]>
git.ipfire.org Git - thirdparty/bugzilla.git/log
Frédéric Buclin [Tue, 2 Nov 2010 23:12:13 +0000 (00:12 +0100)]
Bug 419014: (CVE-2010-3764) [SECURITY] Old charts are not project specific, and product names are viewable in graphs/
r=wurblzap a=LpSolit
Max Kanat-Alexander [Mon, 1 Nov 2010 06:52:34 +0000 (23:52 -0700)]
Bug 608645: Release Notes for Bugzilla 3.4.9
r=LpSolit, a=LpSolit
A. Shimono (himorin) [Sun, 19 Sep 2010 00:11:32 +0000 (02:11 +0200)]
Bug 589547: Wrong description for editing a flag
r/a=LpSolit
A. Shimono (himorin) [Sun, 19 Sep 2010 00:00:50 +0000 (02:00 +0200)]
Bug 589525: fix typo
r/a=LpSolit
Max Kanat-Alexander [Fri, 6 Aug 2010 02:30:18 +0000 (19:30 -0700)]
Bump version number post-release.
Max Kanat-Alexander [Fri, 6 Aug 2010 01:14:04 +0000 (18:14 -0700)]
Bump the version number for 3.4.8.
https://bugzilla.mozilla.org/show_bug.cgi?id=580206
Frédéric Buclin [Wed, 4 Aug 2010 22:15:55 +0000 (00:15 +0200)]
Bug 583690: (CVE-2010-2759) [SECURITY][PostgreSQL] Bugzilla crashes when viewing a bug if a comment contains 'bug <num>' or 'attachment <num>' where <num> is greater than the max allowed integer
r=mkanat a=LpSolit
Frédéric Buclin [Wed, 4 Aug 2010 21:58:19 +0000 (23:58 +0200)]
Bug 577139: (CVE-2010-2758) [SECURITY] request.cgi and duplicates.cgi let you know whether a product exists or not
r=mkanat a=LpSolit
Frédéric Buclin [Wed, 4 Aug 2010 21:46:06 +0000 (23:46 +0200)]
Bug 450013: (CVE-2010-2757) [SECURITY] Can sudo a user without sending email
r=glob a=LpSolit
Frédéric Buclin [Wed, 4 Aug 2010 21:33:33 +0000 (23:33 +0200)]
Bug 417048: (CVE-2010-2756) [SECURITY] Boolean charts let me query for users being in any given group
r=mkanat a=LpSolit
Max Kanat-Alexander [Wed, 4 Aug 2010 18:15:10 +0000 (11:15 -0700)]
Bug 584428: Release Notes for Bugzilla 3.4.8
r=LpSolit
Frédéric Buclin [Thu, 15 Jul 2010 11:07:48 +0000 (13:07 +0200)]
Bug 455585: Installation docs should recommend using package management instead of CPAN
r=glob
Frédéric Buclin [Thu, 15 Jul 2010 10:51:19 +0000 (12:51 +0200)]
Bug 193193: Better explain what the checkboxes in Edit Users-Group Access/Privileges are for
r=glob
Frédéric Buclin [Thu, 15 Jul 2010 10:34:53 +0000 (12:34 +0200)]
Bug 472452: Rephrase documentation about deleting custom fields
r=glob
Frédéric Buclin [Tue, 13 Jul 2010 23:11:42 +0000 (01:11 +0200)]
Bug 536183: Docs claim bug lifecycle is "hard-coded" despite that's no longer true
r=gerv a=mkanat
Frédéric Buclin [Tue, 13 Jul 2010 22:37:36 +0000 (00:37 +0200)]
Bug 577851: config.cgi crashes in 3.4.7, due to Bugzilla::Product::preload (backout of bug 553255)
r/a=mkanat
Frédéric Buclin [Tue, 13 Jul 2010 08:38:14 +0000 (10:38 +0200)]
Bug 236651: Remove obsolete instructions from the "2.1.5 Perl Modules" section
r=reed
Max Kanat-Alexander [Thu, 24 Jun 2010 23:15:18 +0000 (16:15 -0700)]
Bump version number post-release
Max Kanat-Alexander [Thu, 24 Jun 2010 20:44:26 +0000 (13:44 -0700)]
Bump the version number for 3.4.7.
