]>
git.ipfire.org Git - thirdparty/bugzilla.git/log
justdave%syndicomm.com [Tue, 20 Jan 2004 03:38:10 +0000 (03:38 +0000)]
Applied changed by hand to this file so they'll show up on the website... my docbook environment is busted right now so I
can't compile it the usual way.
justdave%syndicomm.com [Tue, 20 Jan 2004 03:36:03 +0000 (03:36 +0000)]
More bug 231445: I missed the text description below the example as well.
justdave%syndicomm.com [Sun, 18 Jan 2004 10:53:33 +0000 (10:53 +0000)]
Bug 228706: Fixes invalid expiration dates on almost all of the cookies. Amazingly it mostly worked before. It'll work better now. :)
r= myk, a= justdave
justdave%syndicomm.com [Sun, 18 Jan 2004 10:47:45 +0000 (10:47 +0000)]
Bug 227513: Add text to shadowdb param description to indicate that the privileges to access the shadowdb must be granted from MySQL prior to entering the shadowdb name in the param.
r= myk, a= justdave
justdave%syndicomm.com [Sun, 18 Jan 2004 10:44:54 +0000 (10:44 +0000)]
Bug 227510: The shadowdb parameter wasn't getting detainted before using it to create the shadowdb.
r= myk, a= justdave
justdave%syndicomm.com [Sun, 18 Jan 2004 09:41:27 +0000 (09:41 +0000)]
Bug 121419: Use the most-specific cookie if more than one exists with different cookiepaths. Should help ease login troubles related to the cookiepath setting.
Patch by Joel Peshkin <bugreport@peshkin.net>
r= bbaetz, a= justdave
justdave%syndicomm.com [Sat, 17 Jan 2004 11:17:20 +0000 (11:17 +0000)]
Bug 231145: wrong number of F's in the SQL to create an additional admin user (2.16 docs only)
justdave%syndicomm.com [Mon, 15 Dec 2003 14:42:02 +0000 (14:42 +0000)]
Bug 188712: Safari thinks it's Gecko, but it doesn't support server-push. Look for it and don't give it server-push.
r=timeless, a=justdave
justdave%syndicomm.com [Sat, 15 Nov 2003 15:38:59 +0000 (15:38 +0000)]
Bug 225474: Fixing regression from bug 217422, xml.cgi got busted, and the patch from bug 217422 (MySQL 4 compatibility for show_bug) didn't accomplish what it was supposed to anyway. This checkin fixes both.
r= bbaetz, a= justdave
justdave%syndicomm.com [Sun, 9 Nov 2003 11:56:32 +0000 (11:56 +0000)]
Bug 95430: Reopening bugs from the "change several bugs at once" page did not work.
r= myk, a= justdave
justdave%syndicomm.com [Mon, 3 Nov 2003 11:54:45 +0000 (11:54 +0000)]
Removing pdf version of the guide from the 2.16 branch because it's broken.
justdave%syndicomm.com [Mon, 3 Nov 2003 11:53:15 +0000 (11:53 +0000)]
Bumping version number to 2.16.4 for release
justdave%syndicomm.com [Mon, 3 Nov 2003 11:50:40 +0000 (11:50 +0000)]
[SECURITY] Bug 219690: When deleting products and the 'usebuggroups' parameter is on, the privilege which allows someone to add people to the group which is being deleted does not get removed, allowing people with that privilege to get that privilege for the next group that is created which reuses that group ID. Note that this only allows someone who had been granted privileges in the past to retain them.
Patch by Stefan Mayr <S.Mayr2@cadenas.de>
r= justdave, joel a= justdave
justdave%syndicomm.com [Mon, 3 Nov 2003 11:46:55 +0000 (11:46 +0000)]
[SECURITY] Bug 219044: A user with 'editkeywords' privileges (i.e. usually an administrator) can inject arbitrary SQL via the URL used to edit an existing keyword.
Patch by Joel Peshkin <bugreport@peshkin.net>
r= justdave, zach a= justdave
justdave%syndicomm.com [Mon, 3 Nov 2003 11:44:38 +0000 (11:44 +0000)]
[SECURITY] Bug 214290: A user with 'editproducts' privileges (i.e. usually an administrator) can select arbitrary SQL to be run by the nightly statistics cron job (collectstats.pl), by giving a product a special name.
Patch by Dave Miller <justdave@bugzilla.org>
r= gerv, bbaetz a= justdave
justdave%syndicomm.com [Mon, 3 Nov 2003 11:39:43 +0000 (11:39 +0000)]
[SECURITY] Bug 209376: If you know the email address of someone who has voted on a secure bug, you can access the summary of that bug even if you do not have sufficient permissions to view the bug itself.
