Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | missing includes | Mario Vavti | 2017-04-13 | 1 | -0/+1 |
| | |||||
* | sql error photos_albums_list with non-logged-in viewer | zotlabs | 2017-04-03 | 1 | -1/+1 |
| | |||||
* | fix connectDefaultShare generated js function, though it isn't obvious if we ↵ | zotlabs | 2017-04-03 | 1 | -19/+11 |
| | | | | still use it. | ||||
* | app sorting issue | zotlabs | 2017-04-03 | 1 | -3/+13 |
| | |||||
* | Merge pull request #710 from dawnbreak/importcsrf | git-marijus | 2017-03-31 | 2 | -0/+6 |
|\ | | | | | :lock: Add CSRF protection for import and import_items. | ||||
| * | :lock: Add CSRF protection for import and import_items. | Klaus Weidenbach | 2017-03-30 | 2 | -0/+6 |
| | | |||||
* | | get rid of some more deprecated uses of $a | zotlabs | 2017-03-31 | 2 | -2/+2 |
| | | |||||
* | | remove obsolete app argument from load_pdl | zotlabs | 2017-03-31 | 2 | -2/+2 |
| | | |||||
* | | get rid of get_app() | zotlabs | 2017-03-31 | 2 | -4/+3 |
| | | |||||
* | | provide compatibility with old-style update system | zotlabs | 2017-03-31 | 1 | -6/+16 |
| | | |||||
* | | get rid of 'davguest' and allow for project specific DB updates (currently ↵ | zotlabs | 2017-03-31 | 3 | -13/+15 |
| | | | | | | | | db updates are common between all possible projects/subprojects/forks). | ||||
* | | move db_upgrade to zlib | zotlabs | 2017-03-31 | 3 | -8/+115 |
|/ | |||||
* | Merge pull request #709 from dawnbreak/docu | Klaus | 2017-03-30 | 2 | -56/+56 |
|\ | | | | | Add some documentation for import functions. | ||||
| * | Add some documentation for import functions. | Klaus Weidenbach | 2017-03-30 | 2 | -56/+56 |
| | | |||||
* | | do not allow creating two wikis with the same name | Mario Vavti | 2017-03-30 | 1 | -3/+10 |
| | | |||||
* | | circular logic - we need the mailbox to find the last message so move the ↵ | zotlabs | 2017-03-30 | 1 | -4/+9 |
| | | | | | | | | code block back where it was, and only set a direct mid if one was specified. | ||||
* | | when clicking a notification to view a private mail message, actually view ↵ | zotlabs | 2017-03-30 | 1 | -2/+9 |
|/ | | | | that message instead of the most recent. | ||||
* | allow setting the system email name/address/reply | zotlabs | 2017-03-29 | 1 | -0/+15 |
| | |||||
* | more cloud updates - upgrade the DAV structures as well. | zotlabs | 2017-03-29 | 2 | -23/+51 |
| | |||||
* | some more photo issues | zotlabs | 2017-03-29 | 1 | -24/+22 |
| | |||||
* | fix photo prvnxt after all the changes yesterday | zotlabs | 2017-03-29 | 1 | -6/+5 |
| | |||||
* | more work on the photo album mess | zotlabs | 2017-03-29 | 1 | -92/+65 |
| | |||||
* | photos_album_exists() requires an observer to work correctly; provide it. | zotlabs | 2017-03-29 | 1 | -2/+2 |
| | |||||
* | use the same host macro for sender address as for reply_to address | zotlabs | 2017-03-29 | 1 | -2/+2 |
| | |||||
* | begin the process of using the relevant attach directory/path for photo ↵ | zotlabs | 2017-03-29 | 1 | -31/+14 |
| | | | | albums instead of an album basename which may not be unique. Created an 'ellipsify()' function to shorten long names and keep the beginning and end intact | ||||
* | more markdown purification | zotlabs | 2017-03-29 | 1 | -5/+5 |
| | |||||
* | perform attach_upgrade() | zotlabs | 2017-03-29 | 1 | -0/+3 |
| | |||||
* | after all of this, I would be very hesitant to use any multi-user system ↵ | zotlabs | 2017-03-29 | 1 | -1/+1 |
| | | | | which uses markdown and which doesn't have a large security budget. | ||||
* | even more fine tuning of the markdown purifier - especially when used with ↵ | zotlabs | 2017-03-29 | 3 | -2/+3 |
| | | | | the wiki | ||||
* | various input filter fixes | zotlabs | 2017-03-29 | 9 | -23/+76 |
| | |||||
* | more work related to attach/photo and os_path, display_path and general code ↵ | zotlabs | 2017-03-29 | 2 | -36/+40 |
| | | | | cleanup | ||||
* | input filter updates | zotlabs | 2017-03-29 | 4 | -46/+9 |
| | |||||
* | class MarkdownSoap to safely store markdown by purifying and preserving ↵ | zotlabs | 2017-03-29 | 1 | -0/+86 |
| | | | | (escaped) what may be unsafe code in codeblocks. The stored item needs to be unescaped just prior to calling the markdown-to-html processor | ||||
* | code_allowed is a real mess. Start the cleanup by remving the account level ↵ | zotlabs | 2017-03-29 | 2 | -23/+4 |
| | | | | code allow and limiting to specific channels only. This reduces the possibility of cross channel security issues coming into play. Then provide a single function for checking the code permission. This is only partially done as we often need to check against the observer or logged in channel as well as the resource owner to ensure that this only returns true for local channels which also own the requested resource. | ||||
* | fix widgets for bs4 again | Mario Vavti | 2017-03-29 | 2 | -4/+4 |
| | |||||
* | namespace error | Mario Vavti | 2017-03-29 | 1 | -1/+1 |
| | |||||
* | widget file update | zotlabs | 2017-03-29 | 1 | -2/+2 |
| | |||||
* | remove include/widgets.php | zotlabs | 2017-03-29 | 5 | -13/+1 |
| | |||||
* | the rest of the standard widgets converted | zotlabs | 2017-03-29 | 20 | -0/+860 |
| | |||||
* | namespace error | Mario Vavti | 2017-03-29 | 1 | -2/+2 |
| | |||||
* | widgets cont. | zotlabs | 2017-03-29 | 9 | -0/+274 |
| | |||||
* | widgets cont. | zotlabs | 2017-03-29 | 9 | -0/+411 |
| | |||||
* | more widget migrations | zotlabs | 2017-03-29 | 4 | -0/+102 |
| | |||||
* | more widgets | zotlabs | 2017-03-29 | 3 | -0/+106 |
| | |||||
* | filename issue | zotlabs | 2017-03-29 | 1 | -0/+0 |
| | |||||
* | more widgets | zotlabs | 2017-03-29 | 3 | -0/+166 |
| | |||||
* | convert more widgets to classes | zotlabs | 2017-03-29 | 5 | -0/+166 |
| | |||||
* | use absolute namespace | zotlabs | 2017-03-29 | 1 | -1/+2 |
| | |||||
* | Comanche: allow widgets to be class based and stored appropriately in Zotlabs | zotlabs | 2017-03-29 | 2 | -0/+37 |
| | |||||
* | Import Module documentation and @-sign replacement. | Klaus Weidenbach | 2017-03-25 | 1 | -111/+115 |
| | | | | | If you copy the identity from your profile page the @-sign is invalid for the import and fails. Replace it for convenience. |