Commit graph

15818 commits

Author SHA1 Message Date
Kijin Sung
01ef797c0b Grant 그룹처리 보완 1844fa4 2017-04-17 11:38:01 +09:00
Kijin Sung
05b8e2e431 Fix malformed tag in config_domains.html 2017-04-16 17:37:10 +09:00
Kijin Sung
1844fa4eee Fix grant error when multiple groups are specified 2017-04-16 17:13:43 +09:00
Kijin Sung
0937da9fff Add jquerycdn to blacklist
We cannot allow half-assed attempts to replace scripts that the
rest of the environment heavily depends on.

Similar functionality will be exposed via a more stable API
at some later time.

https://www.xetown.com/square/564456
2017-04-16 10:16:43 +09:00
Kijin Sung
856544a058 Fix typo in DocumentController::makeCategoryFile() 2017-04-15 21:46:38 +09:00
Kijin Sung
f531c53d37 Add notice that sending a message via email will expose the sender's email address to the recipient #792 2017-04-14 19:58:27 +09:00
Kijin Sung
806f8ab037 Do not check license agreement file 2017-04-14 19:50:54 +09:00
conory
1c3ae98431 권한 기본 값이 적용되지 않는 문제 수정 2017-04-14 18:20:26 +09:00
Kijin Sung
7dd418d379 Version 1.8.36 2017-04-14 16:33:07 +09:00
Kijin Sung
fe489420ad Fix #785 excessive use of cache by counter module 2017-04-14 16:31:49 +09:00
Kijin Sung
f7d19ea47c Fix #785 excessive use of cache in SEO function 2017-04-14 16:16:28 +09:00
Kijin Sung
fb4dd4fddc Version 1.8.35 2017-04-14 15:29:34 +09:00
Kijin Sung
a400cc4b40 Remove unused file: redirect.html
https://github.com/xpressengine/xe-core/issues/2069
2017-04-14 15:25:22 +09:00
bnu
5798face60 close #2068 사용하지 않는 필터 제거 2017-04-14 15:19:21 +09:00
bnu
65152c96f0 fix #2071 XEVE-17-018 설문조사 모듈의 보안 취약점 문제 고침
- 취약점 제보 : conory님
2017-04-14 15:18:27 +09:00
Kijin Sung
e19ef3ab41 Fix #791 missing translation for subtitle_primary 2017-04-13 23:34:56 +09:00
Kijin Sung
dc4616eecc Merge pull request #794 from kijin/pr/board-api-security
Board API를 통한 데이터 노출 방지
2017-04-13 23:31:55 +09:00
Kijin Sung
d343422541 Fix exposure of unnecessary information via board API 2017-04-13 23:18:49 +09:00
bnu
bff80770f1 fix #2064 link 태그 사용 시 self-closing 차이에 따라 뒤에 오는 태그를 head 영역으로 잘못 끌어 올리는 문제 고침 2017-04-12 20:33:59 +09:00
Kijin Sung
1591f8b728 Fix missing default URL during install, especially on SSL
https://www.xetown.com/lakepark/560017
2017-04-11 15:59:19 +09:00
conory
9026f9df8a prevent xss 2017-04-11 14:42:56 +09:00
Kijin Sung
4e157c9ec0 Merge pull request #787 from kijin/pr/ckeditor-ios-br
iOS에서 한글 입력시 줄바꿈이 잘 되지 않는 문제 보완
2017-04-10 15:55:36 +09:00
CONORY
44d6c8f63f Merge pull request #786 from conory/pr/permission
module.xml <action>에 permission 속성 추가
2017-04-10 15:43:08 +09:00
conory
c1d96cddd4 root = is_admin 취급 2017-04-10 15:29:35 +09:00
conory
ddc7d31661 코드 정리 2017-04-10 14:58:31 +09:00
conory
9df5c915a8 Creating default object from empty value 오류 수정 2017-04-10 11:30:42 +09:00
Kijin Sung
f0d52f8a91 Fix escaped XML content: cf. xpressengine/xe-core#2042 2017-04-10 10:06:34 +09:00
conory
3298946a5e 잘못된 동작 수정 2017-04-08 22:41:01 +09:00
Kijin Sung
8147044802 Fix toBool() and add more test cases 2017-04-08 22:02:03 +09:00
Kijin Sung
f73580945d Remove unnecessary polyfill for hex2bin() 2017-04-08 21:57:34 +09:00
conory
5ad0ee91a5 *-managers 정규식 구체화 2017-04-08 20:12:17 +09:00
conory
1d4437135c 승인 권한 (grant) 구분자 변경 2017-04-08 18:10:30 +09:00
Kijin Sung
43f3d41543 Make enter key insert a BR tag instead of P when used on iOS 2017-04-08 17:22:00 +09:00
conory
fc6206ab75 module.xml 3차 정리
action에 permission 속성을 부여하는 방식으로 변경
board, page 모듈 action에  grant 퍼미션 설정
2017-04-08 15:50:06 +09:00
conory
f224a4aea0 <action>에 퍼미션 속성 추가
승인 권한 (grant)도 퍼미션 체크를 할 수 있도록 추가
2017-04-07 14:55:33 +09:00
CONORY
87131a1b93 Merge pull request #765 from conory/pr/grant
모듈 권한 정리 및 퍼미션 체크 지원
2017-04-06 21:58:53 +09:00
conory
9713e99144 standalone 속성 적용으로 의도 되지 않은 부분 차단 2017-04-05 21:49:33 +09:00
conory
0dc3d92465 module.xml 2차 정리
act 를 세밀하게 검토한 후 합당한 퍼미션을 걸어둠
2017-04-05 16:18:18 +09:00
Kijin Sung
0777a66703 Fix incorrect detection of form method if there is an input tag with the name 'method' 2017-04-01 22:07:38 +09:00
conory
fcb17fe9cf module.xml 1차 정리
탭 정리
일부 permission, action 정리
2017-03-29 22:23:26 +09:00
conory
5bdd0091ec 모듈이름 정규식으로 개선 2017-03-29 16:25:05 +09:00
conory
74d1b221d9 특정 모듈의 매니저를 지정할 수 있도록 개선 2017-03-29 15:33:44 +09:00
conory
cd2760c4f5 check_var 속성 기본값 제거
'all-managers', 'same-managers'  퍼미션 타입 추가
코드 정리
2017-03-29 12:54:27 +09:00
BJRambo
36c36cc19b fix typo 2017-03-27 20:46:31 +09:00
Kijin Sung
c41ded3124 Fix #773 no refresh after redirect() when not using mod_rewrite 2017-03-24 16:33:24 +09:00
Kijin Sung
d6de6f479c Pass member info in member.getMemberMenu (before, after) trigger #752 2017-03-23 19:51:18 +09:00
Kijin Sung
16cb56d8dc Prohibit use of reserved word as member extra field #763 2017-03-23 19:48:08 +09:00
Kijin Sung
97047d1279 Add list of reserved words #763 2017-03-23 19:43:49 +09:00
Kijin Sung
fae2a05b6f Fix link to default URL in admin module when SSL is optional 2017-03-23 19:25:13 +09:00
Kijin Sung
d2a3b5203c Fix #767 error when query argument is not an object 2017-03-23 19:23:45 +09:00