]>
git.ipfire.org Git - thirdparty/bugzilla.git/log
David Lawrence [Wed, 14 May 2014 20:49:21 +0000 (16:49 -0400)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
- Only run webservices for Pg with Perl 5.12 due to interaction bug in
5.10
David Lawrence [Thu, 8 May 2014 20:38:41 +0000 (20:38 +0000)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
- Added the PostgreSQL webservices/selenium tests
David Lawrence [Wed, 7 May 2014 16:15:25 +0000 (16:15 +0000)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
David Lawrence [Fri, 2 May 2014 20:33:58 +0000 (20:33 +0000)]
Bug 995209 - Create a Build.PL script using Module::Build for testing/installing/packaging of Bugzilla code
- Fixed incorrect package name Apache-SizeLimit
David Lawrence [Fri, 2 May 2014 15:59:42 +0000 (15:59 +0000)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
David Lawrence [Thu, 1 May 2014 20:56:44 +0000 (20:56 +0000)]
Bug 995209 - Create a Build.PL script using Module::Build for testing/installing/packaging of Bugzilla code
r=glob,a=justdave
David Lawrence [Mon, 21 Apr 2014 21:05:14 +0000 (21:05 +0000)]
Bumped version post-release
David Lawrence [Fri, 18 Apr 2014 22:12:01 +0000 (22:12 +0000)]
Bump version to 4.2.9
Frédéric Buclin [Fri, 18 Apr 2014 21:49:16 +0000 (23:49 +0200)]
Bug 998484: Release notes for Bugzilla 4.2.9
r=dkl a=justdave
David Lawrence [Fri, 18 Apr 2014 21:03:43 +0000 (21:03 +0000)]
Bug 998323 - URLs pasted in comments are no longer displayed
r=LpSolit,a=justdave
David Lawrence [Thu, 17 Apr 2014 21:26:58 +0000 (21:26 +0000)]
Bumped version post-release
David Lawrence [Thu, 17 Apr 2014 17:13:45 +0000 (17:13 +0000)]
Bump version to 4.2.8
Manish Goregaokar [Thu, 17 Apr 2014 16:37:11 +0000 (18:37 +0200)]
Bug 968576: [SECURITY] Dangerous control characters allowed in Bugzilla text
r=glob a=justdave
Frédéric Buclin [Tue, 15 Apr 2014 21:53:26 +0000 (23:53 +0200)]
Bug 996168: Release notes for Bugzilla 4.2.8
r=dkl a=justdave
David Lawrence [Fri, 14 Mar 2014 18:16:05 +0000 (18:16 +0000)]
Copied over .bzrignore to .gitignore
Frédéric Buclin [Sat, 21 Dec 2013 16:45:40 +0000 (17:45 +0100)]
Bug 748095: Bugzilla crashes when the shutdownhtml parameter is set and using a non-cookie based authentication method
r=dkl a=justdave
Frédéric Buclin [Thu, 5 Dec 2013 22:43:34 +0000 (23:43 +0100)]
Bug 942599: Documentation about possible_duplicates() lists 'products' as argument instead of 'product'
r=dkl a=justdave
Frédéric Buclin [Mon, 2 Dec 2013 16:07:30 +0000 (17:07 +0100)]
Bug 938300: vers_cmp() incorrectly compares module versions
r=sgreen a=justdave
Frédéric Buclin [Mon, 2 Dec 2013 16:00:20 +0000 (17:00 +0100)]
Bug 781672: checksetup.pl fails to check the version of the latest Apache2::SizeLimit release (it throws "Invalid version format (non-numeric data)")
r=dkl a=justdave
Frédéric Buclin [Thu, 14 Nov 2013 17:01:14 +0000 (18:01 +0100)]
Bug 938161: sql_date_format() method for SQLite has an incorrect default format
r/a=glob
Frédéric Buclin [Wed, 13 Nov 2013 15:18:48 +0000 (16:18 +0100)]
Bug 843457: PROJECT environment variable is not honored when mod_perl is enabled
r/a=glob
Dave Lawrence [Thu, 17 Oct 2013 15:10:35 +0000 (11:10 -0400)]
Bump version post-release
Dave Lawrence [Wed, 16 Oct 2013 20:36:32 +0000 (16:36 -0400)]
Bump version to 4.2.7
Frédéric Buclin [Wed, 16 Oct 2013 17:26:25 +0000 (19:26 +0200)]
