]>
git.ipfire.org Git - thirdparty/bugzilla.git/log
Frédéric Buclin [Mon, 13 Apr 2015 23:23:06 +0000 (01:23 +0200)]
Bug
1001846 : When editing cc_accessible using Bug.update, the method sometimes returns is_cc_accessible and sometimes cc_accessible as being changed
r=dkl a=justdave
Simon Green [Mon, 13 Apr 2015 20:29:33 +0000 (21:29 +0100)]
Bug
1151290 : It is possible to tell if someone made a private comment on a bug even if you are not an 'insider'
r=dkl,a=glob
Frédéric Buclin [Mon, 16 Mar 2015 17:20:32 +0000 (18:20 +0100)]
Bug
1137669 : 003safesys.t doesn't test any file due to a missing -T argument
r=dylan a=glob
David Lawrence [Tue, 3 Mar 2015 20:01:39 +0000 (15:01 -0500)]
(TaskCluster) Allow retrieval of the selenium.log for Selenium tests
David Lawrence [Tue, 24 Feb 2015 23:27:10 +0000 (23:27 +0000)]
Intial checking of taskgraph.json for TaskCluster CI
David Lawrence [Tue, 17 Feb 2015 02:32:59 +0000 (21:32 -0500)]
- Force use of PostgreSQL 9.1
- Configure DB users in travis.yml
Frédéric Buclin [Wed, 28 Jan 2015 16:07:58 +0000 (17:07 +0100)]
Fix typo
David Lawrence [Tue, 27 Jan 2015 20:10:52 +0000 (20:10 +0000)]
Bump version post-release
David Lawrence [Tue, 27 Jan 2015 15:55:13 +0000 (15:55 +0000)]
Bump version to 4.2.13
David Lawrence [Tue, 27 Jan 2015 15:39:11 +0000 (15:39 +0000)]
Bug
1125188 : Release notes for 4.2.13
r=justdave,a=dkl
David Lawrence [Fri, 23 Jan 2015 17:26:58 +0000 (17:26 +0000)]
Bug
1124716 : regression caused by bug
1090275 to whitelist webservice methods causes test failures with t/012throwables.t
r=dylan,a=glob
David Lawrence [Wed, 21 Jan 2015 22:31:06 +0000 (22:31 +0000)]
Bump version post-release
David Lawrence [Wed, 21 Jan 2015 21:12:27 +0000 (21:12 +0000)]
Bumped version to 4.2.12
David Lawrence [Wed, 21 Jan 2015 20:41:58 +0000 (20:41 +0000)]
Bug
1090275 : WebServices modules should maintain a whitelist of methods that are allowed instead of allowing access to any function imported into its namespace
r=dylan,a=glob
Gervase Markham [Wed, 21 Jan 2015 20:26:39 +0000 (20:26 +0000)]
Bug
1079065 : [SECURITY] Always use the 3 arguments form for open() to prevent shell code injection
r=dylan,a=simon
David Lawrence [Mon, 19 Jan 2015 20:35:10 +0000 (20:35 +0000)]
Bug
1118985 : Release notes for 4.2.12
r=LpSolit,a=glob
Frédéric Buclin [Mon, 5 Jan 2015 18:32:57 +0000 (19:32 +0100)]
Bug
1085182 : Bugzilla::Bug->check must check that a bug ID is defined when it gets a hashref
r=dkl a=glob
Gervase Markham [Thu, 11 Dec 2014 15:15:59 +0000 (15:15 +0000)]
Revert "Bug
1082106 - avoid problem where ->bz_add_columns creates a foreign key constraint causing failure in checksetup.pl when it tries to re-add it later. r,a=glob"
This reverts commit
3c0c6a5b72e342e79b99fc2f33b4b14dd3a3caec .
