:16 +00:00
steinm
4a17ff44e1 - better check for reasonable operations 2012-10-05 19:53:58 +00:00
steinm
c0b77febf9 - omit duplicate entries in document lists 2012-10-05 19:51:57 +00:00
steinm
c3de676329 - output list of documents 2012-10-05 19:50:47 +00:00
steinm
145bdb7768 -check if version maybe deleted 2012-10-05 19:50:21 +00:00
steinm
1b5017cf38 - fixed filtering by stopwords 2012-09-13 13:58:12 +00:00
steinm
4a67f259bf - added form key 2012-09-11 13:15:59 +00:00
steinm
81c0bd8a7e - output name and login of user in lists 2012-09-11 13:00:43 +00:00
steinm
9412479354 - output name and login in all user lists 2012-09-11 12:57:13 +00:00
steinm
14755b838a - prevent xss attack
- no need to decodeString() in javascript anymore
2012-09-11 12:55:29 +00:00
steinm
52fbc5bc29 - fixed more xss security holes 2012-09-11 12:51:46 +00:00
steinm
5e11a14c42 - fixed possible xss security holes 2012-09-05 21:00:14 +00:00
steinm
f14c15ee50 - fixed security hole 2012-08-31 07:44:25 +00:00
steinm
452221fe2b - lots of fixes to prevent CSRF attacks 2012-08-29 20:37:22 +00:00
steinm
ce2843ef6e - handle new settings for password strength, expiration
- prevent some XSS attacs
2012-08-28 07:24:32 +00:00
steinm
7d4c363e5a - output password expiration 2012-08-28 07:22:25 +00:00
steinm
a9d8f415ae - prevent XSS attac 2012-08-28 07:21:56 +00:00
steinm
f4489d6a73 - some minor code formating
- added copyright notice
2012-08-28 07:21:15 +00:00
steinm
a3a42bb451 - some initial coding for auto completion 2012-08-28 07:20:41 +00:00
steinm
75c2adcfc6 - prevent XSS attacs 2012-08-28 07:18:00 +00:00
steinm
4bb7c9307f - check password strength
- allow password change only if current password is entered
2012-08-28 07:09:23 +00:00
steinm
a68a78ceab - check for password strength
- ask for current password before setting a new one
2012-08-28 07:00:19 +00:00
steinm
1b29ae6bd8 - Script for which is called when the login process detects a to old password 2012-08-28 06:37:58 +00:00
steinm
36dc571aa5 - added more configuration settings for password handling, stopwords file
and user listing
2012-08-28 06:34:21 +00:00
steinm
020165de17 - do not list groups/users for which an entry in the acl already exists 2012-05-08 08:10:08 +00:00
steinm
1e06a235da - output file converters for creation of index 2012-02-14 12:54:22 +00:00
steinm
8c6b19f38a - changed line endings from dos to unix 2012-02-13 08:29:10 +00:00
steinm
229b79edad - changed line endings from dos to unix 2012-02-13 08:28:34 +00:00
steinm
5a39bffd73 - replace more <?= by <?php 2012-02-07 10:31:31 +00:00
steinm
f3b2cbe950 - run mimetype through htmlspecialchars() 2012-01-12 17:00:31 +00:00
steinm
8e87e1cd97 - run mimetype through htmlspecialchars() 2012-01-12 16:59:35 +00:00
steinm
95c0a4deee - call htmlspecialchars() on comment 2011-12-06 12:30:18 +00:00
steinm
a731ac5ea0 - call htmlspecialchars() on email 2011-12-06 12:29:39 +00:00
steinm
4e8ba69ba8 - replace html in email address 2011-12-06 12:29:09 +00:00
steinm
2538851beb - do not decode string anymore 2011-12-05 16:45:05 +00:00
steinm
d2a4147de3 - just replace ' by \' in javascript code, do not use htmlspecialchars() 2011-12-05 16:44:09 +00:00
steinm
7c5805badb - call htmlspeciachars() before output of comment 2011-12-05 13:21:09 +00:00