https://bugzilla.mozilla.org/show_bug.cgi?id=559988
Max Kanat-Alexander [Thu, 24 Jun 2010 17:09:26 +0000 (10:09 -0700)]
Bug 309952: (CVE-2010-1204) [SECURITY] Protect boolean chart searches for
time-tracking fields from being used by users who are not in the
timetrackinggroup.
r=LpSolit, a=mkanat
Max Kanat-Alexander [Tue, 22 Jun 2010 04:08:55 +0000 (21:08 -0700)]
Bug 566198: Release Notes for Bugzilla 3.4.7
r=LpSolit, a=mkanat
Frédéric Buclin [Thu, 8 Apr 2010 10:32:16 +0000 (12:32 +0200)]
Bug 284650: Beginning a chart name with an "_" (underscore) causes errors
r=mkanat a=LpSolit
Frédéric Buclin [Wed, 7 Apr 2010 01:02:55 +0000 (03:02 +0200)]
Bug 557686: PostgreSQL crashes when deleting a custom field of type Date/Time
r=mkanat a=LpSolit
Frédéric Buclin [Tue, 6 Apr 2010 23:58:46 +0000 (01:58 +0200)]
Bug 557495: PostgreSQL crashes when deleting a custom field of type BugID
r/a=mkanat
Frank Becker [Fri, 2 Apr 2010 12:49:22 +0000 (14:49 +0200)]
Bug 515515: For clients, mid-air collision results when user's timezone preference differs from server's
r/a=mkanat
Tiago Mello [Mon, 29 Mar 2010 12:36:02 +0000 (14:36 +0200)]
Bug 548327: Administration page should have hooks to extend the admin links
r/a=mkanat
Guy Pyrzak [Sun, 28 Mar 2010 21:45:24 +0000 (14:45 -0700)]
Bug 548975: Under trunk Firefox builds with Direct2D enabled on Windows,
<dt> tags were overly bold
r=mkanat, a=mkanat
Reed Loden [Sun, 28 Mar 2010 06:30:56 +0000 (01:30 -0500)]
Bug 549814 - "Internal error when using login fields in header/footer after visiting token.cgi URL"
[r=mkanat a=mkanat]
Reed Loden [Sun, 28 Mar 2010 04:38:48 +0000 (23:38 -0500)]
Bug 533927 - "email address domain filtering is applying to non-email fields in the history"
[r=LpSolit a=LpSolit]
Max Kanat-Alexander [Thu, 18 Mar 2010 13:56:55 +0000 (06:56 -0700)]
Bug 553267: Allow specifying that you don't want flag data, for config.cgi
r=gerv, a=mkanat
Max Kanat-Alexander [Thu, 18 Mar 2010 13:17:35 +0000 (06:17 -0700)]
Bug 553255: Make config.cgi use Bugzilla::Product::preload, for a small
performance improvement
r=gerv, a=mkanat
Max Kanat-Alexander [Wed, 17 Mar 2010 08:38:32 +0000 (01:38 -0700)]
Bug 538705: Prevent database connections from timing out during long
jobqueue.pl runs.
r=LpSolit, a=mkanat
Frédéric Buclin [Mon, 15 Mar 2010 14:27:10 +0000 (15:27 +0100)]
Bug 552349: A lot of errors are thrown when an Atom feed queries Bugzilla
r/a=mkanat
Max Kanat-Alexander [Sun, 14 Mar 2010 00:35:31 +0000 (16:35 -0800)]
Bug 498309: Speed up show_bug when there are many comments by caching the
results of get_text calls in Bugzilla::Template, and removing the call
to field-descs.none.tmpl from format_comment.txt.tmpl.
r=LpSolit, a=LpSolit
Max Kanat-Alexander [Tue, 9 Mar 2010 17:59:30 +0000 (09:59 -0800)]
Bump version number post-release.
