]> git.ipfire.org Git - thirdparty/bugzilla.git/log
thirdparty/bugzilla.git
14 years agoBug 619588: (CVE-2010-4567) [SECURITY] Safety checks that disallow clicking for javas...
Frédéric Buclin [Mon, 24 Jan 2011 18:29:39 +0000 (19:29 +0100)] 
Bug 619588: (CVE-2010-4567) [SECURITY] Safety checks that disallow clicking for javascript: or data: URLs in the URL field can be evaded with prefixed whitespace

and

Bug 628034: (CVE-2011-0048) [SECURITY] For not-logged-in users, the URL field doesn't safeguard against javascript: or data: URLs

r=dkl a=LpSolit

14 years agoBug 621572: (CVE-2010-4572) [SECURITY] chart.cgi vulnerable to header-injection due...
Reed Loden [Mon, 24 Jan 2011 18:12:00 +0000 (10:12 -0800)] 
Bug 621572: (CVE-2010-4572) [SECURITY] chart.cgi vulnerable to header-injection due to use of |print "Location:"| instead of $cgi->redirect
[r=mkanat a=LpSolit]

14 years agoBug 619648: (CVE-2010-4570) [SECURITY] XSS via summary in "possible duplicates" table...
Reed Loden [Mon, 24 Jan 2011 18:08:37 +0000 (10:08 -0800)] 
Bug 619648: (CVE-2010-4570) [SECURITY] XSS via summary in "possible duplicates" table due to lack of encoding by YUI
[r=mkanat a=LpSolit]

14 years agoBug 619637: (CVE-2010-4569) [SECURITY] XSS in user autocomplete due to lack of encodi...
Reed Loden [Mon, 24 Jan 2011 18:05:09 +0000 (10:05 -0800)] 
Bug 619637: (CVE-2010-4569) [SECURITY] XSS in user autocomplete due to lack of encoding by YUI
[r=mkanat r=dkl a=LpSolit]

14 years agoBug 621110: [SECURITY] Quips (adding/approving/deleting) lacks CSRF protection
Frédéric Buclin [Mon, 24 Jan 2011 17:23:39 +0000 (18:23 +0100)] 
Bug 621110: [SECURITY] Quips (adding/approving/deleting) lacks CSRF protection
r=dkl a=LpSolit

14 years agoBug 621108: [SECURITY] Creating/editing charts lacks CSRF protection
Frédéric Buclin [Mon, 24 Jan 2011 17:12:29 +0000 (18:12 +0100)] 
Bug 621108: [SECURITY] Creating/editing charts lacks CSRF protection
r=dkl a=LpSolit

14 years agoBug 621107: [SECURITY] Sanity checking lacks CSRF protection
Frédéric Buclin [Mon, 24 Jan 2011 17:04:59 +0000 (18:04 +0100)] 
Bug 621107: [SECURITY] Sanity checking lacks CSRF protection
r=dkl a=LpSolit

14 years agoAn optional module was accidentally listed in the "required" section of the
Max Kanat-Alexander [Mon, 24 Jan 2011 04:11:03 +0000 (20:11 -0800)] 
An optional module was accidentally listed in the "required" section of the
release notes.

https://bugzilla.mozilla.org/show_bug.cgi?id=627910

14 years agoBug 627910: Update Release Notes for Bugzilla 4.0rc2
Max Kanat-Alexander [Mon, 24 Jan 2011 03:57:21 +0000 (19:57 -0800)] 
Bug 627910: Update Release Notes for Bugzilla 4.0rc2
r=reed

14 years agoBug 625741: Need a hook in update_fielddefs_definition to enable adding columns to...
rojanu [Sun, 23 Jan 2011 12:06:51 +0000 (13:06 +0100)] 
Bug 625741: Need a hook in update_fielddefs_definition to enable adding columns to fielddefs
r/a=mkanat

14 years agoBug 621128 - Remove trailing whitespace from '<div id="view_disabled" >'
timeless [Sat, 22 Jan 2011 21:22:59 +0000 (13:22 -0800)] 
Bug 621128 - Remove trailing whitespace from '<div id="view_disabled" >'
[r=reed a=LpSolit]