David Lawrence [Thu, 11 Dec 2014 15:15:10 +0000 (15:15 +0000)]
Bug
1082106 - avoid problem where ->bz_add_columns creates a foreign key constraint causing failure in checksetup.pl when it tries to re-add it later. r,a=glob
Frédéric Buclin [Wed, 19 Nov 2014 17:26:34 +0000 (18:26 +0100)]
Bug
1097798 : Do not display the resolution in the dependency tree for open bugs, nor the target milestone if usetargetmilestone is off
r=dkl a=glob
Byron Jones [Thu, 16 Oct 2014 07:31:48 +0000 (15:31 +0800)]
Bug
1082887 : comments made when setting a flag from the attachment details page are not included in the "flag updated" email
r=dkl,a=glob
David Lawrence [Mon, 6 Oct 2014 18:34:00 +0000 (18:34 +0000)]
Bump version post-release
David Lawrence [Mon, 6 Oct 2014 15:21:27 +0000 (15:21 +0000)]
Bump version to 4.2.11
Simon Green [Mon, 6 Oct 2014 15:01:03 +0000 (15:01 +0000)]
Bug
1054702 : CSV export vulnerable to formulae injection
r=glob,a=glob
Simon Green [Mon, 6 Oct 2014 14:42:40 +0000 (14:42 +0000)]
Bug
1064140 : [SECURITY] Private comments can be shown to flagmail recipients who aren't in the insider group
r=glob,a=glob
Frédéric Buclin [Mon, 6 Oct 2014 14:34:26 +0000 (14:34 +0000)]
Bug
1074980 : Forbid the { foo => $cgi->param() } syntax to prevent data override
r=dkl,a=sgreen
Frédéric Buclin [Mon, 6 Oct 2014 14:25:06 +0000 (14:25 +0000)]
Bug
1075578 : [SECURITY] Improper filtering of CGI arguments
r=dkl,a=sgreen
David Lawrence [Mon, 6 Oct 2014 14:14:47 +0000 (14:14 +0000)]
Bug
1072492 : Release notes for 4.2.11
r=LpSolit,a=sgreen
David Lawrence [Thu, 24 Jul 2014 21:40:52 +0000 (21:40 +0000)]
Bump version post-release
David Lawrence [Thu, 24 Jul 2014 17:29:05 +0000 (17:29 +0000)]
Bump to version 4.2.10 (corrected)
Simon Green [Thu, 24 Jul 2014 17:26:23 +0000 (17:26 +0000)]
Bug
1036213 - (CVE-2014-1546) add '/**/' before jsonrpc.cgi callback to avoid swf content type sniff vulnerability
r=glob,a=sgreen
David Lawrence [Thu, 24 Jul 2014 16:56:58 +0000 (16:56 +0000)]
Bump version to 4.2.10
David Lawrence [Thu, 24 Jul 2014 16:40:20 +0000 (16:40 +0000)]
Bug
1042088 - Release notes for 4.2.10
r=glob
David Lawrence [Thu, 15 May 2014 21:44:03 +0000 (21:44 +0000)]
Bug
1011250 - Updates IRC notification text to include commit message and also send to #bugzilla
David Lawrence [Thu, 15 May 2014 02:49:10 +0000 (02:49 +0000)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
- Only run webservices for Pg and MySQL with Perl 5.12 due to interaction bug
in 5.10
David Lawrence [Wed, 14 May 2014 20:49:21 +0000 (16:49 -0400)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
- Only run webservices for Pg with Perl 5.12 due to interaction bug in
5.10
David Lawrence [Thu, 8 May 2014 20:38:41 +0000 (20:38 +0000)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
- Added the PostgreSQL webservices/selenium tests
David Lawrence [Wed, 7 May 2014 16:15:25 +0000 (16:15 +0000)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
David Lawrence [Fri, 2 May 2014 20:33:58 +0000 (20:33 +0000)]
Bug 995209 - Create a Build.PL script using Module::Build for testing/installing/packaging of Bugzilla code