Max Kanat-Alexander [Tue, 9 Mar 2010 06:53:37 +0000 (22:53 -0800)]
Bug 374632: A separate script just to fix file/directory permissions
r=mkanat, a=mkanat (module owner)
Max Kanat-Alexander [Tue, 9 Mar 2010 04:31:31 +0000 (20:31 -0800)]
Bug 551104: Don't install DBD::Pg when using install-module.pl --all unless
the PostgreSQL devel files are actually installed.
r=mkanat, a=mkanat (module owner)
Max Kanat-Alexander [Mon, 8 Mar 2010 07:49:28 +0000 (23:49 -0800)]
Bump version number for 3.4.6.
https://bugzilla.mozilla.org/show_bug.cgi?id=547465
Max Kanat-Alexander [Mon, 8 Mar 2010 02:46:49 +0000 (18:46 -0800)]
Remove CVS "$Id" markers in files. The CVS mirror of bzr was showing
the docs' about.xml and installation.xml being modified on every commit
because of these markers, and the rest of them are simply unnecessary.
Max Kanat-Alexander [Mon, 8 Mar 2010 02:34:13 +0000 (18:34 -0800)]
Bug 549482: Release Notes for Bugzilla 3.4.6
r=LpSolit
Frédéric Buclin [Mon, 8 Mar 2010 01:28:54 +0000 (02:28 +0100)]
Bug 549588: Documentation incorrectly refers to localconfig for priorities, severities, platforms and operating systems
r=glob
Frédéric Buclin [Mon, 8 Mar 2010 01:15:47 +0000 (02:15 +0100)]
Bug 549671: The "1.3. New Versions" section is out-of-date
r=glob
Frédéric Buclin [Mon, 8 Mar 2010 00:51:56 +0000 (01:51 +0100)]
Bug 542464: Dependency graphs cannot be displayed when bug summaries contain UTF8 characters
r/a=mkanat
Frédéric Buclin [Sun, 7 Mar 2010 16:37:03 +0000 (17:37 +0100)]
Bug 549685: Update the list of required and optional Perl modules
r=ghendricks a=LpSolit
David Lawrence [Fri, 5 Mar 2010 18:49:28 +0000 (13:49 -0500)]
Bug 513989 - large search query causing internal server error (500) but valid redirect 302 returned
Decreased CGI_URI_LIMIT to 8000 instead of 10000
a=mkanat
Dave Lawrence [Wed, 3 Mar 2010 21:23:07 +0000 (16:23 -0500)]
Bug 513989 - large search query causing internal server error (500) but valid redirect 302 returned
r=mkanat, a=mkanat
Max Kanat-Alexander [Sun, 28 Feb 2010 23:59:14 +0000 (15:59 -0800)]
Bug 548933: The "Mark as Duplicate" link was changing bugs to RESOLVED FIXED
r=pyrzak, a=mkanat
Max Kanat-Alexander [Sun, 28 Feb 2010 23:18:33 +0000 (15:18 -0800)]
Bug 474738: Make all of the "not" search types show up in search descriptions
r=LpSolit, a=LpSolit
Reed Loden [Sun, 28 Feb 2010 20:15:34 +0000 (14:15 -0600)]
Bug 537834 - "Buglist results using atom ctype do not display users with empty real names"
[r=LpSolit a=LpSolit]
Reed Loden [Sun, 28 Feb 2010 20:09:41 +0000 (14:09 -0600)]
Bug 549177 - "Typo in admin.cgi page header"
[r=LpSolit a=LpSolit]
Max Kanat-Alexander [Wed, 24 Feb 2010 23:41:34 +0000 (15:41 -0800)]
Some lines in the release notes started with a "[% terms" item but didn't
have [%+ on them, so the words would get crunched together, like "thisBugzilla".