14 years agoBug 624696: We need a template hook to add a description to parameters added by exten...
rojanu [Sat, 22 Jan 2011 17:51:36 +0000 (18:51 +0100)] 
Bug 624696: We need a template hook to add a description to parameters added by extensions
r/a=mkanat

14 years agoBug 621109: Column changing lacks CSRF protection
Frédéric Buclin [Sat, 22 Jan 2011 17:15:42 +0000 (18:15 +0100)] 
Bug 621109: Column changing lacks CSRF protection
r=dkl a=mkanat

14 years agoBug 627854: Add 'form' hook to create-guided.html.tmpl similar to create.html.tmpl
David Lawrence [Fri, 21 Jan 2011 21:41:53 +0000 (16:41 -0500)] 
Bug 627854: Add 'form' hook to create-guided.html.tmpl similar to create.html.tmpl
r/a=mkanat

14 years agoBug 591165: (CVE-2010-4411) [SECURITY] Bump minimum required version of CGI.pm to...
Reed Loden [Fri, 21 Jan 2011 21:14:36 +0000 (13:14 -0800)] 
Bug 591165: (CVE-2010-4411) [SECURITY] Bump minimum required version of CGI.pm to v3.51 in order to address header injection vulnerability.
[r=mkanat a=mkanat]

14 years agoBug 627660 - Rename "Send" button on final create account page to "Create", as nothin...
Reed Loden [Fri, 21 Jan 2011 20:53:34 +0000 (12:53 -0800)] 
Bug 627660 - Rename "Send" button on final create account page to "Create", as nothing is actually sent.
[r=mkanat a=mkanat]

14 years agoBug 626292: "Make description private" checkbox should set bz_private class on the...
David Lawrence [Fri, 21 Jan 2011 06:35:50 +0000 (01:35 -0500)] 
Bug 626292: "Make description private" checkbox should set bz_private class on the comment box
r/a=mkanat

14 years agoBug 623608 - Add intro/outro extension hooks to footer.html.tmpl
David Lawrence [Fri, 21 Jan 2011 05:06:40 +0000 (00:06 -0500)] 
Bug 623608 - Add intro/outro extension hooks to footer.html.tmpl
r/a=mkanat

14 years agoBug 626658 - Add (take) link to bug edit page to allow quick assigning to the current...
David Lawrence [Fri, 21 Jan 2011 04:46:40 +0000 (23:46 -0500)] 
Bug 626658 - Add (take) link to bug edit page to allow quick assigning to the current user
r/a=mkanat

14 years agoBug 625190: Typo and Missing FK in Bugzilla::DB::Schema
David Marshall [Sat, 15 Jan 2011 00:11:57 +0000 (01:11 +0100)] 
Bug 625190: Typo and Missing FK in Bugzilla::DB::Schema
r/a=mkanat

14 years agoBug 623408: Message-ID is gone in bugmail for new bugs
Frédéric Buclin [Sat, 15 Jan 2011 00:08:08 +0000 (01:08 +0100)] 
Bug 623408: Message-ID is gone in bugmail for new bugs
r=dkl a=LpSolit

14 years agoBug 624349: Let the config_modify_panels hook add new parameters to existing panels
Frédéric Buclin [Mon, 10 Jan 2011 23:05:53 +0000 (00:05 +0100)] 
Bug 624349: Let the config_modify_panels hook add new parameters to existing panels
r/a=mkanat

14 years agoBug 618841: Bare word "bug" in release notes
A. Shimono [Sun, 9 Jan 2011 14:24:48 +0000 (15:24 +0100)] 
Bug 618841: Bare word "bug" in release notes
r=dkl a=LpSolit

14 years agoBug 622204: Bugzilla::Migrate crashes trying to create bugs with resolutions
<Alex> [Sun, 9 Jan 2011 14:16:34 +0000 (15:16 +0100)] 
Bug 622204: Bugzilla::Migrate crashes trying to create bugs with resolutions
r/a=mkanat

14 years agoBug 558803: Add a parameter to specify the password complexity for new passwords
rojanu [Fri, 7 Jan 2011 14:14:40 +0000 (15:14 +0100)] 
Bug 558803: Add a parameter to specify the password complexity for new passwords
r/a=LpSolit