- Fixed incorrect package name Apache-SizeLimit
David Lawrence [Fri, 2 May 2014 15:59:42 +0000 (15:59 +0000)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
David Lawrence [Thu, 1 May 2014 20:56:44 +0000 (20:56 +0000)]
Bug 995209 - Create a Build.PL script using Module::Build for testing/installing/packaging of Bugzilla code
r=glob,a=justdave
David Lawrence [Mon, 21 Apr 2014 21:05:14 +0000 (21:05 +0000)]
Bumped version post-release
David Lawrence [Fri, 18 Apr 2014 22:12:01 +0000 (22:12 +0000)]
Bump version to 4.2.9
Frédéric Buclin [Fri, 18 Apr 2014 21:49:16 +0000 (23:49 +0200)]
Bug 998484: Release notes for Bugzilla 4.2.9
r=dkl a=justdave
David Lawrence [Fri, 18 Apr 2014 21:03:43 +0000 (21:03 +0000)]
Bug 998323 - URLs pasted in comments are no longer displayed
r=LpSolit,a=justdave
David Lawrence [Thu, 17 Apr 2014 21:26:58 +0000 (21:26 +0000)]
Bumped version post-release
David Lawrence [Thu, 17 Apr 2014 17:13:45 +0000 (17:13 +0000)]
Bump version to 4.2.8
Manish Goregaokar [Thu, 17 Apr 2014 16:37:11 +0000 (18:37 +0200)]
Bug 968576: [SECURITY] Dangerous control characters allowed in Bugzilla text
r=glob a=justdave
Frédéric Buclin [Tue, 15 Apr 2014 21:53:26 +0000 (23:53 +0200)]
Bug 996168: Release notes for Bugzilla 4.2.8
r=dkl a=justdave
David Lawrence [Fri, 14 Mar 2014 18:16:05 +0000 (18:16 +0000)]
Copied over .bzrignore to .gitignore
Frédéric Buclin [Sat, 21 Dec 2013 16:45:40 +0000 (17:45 +0100)]
Bug 748095: Bugzilla crashes when the shutdownhtml parameter is set and using a non-cookie based authentication method
r=dkl a=justdave
Frédéric Buclin [Thu, 5 Dec 2013 22:43:34 +0000 (23:43 +0100)]
Bug 942599: Documentation about possible_duplicates() lists 'products' as argument instead of 'product'
r=dkl a=justdave
Frédéric Buclin [Mon, 2 Dec 2013 16:07:30 +0000 (17:07 +0100)]
Bug 938300: vers_cmp() incorrectly compares module versions
r=sgreen a=justdave
Frédéric Buclin [Mon, 2 Dec 2013 16:00:20 +0000 (17:00 +0100)]
Bug 781672: checksetup.pl fails to check the version of the latest Apache2::SizeLimit release (it throws "Invalid version format (non-numeric data)")
r=dkl a=justdave
Frédéric Buclin [Thu, 14 Nov 2013 17:01:14 +0000 (18:01 +0100)]
Bug 938161: sql_date_format() method for SQLite has an incorrect default format
r/a=glob
Frédéric Buclin [Wed, 13 Nov 2013 15:18:48 +0000 (16:18 +0100)]
Bug 843457: PROJECT environment variable is not honored when mod_perl is enabled
r/a=glob
Dave Lawrence [Thu, 17 Oct 2013 15:10:35 +0000 (11:10 -0400)]
Bump version post-release
Dave Lawrence [Wed, 16 Oct 2013 20:36:32 +0000 (16:36 -0400)]
Bump version to 4.2.7
Frédéric Buclin [Wed, 16 Oct 2013 17:26:25 +0000 (19:26 +0200)]
Bug 924932: (CVE-2013-1743) [SECURITY] Field values are (still) not escaped correctly in tabular reports
r=dkl a=glob
Frédéric Buclin [Wed, 16 Oct 2013 17:19:12 +0000 (19:19 +0200)]
Bug 924802: (CVE-2013-1742) [SECURITY] (XSS) "id" and "sortkey" are not sanitized when editing flag types if categoryAction-foo is set
r=dkl a=glob
Frédéric Buclin [Wed, 16 Oct 2013 17:08:20 +0000 (19:08 +0200)]
Bug 913904: (CVE-2013-1734) [SECURITY] CSRF when updating attachments