Patch by Gervase Markham <gerv@mozilla.org>
r= justdave, bbaetz a= justdave
justdave%syndicomm.com [Mon, 3 Nov 2003 11:35:23 +0000 (11:35 +0000)]
Updated release notes for 2.16.4
jocuri%softhome.net [Sun, 2 Nov 2003 22:02:21 +0000 (22:02 +0000)]
Rebuilding documentation for the 2.16.4 release; the docbook system on landfill proved to be broken.
justdave%syndicomm.com [Sun, 2 Nov 2003 10:58:48 +0000 (10:58 +0000)]
Recompile docs for release
justdave%syndicomm.com [Sun, 2 Nov 2003 10:53:09 +0000 (10:53 +0000)]
Adding paragraph indicating the current version can be found on the website
jocuri%softhome.net [Sat, 1 Nov 2003 18:12:12 +0000 (18:12 +0000)]
Bug 123565: Add to FAQ: Why can't I close bugs from "Change Several Bugs at Once" ?; r=justdave; a=justdave.
jocuri%softhome.net [Fri, 31 Oct 2003 01:45:10 +0000 (01:45 +0000)]
Bug 223937: web site error while updating email address; r=kiko,justdave; a=justdave.
jocuri%softhome.net [Fri, 31 Oct 2003 01:26:17 +0000 (01:26 +0000)]
Bug 223937: web site error while updating email address; r=myk,kiko; a=justdave.
jake%bugzilla.org [Wed, 22 Oct 2003 09:31:07 +0000 (09:31 +0000)]
Bug 178624 - checksetup.pl needs to be run after copying a template to the custom directory.
jocuri%softhome.net [Sun, 19 Oct 2003 15:32:46 +0000 (15:32 +0000)]
Bug 220332: Insecure dependency in exec while running with -T switch at process_bug.cgi line 1267; r=justdave,gerv; a=justdave.
justdave%syndicomm.com [Thu, 16 Oct 2003 13:31:22 +0000 (13:31 +0000)]
removing references to my netscape.com address, since it no longer works
jocuri%softhome.net [Sat, 11 Oct 2003 05:20:24 +0000 (05:20 +0000)]
Bug 221626: Fix for Mozilla-specific report template; patch by rillian@telus.net (Ralph Giles); r=justdave a=justdave.
jocuri%softhome.net [Wed, 8 Oct 2003 03:43:00 +0000 (03:43 +0000)]
Bug 219724: typo in URL in section 4.2.5 of the guide; r=kiko, a=justdave.
jocuri%softhome.net [Wed, 8 Oct 2003 02:37:09 +0000 (02:37 +0000)]
Bug 213384: shutdownhtml login bypass via editparams.cgi is broken under suexec. r=kiko, a=justdave
justdave%syndicomm.com [Sun, 28 Sep 2003 12:25:18 +0000 (12:25 +0000)]
Bug 219508: processmail rescanall would not send e-mails about more than one bug to the same address
r=preed, a=justdave
justdave%syndicomm.com [Fri, 26 Sep 2003 05:29:46 +0000 (05:29 +0000)]
Bug 217422: "0" is missing in "votes: 0" (MySQL 4 Compatibility)
r= bbaetz, a= justdave
justdave%syndicomm.com [Fri, 26 Sep 2003 02:39:37 +0000 (02:39 +0000)]
Bug 160422: If versioncache isn't readable, pretend it doesn't exist and recreate it. This tends to happen after cron jobs run as a user other than the webserver.
r=myk, a=justdave
justdave%syndicomm.com [Mon, 1 Sep 2003 08:28:14 +0000 (08:28 +0000)]
Bug 177828: Fixes taint warning from post_bug with perl 5.8
r= bbaetz, a= justdave
justdave%syndicomm.com [Sat, 9 Aug 2003 07:16:16 +0000 (07:16 +0000)]
take 2 - fix tinderbox bustage
justdave%syndicomm.com [Sat, 9 Aug 2003 07:10:45 +0000 (07:10 +0000)]
fix bustage
justdave%syndicomm.com [Sat, 9 Aug 2003 06:06:13 +0000 (06:06 +0000)]
Bug 212095: DBD::mysql versions after 2.1026 return the table list quoted, which broke the existing "table exists" check.