14 years agoBug 255524: The duplicates table inherits no CSS classes when viewed in simple format
Frédéric Buclin [Fri, 7 Jan 2011 12:32:19 +0000 (13:32 +0100)] 
Bug 255524: The duplicates table inherits no CSS classes when viewed in simple format
r=dkl a=LpSolit

14 years agoProvide user objects to bugmail_recipients hook. r,a=mkanat.
Gervase Markham [Fri, 7 Jan 2011 11:00:25 +0000 (11:00 +0000)] 
Provide user objects to bugmail_recipients hook. r,a=mkanat.

https://bugzilla.mozilla.org/show_bug.cgi?id=622813

14 years agoBug 621090 - [SECURITY] Adding saved searches lacks CSRF protection
David Lawrence [Fri, 7 Jan 2011 04:02:28 +0000 (23:02 -0500)] 
Bug 621090 - [SECURITY] Adding saved searches lacks CSRF protection
r/a=mkanat

14 years agoDocument how to add user settings. r,a=mkanat.
Gervase Markham [Wed, 5 Jan 2011 16:58:05 +0000 (16:58 +0000)] 
Document how to add user settings. r,a=mkanat.

https://bugzilla.mozilla.org/show_bug.cgi?id=616427

14 years agoAllow extensions to add new Jobs. r,a=mkanat.
Gervase Markham [Wed, 5 Jan 2011 11:48:49 +0000 (11:48 +0000)] 
Allow extensions to add new Jobs. r,a=mkanat.

https://bugzilla.mozilla.org/show_bug.cgi?id=617012

14 years agoBug 622822 - add additional_links hook to front page. r,a=mkanat.
Gervase Markham [Wed, 5 Jan 2011 10:35:10 +0000 (10:35 +0000)] 
Bug 622822 - add additional_links hook to front page. r,a=mkanat.

14 years agoBug 595410: Make it faster to display a bug that has a lot of dependencies.
Max Kanat-Alexander [Tue, 4 Jan 2011 02:09:42 +0000 (18:09 -0800)] 
Bug 595410: Make it faster to display a bug that has a lot of dependencies.
r=LpSolit, a=LpSolit

14 years agoBug 622437: Remove 'colchange_columns' hook from the Example extension
Tiago Mello [Sun, 2 Jan 2011 19:50:43 +0000 (17:50 -0200)] 
Bug 622437: Remove 'colchange_columns' hook from the Example extension
r/a=LpSolit

14 years agoBug 622105 - Misspelling in setting_info_invalid error message
David Lawrence [Thu, 30 Dec 2010 16:36:59 +0000 (11:36 -0500)] 
Bug 622105 - Misspelling in setting_info_invalid error message
r/a=LpSolit

14 years agoBug 621597: Make mod_perl.pl do the INC configuration itself, instead of
Max Kanat-Alexander [Tue, 28 Dec 2010 22:47:33 +0000 (14:47 -0800)] 
Bug 621597: Make mod_perl.pl do the INC configuration itself, instead of
requiring it to be in httpd.conf.
r=dkl, a=mkanat

14 years agoRemove unused variable, per my review comment
Frédéric Buclin [Tue, 28 Dec 2010 02:09:31 +0000 (03:09 +0100)] 
Remove unused variable, per my review comment

https://bugzilla.mozilla.org/show_bug.cgi?id=615574

14 years agoBug 618844: Make clear that the Apache module must be enabled in release notes
A. Shimono (himorin) [Mon, 27 Dec 2010 22:36:28 +0000 (23:36 +0100)] 
Bug 618844: Make clear that the Apache module must be enabled in release notes
r/a=mkanat

14 years agoBug 618842: Enclose checksetup.pl between <kbd> and </kbd> tags in templates
A. Shimono (himorin) [Mon, 27 Dec 2010 22:29:06 +0000 (23:29 +0100)] 
Bug 618842: Enclose checksetup.pl between <kbd> and </kbd> tags in templates
r/a=mkanat