r=dkl a=sgreen
Dave Lawrence [Wed, 16 Oct 2013 16:27:00 +0000 (12:27 -0400)]
Bug 906745 - In MySQL, tokens are not case-sensitive, reducing total entropy and allowing easier brute force
r=LpSolit,a=sgreen
Dave Lawrence [Wed, 16 Oct 2013 16:14:11 +0000 (12:14 -0400)]
Bug 907438 - In MySQL, login cookie checking is not case-sensitive, reducing total entropy and allowing easier brute force
r=LpSolit,a=sgreen
Dave Lawrence [Wed, 16 Oct 2013 16:05:10 +0000 (12:05 -0400)]
Bug 906745 - In MySQL, tokens are not case-sensitive, reducing total entropy and allowing easier brute force
r=LpSolit,a=glob
Frédéric Buclin [Fri, 11 Oct 2013 22:13:42 +0000 (00:13 +0200)]
Bug 912640: Release notes for Bugzilla 4.2.7
r=dkl a=LpSolit
Frédéric Buclin [Thu, 26 Sep 2013 23:22:30 +0000 (01:22 +0200)]
Bug 914262: KHTML-based browsers such as Konqueror do not support the Server-Push technology
r=dkl a=justdave
Jiří Netolický [Mon, 23 Sep 2013 15:44:20 +0000 (17:44 +0200)]
Bug 919475: [Oracle] Crash when non-mandatory free text custom fields are left empty on bug creation
r=LpSolit a=justdave
Mateusz Kuśmierczyk [Tue, 3 Sep 2013 09:45:44 +0000 (11:45 +0200)]
Bug 848063: [Oracle] importxml.pl fails with ORA-01830: comment timestamps are not correctly formatted
r=LpSolit a=sgreen
Frédéric Buclin [Sat, 10 Aug 2013 00:45:28 +0000 (02:45 +0200)]
Back out bug 868330 for the 4.2 branch. This is not a security fix
Frédéric Buclin [Fri, 9 Aug 2013 09:30:58 +0000 (11:30 +0200)]
Bug 902515: Internet Explorer 11 receives multipart/x-mixed-replace content from buglist.cgi
r=dkl a=sgreen
Sunil Joshi [Fri, 9 Aug 2013 04:02:41 +0000 (14:02 +1000)]
Bug 868330 - Password creation directions incomplete
r=sgreen, a=sgreen
Simon Green [Fri, 9 Aug 2013 03:57:38 +0000 (13:57 +1000)]
Bug 897264 - letters_numbers_specialchars password restriction is incorrect
r=LpSolit, a=sgreen
Sunil Joshi [Wed, 7 Aug 2013 05:29:13 +0000 (15:29 +1000)]
Bug 901620 - Grammar error in the documentation
r=sgreen, a=glob
Dave Lawrence [Wed, 24 Jul 2013 14:19:05 +0000 (10:19 -0400)]
Bug 880653 - Add POD for Bug.possible_duplicates webservice
r=LpSolit,a=sgreen
Dave Lawrence [Mon, 15 Jul 2013 03:47:22 +0000 (23:47 -0400)]
Bug 787328 - xmlrpc.cgi doesn't send any security-related headers
r=glob,a=justdave
Dave Lawrence [Wed, 22 May 2013 20:09:47 +0000 (16:09 -0400)]
Bump version post-release
Dave Lawrence [Wed, 22 May 2013 18:46:58 +0000 (14:46 -0400)]
Bump version to 4.2.6
Byron Jones [Wed, 22 May 2013 17:03:13 +0000 (01:03 +0800)]
Bug 828344: add missing xt broken tests
Byron Jones [Mon, 20 May 2013 17:54:06 +0000 (01:54 +0800)]
Bug 828344: "contains all of the words" no longer looks for all words within the same comment or flag
r=LpSolit, a=LpSolit
Frédéric Buclin [Sat, 18 May 2013 14:06:25 +0000 (16:06 +0200)]
Bug 870701: Release notes for Bugzilla 4.2.6
r=dkl a=LpSolit
Frédéric Buclin [Sun, 5 May 2013 21:35:46 +0000 (23:35 +0200)]
Bug 212471: Tabular reports do not link bug counts involving the empty resolution correctly
r=dkl a=LpSolit
Dave Lawrence [Fri, 3 May 2013 22:23:50 +0000 (18:23 -0400)]