r= jouni, a= justdave
preed%sigkill.com [Thu, 24 Jul 2003 07:52:24 +0000 (07:52 +0000)]
Bug 146087 - 'sendmailnow' should be on by default. Original patch by jocuri@softhome.net (Vlad Dascalu), updated patch by me; r=justdave/preed, a=justdave(ish)
jake%bugzilla.org [Fri, 13 Jun 2003 23:36:28 +0000 (23:36 +0000)]
Optionally create a PDF version of the docs.
jake%bugzilla.org [Tue, 6 May 2003 11:51:11 +0000 (11:51 +0000)]
Picking up recent changes from the XML source
jake%bugzilla.org [Tue, 6 May 2003 11:44:32 +0000 (11:44 +0000)]
Bug 190864 - Fix the ordering of the ' and >.
burnus%gmx.de [Sat, 26 Apr 2003 21:15:54 +0000 (21:15 +0000)]
Bug 203318 - 008filter.t fails to do chdir $topdir - if @Support::Templates::include_paths returns more than one path
r=justdave,gerv
a=justdave
jake%bugzilla.org [Sat, 26 Apr 2003 09:58:47 +0000 (09:58 +0000)]
Bug 203160 - mod_throttle has a new URL
justdave%syndicomm.com [Fri, 25 Apr 2003 13:37:23 +0000 (13:37 +0000)]
Release notes for 2.16.3
bbaetz%acm.org [Fri, 25 Apr 2003 11:18:13 +0000 (11:18 +0000)]
Bug 172331 - importxml.pl warnings under perl 5.8
r,a=justdave
bbaetz%acm.org [Fri, 25 Apr 2003 05:36:37 +0000 (05:36 +0000)]
Bug 197153 - Add wording schange requested by reviewer which wasn't in the
patch on the bug, and so wasn't checked in.
r,a=justdave
justdave%syndicomm.com [Fri, 25 Apr 2003 05:03:41 +0000 (05:03 +0000)]
Bumping version number to 2.16.3 for release
justdave%syndicomm.com [Fri, 25 Apr 2003 04:38:33 +0000 (04:38 +0000)]
Fixing tinderbox test failure resulting from the checkin for bug 197153
justdave%syndicomm.com [Fri, 25 Apr 2003 04:15:44 +0000 (04:15 +0000)]
Bug 197153: Fix for insecure temporary filename handling.
Patch by Brad Baetz <bbaetz@acm.org>
r= justdave, gerv
a= justdave
justdave%syndicomm.com [Fri, 25 Apr 2003 04:01:52 +0000 (04:01 +0000)]
Bug 194394: Someone listed as QA contact on a bug could still access a bug with QA contact privileges if "useqacontact" was later disabled via the parameters.
Patch by Brad Baetz <bbaetz@acm.org>
r= justdave
a= justdave
justdave%syndicomm.com [Fri, 25 Apr 2003 03:56:07 +0000 (03:56 +0000)]
Bug 192661: Dependency graphs were printing bug summaries without HTML filtering.
r= bbaetz, gerv
a= justdave
justdave%syndicomm.com [Fri, 25 Apr 2003 03:45:08 +0000 (03:45 +0000)]
Bug 192677: Add new test to flag failure-to-filter situations in the templates, and correct the XSS holes that were discovered as a result of it.
Filter patch by Gervase Markham <gerv@mozilla.org>
Template patches by Gervase Markham <gerv@mozilla.org> and Dave Miller <justdave@netscape.com>
r= gerv, bbaetz, justdave
a= justdave
zach%zachlipton.com [Wed, 23 Apr 2003 21:10:18 +0000 (21:10 +0000)]
Fix (on the 2.16 branch) for bug 160279: checksetup.pl doesn't check permission on data/comments. Patch adds a fixPerms() call for data/comments.
Patch by Steve Wadsworth <sjwadsw@pacbell.net>, r,a=justdave, patch typo fix by me.
jake%bugzilla.org [Wed, 23 Apr 2003 10:22:20 +0000 (10:22 +0000)]
Missed a couple SGML references that should have been changed.
jake%bugzilla.org [Wed, 23 Apr 2003 10:15:36 +0000 (10:15 +0000)]
Realphabatize the directory list.
jake%bugzilla.org [Wed, 23 Apr 2003 09:34:09 +0000 (09:34 +0000)]
Recompile the docs in anticipation of the 2.16.3 release.
jake%bugzilla.org [Wed, 23 Apr 2003 09:28:00 +0000 (09:28 +0000)]
Update the date for the 2.16.3 release.
jake%bugzilla.org [Wed, 23 Apr 2003 09:23:49 +0000 (09:23 +0000)]
The source files for the Bugzilla Guide have long been using the XML version of DocBook but still residing in the sgml/ directory with an extension of .sgml.