steinm
73f4c8d90d - use htmlspecialchars() whenever data from the database is output
(this does currently break the output, because data was already
	encoded when saved)
2011-12-02 16:23:36 +00:00
steinm
b4d4317e89 - set unix line endings 2011-12-02 08:03:01 +00:00
steinm
9fdcd9ab1f - get rid of function sanitizeString() 2011-12-01 14:11:07 +00:00
steinm
f51a97b4b2 - run repair function for documents
- nicer output
2011-11-29 09:02:55 +00:00
steinm
3e3754c8e7 - added initial version of document/folder check 2011-11-29 07:23:20 +00:00
steinm
df5d8e3fbd - use two columns instead of 1 with colspan=2 2011-10-27 09:34:30 +00:00
steinm
c594cb334a - do not output user/group if access rights are not sufficient to add
a notification
2011-10-27 07:58:37 +00:00
steinm
77ff174228 - allow to set _enableLargeFileUpload and _enablePasswordForgotten 2011-10-25 13:38:21 +00:00
steinm
a94d45b111 - check for _enableLargeFileUpload and disable links if not set 2011-10-25 13:37:45 +00:00
steinm
9177ba39eb - check for _enableLargeFileUpload and disable links if not set 2011-10-25 13:37:26 +00:00
steinm
662b657e9d ?? 2011-10-16 20:00:26 +00:00
steinm
3106ca2a9b - ?? 2011-10-16 19:59:35 +00:00
steinm
51b92c5c0a - added scripts for password change 2011-10-12 06:29:48 +00:00
steinm
30bf179ea2 - simplyfied code 2011-10-10 14:10:51 +00:00
steinm
46350ee830 - added link back to login form 2011-10-10 08:42:24 +00:00
steinm
1582601f17 - added link to password forgotten function at and of page if enabled 2011-10-10 08:40:05 +00:00
steinm
eb8254e9bc - used translated phrases 2011-10-10 07:35:58 +00:00
steinm
e869ebe2ef - scripts for sending forgotten password 2011-10-07 16:22:05 +00:00
steinm
a590083015 - allow managers of a group to manage their group 2011-10-07 16:18:23 +00:00
steinm
3cab08702d - check if configuration file is writeable and issue a message if not 2011-07-27 06:23:17 +00:00
steinm
44850571e8 - fixed error in html tagging 2011-07-22 20:46:32 +00:00
steinm
7053895c5b - update an document with a file larger than what can be handled by the browser 2011-07-21 13:30:47 +00:00
steinm
5a96986c5f - added new config variable _lucenceClassDir 2011-07-21 06:55:07 +00:00
steinm
fbd0e28e91 - use new config variable _luceneClassDir 2011-07-21 06:54:24 +00:00
steinm
17f7770b55 - use new config variable _luceneClassDir 2011-07-21 06:54:02 +00:00
steinm
545043cd94 - show submit review link only for logged in user 2011-07-20 17:12:03 +00:00
steinm
ea6611d78e - make keywords selectable from keyword list 2011-07-20 15:58:38 +00:00
steinm
8a754b5f63 - do not ask for a filename if _strictFormCheck is set to false
- do not erase file selection fields if a new document is added
2011-07-20 10:27:38 +00:00
steinm
c7c5c1f431 - use intval() instead of sanitizeString() where an integer is expected anyway 2011-06-15 06:08:47 +00:00
steinm
ae2cff47bc - added new phrase 2011-05-31 18:31:10 +00:00
steinm
016f05e87b - instead of blank entry in list of user roles say 'User' 2011-04-15 08:34:10 +00:00
steinm
5e6973cca9 - fixed output of backup date 2011-04-14 09:00:30 +00:00
steinm
93e293f904 - fixed output of backup file creation time 2011-04-11 06:36:01 +00:00
steinm