Bug 924932: (CVE-2013-1743) [SECURITY] Field values are (still) not escaped correctly in tabular reports
r=dkl a=glob
Frédéric Buclin [Wed, 16 Oct 2013 17:19:12 +0000 (19:19 +0200)]
Bug 924802: (CVE-2013-1742) [SECURITY] (XSS) "id" and "sortkey" are not sanitized when editing flag types if categoryAction-foo is set
r=dkl a=glob
Frédéric Buclin [Wed, 16 Oct 2013 17:08:20 +0000 (19:08 +0200)]
Bug 913904: (CVE-2013-1734) [SECURITY] CSRF when updating attachments
r=dkl a=sgreen
Dave Lawrence [Wed, 16 Oct 2013 16:27:00 +0000 (12:27 -0400)]
Bug 906745 - In MySQL, tokens are not case-sensitive, reducing total entropy and allowing easier brute force
r=LpSolit,a=sgreen
Dave Lawrence [Wed, 16 Oct 2013 16:14:11 +0000 (12:14 -0400)]
Bug 907438 - In MySQL, login cookie checking is not case-sensitive, reducing total entropy and allowing easier brute force
r=LpSolit,a=sgreen
Dave Lawrence [Wed, 16 Oct 2013 16:05:10 +0000 (12:05 -0400)]
Bug 906745 - In MySQL, tokens are not case-sensitive, reducing total entropy and allowing easier brute force
r=LpSolit,a=glob
Frédéric Buclin [Fri, 11 Oct 2013 22:13:42 +0000 (00:13 +0200)]
Bug 912640: Release notes for Bugzilla 4.2.7
r=dkl a=LpSolit
Frédéric Buclin [Thu, 26 Sep 2013 23:22:30 +0000 (01:22 +0200)]
Bug 914262: KHTML-based browsers such as Konqueror do not support the Server-Push technology
r=dkl a=justdave
Jiří Netolický [Mon, 23 Sep 2013 15:44:20 +0000 (17:44 +0200)]
Bug 919475: [Oracle] Crash when non-mandatory free text custom fields are left empty on bug creation
r=LpSolit a=justdave
Mateusz Kuśmierczyk [Tue, 3 Sep 2013 09:45:44 +0000 (11:45 +0200)]
Bug 848063: [Oracle] importxml.pl fails with ORA-01830: comment timestamps are not correctly formatted
r=LpSolit a=sgreen
Frédéric Buclin [Sat, 10 Aug 2013 00:45:28 +0000 (02:45 +0200)]
Back out bug 868330 for the 4.2 branch. This is not a security fix
Frédéric Buclin [Fri, 9 Aug 2013 09:30:58 +0000 (11:30 +0200)]
Bug 902515: Internet Explorer 11 receives multipart/x-mixed-replace content from buglist.cgi
r=dkl a=sgreen
Sunil Joshi [Fri, 9 Aug 2013 04:02:41 +0000 (14:02 +1000)]
Bug 868330 - Password creation directions incomplete
r=sgreen, a=sgreen
Simon Green [Fri, 9 Aug 2013 03:57:38 +0000 (13:57 +1000)]
Bug 897264 - letters_numbers_specialchars password restriction is incorrect
r=LpSolit, a=sgreen
Sunil Joshi [Wed, 7 Aug 2013 05:29:13 +0000 (15:29 +1000)]
Bug 901620 - Grammar error in the documentation
r=sgreen, a=glob
Dave Lawrence [Wed, 24 Jul 2013 14:19:05 +0000 (10:19 -0400)]
Bug 880653 - Add POD for Bug.possible_duplicates webservice
r=LpSolit,a=sgreen
Dave Lawrence [Mon, 15 Jul 2013 03:47:22 +0000 (23:47 -0400)]
Bug 787328 - xmlrpc.cgi doesn't send any security-related headers
r=glob,a=justdave
Dave Lawrence [Wed, 22 May 2013 20:09:47 +0000 (16:09 -0400)]
Bump version post-release
Dave Lawrence [Wed, 22 May 2013 18:46:58 +0000 (14:46 -0400)]
Bump version to 4.2.6
Byron Jones [Wed, 22 May 2013 17:03:13 +0000 (01:03 +0800)]
Bug 828344: add missing xt broken tests
Byron Jones [Mon, 20 May 2013 17:54:06 +0000 (01:54 +0800)]
Bug 828344: "contains all of the words" no longer looks for all words within the same comment or flag
r=LpSolit, a=LpSolit
Frédéric Buclin [Sat, 18 May 2013 14:06:25 +0000 (16:06 +0200)]
Bug 870701: Release notes for Bugzilla 4.2.6
r=dkl a=LpSolit
