Kijin Sung
1233919dba
Fix missing default font config under some circumstances
2017-03-01 14:25:18 +09:00
Kijin Sung
fda9763e82
Replace CDATA with proper escape in XML output
2017-02-27 22:47:26 +09:00
Kijin Sung
fc63b2e9b8
Properly initialize user object even when not logged in
2017-02-27 15:45:25 +09:00
Min-Soo Kim
5140047b5f
네모의 꿈/ 컨텐츠 위젯 스킨 ( #712 )
...
## 컨텐츠 모듈 스킨
- 사이트 테마를 따르지 않고 다른 색을 선택할 수 있도록 네모의 꿈 회원 스킨 컬러셋 추가.
- 탭이 많을 때 터치 환경이 아니면 좌우로 넘기기 어려운 점을 고려하여서 메뉴를 펼침.
- 작은 화면에서 화면을 최대한 활용하도록, 레이아웃 햄버거 메뉴를 부드럽게 나타내고 감춥니다.
## 위젯에서 LESS/SCSS 의 사용
- 변수를 위젯 캐시에도 전달할 수 있도록 해서 LESS 나 SCSS 에 값 전달이 가능하도록 함.
- LESS 나 SCSS 를 사용한 경우에 위젯 코드 캐싱 코드가 적절하게 기록되도록 해서 LESS나 SCSS 를 사용
가능하도록 수정.
## 그 외 변화
- Reduce the number of regular expressions.
2017-02-26 01:05:57 +09:00
Kijin Sung
f338d38538
Improve regexp for template filters
2017-02-23 22:25:13 +09:00
Kijin Sung
d03c64d069
Make the test for filters more strict to prevent unintended parsing
2017-02-23 22:14:51 +09:00
Kijin Sung
5638207fb0
Change behavior of 'autoescape' filter to always escape (but not double-escape)
2017-02-22 21:29:15 +09:00
Kijin Sung
0c4dbc34ff
Add 'trim' filter and adjust some other settings
2017-02-22 21:24:10 +09:00
Kijin Sung
0c20794219
Implement several template filters
2017-02-22 20:58:37 +09:00
Kijin Sung
4ee115e4f3
Improve server environment display
2017-02-22 19:49:49 +09:00
Kijin Sung
780034d4ee
Do not explicitly set the domain for session cookies
2017-02-17 19:33:05 +09:00
Kijin Sung
cbae2c374e
Use meta refresh instead of 302 redirect on new session
...
Attempting to fix missing session cookie in some versions of Android webview and Chrome.
This may or may not be of any use, but why not try?
See https://bugs.chromium.org/p/chromium/issues/detail?id=150066
2017-02-16 11:53:27 +09:00
Kijin Sung
ba925150a3
Quash www subdomain to prevent duplicate sessions
2017-02-13 13:55:47 +09:00
conory
0869e629b9
getUrl 에 rewrite category 추가
2017-02-11 20:27:55 +09:00
Kijin Sung
99cb67b5db
Merge pull request #567 from kijin/pr/session-class
...
세션 처리 관련 기능 정리 및 개선
2017-02-10 21:30:06 +09:00
Kijin Sung
03866c7777
Populate an empty SessionHelper object if not logged in
2017-02-10 21:26:38 +09:00
Kijin Sung
11883fb965
Populate 'user' property of TemplateHandler instances
2017-02-10 21:18:53 +09:00
Kijin Sung
45e930f04c
Populate 'user' property of every module instance with current user info
2017-02-10 21:08:05 +09:00
Kijin Sung
dfdbc1db85
Add session helper class and move remainder of session validation logic to Session class
2017-02-10 20:50:38 +09:00
Kijin Sung
2af90c8e1d
Implement autologin in the Session class
2017-02-08 17:08:31 +09:00
Kijin Sung
ca9a0aef25
Update autologin table with more columns
2017-02-08 16:16:31 +09:00
Kijin Sung
1a8dcd6a34
Do not cause fatal error when query cache file failed to load
2017-02-08 14:12:44 +09:00
Kijin Sung
af41f36bf7
Move checkSSO() from Context class to Session class
2017-02-07 23:26:43 +09:00
Kijin Sung
483ac84796
Merge branch 'develop' into pr/session-class
2017-02-07 22:13:08 +09:00
Kijin Sung
607e9357c2
Merge pull request #686 from kijin/pr/delete-empty-folders
...
