]>
git.ipfire.org Git - thirdparty/bugzilla.git/log
Frédéric Buclin [Thu, 19 Nov 2015 23:45:35 +0000 (00:45 +0100)]
Bug
1223790 : "AllowOverride AuthConfig" is required to use the "Require" directive in .htaccess
r=gerv a=dkl
David Lawrence [Thu, 10 Sep 2015 21:39:08 +0000 (17:39 -0400)]
Bumped version post-release
David Lawrence [Thu, 10 Sep 2015 17:44:09 +0000 (13:44 -0400)]
Bumped version to 4.4.10
Byron Jones ‹:glob› [Thu, 10 Sep 2015 17:27:44 +0000 (13:27 -0400)]
Bug
1202447 : [SECURITY] The email address is not properly validated during registration if longer than 127 characters
r=LpSolit,a=justdave
Frédéric Buclin [Wed, 9 Sep 2015 22:02:37 +0000 (00:02 +0200)]
Bug
1202464 : Release notes for Bugzilla 4.4.10
r=dkl
Byron Jones [Sat, 29 Aug 2015 09:46:40 +0000 (11:46 +0200)]
Bug
1031035 : xmlrpc can be DoS'd with billion laughs attack
r=LpSolit a=justdave
David Lawrence [Tue, 11 Aug 2015 21:57:09 +0000 (17:57 -0400)]
Taskcluster infrastructure improvements and cleanup
Frédéric Buclin [Fri, 5 Jun 2015 09:07:24 +0000 (11:07 +0200)]
Bug
1124401 : Explicitly depend on DateTime::TimeZone::Local::Win32 on Windows
r=dylan a=glob
Byron Jones [Thu, 4 Jun 2015 13:46:42 +0000 (21:46 +0800)]
Bug
1134743 : javascript filter should escape unicode line and paragraph separators (causes "Unterminated string literal" javascript error)
r=dylan,a=glob
Jeff Fearn [Mon, 18 May 2015 04:38:47 +0000 (12:38 +0800)]
Bug
1162334 : email_enabled value inverted in User.update RPC call
r=glob,a=glob
Frédéric Buclin [Fri, 24 Apr 2015 16:48:33 +0000 (18:48 +0200)]
Bug
1157405 : Bugzilla.parameters is not accessible when requirelogin = 1 and the user is not logged in
r=dkl a=glob
David Lawrence [Wed, 15 Apr 2015 19:33:11 +0000 (20:33 +0100)]
Bump version post-release
David Lawrence [Wed, 15 Apr 2015 16:00:49 +0000 (17:00 +0100)]
Bumped version to 4.4.9
David Lawrence [Wed, 15 Apr 2015 03:02:59 +0000 (04:02 +0100)]
Bug
1154316 : Release notes for 4.4.9
r=LpSolit,a=dkl
Matt Tyson [Tue, 14 Apr 2015 23:39:13 +0000 (01:39 +0200)]
Bug
1154099 : Bug.get_bugs and Bug.get_history are missing from PUBLIC_METHODS (for backwards compatibility)
r=LpSolit a=glob
Simon Green [Mon, 13 Apr 2015 20:35:28 +0000 (21:35 +0100)]
Bug
1151290 : It is possible to tell if someone made a private comment on a bug even if you are not an 'insider'
r=dkl,a=glob
Frédéric Buclin [Mon, 16 Mar 2015 17:18:49 +0000 (18:18 +0100)]
Bug
1137669 : 003safesys.t doesn't test any file due to a missing -T argument
r=dylan a=glob
Frédéric Buclin [Wed, 11 Mar 2015 17:26:25 +0000 (18:26 +0100)]
Bug
1138463 : mod_perl does not support Apache 2.4 directives
r=dkl a=glob
David Lawrence [Tue, 3 Mar 2015 20:00:56 +0000 (15:00 -0500)]
(TaskCluster) Allow retrieval of the selenium.log for Selenium tests
David Lawrence [Tue, 24 Feb 2015 23:28:28 +0000 (23:28 +0000)]
Intial checking of taskgraph.json for TaskCluster CI
Frédéric Buclin [Fri, 20 Feb 2015 12:05:19 +0000 (13:05 +0100)]
Bug
1133690 : .htaccess incorrectly assumes that Apache 2.2.x can read new 2.4 directives
r=dkl a=glob