Frédéric Buclin [Sun, 5 May 2013 21:35:46 +0000 (23:35 +0200)]
Bug 212471: Tabular reports do not link bug counts involving the empty resolution correctly
r=dkl a=LpSolit
Dave Lawrence [Fri, 3 May 2013 22:23:50 +0000 (18:23 -0400)]
Bug 859118 - Bug.search called with no arguments returns all visible bugs, ignoring max_search_results and search_allow_no_criteria
r/a=LpSolit
Frédéric Buclin [Sun, 28 Apr 2013 11:51:50 +0000 (13:51 +0200)]
Bug 848635: Old queries based on tags are no longer listed in the page footer by default when upgrading from 4.0 or older to 4.2
r=glob a=LpSolit
Frédéric Buclin [Sun, 28 Apr 2013 11:40:12 +0000 (13:40 +0200)]
Bug 858909: When running checksetup.pl for the first time using Oracle as DB server, you get an "uninitialized value" warning
r=dkl a=LpSolit
Frédéric Buclin [Wed, 17 Apr 2013 23:26:19 +0000 (01:26 +0200)]
Bug 858911: Oracle fails with "ORA-04043: object T_GROUP_CONCAT does not exist" when installing Bugzilla for the first time
r=dkl a=LpSolit
Byron Jones [Wed, 17 Apr 2013 17:38:22 +0000 (01:38 +0800)]
revert commit for bug 828344
Byron Jones [Wed, 17 Apr 2013 17:18:03 +0000 (01:18 +0800)]
Bug 828344: Make "contains all of the words" look for all words within the same comment or flag
r=LpSolit, a=LpSolit
Pami Ketolainen [Tue, 16 Apr 2013 10:14:23 +0000 (12:14 +0200)]
Bug 782210: If a custom field depends on a product, component or classification, the "mandatory" bit is ignored on bug creation
r/a=LpSolit
Frédéric Buclin [Mon, 15 Apr 2013 21:27:10 +0000 (23:27 +0200)]
Bug 861528: $user->can_enter_product() now returns the product object instead of 1
r=glob a=LpSolit
Pami Ketolainen [Thu, 11 Apr 2013 13:18:07 +0000 (15:18 +0200)]
Bug 860723: Custom fields are shown twice in report axis selectors
r/a=LpSolit
Christopher Trom [Tue, 9 Apr 2013 10:26:06 +0000 (12:26 +0200)]
Bug 355620: Lines enclosed in <simplelist> do not wrap in the PDF version of the Bugzilla Guide
r/a=LpSolit
Frédéric Buclin [Fri, 5 Apr 2013 20:00:12 +0000 (22:00 +0200)]
Bug 857562: ajax_user_autocompletion param ignored on Search by People fields
r=dkl a=LpSolit
Frédéric Buclin [Fri, 5 Apr 2013 19:54:25 +0000 (21:54 +0200)]
Bug 855258: The dependency graph always uses urlbase, even when sslbase is in use
r=glob a=LpSolit
Frédéric Buclin [Tue, 26 Mar 2013 11:07:25 +0000 (12:07 +0100)]
Bug 854074: Remove all references to the uwinnipeg.ca PPM repository as it is no longer available
r=glob a=LpSolit
Frédéric Buclin [Wed, 20 Mar 2013 12:07:04 +0000 (13:07 +0100)]
Bug 852560: Bugzilla cannot be installed with MySQL 5.6, because the have_innodb variable no longer exists
r=glob a=LpSolit
Hugo Seabrook [Sat, 16 Mar 2013 16:21:37 +0000 (17:21 +0100)]
Bug 827983: "[reply]" link besides the original description will insert ("in reply to comment #N+1") when the comments order is "Newest to Oldest, but keep Descritption at the top"
r/a=LpSolit
Reed Loden [Tue, 12 Mar 2013 17:06:32 +0000 (10:06 -0700)]
Bug 850126 - 'token' id defined twice on logged-out pages (in header and footer)
[r=LpSolit a=LpSolit]
Frédéric Buclin [Fri, 8 Mar 2013 11:55:02 +0000 (12:55 +0100)]
Bug 848250: Bug summary tooltip now includes "---" for unresolved bugs
r=dkl a=LpSolit
Dave Lawrence [Wed, 20 Feb 2013 01:16:57 +0000 (20:16 -0500)]
Bump version post-release
Dave Lawrence [Tue, 19 Feb 2013 18:42:23 +0000 (13:42 -0500)]