Guy Pyrzak [Thu, 18 Feb 2010 19:01:41 +0000 (20:01 +0100)]
Bug 546763: Extra spaces when copying bug header
r=reed a=mkanat
Guy Pyrzak [Thu, 18 Feb 2010 18:57:54 +0000 (19:57 +0100)]
Bug 546719: When reopening a Resolved Duplicated bug in IE, JS error stops the correct page behavior
r/a=mkanat
Frédéric Buclin [Thu, 18 Feb 2010 00:19:45 +0000 (01:19 +0100)]
Bug 533018: "Confirm match" displays full email address to logged-out users in request.cgi
r/a=mkanat
Gordon P. Hemsley [Wed, 17 Feb 2010 22:38:46 +0000 (14:38 -0800)]
Bug 546338: Fix an unclosed <a> tag in fields.html
r=mkanat, a=mkanat
Max Kanat-Alexander [Wed, 17 Feb 2010 22:07:00 +0000 (14:07 -0800)]
Bug 538211: Make value-controlled and visibility-controlled fields behave
correctly on enter_bug.cgi when the user uses a bookmarkable template to
pre-fill values in the controller.
r=LpSolit, a=LpSolit
Reed Loden [Thu, 11 Feb 2010 19:34:50 +0000 (13:34 -0600)]
Bug 545695 - "show_bug.cgi: Use of uninitialized value"
[r=LpSolit a=LpSolit]
Max Kanat-Alexander [Wed, 10 Feb 2010 05:16:00 +0000 (21:16 -0800)]
Bug 545277: Closed bugs were always marked as FIXED in the resolution
<select> when show_bug.cgi was loaded
r=LpSolit, a=mkanat
Max Kanat-Alexander [Mon, 8 Feb 2010 23:44:48 +0000 (15:44 -0800)]
Bug 520993: If the "FIXED" resolution was a visibility or value controller,
then controlled fields weren't properly changing when the status changed to
RESOLVED and "FIXED" appeared as the first value in the Resolution field.
r=LpSolit, a=mkanat
Max Kanat-Alexander [Mon, 8 Feb 2010 04:04:28 +0000 (20:04 -0800)]
Bug 544812: Template hooks for reports/menu.html.tmpl
r=mkanat, a=mkanat (module owner)
Frédéric Buclin [Sat, 6 Feb 2010 18:04:07 +0000 (19:04 +0100)]
Bug 515568: handle_login() doesn't check $@ after eval
r/a=mkanat
Frédéric Buclin [Thu, 4 Feb 2010 22:29:31 +0000 (23:29 +0100)]
Bug 470214: Query sorting by multiple columns sometimes loses a column
r=ghendricks a=LpSolit
Max Kanat-Alexander [Thu, 4 Feb 2010 02:04:45 +0000 (18:04 -0800)]
Update .bzrignore to properly exclude the contents of lib/.
Max Kanat-Alexander [Mon, 1 Feb 2010 22:30:56 +0000 (14:30 -0800)]
Bump version number post-release.
Max Kanat-Alexander [Mon, 1 Feb 2010 22:29:54 +0000 (14:29 -0800)]
Convert .cvsignore files into a .bzrignore.
Max Kanat-Alexander [Mon, 1 Feb 2010 21:44:51 +0000 (13:44 -0800)]
Fix the data in the bzr repo to match the data in the CVS repo.
During the CVS imports into Bzr, there were some inconsistencies introduced
(mostly that files that were deleted in CVS weren't being deleted in Bzr).
So this checkin makes the bzr repo actually consistent with the CVS repo,
including fixing permissions of files.
Max Kanat-Alexander [Mon, 1 Feb 2010 21:32:08 +0000 (13:32 -0800)]
Bump version number for 3.4.5.