Frédéric Buclin [Tue, 17 Feb 2015 20:36:30 +0000 (21:36 +0100)]
Bug
1132887 : When starting a sudo session, the password is not validated
r=dkl a=glob
Frédéric Buclin [Tue, 17 Feb 2015 20:30:05 +0000 (21:30 +0100)]
Bug
1112181 : Relative dates in the future involving months are incorrectly converted
r=dylan a=glob
Gervase Markham [Tue, 17 Feb 2015 17:21:48 +0000 (17:21 +0000)]
Bug
1132862 - Update README; add LICENSE file. r,a=glob
David Lawrence [Tue, 17 Feb 2015 02:31:17 +0000 (21:31 -0500)]
- Force use of PostgreSQL 9.1
- Configure DB users in travis.yml
Byron Jones [Mon, 16 Feb 2015 04:17:48 +0000 (12:17 +0800)]
Bug 651786: Modifying the default user object modifies the DEFAULT_USER constant
r=sgreen,a=glob
Jochen Wiedmann [Mon, 2 Feb 2015 16:34:21 +0000 (16:34 +0000)]
Bug
1121477 : Support for Apache HTTPD 2.4
r=dkl,a=glob
Frédéric Buclin [Wed, 28 Jan 2015 16:06:01 +0000 (17:06 +0100)]
Fix typo
David Lawrence [Tue, 27 Jan 2015 20:01:23 +0000 (20:01 +0000)]
Bump version post-release
David Lawrence [Tue, 27 Jan 2015 15:53:10 +0000 (15:53 +0000)]
Bumped version to 4.4.8
David Lawrence [Tue, 27 Jan 2015 15:43:02 +0000 (15:43 +0000)]
Bug
1125186 : Release notes for 4.4.8
r=justdave,a=dkl
David Lawrence [Fri, 23 Jan 2015 17:13:32 +0000 (17:13 +0000)]
Bug
1124716 : regression caused by bug
1090275 to whitelist webservice methods causes test failures with t/012throwables.t
r=dylan,a=glob
Albert Ting [Thu, 22 Jan 2015 12:10:44 +0000 (12:10 +0000)]
Bug
1116614 : checksetup "use lib" called too late. r=gerv, a=glob.
David Lawrence [Wed, 21 Jan 2015 22:30:09 +0000 (22:30 +0000)]
Bump version post-release
David Lawrence [Wed, 21 Jan 2015 21:09:16 +0000 (21:09 +0000)]
Bumped version to 4.4.7
David Lawrence [Wed, 21 Jan 2015 20:41:11 +0000 (20:41 +0000)]
Bug
1090275 : WebServices modules should maintain a whitelist of methods that are allowed instead of allowing access to any function imported into its namespace
r=dylan,a=glob
Gervase Markham [Wed, 21 Jan 2015 20:22:21 +0000 (20:22 +0000)]
Bug
1079065 : [SECURITY] Always use the 3 arguments form for open() to prevent shell code injection
r=dylan,a=simon
Frédéric Buclin [Mon, 19 Jan 2015 21:33:04 +0000 (22:33 +0100)]
Fix an obsolete ID
David Lawrence [Mon, 19 Jan 2015 20:33:44 +0000 (20:33 +0000)]
Bug
1118984 : Release notes for 4.4.7
r=LpSolit,a=glob
Frédéric Buclin [Mon, 5 Jan 2015 18:30:57 +0000 (19:30 +0100)]
Bug
1085182 : Bugzilla::Bug->check must check that a bug ID is defined when it gets a hashref
r=dkl a=glob
Frédéric Buclin [Tue, 23 Dec 2014 10:02:20 +0000 (11:02 +0100)]
Bug
1106653 : Truncate the field-* and type-* values in error messages
r=dkl a=glob
Frédéric Buclin [Wed, 17 Dec 2014 19:42:10 +0000 (20:42 +0100)]
Bug
1111043 : Bug.add_comment returns the wrong comment ID
r/a=dkl
David Lawrence [Thu, 20 Nov 2014 15:16:33 +0000 (15:16 +0000)]
Bug
1101151 : OS sniffing should detect Windows 10 from "Windows NT 6.4" instead of detecting Windows NT
r=LpSolit,a=glob
Frédéric Buclin [Wed, 19 Nov 2014 17:23:22 +0000 (18:23 +0100)]
Bug
