| Commit message (Collapse) | Author | Age | Files | Lines |
|
|
|
|
|
|
|
| |
This should fix issue #1877 fully.
(cherry picked from commit 065f85bab11e13b95af6b99ce082c8a2f84a9de1)
Co-authored-by: Harald Eilertsen <haraldei@anduin.net>
|
|
|
|
|
| |
(cherry picked from commit 160c40b5807aea8e05f5cea6c4ed0115ac6a7f53)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit 0207c024201eec8d3fe83d4151f8cb5165e28886)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit 0e50b1d10ca5b68ca0d91e844ce32ce092773eb3)
Co-authored-by: Mario Vavti <mario@mariovavti.com>
|
|
|
|
|
|
|
| |
will be checked in item_store() anyway)
(cherry picked from commit e530476e6c5d2319f3a0a09dfe73ec181e923325)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit 1411eafa9b5411df9cfbd8b563025a6665a0a7db)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit f4495fd441a06c2ee58dd5073348627803d5ccb3)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This fixes the issue where the text after the URL would be included in
the link if it was immediately followed by a newline.
Example:
https://example.com
this is a test.
Would become:
#^[url=https://example.com_this]https://example.com_this[/url]
is a test
(cherry picked from commit 687cda367316edb9f84b3e425e76c9e9279e96be)
Co-authored-by: Harald Eilertsen <haraldei@anduin.net>
|
|
|
|
|
| |
(cherry picked from commit e2cfe245b79cb08930c0ba2258c26803361d4b2a)
Co-authored-by: Mario Vavti <mario@mariovavti.com>
|
| |
|
|
|
|
|
| |
(cherry picked from commit a5c1b669b461cb76e9ed8b15e9828183c5ccaf9e)
Co-authored-by: Mario Vavti <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit 2aee659cbdd147eca1c49385ea867ea11d2a72e5)
Co-authored-by: Mario Vavti <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit 44232677c85249b5ae7e83aa0e040586acf2c7cc)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit 16603ca85468162e117e71db53654de0d25611c8)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit 2693e9e99097c4bbcf8c9103a5876bc0585ff84c)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit 04741c761aeb944c8b54472ac7e3d1e9460a8cfc)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit 8f890fb6fa43ee8ee13ef9254e73a68280d545e0)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit 1afb2a4ce85c8a5215b99363b648a2cfa711b0e6)
Co-authored-by: Mario <mario@mariovavti.com>
|
| |
|
|
|
|
|
| |
(cherry picked from commit afbeb58c1626c3ba35041c834622c8134d0275e7)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit 8ffab25f5d848bb8b788c97cf7ec206729fc015a)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit 7d41deebce656a3812cea6556123e5c5805196da)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit 7e48caae6b104896e0b6bf95cf834d03962fdc09)
Co-authored-by: Mario <mario@mariovavti.com>
|
|\ |
|
| |
| |
| |
| |
| | |
(cherry picked from commit 5b93aa1148d647026b309e4f9e0eeca4f09d53ee)
Co-authored-by: Harald Eilertsen <haraldei@anduin.net>
|
|/ |
|
|
|
|
|
| |
(cherry picked from commit 9008760aa616752c109878187d835fcbfad49018)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
|
|
|
| |
This finally fixes the help for languages other than english.
(cherry picked from commit 4daa03f025505fc6f98f6a169cf743df1b958741)
Co-authored-by: Harald Eilertsen <haraldei@anduin.net>
|
|
|
|
|
|
|
|
|
|
| |
The drop shadow looked terrible in dark mode. While that could be fixed,
I think it looks better with just using the link hover color and making
the selected item bold.
(cherry picked from commit 8ae9df3bb7ab76bf8c1f864ac6c4869366e8b497)
Co-authored-by: Harald Eilertsen <haraldei@anduin.net>
|
|
|
|
|
| |
(cherry picked from commit 25d9d3ba1b6eed803c838f8cbfb67fb9b60e9185)
Co-authored-by: Harald Eilertsen <haraldei@anduin.net>
|
|
|
|
|
|
|
|
|
| |
This allows us to get rid of some more unneccessary JavaScript that just
implements stuff that web browsers now do anyways.
