Thomas Hochstein
9999a5b0e1
Add plugin update notification to dashboard.
...
Signed-off-by: Thomas Hochstein <thh@inter.net>
2019-08-10 23:40:15 +02:00
onli
60e975ee27
Fix: Don't show "Array" string under update notification
2019-08-03 21:11:53 +02:00
onli
ba6ccb3dbb
Make $entry available for templates ( fix #610 )
2019-07-03 17:51:36 +02:00
onli
46c408c19b
Make stablearchive default
2019-04-27 18:13:16 +02:00
onli
92a1106405
Set distinct cache directory for voku/simple-cache ( #597 )
2019-03-18 21:37:56 +01:00
Jari Turkia
260efcc5a6
Make sure there is a $serendipity['lang'] defined by serendipity_getSessionLanguage()
2019-03-10 11:31:25 +01:00
onli
f5d5b73c26
Bump required PHP version to 7.0 ( #596 )
2019-03-06 00:48:50 +01:00
Stephan Brunker
db0f47a10a
upgrader move force: array check for serendipity_db_query
2019-03-05 18:38:22 +01:00
Stephan Brunker
722c1cf7f8
plugin spamblock: if forcemoderation is set, activate the new option moderation_auto
2019-03-05 18:38:22 +01:00
onli
cd0adf5550
Set templates_c as opcache destination for voku/simple-cache
2019-03-04 11:07:32 +01:00
onli
f948279583
Fix autologin token, form tokens failed cause session was not set
2019-02-20 23:06:13 +01:00
onli
c737565c13
Improve autologin token security by setting httpOnly and secure flag
2019-02-20 22:24:05 +01:00
onli
f295a3b123
Fix self-XSS on file upload
...
The filename was used without escaping in the scucess message shown after upload
2019-02-20 21:38:13 +01:00
onli
153b5a37f1
Fix: Do not throw error when entry got deleted, go to 404 page
2019-02-16 14:46:46 +01:00
onli
ba9c401697
Remove check of undefined constant ( #556 )
2019-02-16 13:36:15 +01:00
onli
4c4545428d
Fix internal cache, init proper functions API
2019-02-16 13:07:53 +01:00
onli
e0f230dd15
Remove serendipity_purgeEntry
...
Removed pregenerated entries, but that functionality is long gone
2019-02-12 23:18:52 +01:00
onli
d52f0004a4
Add voku/simplecache as alternative to Cache/Lite and use it cache
...
Cache/Lite is abandoned
2019-02-12 18:52:08 +01:00
onli
88073e9816
Activate internal cache by default
2019-02-11 18:26:37 +01:00
onli
98261856db
Preserve manual set image link when moving/renaming image ( #509 )
2019-02-10 13:44:14 +01:00
onli
f049892e39
Make serendipity_event_responsiveimages a default plugin
...
That means it will be activated during the s9y installation
2019-02-09 15:17:25 +01:00
Hanno
4445926033
Avoid warning about non-countable var, fix #587 .
2019-01-11 16:28:08 +01:00
onli
e3aaefd2e9
ML: Add mediaproperties on rename ( #509 )
2018-11-18 22:57:51 +01:00
onli
732f1ae851
ML: Update links, not just thumbnail, when renaming images ( #509 )
2018-11-18 21:47:45 +01:00
Garvin Hicking
0dc6f620c1
[BUGFIX] Fixes media library regression, references #509
...
Adds missing ACL renames
Missing trailing / when managing dirs
Fix typo that did not evaluate read/write properly
Add missing NEWS entries
2018-11-05 15:59:49 +01:00
Garvin Hicking
0b259ce52f
[BUGFIX] Fixes broken installer due to missing serendipity_db_probe() call.
2018-10-31 09:39:31 +01:00
onli
fdb4428191
Restore backend_media_rename ( #509 )
2018-10-30 19:51:37 +01:00
onli
52838c0f7b
fix: plugin page died because of non-countable object
2018-10-07 19:08:15 +02:00
onli
10585fff80
Fix: Unknown constant error RSS
2018-10-07 19:04:22 +02:00
onli
166b2d4658
security: Prevent XSS via multicategory pagination
2018-09-13 16:27:28 +02:00
onli
58ed05f187
fix: missing variable orderkey was supposed to be a string
2018-09-13 14:49:15 +02:00
onli
835b076c99
php 7.2: Remove invalid constant check ( #563 )
2018-09-13 14:27:51 +02:00
onli
0a35bd4c59
Update Smarty to 3.1.32
2018-08-17 09:35:36 +02:00
Hanno
2669745975
replace deprecated each() with foreach()
2018-07-31 20:58:48 +02:00
onli
47b8a13911
Make the $view variable more reliable
...
t could happen that $view was not set, which lead to noindex being set to all frontpage pages. See https://board.s9y.org/viewtopic.php?f=3&t=24041
2018-07-31 20:35:52 +02:00
Garvin Hicking
005a86da1c
Another cast for safety
2018-07-19 09:25:18 +02:00
Garvin Hicking
19513cdf14
Security fixes
2018-07-18 11:23:02 +02:00
onli
9d1fa83a39
Allow svgs in the media library ( #529 )
2018-06-14 22:14:04 +02:00
onli
23d3a73b01
init maintenance mode ( #467 )
2018-06-13 19:31:28 +02:00
onli
567587718b
React to errors when comment could not be deleted ( #527 )
2018-06-12 23:49:11 +02:00
onli
3ef2b78014
Make comment subscription with full text the default ( #483 )
2018-06-12 22:44:45 +02:00
onli
c7c133ef1d
Set the bcrypt hashtype as the default for user creation
2018-06-12 22:43:19 +02:00
onli
9e8eebac15
Fix user creation, also fixes installer
...
Because the hashtype was not set to the new default, but bcrypt already used, the user could not log in
2018-06-12 22:40:02 +02:00
Garvin Hicking
775b71134c
* Fixed bug in pull request #392 which overwrote user specified
...
input for logged in authors with an empty realname (wrong array
key name) and deleted all existing text input
2018-04-23 11:58:32 +02:00
onli
40993037b2
init media gallery insert
2018-04-06 17:09:51 +02:00
mariohommel
dcb693ba54
Generating token for comment moderation in a global function now.
2018-03-30 11:04:21 +02:00
Mario Hommel
0d8cdd59fa
Fix variable name in hook backend_sendcomment
2018-03-24 18:31:14 +01:00
onli
eafc4dd625
Move from SHA1 to bcrypt
...
SHA1 is not an ideal password hash, even when salted, because it is cheap to compute. Since version 5.5 PHP offers bcrypt built in, which is a more expensive and secure hash function specifically suited for passwords
2018-03-23 18:02:02 +01:00
onli
52a41b37d5
Rework autologin to use a token approach
...
The prior code stored encrypted user data in the cookie that was then checked. This new approach is cleaner, as it only stores a token, and it does not use problematic crypto functions deprecated in PHP 7.2
2018-03-23 18:01:32 +01:00
Garvin Hicking
b2eecb9a3d
backport constant check
2018-01-10 11:21:59 +01:00