Bug 859118 - Bug.search called with no arguments returns all visible bugs, ignoring max_search_results and search_allow_no_criteria
r/a=LpSolit
Frédéric Buclin [Sun, 28 Apr 2013 11:51:50 +0000 (13:51 +0200)]
Bug 848635: Old queries based on tags are no longer listed in the page footer by default when upgrading from 4.0 or older to 4.2
r=glob a=LpSolit
Frédéric Buclin [Sun, 28 Apr 2013 11:40:12 +0000 (13:40 +0200)]
Bug 858909: When running checksetup.pl for the first time using Oracle as DB server, you get an "uninitialized value" warning
r=dkl a=LpSolit
Frédéric Buclin [Wed, 17 Apr 2013 23:26:19 +0000 (01:26 +0200)]
Bug 858911: Oracle fails with "ORA-04043: object T_GROUP_CONCAT does not exist" when installing Bugzilla for the first time
r=dkl a=LpSolit
Byron Jones [Wed, 17 Apr 2013 17:38:22 +0000 (01:38 +0800)]
revert commit for bug 828344
Byron Jones [Wed, 17 Apr 2013 17:18:03 +0000 (01:18 +0800)]
Bug 828344: Make "contains all of the words" look for all words within the same comment or flag
r=LpSolit, a=LpSolit
Pami Ketolainen [Tue, 16 Apr 2013 10:14:23 +0000 (12:14 +0200)]
Bug 782210: If a custom field depends on a product, component or classification, the "mandatory" bit is ignored on bug creation
r/a=LpSolit
Frédéric Buclin [Mon, 15 Apr 2013 21:27:10 +0000 (23:27 +0200)]
Bug 861528: $user->can_enter_product() now returns the product object instead of 1
r=glob a=LpSolit
Pami Ketolainen [Thu, 11 Apr 2013 13:18:07 +0000 (15:18 +0200)]
Bug 860723: Custom fields are shown twice in report axis selectors
r/a=LpSolit
Christopher Trom [Tue, 9 Apr 2013 10:26:06 +0000 (12:26 +0200)]
Bug 355620: Lines enclosed in <simplelist> do not wrap in the PDF version of the Bugzilla Guide
r/a=LpSolit
Frédéric Buclin [Fri, 5 Apr 2013 20:00:12 +0000 (22:00 +0200)]
Bug 857562: ajax_user_autocompletion param ignored on Search by People fields
r=dkl a=LpSolit
Frédéric Buclin [Fri, 5 Apr 2013 19:54:25 +0000 (21:54 +0200)]
Bug 855258: The dependency graph always uses urlbase, even when sslbase is in use
r=glob a=LpSolit
Frédéric Buclin [Tue, 26 Mar 2013 11:07:25 +0000 (12:07 +0100)]
Bug 854074: Remove all references to the uwinnipeg.ca PPM repository as it is no longer available
r=glob a=LpSolit
Frédéric Buclin [Wed, 20 Mar 2013 12:07:04 +0000 (13:07 +0100)]
Bug 852560: Bugzilla cannot be installed with MySQL 5.6, because the have_innodb variable no longer exists
r=glob a=LpSolit
Hugo Seabrook [Sat, 16 Mar 2013 16:21:37 +0000 (17:21 +0100)]
Bug 827983: "[reply]" link besides the original description will insert ("in reply to comment #N+1") when the comments order is "Newest to Oldest, but keep Descritption at the top"
r/a=LpSolit
Reed Loden [Tue, 12 Mar 2013 17:06:32 +0000 (10:06 -0700)]
Bug 850126 - 'token' id defined twice on logged-out pages (in header and footer)
[r=LpSolit a=LpSolit]
Frédéric Buclin [Fri, 8 Mar 2013 11:55:02 +0000 (12:55 +0100)]
Bug 848250: Bug summary tooltip now includes "---" for unresolved bugs
r=dkl a=LpSolit
Dave Lawrence [Wed, 20 Feb 2013 01:16:57 +0000 (20:16 -0500)]
Bump version post-release
Dave Lawrence [Tue, 19 Feb 2013 18:42:23 +0000 (13:42 -0500)]
Bumped current year