In an effort to maintain CVS history, the raw files were copied on the CVS server to the xml/ directory and renamed to have .xml for the extension; any checkins before this one did have the .sgml extension.
jake%bugzilla.org [Tue, 22 Apr 2003 23:12:22 +0000 (23:12 +0000)]
Rewrite the Credits page to match what's on the tip. Also, add a couple glossary links.
bbaetz%acm.org [Mon, 14 Apr 2003 18:50:52 +0000 (18:50 +0000)]
Bug 194125 - CGI.pl perl warning: Character in "c" format wrapped
r,a=justdave
jake%bugzilla.org [Wed, 2 Apr 2003 11:54:06 +0000 (11:54 +0000)]
Bug 195424 - Add a note about new MySQL permissions needed for Bugzilla in MySQL 4.
jake%bugzilla.org [Wed, 2 Apr 2003 09:09:21 +0000 (09:09 +0000)]
Misc. FAQ updates
jake%bugzilla.org [Wed, 2 Apr 2003 08:44:09 +0000 (08:44 +0000)]
Bug 171674 - Adding a section to the Troubleshooting section describing how to fix the File::Temp problems in perl 5.6.0.
bbaetz%acm.org [Sun, 16 Mar 2003 14:19:34 +0000 (14:19 +0000)]
Bug 197180 - long component name not flagged as error
Because of a mismatch between the size of bugs.component and
components.program, this caused silent failures when creating/moving bugs
in that component.
r/a=justdave
jake%bugzilla.org [Wed, 19 Feb 2003 06:09:01 +0000 (06:09 +0000)]
Missed a couple of changes.
jake%bugzilla.org [Wed, 19 Feb 2003 05:58:55 +0000 (05:58 +0000)]
Backport changes to the FAQ from the tip.
jake%bugzilla.org [Wed, 19 Feb 2003 04:59:03 +0000 (04:59 +0000)]
Copy variants section verbatim from the tip.
jake%bugzilla.org [Wed, 19 Feb 2003 04:57:34 +0000 (04:57 +0000)]
The license belongs at the end (in an appendix)
jake%bugzilla.org [Wed, 19 Feb 2003 04:47:15 +0000 (04:47 +0000)]
Backport glossary changes from the tip
justdave%syndicomm.com [Mon, 17 Feb 2003 10:50:58 +0000 (10:50 +0000)]
oops, I accidently eliminated the tests for processmail and syncshadowdb...
justdave%syndicomm.com [Mon, 17 Feb 2003 10:35:54 +0000 (10:35 +0000)]
Updating template testing infrastructure to match all of the tests performed on the trunk (which are still compatible with 2.16). The main benefit is if someone drops in a localized template pack, the tests will also test the localized templates instead of only the English ones. (no bug number)
justdave%syndicomm.com [Mon, 17 Feb 2003 10:33:31 +0000 (10:33 +0000)]
runtests.pl now lets you specify a test number on the command line if you only want to run that specific test instead of all of them. (no bug number)
jake%bugzilla.org [Sun, 16 Feb 2003 23:41:03 +0000 (23:41 +0000)]
Recompile docs for the 2.16.3 release
jake%bugzilla.org [Sun, 16 Feb 2003 23:34:32 +0000 (23:34 +0000)]
Update version information in anticipation for 2.16.3
jake%bugzilla.org [Sun, 16 Feb 2003 05:46:25 +0000 (05:46 +0000)]
Port security section rewrite from bug 191537 to the 2.16 docs.
justdave%syndicomm.com [Wed, 12 Feb 2003 13:05:57 +0000 (13:05 +0000)]
Bug 157704: Deleting a product could potentially remove privileges from administrators.
r= joel, a= justdave
justdave%syndicomm.com [Fri, 7 Feb 2003 08:35:05 +0000 (08:35 +0000)]
adding runtests.pl so the new Tinderbox clients will work
jake%bugzilla.org [Thu, 6 Feb 2003 10:48:45 +0000 (10:48 +0000)]
Bug 191971 - The guide incorrectly stated that you could close a bug by sending an email with the code in contib/
jake%bugzilla.org [Tue, 14 Jan 2003 05:06:08 +0000 (05:06 +0000)]
Bug 188757 - 2.16 shipped with the problem mentioned in bug 174255 and that fix was never ported to 2.16's documentation, so the error was still on bugzilla.org.