Bumped current year
Dave Lawrence [Tue, 19 Feb 2013 17:42:30 +0000 (12:42 -0500)]
Bump version to 4.2.5
Frédéric Buclin [Tue, 19 Feb 2013 17:27:50 +0000 (18:27 +0100)]
Bug 842038: (CVE-2013-0785) [SECURITY] XSS in show_bug.cgi when using an invalid page format
r=glob a=LpSolit
Simon Green [Tue, 19 Feb 2013 17:14:59 +0000 (18:14 +0100)]
Bug 824399: (CVE-2013-0786) [SECURITY] build_subselect() leaks the existence of products and components you cannot access
r/a=LpSolit
Frédéric Buclin [Tue, 19 Feb 2013 08:58:54 +0000 (09:58 +0100)]
Bug 832264: Release notes for Bugzilla 4.2.5
r=dkl a=LpSolit
Matt Tyson [Sun, 17 Feb 2013 01:19:08 +0000 (02:19 +0100)]
Bug 839950: Cannot search by Change History on multi-select fields
r/a=LpSolit
Simon Green [Sat, 16 Feb 2013 21:58:00 +0000 (22:58 +0100)]
Bug 840824: It is possible to create a new bug with a non active target milestone, version or component
r/a=LpSolit
Dave Lawrence [Thu, 17 Jan 2013 17:49:28 +0000 (12:49 -0500)]
Bug 752946 - Fixed uninitialized error
Dave Lawrence [Thu, 17 Jan 2013 16:29:07 +0000 (11:29 -0500)]
Bug 752946 - Moving a bug into another product lists inactive components, milestones and versions
r/a=LpSolit
Frédéric Buclin [Mon, 14 Jan 2013 17:53:09 +0000 (18:53 +0100)]
Bug 829939: Only build default_authorizer on request
r=glob a=LpSolit
Frédéric Buclin [Sat, 5 Jan 2013 23:26:36 +0000 (00:26 +0100)]
Bug 826678: Disable warnings about the deprecated Return::Value module when loading Email::Send
r=wicked a=LpSolit
Matt Selsky [Thu, 3 Jan 2013 12:25:57 +0000 (13:25 +0100)]
Bug 824616: The urlbase field in global/header.html.tmpl must be filtered
r/a=LpSolit
Sunil Joshi [Wed, 2 Jan 2013 00:42:35 +0000 (01:42 +0100)]
Bug 825524: When cloning a bug, the "We've made a guess at your operating system and platform" message should not be displayed
r/a=LpSolit
Frédéric Buclin [Wed, 19 Dec 2012 22:52:54 +0000 (23:52 +0100)]
Bug 818621: Perl 5.16 complains with "Variable length lookbehind not implemented in regex" when the Example extension is enabled
r=dkl a=LpSolit
Alexander Tereschenko [Mon, 17 Dec 2012 22:41:09 +0000 (23:41 +0100)]
Bug 818890: Bugzilla doesn't obey the "Comment required on status transition" for {Start}-> transition (for new bugs)
r/a=LpSolit
Sunil Joshi [Sun, 16 Dec 2012 13:14:31 +0000 (14:14 +0100)]
Bug 406758: The help page for keywords uses "tag", but tags are something else
r/a=LpSolit
Alexander Tereschenko [Sun, 16 Dec 2012 13:08:49 +0000 (14:08 +0100)]
Bug 806809: Custom field values with "Enabled for bugs" set to "No" break the values list if the field's values visibility depends on another field values
r/a=LpSolit
Frédéric Buclin [Fri, 7 Dec 2012 13:09:04 +0000 (14:09 +0100)]
Bug 818007: Searching by commenter is slow
r=dkl a=LpSolit
Hugo [Thu, 29 Nov 2012 19:12:21 +0000 (14:12 -0500)]
Bug 579189 - New methods added to Bugzilla/User.pm by bug 24896 have no POD
r=dkl, a=LpSolit
Thorsten Schöning [Thu, 22 Nov 2012 23:39:37 +0000 (00:39 +0100)]
Bug 385283: bz_webservice_demo.pl --product-name fails (Product.get_product no longer exists)
Part 2: correctly display components, milestones and versions
r/a=LpSolit
Dave Miller [Tue, 20 Nov 2012 19:07:13 +0000 (14:07 -0500)]
Bug 640756 - Make the documentation clearer that attachments created with Bug.add_attachment must by of type 'base64' when non-ASCII
.