빈 폴더 자동 삭제 및 일괄 삭제
2017-02-05 22:57:02 +09:00
Kijin Sung
bef2e35f84
Fix disappearing validator message due to XE 1.8.29 security patch
...
- xpressengine/xe-core#2020
- https://www.xetown.com/qna/491042
2017-02-02 15:33:58 +09:00
Kijin Sung
2ef85c2555
Use Storage::deleteEmptyDirectory() in FileHandler::removeEmptyDir()
2017-01-26 18:01:47 +09:00
Kijin Sung
079daf8a21
XEVE-16-009 보완
2017-01-12 14:53:04 +09:00
bnu
fe5feddc63
Fix #2006 XEVE-16-009 Form validator에서 사용되는 세션 데이터가 G/P/C 데이터로 대치되어 발생할 수 있는 XSS 취약점 해결
...
- 제보 : setuid0
2017-01-12 14:42:13 +09:00
Kijin Sung
67d16d0f3c
Fix xe_validator_id being overwritten by input error
2017-01-10 00:09:50 +09:00
Kijin Sung
4f15ae24ea
Display GB and TB sizes correctly in FileHandler::filesize()
2016-12-17 22:30:51 +09:00
Kijin Sung
d34ef5901f
Improve FileHandler::returnBytes() to handle a wider range of sizes
2016-12-17 20:49:10 +09:00
Kijin Sung
2db14c1ea9
Show query errors in debug panel and error log
2016-12-13 14:09:51 +09:00
Kijin Sung
98b32a2572
Do not apply site lock when called on the CLI
2016-11-22 09:44:07 +09:00
Kijin Sung
eb467b5799
Fix #615 SEO compatibility with third-party modules using their own $oDocument
2016-10-23 15:05:11 +09:00
Kijin Sung
db7b613d03
Prevent Mobile class from adding data to session
2016-10-05 17:55:25 +09:00
Kijin Sung
a1618c236f
Merge branch 'develop' into pr/session-class
2016-10-05 17:26:12 +09:00
Kijin Sung
b7c558a96f
Move session delay feature into Session class
2016-10-05 17:26:05 +09:00
Kijin Sung
e9df310364
Additional fixes for #601
2016-10-01 23:32:59 +09:00
Kijin Sung
95a36477b7
Clean up path handling in TemplateHandler
2016-10-01 21:54:25 +09:00
Kijin Sung
b6113b9df8
Allow access to superglobals and constants in template code
2016-10-01 21:39:04 +09:00
Kijin Sung
78a0e857b5
Also trigger warning when template is not found
2016-10-01 21:16:01 +09:00
Kijin Sung
7e5356380f
Fix #579 insufficient information in template error
2016-10-01 21:13:24 +09:00
Kijin Sung
69ea93914a
Don't redirect from site start module unless request method is GET
2016-09-18 20:59:07 +09:00
Kijin Sung
be9a109a37
Support <offset> in XML query <navigation> section
2016-09-14 13:44:35 +09:00
Kijin Sung
d07bd15b80
Integrate session class with Context class and Member module
2016-08-15 21:49:17 +09:00
BJRambo
81f59b83bd
Fixed typo
2016-08-10 21:37:43 +09:00
BJRambo
d59f7ae29c
fixed typo
2016-08-08 21:30:04 +09:00
BJRambo
792a6b731b
태블릿 설정여부와 상관없이 모바일최적화 버튼이 뜨는 문제 고침
2016-08-08 21:23:15 +09:00
Kijin Sung
e771e4ae0b
Apply non-GET/non-POST CSRF patch from XE 1.8.24 (bed604e)
2016-08-05 17:03:24 +09:00