720d5532a8 - convert to unix line endings 2011-04-09 11:34:30 +00:00
steinm
dcd17cfddb - show lock in Folder list of document is locked 2011-04-08 20:43:35 +00:00
steinm
6315adeebb - removed lots of white space 2011-03-24 07:17:24 +00:00
steinm
aff1c950d9 - check if $_GET["categoryid"] is set before using it 2011-03-24 07:15:56 +00:00
steinm
3192692be2 - check for non null $logname 2011-03-23 13:27:07 +00:00
steinm
d6aad94576 - added link to out.AddFile2.php 2011-03-15 14:23:08 +00:00
steinm
dce389314d - add link to out.AddMultiDocument.php 2011-03-15 14:22:51 +00:00
steinm
740c4954cb - added new configuration variables 2011-03-15 14:19:17 +00:00
steinm
1bb837cc46 - old layout if fulltext search is disabled 2011-03-14 16:36:54 +00:00
steinm
5979c13d04 - added link to new configuration tool 2011-03-14 16:36:24 +00:00
steinm
1c296ea582 - output list of categories 2011-03-10 14:50:40 +00:00
steinm
7d9ccc3951 - added link to alternative upload method using jumploader 2011-03-10 14:50:07 +00:00
steinm
6e89a7c10b - added category management 2011-03-10 14:49:30 +00:00
steinm
92c69f5d51 - added category selection 2011-03-10 14:48:46 +00:00
steinm
b94bed96e7 - search form is splitt in to regular database search and fulltext search 2011-03-10 14:48:10 +00:00
steinm
c7d2c3a642 - include links to category management and creating fulltext index 2011-03-10 14:47:03 +00:00
steinm
d983759a0c - added gui for uploading files with jumploader 2011-03-10 14:32:22 +00:00
steinm
8f58f9909d - added gui to manage categories 2011-03-10 14:30:40 +00:00
steinm
dc37217fd5 - added support for fulltext index 2011-03-10 14:13:39 +00:00
steinm
1e4983a22b - allow to set targer field which is updated when closing the dialog 2011-02-18 16:17:37 +00:00
steinm
aff98f7ca4 - get list of all admin ids instead of using the one in $settings 2011-02-10 09:00:35 +00:00
steinm
a60b24de15 - do not use LetoDMS_Core_DocumentContent::viewOnline() anymore 2011-02-01 07:13:26 +00:00
steinm
6ebfb6470a - use $dms->contentDir 2011-01-28 08:03:54 +00:00
steinm
38760a712d - use $dms->contentDir 2011-01-28 07:42:10 +00:00
steinm
a311e61343 - fixed typo which caused a php error 2011-01-21 08:33:31 +00:00
steinm
3e1d956fba - do not include LetoDMS_Core.php anymore it is now include bei inc.DBInit.php 2011-01-20 12:39:25 +00:00
steinm
8a84bc3b51 - rename all classes belonging to the core of LetoDMS into LetoDMS_Core_xxx
- move them all into LetoDMS_Core
2011-01-20 08:18:37 +00:00
steinm
5e70f949f7 - do not include inc.DBAccess.php, because it is included by inc.ClassDMS.php 2011-01-14 19:45:29 +00:00
steinm
955be450f3 - getFolderPathHTML() is now a function in inc/inc.Utils.php because
it uses links only known by the calling application
2010-12-22 08:50:57 +00:00
steinm
64521a544f - use new methode LetoDMS_User::getImage() 2010-12-21 17:39:59 +00:00
steinm
1ac1b3810a - better output text if no review or approval is pending 2010-12-14 16:05:07 +00:00
steinm
f55a496fee - replaced getMLtext() by getMLText() 2010-12-14 16:04:23 +00:00
steinm
1e6f63237e - get rid of those missing phrases with key 'empty_notify_list' and
replaced them with appropriate phrases
2010-12-14 14:17:02 +00:00
steinm