1097798 : Do not display the resolution in the dependency tree for open bugs, nor the target milestone if usetargetmilestone is off
r=dkl a=glob
David Lawrence [Wed, 12 Nov 2014 16:58:12 +0000 (16:58 +0000)]
Bug
1001462 : Bug.search causes error when using simple token auth and specifying 'token' instead of 'Bugzilla_token'
r=glob,a=glob
David Lawrence [Tue, 4 Nov 2014 19:21:11 +0000 (19:21 +0000)]
Bug
1082106 : $dbh->bz_add_columns creates a foreign key constraint causing failure in checksetup.pl when it tries to re-add it later
r=glob,a=glob
Frédéric Buclin [Mon, 27 Oct 2014 10:47:25 +0000 (11:47 +0100)]
Bug
1087400 : CGI 4.05 throws tons of "CGI::param called in list context" warnings
r/a=glob
Frédéric Buclin [Mon, 27 Oct 2014 10:44:53 +0000 (11:44 +0100)]
Bug
1088483 : Remove references to the "enable bug tagging" preference from the documentation
r=gerv a=glob
Frédéric Buclin [Wed, 22 Oct 2014 01:15:20 +0000 (03:15 +0200)]
Bug
1033068 : The "unknown_action" error message could confuse the user
r=dkl a=sgreen
David Lawrence [Tue, 21 Oct 2014 13:58:58 +0000 (13:58 +0000)]
Bug
1082882 : custom date field not recognized as date type in advanced search
r=glob,a=glob
Frédéric Buclin [Tue, 21 Oct 2014 10:09:31 +0000 (12:09 +0200)]
Bug
1083737 : Validate the smtpserver parameter
r=dkl a=glob
Byron Jones [Thu, 16 Oct 2014 07:31:53 +0000 (15:31 +0800)]
Bug
1082887 : comments made when setting a flag from the attachment details page are not included in the "flag updated" email
r=dkl,a=glob
Simon Green [Wed, 8 Oct 2014 03:02:24 +0000 (13:02 +1000)]
Bug
1009406 - A user with local editcomponents privs cannot update the inclusion and exclusion lists when the flagtype is already restricted to products the user cannot edit
r=dkl, a=simon
David Lawrence [Mon, 6 Oct 2014 18:36:39 +0000 (18:36 +0000)]
Bump version post-release
David Lawrence [Mon, 6 Oct 2014 15:24:58 +0000 (15:24 +0000)]
Bump version to 4.4.6
Simon Green [Mon, 6 Oct 2014 15:03:41 +0000 (15:03 +0000)]
Bug
1054702 : CSV export vulnerable to formulae injection
r=glob,a=glob
Simon Green [Mon, 6 Oct 2014 14:47:38 +0000 (14:47 +0000)]
Bug
1064140 : [SECURITY] Private comments can be shown to flagmail recipients who aren't in the insider group
r=glob,a=glob
Frédéric Buclin [Mon, 6 Oct 2014 14:35:25 +0000 (14:35 +0000)]
Bug
1074980 : Forbid the { foo => $cgi->param() } syntax to prevent data override
r=dkl,a=sgreen
Frédéric Buclin [Mon, 6 Oct 2014 14:27:01 +0000 (14:27 +0000)]
Bug
1075578 : [SECURITY] Improper filtering of CGI arguments
r=dkl,a=sgreen
David Lawrence [Mon, 6 Oct 2014 14:16:24 +0000 (14:16 +0000)]
Bug
1072490 : Release notes for 4.4.6
r=LpSolit,a=sgreen
Simon Green [Wed, 1 Oct 2014 11:00:23 +0000 (21:00 +1000)]
Bug
1069760 - Cannot use 'component' in a template
r=gerv, a=justdave
Frédéric Buclin [Wed, 1 Oct 2014 10:07:34 +0000 (12:07 +0200)]
Fix bustage due to bug
1061247
Reed Loden [Wed, 1 Oct 2014 05:37:11 +0000 (22:37 -0700)]
Bug
1061247 - Successfully using a password change token should invalidate all other password change tokens for that user
r=gerv a=glob
