Commit Graph

4707 Commits (375eae1a5c1cd97501e6f2b770ee2b22668a91e1)
 

Author SHA1 Message Date
Lukas Reschke 375eae1a5c Use openssl_random_pseudo_bytes if available
This is a backport of ef57e92 /cc @DeepDiver1975
2012-10-06 14:19:58 +07:00
Thomas Tanghus ca216b5296 Trim trailing whitespace from version. 2012-09-26 11:33:14 +07:00
Arthur Schiwon c212d118ba fix default values in table fscache 2012-09-26 11:28:47 +07:00
Lukas Reschke 292d20595d Passwords containing a ":" don't work with this explode
Thanks to mETz
2012-09-25 19:49:42 +07:00
Lukas Reschke 1e7ac8ba15 Sanitize user input 2012-09-22 10:55:25 +07:00
Tom Needham 1954f80fa3 Don't store users password hash when exporting. 2012-09-19 16:19:47 +07:00
Tom Needham a5c42edbe5 Only try to delete migration.db if it was created. 2012-09-18 16:31:27 +07:00
Tom Needham 3b465f419a Allow exporting of users from any user backend, fixed oc-1645 2012-09-18 16:30:13 +07:00
Arthur Schiwon 0f489e80ad LDAP: transliterate other latin characters to ASCII when creating owncloud names. Already created usernames are not being affected. Fixes ugly names with removed Umlauts, chars with accents and likes. 2012-09-18 17:10:21 +07:00
Victor Dubiniuk 95a748152e Fix for cyrillic folder names. ref#oc-1683 2012-09-11 23:57:13 +07:00
Lukas Reschke d050e6e04e Merge pull request #11 from ne704/typos
fix message about 'apps' directory
2012-09-10 10:13:21 +07:00
Niko Ehrenfeuchter ae3ea39a4c fix message about 'apps' directory 2012-09-10 19:06:03 +07:00
Lukas Reschke 943a9a2e09 Merge pull request #10 from ne704/typos
Typos
2012-09-10 09:41:26 +07:00
Niko Ehrenfeuchter 76ccd69cec mark unused variables 2012-09-10 16:04:05 +07:00
Niko Ehrenfeuchter 88d95823b2 fix typos 2012-09-10 16:04:03 +07:00
Niko Ehrenfeuchter ac4364040d fix typos + copy-paste errors in comments 2012-09-10 16:03:46 +07:00
Georg Ehrke b37d318159 back port better input validation in calendar from apps repo 2012-08-31 14:27:03 +07:00
Arthur Schiwon b11203537e LDAP: check for existing username from other backends when creating one for an LDAP user or group. Fixes oc-1551 in stable4. Also optimizes groupExists() function as side effect. 2012-08-29 18:07:32 +07:00
Lukas Reschke a79175330e Gitorious => Github 2012-08-26 11:32:20 +07:00
Lukas Reschke 49c17fc391 I like TLS/SSL 2012-08-26 00:56:18 +07:00
Lukas Reschke 5afdfec91d Sanitizing the user input to prevent a reflected XSS. Thanks to Nico Golde (ngolde.de) 2012-08-21 17:56:20 +07:00
Arthur Schiwon 2051a5db5d Fix deletion for browser that do not support onBeforeUnload, fixes oc-1534 2012-08-20 17:04:57 +07:00
Lukas Reschke 4984a72d0d Add a missing exit(); 2012-08-18 14:57:19 +07:00
Lukas Reschke 45003593e1 Use SCRIPT_NAME instead of PHP_SELF which won't send the PATH_INFO, this prevents XSS in old browsers. Thanks to Nico Golde. 2012-08-18 09:26:58 +07:00
Georg Ehrke f53dd22cd9 backport 1bccc80996 2012-08-16 15:30:55 +07:00
Frank Karlitschek 526e704c9f 4.0.7
and remove some ^M while at it
2012-08-14 20:07:58 +07:00
Lukas Reschke 4682846d3e Disable user enumeration 2012-08-14 17:19:20 +07:00
Michael Gapczynski 95ef80e6db Check blacklist when renaming files 2012-08-13 01:29:32 +07:00
Lukas Reschke 4fd069b479 Also check some other files 2012-08-13 01:26:28 +07:00
Lukas Reschke 2024d424cd Disable listing of all users 2012-08-13 01:22:53 +07:00
Jakob Sack 6d94455540 Fix OC_Connector_Sabre_Locks for SQLite 2012-08-12 09:06:46 +07:00
Lukas Reschke 2871896d54 Check if webfinger is enabled 2012-08-10 16:38:32 +07:00
Michael Gapczynski e9a63900de Don't return file handle if the mode supports writing and the file is not writable
Conflicts:
	apps/files_sharing/sharedstorage.php
2012-08-10 09:46:44 +07:00
Lukas Reschke baab13ae13 Validate cookie to prevent auth bypasses. 2012-08-10 15:23:04 +07:00
Lukas Reschke 5192eecce2 Added XSRF check 2012-08-10 00:11:04 +07:00
Lukas Reschke 7581d55428 Missed an "echo" 2012-08-09 22:17:52 +07:00
Lukas Reschke aae17d4ae8 Sanitize user input 2012-08-09 22:14:48 +07:00
Thomas Tanghus a366ba4c0c Fix for broken Mail App in OSX Mountain Lion. https://mail.kde.org/pipermail/owncloud/2012-August/004649.html 2012-08-09 17:22:56 +07:00
Bjoern Schiessle 2cfc7f7454 fix for bug 879 - add parent directory to file cache if it does not exist yet.
For example this can happen if the sync client is used before the user created the root directory (e.g. through web login).
2012-08-08 11:47:23 +07:00
Arthur Schiwon e9e84b5c3b Merge branch 'stable4' of git://gitorious.org/owncloud/owncloud into stable4 2012-08-05 21:17:39 +07:00
Georg Ehrke c32a99b14c fix label for versioning in admin settings 2012-08-04 18:50:05 +07:00
Bart Visscher 758ae42df0 Calendar: remove double html encoding 2012-08-03 16:26:05 +07:00
Bart Visscher 0970a3c60e Contacts: Fix no active Addressbooks 2012-08-03 16:11:10 +07:00
Arthur Schiwon 6b78ca1a5a LDAP: sanitize base, user and group trees. fixes oc-1302 2012-08-03 15:51:25 +07:00
Arthur Schiwon e899c9989e Show Login-Button when user+pw are autocompleted, fixes oc-1068 2012-08-03 13:16:25 +07:00
Frank Karlitschek aa60771736 4.0.6 2012-07-31 10:13:10 +07:00
Arthur Schiwon b523366acd LDAP: don't die on unexpected collisions, handle empty display-name attributes properly 2012-07-30 17:30:11 +07:00
Michael Gapczynski b9bd54bd98 Add additional error handling for emailing private links 2012-07-30 10:07:20 +07:00
Michael Gapczynski dab708b625 Correction for 'Fix group detection for sharing in case username contains '@', fix for oc-1270' 2012-07-30 10:07:20 +07:00
Michael Gapczynski 519eb39422 Remove delete tipsy if file is deleted, fixes bug oc-958 2012-07-30 10:07:19 +07:00