4087d7f953 - do not user _adminID anymore 2010-12-10 13:41:00 +00:00
steinm
5650c23595 - more replacement of former global settings variable _adminID 2010-12-10 13:38:03 +00:00
steinm
86057c0f26 - replaced checkboxes for isAdmin and isGuest by select menu für role 2010-12-05 20:31:30 +00:00
steinm
a32a2e7237 - do not use global variable settings->_guestID anymore. Use
LetoDMS_User::isGuest() instead
2010-12-03 07:22:56 +00:00
steinm
0258d905a5 - added 'global' statement in function 2010-12-01 13:37:44 +00:00
steinm
d3744c0264 - inc.ClassKeywords.php is now included by inc.ClassDMS.php
- moved all static functions to get and add keywords in LetoDMS_DMS
2010-11-27 20:52:03 +00:00
steinm
f81a7063df - getUser(), getFolder(), getDocument() are now methods of LetoDMS_DMS 2010-11-26 08:34:47 +00:00
steinm
c522f28497 - getFolder() is now a methode of class LetoDMS_DMS 2010-11-26 08:31:08 +00:00
steinm
72defaaacf - no need to include inc.FileUtils.php anymore. It is included
by LetoDMS_DMS
2010-11-25 21:28:59 +00:00
steinm
fa4f798d3b - do not use LetoDMS_User::getImageURL() anymore. It just returnen an
URL and used global variables and file names only known outside the class
2010-11-25 07:38:37 +00:00
steinm
35b663eb74 - inc.ClassAccess is now included by inc.ClassDMS.php 2010-11-23 08:13:17 +00:00
steinm
a029cd22c2 - filterAccess() and filterUsersByAccess() are now static functions in
LetoDMS_DMS and inc.AccessUtils.php is included in inc.ClassDMS.php
2010-11-22 20:42:19 +00:00
steinm
81f4c235d5 - various global function have moved into LetoDMS_DMS 2010-11-18 10:26:47 +00:00
steinm
73494943d5 - getAllUsers() and getAllGroups() are now in LetoDMS_DMS 2010-11-18 10:25:43 +00:00
steinm
f781650133 - getAllGroups() is now a method of LetoDMD_DMS 2010-11-17 07:30:54 +00:00
steinm
d619bc8dc8 - do not include inc.ClassEmail.php, it is already included in inc.ClassDMS.php 2010-11-17 07:30:11 +00:00
steinm
9acbde3e0e - getAllUsers() and gelAllGroups() are now methods of LetoDMЅ_DMS 2010-11-17 07:29:11 +00:00
steinm
70762ca49e - getAllUsers() and getAllGroups() are now methods of LetoDMЅ_DMS 2010-11-17 07:27:12 +00:00
steinm
ced611f5b9 - do not global functions getAll[Users|Groups] anymore 2010-11-15 21:10:37 +00:00
steinm
0a116adc88 - moved functions to create users and groups completely in LetoDMS_DMS 2010-11-15 21:08:07 +00:00
steinm
4678218f1a - moved function to admin users and groups in LetoDMS_DMS 2010-11-15 12:01:21 +00:00
steinm
7a750de5b4 - fixed overall folder and document overview 2010-11-12 23:00:36 +00:00
steinm
9f61a7d9be - was just a copy anyway 2010-11-12 22:51:06 +00:00
steinm
cfd3eaae06 - first step to get rid of global variables from all files in inc/
- added new Class LetoDMS_DMS which represents the DMS, contains
  all settings for the DMS and the database connection. A document
	and a folder have a reference to the DMS
2010-11-12 22:47:41 +00:00
steinm
92a797f032 - replace $user->getID($user) by $user->getID() 2010-11-08 12:49:21 +00:00
steinm
f1778edd4f - took over changes from stable release 2.0.2 2010-11-05 21:45:21 +00:00
steinm
be2024b912 - renamed class Version to LetoDMS_Version 2010-11-03 12:50:58 +00:00
steinm
b5bc621318 - move all sources into trunk 2010-10-29 13:19:51 +00:00