14 years agoBug 599539: Update the mod_perl code for Apache2::SizeLimit 0.92
Max Kanat-Alexander [Mon, 27 Dec 2010 22:19:08 +0000 (14:19 -0800)] 
Bug 599539: Update the mod_perl code for Apache2::SizeLimit 0.92
r=glob, a=mkanat

14 years agoBug 615574: Make every search done by buglist.cgi create a list_id, so that
Max Kanat-Alexander [Mon, 27 Dec 2010 22:13:38 +0000 (14:13 -0800)] 
Bug 615574: Make every search done by buglist.cgi create a list_id, so that
even Saved Searches get "last list" support.
r=LpSolit, a=LpSolit

14 years agoBug 603762: Vertical margins between header, footer, and content are not consistent
Christian Legnitto [Mon, 27 Dec 2010 22:00:07 +0000 (23:00 +0100)] 
Bug 603762: Vertical margins between header, footer, and content are not consistent
r=pyrzak a=mkanat

14 years agoBug 588013: Fix typo
timeless [Mon, 27 Dec 2010 21:49:36 +0000 (22:49 +0100)] 
Bug 588013: Fix typo
r/a=mkanat

14 years agoAdd contributor lines for mkanat and myself for the new BugUrl modules.
Reed Loden [Thu, 23 Dec 2010 09:42:48 +0000 (03:42 -0600)] 
Add contributor lines for mkanat and myself for the new BugUrl modules.
Add missing period in original developer line in license block.
[a=mkanat]

14 years agoBug 620796: Make Bugzilla::Migrate skip abnormal fields when doing
Max Kanat-Alexander [Tue, 21 Dec 2010 23:53:49 +0000 (15:53 -0800)] 
Bug 620796: Make Bugzilla::Migrate skip abnormal fields when doing
create_legal_values (otherwise it tried to create Components there, when
it should not have).
r=mkanat, a=mkanat (module owner)

14 years agoBug 593539: Fix the bugs activity for the see_also field.
Tiago Mello [Tue, 21 Dec 2010 12:30:45 +0000 (10:30 -0200)] 
Bug 593539: Fix the bugs activity for the see_also field.
r/a=mkanat

14 years agoBug 593539: Refactor See Also to use separate modules for each type of URL
Tiago Mello [Mon, 20 Dec 2010 22:49:10 +0000 (20:49 -0200)] 
Bug 593539: Refactor See Also to use separate modules for each type of URL
r/a=mkanat

14 years agoBug 475894 - Send the 'X-Frame-Options: SAMEORIGIN' header to help protect against...
Reed Loden [Sat, 18 Dec 2010 08:40:24 +0000 (00:40 -0800)] 
Bug 475894 - Send the 'X-Frame-Options: SAMEORIGIN' header to help protect against clickjacking.
[r=mkanat a=mkanat]

14 years agoRemove some real configuration data that had crept into bzdbcopy.pl.
Max Kanat-Alexander [Thu, 16 Dec 2010 19:26:19 +0000 (11:26 -0800)] 
Remove some real configuration data that had crept into bzdbcopy.pl.

https://bugzilla.mozilla.org/show_bug.cgi?id=619581

14 years agoBug 619581: Make contrib/bzdbcopy.pl work again, and also make it work with
Max Kanat-Alexander [Thu, 16 Dec 2010 01:42:37 +0000 (17:42 -0800)] 
Bug 619581: Make contrib/bzdbcopy.pl work again, and also make it work with
SQLite.
r=mkanat, a=mkanat

14 years agoCheckin fix for bug 619016: "DEFAULT TRUE" and "DEFAULT FALSE" were no longer
Max Kanat-Alexander [Wed, 15 Dec 2010 23:18:52 +0000 (15:18 -0800)] 
Checkin fix for bug 619016: "DEFAULT TRUE" and "DEFAULT FALSE" were no longer
getting properly translated to 1 and 0 inside of _set_nulls_sql in
Bugzilla::DB::Schema.