Dylan William Hardison [Tue, 30 Sep 2014 22:01:38 +0000 (18:01 -0400)]
Bug
1070317 - Bugzilla::Flag's attribute modification_date is affected by the user's timezone and differs from the database copy after a call to $flag->update()
r=dkl, a=justdave
David Lawrence [Mon, 22 Sep 2014 13:58:37 +0000 (13:58 +0000)]
Bug
1069363 : "show user list again" link does not include is_enabled for showing previous results list
r=glob,a=glob
Vishant Gautam [Mon, 15 Sep 2014 16:06:23 +0000 (18:06 +0200)]
Bug 252555: Remove the ANSI mode when running MySQL
r=LpSolit a=sgreen
Matt Tyson [Wed, 10 Sep 2014 15:05:52 +0000 (23:05 +0800)]
Bug
1036242 : "TypeError: bug_status is undefined" when creating a bug
r=glob,a=sgreen
Frédéric Buclin [Mon, 8 Sep 2014 10:35:08 +0000 (12:35 +0200)]
Bug
1046213 : datetime_from() generates wrong dates if year < 1901
r=sgreen a=glob
Simon Green [Mon, 8 Sep 2014 03:51:42 +0000 (13:51 +1000)]
Bug 768892 - Specific Search without search words yields invalid_column_name message, complaining about sort order "relevance desc"
r=gerv, a=glob
Dylan William Hardison [Thu, 4 Sep 2014 01:05:50 +0000 (21:05 -0400)]
Bug
1040728 - testserver.pl on Ubuntu 12.04 with Apache2 invalidly gives error 'Failed to find the GID for the 'httpd' process' due to truncated command name
r=gerv,a=sgreen
Simon Green [Sun, 24 Aug 2014 00:12:01 +0000 (10:12 +1000)]
Bug
1008766 - Fix typo in documentation
r=glob, a=sgreen
Frédéric Buclin [Tue, 19 Aug 2014 10:36:52 +0000 (12:36 +0200)]
Bug
1053802 : Groups used for the comment_taggers_group and debug_group parameters can be deleted
r=sgreen a=glob
Frédéric Buclin [Tue, 5 Aug 2014 23:44:20 +0000 (01:44 +0200)]
Bug
1046145 : It is no longer possible to cancel an email address change when this one has already been confirmed
r=dkl a=sgreen
David Lawrence [Thu, 24 Jul 2014 21:38:49 +0000 (21:38 +0000)]
Bump version post-release
David Lawrence [Thu, 24 Jul 2014 17:42:07 +0000 (17:42 +0000)]
Bump version to 4.4.5 (corrected)
Simon Green [Thu, 24 Jul 2014 17:34:12 +0000 (17:34 +0000)]
Bug
1036213 - (CVE-2014-1546) add '/**/' before jsonrpc.cgi callback to avoid swf content type sniff vulnerability
r=glob,a=sgreen
David Lawrence [Thu, 24 Jul 2014 17:02:01 +0000 (17:02 +0000)]
Bump version to 4.4.5
David Lawrence [Thu, 24 Jul 2014 16:42:44 +0000 (16:42 +0000)]
Bug
1042087 - Release notes for 4.4.5
r=glob
rojanu [Mon, 16 Jun 2014 23:24:19 +0000 (09:24 +1000)]
Bug
1024987 - contrib/bz_webservice_demo.pl fails after User Token login update
r=sgreen, a=justdave
Simon Green [Mon, 16 Jun 2014 23:11:05 +0000 (09:11 +1000)]
Bug 653597 - Reports with "Real Name" fields use foo_real_name in the url parameters for linked queries
r=gerv, a=justdave
Byron Jones [Wed, 11 Jun 2014 15:12:09 +0000 (23:12 +0800)]
Bug 978146: activity entry when setting flags isn't split across multiple rows
r=dkl,a=sgreen
Byron Jones [Tue, 20 May 2014 05:50:48 +0000 (13:50 +0800)]
Bug
1009017 : users are unable to log in if their password needs to be
re-encrypted and their password does not match the current complexity
