Go to file
Ingo Schommer 2700d73e97 ENHANCEMENT Limiting "alc_enc" cookie (remember login token) to httpOnly to reduce risk of information exposure through XSS
git-svn-id: svn://svn.silverstripe.com/silverstripe/open/modules/sapphire/trunk@86027 467b73ca-7a2a-4603-9d3b-597d59a354a9
2009-09-10 03:23:31 +00:00
api BUGFIX Only set response header in XMLDataFormatter->convertDataObject() if a response is defined (merged from branches/2.3-nzct) 2009-07-16 23:47:12 +00:00
cli Merged changes from 2.3 branch 2009-02-01 23:49:53 +00:00
conf API CHANGE: Added SS_DATABASE_CLASS as an option for _ss_environment.php 2009-05-26 23:45:54 +00:00
core ENHANCEMENT Added full parameter signature of PHP's set_cookie() to Cookie::set(), including the new $httpOnly flag 2009-09-10 03:22:50 +00:00
css Merged from branches/2.3 2009-05-25 06:59:21 +00:00
dev BUGFIX Consistently returning from a Security::permissionFailure() to avoid ambiguous situations when controllers are in ajax mode 2009-09-10 02:00:42 +00:00
email API CHANGE: Added increase_time_limit_to(), which respects safe_mode. 2009-06-28 02:36:46 +00:00
filesystem BUGFIX Consistently returning from a Security::permissionFailure() to avoid ambiguous situations when controllers are in ajax mode 2009-09-10 02:00:42 +00:00
forms BUGFIX Detecting DataObjectSet for readonly transformations in CheckboxSetField (thanks martijn, #4527) 2009-09-05 00:05:02 +00:00
images MINOR merged from branches/2.3 2009-01-07 23:00:54 +00:00
integration MINOR: added check for exec() and fixed the path for the wordlist file. Ticket #4428 2009-09-03 23:36:45 +00:00
javascript MINOR: fine tuning behavior of selected radio in SelectionGroup 2009-08-25 22:38:52 +00:00
lang ENHANCEMENT Avoid information disclosure in Security/lostpassword form by returning the same message regardless wether a matching email address was found in the database. 2009-09-10 03:01:46 +00:00
parsers MINOR Removed debug code 2009-03-31 17:07:16 +00:00
profiler Merged changes from 2.3 branch 2009-02-01 23:49:53 +00:00
search ENHANCEMENT: add "InnerJoin" clause for an has_many component's ancestry classes for SearchFilter::applyRelation() so that an searchfliter could filter on that component's ancestry's field. add unit tests for this enhancement and r83500 2009-08-10 23:34:32 +00:00
security ENHANCEMENT Limiting "alc_enc" cookie (remember login token) to httpOnly to reduce risk of information exposure through XSS 2009-09-10 03:23:31 +00:00
tasks MINOR Unified permission control for i18nTextCollectorTask, TaskRunner, TestRunner, ModelViewer, DevelopmentAdmin, TestViewer, MigrateTranslatableTask 2009-09-10 01:49:56 +00:00
templates API CHANGE Removed unnecessary WidgetFormProxy class and Widget->FormObjectLink(), broken functionality since the RequestHandler restructuring in 2.3. Use Widget_Controller instead. 2009-09-07 03:28:23 +00:00
tests API CHANGE Don't exempt 'index' controller actions from $allowed_actions check - they might still contain sensitive information (for example ImageEditor). This action has to explicitly allowed on controllers with $allowed_actions defined now. 2009-09-10 01:37:44 +00:00
thirdparty Updated externals, to bring Zend into our repository and use relative externals. 2009-05-22 04:19:44 +00:00
widgets ENHANCEMENT Allowing Widget->Content() to render with any templates found in ancestry instead of requiring a template for the specific subclass 2009-09-07 06:26:49 +00:00
_config.php MINOR Updated MCE_ROOT constant to reflect new location of tiny_mce 2009-06-15 02:04:29 +00:00
.htaccess Merged from branches/2.3 2009-04-28 23:52:15 +00:00
cli-script.php ENHANCEMENT: Change MySQLDatabase connection to operate in ANSI SQL mode, to ease the transition to DB abstraction 2008-11-22 03:51:04 +00:00
main.php MINOR: Use version_compare to test for correct PHP version. 2009-08-11 03:50:40 +00:00
main.php5 MINOR phpdoc documentation 2009-03-22 22:59:14 +00:00
Makefile MINOR: Added flush=1 to test executor 2009-05-04 05:14:00 +00:00
sake Merged changes from 2.3 branch 2009-02-01 23:49:53 +00:00
silverstripe_version fixed $ 2007-12-14 04:35:28 +00:00
static-main.php MINOR batchactions JS fix 2009-08-03 21:53:30 +00:00