14 years agoBug 313583: Remove long_list.cgi, showattachment.cgi and xml.cgi.
Frédéric Buclin [Wed, 15 Dec 2010 23:09:17 +0000 (00:09 +0100)] 
Bug 313583: Remove long_list.cgi, showattachment.cgi and xml.cgi.
They are all deprecated since Bugzilla 2.19.
r/a=mkanat

14 years agoAdditional fix for bug 619016: The FK adding/removing code for SQLite didn't
Max Kanat-Alexander [Wed, 15 Dec 2010 22:48:38 +0000 (14:48 -0800)] 
Additional fix for bug 619016: The FK adding/removing code for SQLite didn't
work when it was modifying tables to have their first FK or removing all
the FKs on a table.
r=mkanat, a=mkanat (module owner)

14 years agoBug 619016: Make SQLite installations able to alter an existing schema,
Max Kanat-Alexander [Wed, 15 Dec 2010 22:13:11 +0000 (14:13 -0800)] 
Bug 619016: Make SQLite installations able to alter an existing schema,
meaning that SQLite installations can now upgrade and add custom fields.
r=mkanat, a=mkanat (module owner)

14 years agoBug 619466: Make searching by work_time search the total time on the bug
Max Kanat-Alexander [Wed, 15 Dec 2010 22:06:01 +0000 (14:06 -0800)] 
Bug 619466: Make searching by work_time search the total time on the bug
instead of searching the time on individual comments.
r=mkanat, a=mkanat (module owner)

14 years agoBug 617477: Fix numerous consistency and behavior issues surroudning Bug.update
Max Kanat-Alexander [Mon, 13 Dec 2010 20:54:20 +0000 (12:54 -0800)] 
Bug 617477: Fix numerous consistency and behavior issues surroudning Bug.update
and Bugzilla::Bug. See https://bugzilla.mozilla.org/show_bug.cgi?id=617477#c2
for details.
r=LpSolit, a=LpSolit

14 years agoBug 618161: Make VERSION into a constant in two included extensions so that
Max Kanat-Alexander [Sun, 12 Dec 2010 18:55:17 +0000 (10:55 -0800)] 
Bug 618161: Make VERSION into a constant in two included extensions so that
calling $class->VERSION on them won't throw an error on Perl 5.12 when there
are non-numeric characters in BUGZILLA_VERSION.
r=LpSolit, a=LpSolit

14 years agoBug 610182: Support enabling UNCONFIRMED in all products when using
Frank Becker [Fri, 10 Dec 2010 21:31:37 +0000 (13:31 -0800)] 
Bug 610182: Support enabling UNCONFIRMED in all products when using
contrib/convert-workflow.pl
r=mkanat, a=mkanat

14 years agoBug 617684: Values starting with a dot or an underscore are no longer hidden in reports
Frédéric Buclin [Wed, 8 Dec 2010 20:13:06 +0000 (21:13 +0100)] 
Bug 617684: Values starting with a dot or an underscore are no longer hidden in reports
r/a=mkanat

14 years agoBug 617630: Improve get_names() in report.cgi
Frédéric Buclin [Wed, 8 Dec 2010 18:41:52 +0000 (19:41 +0100)] 
Bug 617630: Improve get_names() in report.cgi
a=LpSolit

14 years agoBug 567953: Components which exist in several products are duplicated in tabular...
miketosh [Wed, 8 Dec 2010 15:29:46 +0000 (16:29 +0100)] 
Bug 567953: Components which exist in several products are duplicated in tabular reports
r/a=LpSolit

14 years agoBug 617030 - Add an error code for json_rpc_invalid_callback, and fix the
Max Kanat-Alexander [Mon, 6 Dec 2010 18:59:23 +0000 (10:59 -0800)] 
Bug 617030 - Add an error code for json_rpc_invalid_callback, and fix the
regex used by _bz_callback in Bugzilla::WebService::Server::JSONRPC to
accept numbers other than 0 or 1.
r=LpSolit, a=mkanat

14 years agoBug 542931: Bug in SOAP::Lite prevents WebService:XMLRPC logins from persisting
Frédéric Buclin [Mon, 6 Dec 2010 17:10:29 +0000 (18:10 +0100)] 
Bug 542931: Bug in SOAP::Lite prevents WebService:XMLRPC logins from persisting
r/a=mkanat