(cherry picked from commit 26ce231951e62f1912d457c8f6e6b0f2092173f1)
Co-authored-by: Harald Eilertsen <haraldei@anduin.net>
|
|
|
|
|
|
|
|
|
| |
Changes the element where the jQuery.toc plugin looks for headings to
only include the actual help contents, not the toc itself.
(cherry picked from commit fb9464437e68c13474409c969f934afe13768649)
Co-authored-by: Harald Eilertsen <haraldei@anduin.net>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This eliminates a potential vulnerability where an template author could
inject arbitrary PHP files to be run via the 'extends' tag.
See:
- https://github.com/smarty-php/smarty/security/advisories/GHSA-4rmg-292m-wg3w
- https://github.com/smarty-php/smarty/commit/0be92bc8a6fb83e6e0d883946f7e7c09ba4e857a
Impact assessment:
In our case I would consider this a low severity issue as we don't
allow users to dynamically add or edit smarty templates. Templates has
to be updated via merge requests, or by installing a theme. In both
cases a malicious attacker already has easier ways to inject whatever
code they want.
Further, the extend tag is not in use in any of our core templates.
(cherry picked from commit 4dff1a1e5b6d1117cf3a8ad9924d38fb7d01b687)
Co-authored-by: Harald Eilertsen <haraldei@anduin.net>
|
|
|
|
|
| |
(cherry picked from commit 1c45030c583d8a165bac81e52eab5ee209e398b5)
Co-authored-by: Mario <mario@mariovavti.com>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
When passing a content throught the `markdown_to_bb` function
to convert any markdown in the content, any recognized URLs in the
content would be converted to BBCode links as a post processing step
after the main conversion.
After commit a1ccacb825edac6ae36e5db4f62ebfe7aeaebe9f this did no longer
consider content within code blocks, and would thus convert them as
to BBCode links.
Example: The following content
[code]
example url: https://example.com
[/code]
Would be converted to
[code]
example url: [url=https://example.com]https://example.com[/url]
[/code]
Prior to commit a1ccacb825edac6ae36e5db4f62ebfe7aeaebe9f, code blocks
would be protected, so this would not happen.
This patch removes the post processing step for converting plain URLs to
links completely from this routine. This functionality is in any case
covered in the actual BBCode parser where it belongs.
This will have some other side effects as well, such as images and links
created using Markdown, will not be converted to [zmg] or [zrl] tags
where that would be done automatically before. If you intend to use a
[zrl] or [zmg] tag, you now need to do so explicitly.
(cherry picked from commit 803cd74b4881a617a56be4fb5780d6d25fd5433f)
Co-authored-by: Harald Eilertsen <haraldei@anduin.net>
|
|
|
|
|
|
|
| |
but the previous logic was throwing error in postgresql (while the result was correct anyway)
(cherry picked from commit a5f0253aef7784ace13fa6bd87048b86d9cd50c3)
Co-authored-by: Mario Vavti <mario@mariovavti.com>
|
|
|
|
|
| |
(cherry picked from commit 5cbd42bbc4de4cbae68148868525fe0c5952cee5)
Co-authored-by: Mario <mario@mariovavti.com>
|
|\ |
|
| | |
|
| |
| |
| |
| |
| | |
(cherry picked from commit 5281f4dd9bef5275c2b0f377b6d6768fadc1b8a6)
Co-authored-by: Mario <mario@mariovavti.com>
|
| |
| |
| |
| |
| | |
(cherry picked from commit 424b31b7f093f6264ce11a259cff4953696b20de)
Co-authored-by: Mario <mario@mariovavti.com>
|
| |\ |
|
| | | |
|
| | | |
|
| |\| |
|
| | | |
|
| | |
| | |
| | |
| | | |
minor code cleanup
|
| | | |
|
| |/
| |
| |
| |
| |
| |
| | |
minor code cleanup
(cherry picked from commit 3733a80c1de0e3bf69b91f1dc7ee217fd3e29fe5)
Co-authored-by: Mario Vavti <mario@mariovavti.com>
|
| | |
|