Commit graph

15545 commits

Author SHA1 Message Date
Kijin Sung
24c29cfbdb Version 1.8.31 2017-02-25 15:35:16 +09:00
Kijin Sung
f3a43d071e Fix vulnerability in procMemberDeleteSavedDocument 2017-02-25 15:08:42 +09:00
Kijin Sung
6df32746c3 Refresh isAccessible() if document or comment is updated
https://www.xetown.com/qna/510717
2017-02-24 15:47:01 +09:00
Kijin Sung
3d16272d01 Merge pull request #727 from kijin/pr/template-filters
템플릿 필터 지원
2017-02-23 22:37:28 +09:00
Kijin Sung
77282401e3 Add even more unit tests for malformed filter detection 2017-02-23 22:25:25 +09:00
Kijin Sung
f338d38538 Improve regexp for template filters 2017-02-23 22:25:13 +09:00
Kijin Sung
c4c5fa9e0d Add more unit tests for edge cases 2017-02-23 22:15:03 +09:00
Kijin Sung
d03c64d069 Make the test for filters more strict to prevent unintended parsing 2017-02-23 22:14:51 +09:00
Kijin Sung
1974f21482 Version 1.8.30 2017-02-23 16:11:06 +09:00
bnu
628242a387 Fix #2036 XEVE-17-003 커뮤니케이션 모듈의 쪽지를 임의로 삭제할 수 있는 문제 고침 2017-02-23 16:06:17 +09:00
Kijin Sung
ad21b1e706 Fix warning in fileAdminView when upload target type does not exist 2017-02-22 23:11:29 +09:00
Kijin Sung
5638207fb0 Change behavior of 'autoescape' filter to always escape (but not double-escape) 2017-02-22 21:29:15 +09:00
Kijin Sung
7fd0f5df7b Add unit tests for template filters 2017-02-22 21:24:26 +09:00
Kijin Sung
0c4dbc34ff Add 'trim' filter and adjust some other settings 2017-02-22 21:24:10 +09:00
Kijin Sung
0c20794219 Implement several template filters 2017-02-22 20:58:37 +09:00
Kijin Sung
8ad6f40abd Enable ztime() function to process Unix timestamps 2017-02-22 20:20:55 +09:00
Kijin Sung
4ee115e4f3 Improve server environment display 2017-02-22 19:49:49 +09:00
bnu
954d2c7ec6 Fix #2035 XEVE-17-002 쉬운 설치 페이지에서 발생하는 보안 취약점 고침
- 제보자 : 최봉환(stayp05)
2017-02-22 16:46:34 +09:00
Kijin Sung
fbe47e0610 Remove temporary list of override domains in Session class 2017-02-18 22:57:39 +09:00
Kijin Sung
f85a1f036c Merge pull request #721 from kijin/pr/video-autoinsert
동영상 소스를 에디터에 붙여넣으면 자동 삽입되도록 개선
2017-02-18 17:10:40 +09:00
Kijin Sung
a305745aa5 Automatically insert video when iframe source is pasted into editor 2017-02-18 17:04:07 +09:00
bnu
b340d95e18 Fix #2033 PHP 7.1 환경에서 DB 세션 사용 시 로그인 등 세션처리 문제 고침
- 필요 없는 column 확인 코드 제거
2017-02-17 21:55:49 +09:00
Kijin Sung
58a3b47246 Add unit test to ensure that data-file-srl is not deleted 2017-02-17 21:48:52 +09:00
Kijin Sung
cbc0197be6 Fix data-file-srl attribute being deleted by HTMLFilter 2017-02-17 21:45:03 +09:00
Kijin Sung
5c8a41a655 Fix PHP warning 2017-02-17 21:38:03 +09:00
Kijin Sung
2582ef2100 More thoroughly delete conflicting cookies 2017-02-17 21:09:57 +09:00
Kijin Sung
64f0d5cb45 Remove Android Chrome from buggy user-agent list 2017-02-17 20:24:13 +09:00
Kijin Sung
205180a632 Fix unit tests 2017-02-17 20:23:10 +09:00
Kijin Sung
563814a2f3 Remove unnecessary calculation of comment count 2017-02-17 20:16:16 +09:00
Kijin Sung
51acad706e Remove unnecessary regex replacement 2017-02-17 20:15:56 +09:00
Kijin Sung
50410ec482 Delete conflicting wildcard cookies from subdomain 2017-02-17 19:44:01 +09:00
Kijin Sung
780034d4ee Do not explicitly set the domain for session cookies 2017-02-17 19:33:05 +09:00
Kijin Sung
0801c1283e Merge pull request #719 from kijin/pr/ckeditor-update
CKEditor 최신 버전으로 업데이트
2017-02-16 16:38:12 +09:00
Kijin Sung
fa36fd184c Fix default editor skin in signature editor 2017-02-16 12:14:54 +09:00
Kijin Sung
cbae2c374e Use meta refresh instead of 302 redirect on new session
Attempting to fix missing session cookie in some versions of Android webview and Chrome.
This may or may not be of any use, but why not try?

See https://bugs.chromium.org/p/chromium/issues/detail?id=150066
2017-02-16 11:53:27 +09:00
Kijin Sung
d4353fa8d2 Change default editor colorset in other modules to moono-lisa 2017-02-16 01:26:08 +09:00
Kijin Sung
e17c4b9c38 Update CKEditor to 4.6.2 2017-02-16 01:17:15 +09:00
Kijin Sung
5afa29484c Fix inconsistent use of whitespace 2017-02-16 00:09:07 +09:00
Kijin Sung
852df061de Fix inconsistent use of whitespace 2017-02-16 00:08:45 +09:00
Kijin Sung
48db8bf660 Fix #709 invalid update of autologin security keys 2017-02-16 00:06:29 +09:00
Kijin Sung
3a46d7d6c2 Fix #716 incorrect display of default view count option 2017-02-15 23:13:04 +09:00
Kijin Sung
4f774bb460 Fix unit tests 2017-02-15 11:47:43 +09:00
Kijin Sung
6b0dd6c192 Standardize password hashing work factor to 10 by default 2017-02-15 11:34:39 +09:00
Kijin Sung
45bde4d1f0 Set session.use_keys to false by default 2017-02-15 11:30:49 +09:00
Kijin Sung
3b7d0da0f6 Fix #607 #662 thumbnail_type=none always overrides custom setting 2017-02-14 16:09:43 +09:00
Kijin Sung
b068dfe4ba Merge pull request #714 from kijin/pr/session-options
세션 보안기능 관련 옵션 추가
2017-02-14 13:58:52 +09:00
Kijin Sung
38d83a9761 Reorder and clean up session-related settings in admin module 2017-02-14 13:46:05 +09:00
Kijin Sung
b43c653186 Add options to control session keys and SSL-only attribute 2017-02-14 13:37:30 +09:00
Kijin Sung
e7511cdead Fix #713 missing rewrite rule for category URL 2017-02-14 10:42:21 +09:00
Kijin Sung
782caa966a Fix unit tests 2017-02-13 17:55:05 +09:00