14 years agoBug 607138: Don't send the Strict-Transport-Security header for the
Max Kanat-Alexander [Mon, 6 Dec 2010 15:52:31 +0000 (07:52 -0800)] 
Bug 607138: Don't send the Strict-Transport-Security header for the
attachment_base.
r=LpSolit, a=LpSolit

14 years agoBug 529974: Let users with local editcomponents privs manage flags for products they...
Frédéric Buclin [Sat, 4 Dec 2010 01:22:49 +0000 (02:22 +0100)] 
Bug 529974: Let users with local editcomponents privs manage flags for products they can administer
a=LpSolit (module owner)

14 years agoBug 607675: In Firefox, YAHOO.util.Event.addListener/on events no longer exist after...
Guy Pyrzak [Fri, 3 Dec 2010 00:08:17 +0000 (16:08 -0800)] 
Bug 607675: In Firefox, YAHOO.util.Event.addListener/on events no longer exist after a user clicks back
r:LpSolit, a:mkanat

14 years agoFix typo
A. Shimono [Tue, 30 Nov 2010 17:43:06 +0000 (18:43 +0100)] 
Fix typo
r/a=LpSolit

https://bugzilla.mozilla.org/show_bug.cgi?id=615570

14 years agoBug 416784: In PostgreSQL 8.1 and newer, createuser takes the argument -R instead...
Frédéric Buclin [Sat, 27 Nov 2010 21:10:02 +0000 (22:10 +0100)] 
Bug 416784: In PostgreSQL 8.1 and newer, createuser takes the argument -R instead of -A
r=manu a=LpSolit

14 years agoBug 386600: Implement auto-completion for the requestee field
Guy Pyrzak [Sun, 21 Nov 2010 13:19:10 +0000 (14:19 +0100)] 
Bug 386600: Implement auto-completion for the requestee field
r/a=LpSolit

14 years agoBug 611891: Don't generate cookies for logins done over GET via the WebService
Max Kanat-Alexander [Mon, 15 Nov 2010 07:36:39 +0000 (23:36 -0800)] 
Bug 611891: Don't generate cookies for logins done over GET via the WebService
r=glob, a=mkanat

14 years agoBug 599552: Clean up mod_perl.pl, and make it use the same CGI.pm compile
Max Kanat-Alexander [Mon, 15 Nov 2010 07:28:13 +0000 (23:28 -0800)] 
Bug 599552: Clean up mod_perl.pl, and make it use the same CGI.pm compile
options as mod_cgi does.
r=glob, a=mkanat

14 years agoBug 610217: config.cgi?ctype=rdf should include product.allows_unconfirmed
Frank Becker [Sun, 14 Nov 2010 19:11:39 +0000 (20:11 +0100)] 
Bug 610217: config.cgi?ctype=rdf should include product.allows_unconfirmed
r/a=mkanat

14 years agoBug 611974: collectstats.pl --regenerate fails with PostgreSQL 8.4.x (sql_from_days...
Sam Morris [Sun, 14 Nov 2010 19:02:08 +0000 (20:02 +0100)] 
Bug 611974: collectstats.pl --regenerate fails with PostgreSQL 8.4.x (sql_from_days() doesn't accept integers as argument)
r/a=LpSolit

14 years agoBug 611979: Undefined subroutine &Bugzilla::Config::Advanced::check_multi when enabli...
Frédéric Buclin [Sun, 14 Nov 2010 18:52:55 +0000 (19:52 +0100)] 
Bug 611979: Undefined subroutine &Bugzilla::Config::Advanced::check_multi when enabling strict_transport_security
r=glob a=LpSolit

14 years agoBug 611623: The alias is not filtered in QuickSearch when passed to show_bug.cgi
Frédéric Buclin [Sat, 13 Nov 2010 00:06:32 +0000 (01:06 +0100)] 
Bug 611623: The alias is not filtered in QuickSearch when passed to show_bug.cgi
r=glob a=LpSolit

14 years agoBug 591165: (CVE-2010-2761) [SECURITY] Bump minimum required version of CGI.pm to...
Reed Loden [Thu, 11 Nov 2010 02:08:54 +0000 (18:08 -0800)] 
Bug 591165: (CVE-2010-2761) [SECURITY] Bump minimum required version of CGI.pm to v3.50 in order to address header injection vulnerability.
[r=mkanat a=mkanat]