Reed Loden [Mon, 1 Feb 2010 21:27:56 +0000 (13:27 -0800)]
Bug 434801: [SECURITY] .htaccess doesn't prevent reading old-params.txt from the web
Patch by Reed Loden <reed@reedloden.com> r=mkanat a=LpSolit
Max Kanat-Alexander [Mon, 1 Feb 2010 21:24:07 +0000 (13:24 -0800)]
Bug 314871: (CVE-2009-3989) [SECURITY] Prevent web browsers from accessing CVS/, contrib/, docs/, and t/ directories
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit
Frédéric Buclin [Mon, 1 Feb 2010 21:21:21 +0000 (13:21 -0800)]
Bug 532493: [SECURITY] Restricting a bug to a group while moving it to another product has no effect if the group is not used by both products
Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=LpSolit
Max Kanat-Alexander [Mon, 1 Feb 2010 20:53:59 +0000 (12:53 -0800)]
Bug 543342: Release Notes for Bugzilla 3.4.5
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=mkanat
Frédéric Buclin [Mon, 1 Feb 2010 20:49:32 +0000 (12:49 -0800)]
Bug 533363: [PostgreSQL] Using "Bug ID contains foo" in boolean charts or "Exclude bug numbered" charts crash PostgreSQL 8.3 and newer (non-character data types are no longer automatically cast to TEXT)
Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
Max Kanat-Alexander [Mon, 1 Feb 2010 17:54:47 +0000 (09:54 -0800)]
Bug 480968: Make checksetup.pl never show popup windows for errors, on Windows, to work around the error that pops up every time it tries to load DBD::Oracle.
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=Wurblzap, a=mkanat
lpsolit%gmail.com [Tue, 12 Jan 2010 16:12:59 +0000 (16:12 +0000)]
Bug 509030: "Changes older than" in Advanced Search is sometimes ignored - Patch by Frédéric Buclin <LpSolit@gmail.com> r=gerv a=LpSolit
gerv%gerv.net [Thu, 7 Jan 2010 15:05:38 +0000 (15:05 +0000)]
Bug 514703 - revert changes to bug link detection algorithm. r,a=LpSolit.
lpsolit%gmail.com [Wed, 6 Jan 2010 15:00:47 +0000 (15:00 +0000)]
Bug 535675: Typing +foo in the QuickSearch box throws an "uninitialized value" warning (missing 'order' parameter) - Patch by Frédéric Buclin <LpSolit@gmail.com> r=wicked a=LpSolit
lpsolit%gmail.com [Tue, 5 Jan 2010 23:54:08 +0000 (23:54 +0000)]
Bug 538039: Typo when deleting a custom field value - Patch by Frédéric Buclin <LpSolit@gmail.com> r=reed a=LpSolit
reed%reedloden.com [Tue, 5 Jan 2010 07:07:46 +0000 (07:07 +0000)]
Bug 534587 - "Bugmail uses the timezone of the changee instead of the user receiving the mail" [p=reed r=mkanat a=mkanat]
lpsolit%gmail.com [Thu, 31 Dec 2009 12:18:06 +0000 (12:18 +0000)]
Bug 385606: Logincookies are recreated at each HTTP request when using the 'Env' auth method - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
lpsolit%gmail.com [Thu, 31 Dec 2009 12:04:28 +0000 (12:04 +0000)]
Bug 537328: Clicking 'reply' shouldn't add anything to my history - Patch by Paul O'Shannessy [:zpao] <paul@oshannessy.com> r=LpSolit a=mkanat
lpsolit%gmail.com [Wed, 30 Dec 2009 14:31:32 +0000 (14:31 +0000)]
Bug 483987: Administrators can't create user accounts when using the Env authentication method - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
lpsolit%gmail.com [Mon, 28 Dec 2009 01:00:48 +0000 (01:00 +0000)]
Bug 511216: Assignee is blank in Whine emails - Patch by Kent Rogers <kar@cray.com> r/a=LpSolit
wicked%sci.fi [Sun, 27 Dec 2009 14:33:11 +0000 (14:33 +0000)]
Bug 475523: Fix instructions on whineatnews email to refer to correct show_bug options. Patch by Kent Rogers <kar@cray.com> r=wicked a=mkanat
mkanat%bugzilla.org [Tue, 15 Dec 2009 01:52:16 +0000 (01:52 +0000)]
After the checkin of bug 524603, checksetup.pl printed "No such file or directory at Bugzilla/Install/Filesystem.pm line 465" the first time the new code was run. This fixes the warning.