jake%bugzilla.org [Mon, 13 Jan 2003 09:19:07 +0000 (09:19 +0000)]
Bug 187566 - Update upgrade section in the 2.16 branch as was done on the tip
justdave%syndicomm.com [Fri, 3 Jan 2003 01:10:56 +0000 (01:10 +0000)]
correcting deprecations
matty%chariot.net.au [Sat, 28 Dec 2002 21:16:37 +0000 (21:16 +0000)]
Release notes updates.
bugreport%peshkin.net [Mon, 23 Dec 2002 09:54:23 +0000 (09:54 +0000)]
Bug 186383 Checksetup leaves editor backups of localconfig accessible (revised)
bugreport%peshkin.net [Mon, 23 Dec 2002 09:53:33 +0000 (09:53 +0000)]
Backing out patch from bug 186383 because it broke quicksearch
bugreport%peshkin.net [Sun, 22 Dec 2002 05:16:49 +0000 (05:16 +0000)]
Bug 186383 Checksetup leaves editor backups of localconfig accessible
r=zach
a=justdave
justdave%syndicomm.com [Fri, 13 Dec 2002 19:30:38 +0000 (19:30 +0000)]
Bumping version number to 2.16.2
justdave%syndicomm.com [Fri, 13 Dec 2002 19:02:26 +0000 (19:02 +0000)]
Bug 183188: collectstats.pl no longer makes data/mining world-readable
patch by Christian Franke <Franke@computer.org>
r= bbaetz, justave a= justdave
justdave%syndicomm.com [Wed, 27 Nov 2002 04:32:00 +0000 (04:32 +0000)]
Bug 179329: filter HTML from quips in "show all the quips"
matty%chariot.net.au [Sun, 29 Sep 2002 12:24:53 +0000 (12:24 +0000)]
Release notes.
preed%sigkill.com [Sun, 29 Sep 2002 06:54:50 +0000 (06:54 +0000)]
Bumping the rev number for the 2.16.1 release
bugreport%peshkin.net [Wed, 25 Sep 2002 11:03:00 +0000 (11:03 +0000)]
Bug 166023 - On failure in template->new, a template is used to display error
r=bbaetz
preed%sigkill.com [Mon, 23 Sep 2002 00:47:12 +0000 (00:47 +0000)]
Bug 167485; group_id is wrong when usebuggroups is on; patch=joel, r=bbaetz/preed
bbaetz%student.usyd.edu.au [Tue, 3 Sep 2002 14:24:54 +0000 (14:24 +0000)]
Bug 161203 - Bug changes with intermediate pages munges fields with
multiple values (e.g., CC)
original patch by randall_gee_51227124@yahoo.com (Randall M! Gee),
r=bbaetz, myk
Ported to 2.16 by me, r=preed x2
bbaetz%student.usyd.edu.au [Tue, 3 Sep 2002 13:39:06 +0000 (13:39 +0000)]
bug 163024 - bugzilla_email_append calls processmail incorrectly
r=joel, preed
preed%sigkill.com [Fri, 30 Aug 2002 22:29:24 +0000 (22:29 +0000)]
Bug 165221: Apostrophes not properly handled during account creation. r=joel,r2=bbaetz
bugreport%peshkin.net [Sun, 25 Aug 2002 23:50:08 +0000 (23:50 +0000)]
Bug 164464 - Importxml will fail if versioncache needs update
r=bbaetz, timeless
bbaetz%student.usyd.edu.au [Sat, 17 Aug 2002 21:24:09 +0000 (21:24 +0000)]
bug 160631 - bug_email.pl is broken
r=joel x2
bbaetz%student.usyd.edu.au [Thu, 15 Aug 2002 06:32:04 +0000 (06:32 +0000)]
Bug 151619 - Problem with the regex in checksetup.pl to find dependancies
r=jouni, joel
bbaetz%student.usyd.edu.au [Tue, 13 Aug 2002 13:57:00 +0000 (13:57 +0000)]
Bug 160710 - Taint checking causes problem with rename function
r=joel, preed
bbaetz%student.usyd.edu.au [Thu, 8 Aug 2002 07:41:33 +0000 (07:41 +0000)]
Bug 161304 - SQL error with allowemailchange with mysql 3.22
r=justdave x2
bbaetz%student.usyd.edu.au [Thu, 1 Aug 2002 16:59:32 +0000 (16:59 +0000)]
Bug 160227 - VERSION cookie not set correctly
r=myk x2