14 years agoBug 591535: "Give me some help" link's iframe behavior is no longer necessary
Guy Pyrzak [Wed, 10 Nov 2010 23:48:30 +0000 (00:48 +0100)] 
Bug 591535: "Give me some help" link's iframe behavior is no longer necessary
r=LpSolit r=mkanat a=mkanat

14 years agoBug 596611: Add a hook to email_in.pl
Frédéric Buclin [Thu, 4 Nov 2010 17:09:30 +0000 (18:09 +0100)] 
Bug 596611: Add a hook to email_in.pl
r/a=mkanat

14 years agoBug 485418: Code and template hooks for userprefs.cgi to be able to add additional...
Frédéric Buclin [Thu, 4 Nov 2010 17:00:58 +0000 (18:00 +0100)] 
Bug 485418: Code and template hooks for userprefs.cgi to be able to add additional tabs
r=mkanat a=LpSolit

14 years agoBug 605573: List all available WebService methods at the top of the POD
Frédéric Buclin [Thu, 4 Nov 2010 16:52:29 +0000 (17:52 +0100)] 
Bug 605573: List all available WebService methods at the top of the POD
r/a=mkanat

14 years agoBug 474766: The [details] string is duplicated when replying to a comment containing...
Frédéric Buclin [Thu, 4 Nov 2010 16:43:19 +0000 (17:43 +0100)] 
Bug 474766: The [details] string is duplicated when replying to a comment containing a link to an attachment
r/a=mkanat

14 years agoBug 607909: Hours worked / work_time is marked as changing when commenting even when...
Christian Legnitto [Wed, 3 Nov 2010 15:33:30 +0000 (16:33 +0100)] 
Bug 607909: Hours worked / work_time is marked as changing when commenting even when you don't enter a value
r/a=LpSolit

14 years agoThe patch that made Bugzilla::Bug use Bugzilla::Comment to add comments
Max Kanat-Alexander [Wed, 3 Nov 2010 01:02:28 +0000 (18:02 -0700)] 
The patch that made Bugzilla::Bug use Bugzilla::Comment to add comments
fixed certain work_time tests in xt/search.t.

14 years agoWhen inserting comments during Bug->update, make sure that the comment
Max Kanat-Alexander [Wed, 3 Nov 2010 00:21:09 +0000 (17:21 -0700)] 
When inserting comments during Bug->update, make sure that the comment
timestamp is identical to the timestamp passed in to update().

https://bugzilla.mozilla.org/show_bug.cgi?id=590334

14 years agoThe changes to bz_create_database done by the SQLite patch broke the
Max Kanat-Alexander [Tue, 2 Nov 2010 23:39:57 +0000 (16:39 -0700)] 
The changes to bz_create_database done by the SQLite patch broke the
creation of databases on other systems. This restores the original
behavior while still retaining the correct error-throwing behavior
for systems that can't create a SQLite database.

https://bugzilla.mozilla.org/show_bug.cgi?id=337776

14 years agoBug 600464: (CVE-2010-3172) [SECURITY] Content/Header injection due to non-random...
Byron Jones [Tue, 2 Nov 2010 23:18:33 +0000 (00:18 +0100)] 
Bug 600464: (CVE-2010-3172) [SECURITY] Content/Header injection due to non-random multipart/x-mixed-replace boundary
r=mkanat a=LpSolit

14 years agoBug 419014: (CVE-2010-3764) [SECURITY] Old charts are not project specific, and produ...
Frédéric Buclin [Tue, 2 Nov 2010 23:06:15 +0000 (00:06 +0100)] 
Bug 419014: (CVE-2010-3764) [SECURITY] Old charts are not project specific, and product names are viewable in graphs/
r=wurblzap a=LpSolit

14 years agoBug 607581: URLs in the See Also field are not linkified when the user is logged out
Frédéric Buclin [Tue, 2 Nov 2010 22:58:27 +0000 (23:58 +0100)] 
Bug 607581: URLs in the See Also field are not linkified when the user is logged out
r=pyrzak a=LpSolit