rule
r=dkl, a=glob
David Lawrence [Thu, 15 May 2014 21:42:37 +0000 (21:42 +0000)]
Bug
1011250 - Updates IRC notification text to include commit message and also send to #bugzilla
David Lawrence [Thu, 15 May 2014 02:50:07 +0000 (02:50 +0000)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
- Only run webservices for Pg and MySQL with Perl 5.12 due to interaction bug
in 5.10
David Lawrence [Wed, 14 May 2014 20:47:16 +0000 (16:47 -0400)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
- Only run webservices for Pg with Perl 5.12 due to interaction bug in
5.10
Byron Jones [Wed, 14 May 2014 05:28:41 +0000 (13:28 +0800)]
Bug
1006288 : add File::Slurp to the list of optional modules
r=dkl, a=glob
David Lawrence [Mon, 12 May 2014 19:14:53 +0000 (15:14 -0400)]
Backed out Bug
1001462 - Bug.search causes error when using simple token auth and specifying 'token' instead of 'Bugzilla_token'
Frédéric Buclin [Mon, 12 May 2014 17:29:10 +0000 (19:29 +0200)]
Bug
1003852 : Digest::SHA 5.82 and newer always croak on wide characters, preventing users with Unicode passwords from logging in
r/a=glob
David Lawrence [Mon, 12 May 2014 14:38:02 +0000 (14:38 +0000)]
Bug
1001462 - Bug.search causes error when using simple token auth and specifying 'token' instead of 'Bugzilla_token'
r/a=glob
David Lawrence [Thu, 8 May 2014 20:37:06 +0000 (20:37 +0000)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
- Added the PostgreSQL webservices/selenium tests
David Lawrence [Wed, 7 May 2014 16:18:44 +0000 (16:18 +0000)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
Byron Jones [Mon, 5 May 2014 07:15:37 +0000 (15:15 +0800)]
Bug 999331: searching attachment data is very slow due to an unbounded
select
r=LpSolit, a=glob
David Lawrence [Fri, 2 May 2014 20:33:08 +0000 (20:33 +0000)]
Bug 995209 - Create a Build.PL script using Module::Build for testing/installing/packaging of Bugzilla code
- Fixed incorrect package name Apache-SizeLimit
David Lawrence [Fri, 2 May 2014 15:56:22 +0000 (15:56 +0000)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
David Lawrence [Fri, 2 May 2014 15:55:33 +0000 (15:55 +0000)]
Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ci
Dave Miller [Fri, 2 May 2014 02:12:25 +0000 (22:12 -0400)]
Bug 999296: Make checksetup.pl not complain about having added new
values to localconfig when those values were supplied by an answer file.
r=LpSolit, a=justdave
David Lawrence [Thu, 1 May 2014 20:54:55 +0000 (20:54 +0000)]
Bug 995209 - Create a Build.PL script using Module::Build for testing/installing/packaging of Bugzilla code
r=glob,a=justdave
Frédéric Buclin [Tue, 29 Apr 2014 17:06:34 +0000 (19:06 +0200)]
Bug
1001846 : When editing cc_accessible using Bug.update, the method should always return is_cc_accessible as being changed
r=dkl a=justdave
Frédéric Buclin [Fri, 25 Apr 2014 20:19:43 +0000 (22:19 +0200)]
Bug
1001497 : User.login incorrectly returns id = 0 when the login or password is missing
r=dkl a=justdave
David Lawrence [Mon, 21 Apr 2014 21:03:59 +0000 (21:03 +0000)]
Bumped version post-release