r=LpSolit, a=LpSolit
Thorsten Schöning [Tue, 20 Nov 2012 16:50:17 +0000 (17:50 +0100)]
Bug 385283: bz_webservice_demo.pl --product-name fails (Product.get_product no longer exists)
r/a=LpSolit
Dave Lawrence [Tue, 13 Nov 2012 23:29:10 +0000 (18:29 -0500)]
Bump version post-release
https://bugzilla.mozilla.org/show_bug.cgi?id=805644
Dave Lawrence [Tue, 13 Nov 2012 20:00:43 +0000 (15:00 -0500)]
Bump version to 4.2.4
https://bugzilla.mozilla.org/show_bug.cgi?id=805644
Frédéric Buclin [Tue, 13 Nov 2012 17:56:26 +0000 (18:56 +0100)]
Bug 790296 (CVE-2012-4189): [SECURITY] Field values are not escaped correctly in tabular reports
r=dkl a=LpSolit
Frédéric Buclin [Tue, 13 Nov 2012 17:48:12 +0000 (18:48 +0100)]
Bug 808845 (CVE-2012-5475): [SECURITY] Security vulnerability in YUI's swfstore.swf in YUI 2.8.2 and 2.9.0
a=LpSolit
Frédéric Buclin [Tue, 13 Nov 2012 17:36:33 +0000 (18:36 +0100)]
Bug 781850 (CVE-2012-4198): [SECURITY] Do not leak the existence of groups when using User.get()
r=dkl a=LpSolit
Frédéric Buclin [Tue, 13 Nov 2012 17:23:13 +0000 (18:23 +0100)]
Bug 802204 (CVE-2012-4197): [SECURITY] Marking an attachment you cannot see as obsolete can disclose its description
r=gerv a=LpSolit
Frédéric Buclin [Tue, 13 Nov 2012 17:09:30 +0000 (18:09 +0100)]
Bug 731178 (CVE-2012-4199): [SECURITY] field-events.js.tmpl discloses product and component names that the user is not allowed to see
r=dkl a=LpSolit
Frédéric Buclin [Sat, 3 Nov 2012 18:58:26 +0000 (19:58 +0100)]
Back out the last checkin, it was already there
Frédéric Buclin [Sat, 3 Nov 2012 17:53:41 +0000 (18:53 +0100)]
Bug 805647: One more item for the 4.2.4 release notes
Frédéric Buclin [Fri, 2 Nov 2012 23:18:32 +0000 (00:18 +0100)]
Bug 804505: Oracle crashes when typing "word1 word2" in QuickSearch with "ORA-29907: found duplicate labels in primary invocations"
r=dkl a=LpSolit
Frédéric Buclin [Fri, 2 Nov 2012 17:35:38 +0000 (18:35 +0100)]
Bug 806012: Installation docs need to be updated with instructions for bzr
r=dkl a=LpSolit
Frédéric Buclin [Fri, 2 Nov 2012 12:56:57 +0000 (13:56 +0100)]
Fix typo
Koosha Khajeh Moogahi [Fri, 2 Nov 2012 12:45:33 +0000 (13:45 +0100)]
Bug 807937: Fix POD
r/a=LpSolit
Frédéric Buclin [Fri, 26 Oct 2012 15:13:05 +0000 (17:13 +0200)]
Bug 805647: Release notes for Bugzilla 4.2.4
r=dkl