14 years agoBug 608375: The calendar widget is not available in the Time Summary page
Guy Pyrzak [Tue, 2 Nov 2010 22:51:47 +0000 (23:51 +0100)] 
Bug 608375: The calendar widget is not available in the Time Summary page
r=wicked a=mkanat

14 years agoBug 606618: Update YUI to 2.8.2
Max Kanat-Alexander [Mon, 1 Nov 2010 00:11:56 +0000 (17:11 -0700)] 
Bug 606618: Update YUI to 2.8.2
r=LpSolit, a=mkanat

14 years agoBug 607323: Be clearer in the release notes that a new Apache configuration
Max Kanat-Alexander [Sun, 31 Oct 2010 23:53:41 +0000 (16:53 -0700)] 
Bug 607323: Be clearer in the release notes that a new Apache configuration
is required
r=LpSolit, a=mkanat

14 years agoBug 608437: Unused variables passed to flag/list.html.tmpl
Frédéric Buclin [Fri, 29 Oct 2010 23:44:27 +0000 (01:44 +0200)] 
Bug 608437: Unused variables passed to flag/list.html.tmpl
a=LpSolit (module owner)

14 years agoBug 600516: The "Content Type" and "Flags" sections are not displayed when trying...
Frédéric Buclin [Fri, 29 Oct 2010 10:09:26 +0000 (12:09 +0200)] 
Bug 600516: The "Content Type" and "Flags" sections are not displayed when trying to add attachments on an existing bug and the user previously clicked "Hide Advanced Fields" in enter_bug.cgi
a=LpSolit (module owner)

14 years agoBug 602456: Make Search.pm not quote numeric input for numeric fields
Max Kanat-Alexander [Thu, 28 Oct 2010 22:38:45 +0000 (15:38 -0700)] 
Bug 602456: Make Search.pm not quote numeric input for numeric fields
when generating SQL.
r=glob, a=mkanat

14 years agoBug 607966: Use of qw(...) as parentheses is deprecated since Perl 5.13.5
Frédéric Buclin [Thu, 28 Oct 2010 15:20:46 +0000 (17:20 +0200)] 
Bug 607966: Use of qw(...) as parentheses is deprecated since Perl 5.13.5
r=gerv a=LpSolit

14 years agoBug 585802: Change the cc/user autocomplete (and backend) usermatching to ignore...
Christian Legnitto [Thu, 28 Oct 2010 13:19:51 +0000 (15:19 +0200)] 
Bug 585802: Change the cc/user autocomplete (and backend) usermatching to ignore spaces / search on space separated names
r/a=mkanat

14 years agoBug 607716: The attachment content is pasted into a comment when editing an attachmen...
Guy Pyrzak [Thu, 28 Oct 2010 00:35:16 +0000 (02:35 +0200)] 
Bug 607716: The attachment content is pasted into a comment when editing an attachment with JS disabled
r=LpSolit r=mkanat a=LpSolit

14 years agoBug 337776: Basic SQLite Support for Bugzilla
Max Kanat-Alexander [Wed, 27 Oct 2010 07:56:15 +0000 (00:56 -0700)] 
Bug 337776: Basic SQLite Support for Bugzilla
r=LpSolit, a=mkanat

14 years agoBug 602458: Add is_mandatory to Bug.fields output.
Max Kanat-Alexander [Wed, 27 Oct 2010 07:52:20 +0000 (00:52 -0700)] 
Bug 602458: Add is_mandatory to Bug.fields output.
r=timello, a=mkanat

14 years agoBug 581933: Make YUI user autocomplete work with non-ASCII characters
Max Kanat-Alexander [Wed, 27 Oct 2010 07:48:57 +0000 (00:48 -0700)] 
Bug 581933: Make YUI user autocomplete work with non-ASCII characters
r=Wurblzap, a=LpSolit

14 years agoThe browser-side comment-wrapping patch didn't actually make 4.0, so remove
Max Kanat-Alexander [Tue, 26 Oct 2010 23:07:28 +0000 (16:07 -0700)] 
The browser-side comment-wrapping patch didn't actually make 4.0, so remove
it from the release notes.