mkanat%bugzilla.org [Mon, 14 Dec 2009 23:13:26 +0000 (23:13 +0000)]
Bug 524603: Allow a non-root jobqueue.pl to write to data/mailer.testfile (for the "Test" mail_delivery_method)
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit
mkanat%bugzilla.org [Fri, 4 Dec 2009 14:47:37 +0000 (14:47 +0000)]
Bug 531500: Allow the mailer-before_send hook to modify the arguments passed to Email::Send
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=dkl, a=mkanat
lpsolit%gmail.com [Mon, 23 Nov 2009 22:42:46 +0000 (22:42 +0000)]
Bug 529863: The product list when listing all flagtypes in editflagtypes.cgi is empty after editing them - Patch by Frédéric Buclin <LpSolit@gmail.com> r=ghendricks a=LpSolit
lpsolit%gmail.com [Sun, 22 Nov 2009 22:26:03 +0000 (22:26 +0000)]
Bug 530270: Whining fails if mail queueing is enabled - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=LpSolit
mkanat%bugzilla.org [Thu, 19 Nov 2009 05:05:15 +0000 (05:05 +0000)]
Bump version number post-release.
mkanat%bugzilla.org [Thu, 19 Nov 2009 02:12:01 +0000 (02:12 +0000)]
Bug 529416: (CVE-2009-3386) [SECURITY] Dependency lists display bug aliases even for bugs the user cannot access
Patch by Dave Miller <justdave@bugzilla.org> r=LpSolit, a=mkanat
reed%reedloden.com [Wed, 18 Nov 2009 18:25:45 +0000 (18:25 +0000)]
Bug 360626 - "ThrowTemplateError() used in Util.pm" [p=reed r=LpSolit a=LpSolit]
mkanat%bugzilla.org [Wed, 18 Nov 2009 06:55:44 +0000 (06:55 +0000)]
Bug 529483: Release Notes for Bugzilla 3.4.4
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=reed
mkanat%bugzilla.org [Wed, 18 Nov 2009 06:31:59 +0000 (06:31 +0000)]
Bug 526189: Silently ignore any attempts to add an inactive group to a bug, which fixes the fact that mandatory groups were being added to bugs when changing products, even if they were inactive (not used for bugs).
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit
lpsolit%gmail.com [Mon, 16 Nov 2009 11:21:29 +0000 (11:21 +0000)]
Bug 475234: OS sniffing doesn't detect Windows 7 - Patch by Siddharth Agarwal [:sid0] <sid.bugzilla@gmail.com> r=timeless a=LpSolit
mkanat%bugzilla.org [Thu, 5 Nov 2009 18:56:34 +0000 (18:56 +0000)]
Bump version number post-release.
mkanat%bugzilla.org [Thu, 5 Nov 2009 12:34:12 +0000 (12:34 +0000)]
Fix an 009bugwords runtests.pl failure related to the release-notes.
mkanat%bugzilla.org [Thu, 5 Nov 2009 12:26:05 +0000 (12:26 +0000)]
Bump version number for 3.4.3.
mkanat%bugzilla.org [Thu, 5 Nov 2009 12:16:14 +0000 (12:16 +0000)]
Add bug 525025 to the 3.4.3 release notes.
lpsolit%gmail.com [Tue, 3 Nov 2009 23:50:20 +0000 (23:50 +0000)]
Bug 525254: editproducts.cgi shouldn't display the "Edit classification 'Foo'" link if you haven't editclassifications privs - Patch by Frédéric Buclin <LpSolit@gmail.com> r=ghendricks a=LpSolit
mkanat%bugzilla.org [Sun, 1 Nov 2009 20:14:11 +0000 (20:14 +0000)]
Bug 524891: Make leading whitespace not be trimmed from comments on display.
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=mkanat