Commit graph

11495 commits

Author SHA1 Message Date
Kijin Sung
90f1238b23 Use DocumentModel::getBlankDocument() to obtain a dummy document with module_srl in BoardView 2026-03-31 22:28:39 +09:00
Kijin Sung
cbb363671a Add DocumentModel::getBlankDocument() and fix some incorrect return type comments 2026-03-31 22:27:20 +09:00
Kijin Sung
6be98ff58c Simplify RVE-2026-6 patch using R\F\Security::sanitize() 2026-03-31 21:04:39 +09:00
Kijin Sung
ae44685306 Merge branch 'security/rve-2026-6' 2026-03-31 20:51:14 +09:00
Kijin Sung
b7489e6e7b Merge branch 'security/rve-2026-5' 2026-03-31 20:51:11 +09:00
Kijin Sung
f3a08ba8f3 Merge branch 'security/rve-2026-4' 2026-03-31 20:51:08 +09:00
Kijin Sung
ea4f116b4c Merge branch 'security/rve-2026-3' 2026-03-31 20:51:05 +09:00
Kijin Sung
1d8718a256 Remove unused methods in menu module 2026-03-31 20:50:58 +09:00
Kijin Sung
01d65dee7f Fix pre-conversion file size limit applying to admins 2026-03-31 19:54:53 +09:00
Kijin Sung
81b32378ca Support timeouts for ffmpeg and magick commands
https://rhymix.org/qna/1935749
2026-03-31 19:53:08 +09:00
Kijin Sung
7c30af23c5 Allow admin to delete comment placeholders from list #967 2026-03-29 16:37:23 +09:00
Kijin Sung
057507d3d7 Fix member extra field being reset to public after editing 2026-03-29 16:23:38 +09:00
Kijin Sung
e61ccf84b8 Always cast module_srl to int when parsing include_modules 2026-03-22 14:59:01 +09:00
Kijin Sung
4ee0699dea Fix RVE-2026-6 possible command injection via magick 2026-03-19 17:50:44 +09:00
Kijin Sung
c906eae5d3 Disallow GET requests to procMemberFindAccount, and add route to procMemberAuthEmailAddress 2026-03-19 17:35:42 +09:00
Kijin Sung
00c9a5316c Fix RVE-2026-5 unconfigured domain in auth email 2026-03-19 17:33:08 +09:00
Kijin Sung
94008fbe9b Allow larger images/videos to be uploaded if they are going to be converted
- 변환 대상인 이미지나 동영상 파일은 용량 제한을 더 느슨하게 설정할 수 있도록 함
- 변환 후에 다시 용량을 체크하여 각 게시판의 업로드 정책 적용
- https://rhymix.org/qna/1926104
2026-03-10 19:45:38 +09:00
Kijin Sung
44cf008ac7 Allow setting list_count in various admin list pages #2549 2026-03-10 13:32:42 +09:00
Kijin Sung
8901cb6e36 Fix duplicate message content when document is moved #2686 2026-03-09 21:28:51 +09:00
Kijin Sung
3ca12cca6f Always set correct module_srl, even on empty documents 2026-03-09 20:34:34 +09:00
Kijin Sung
8b8dc99431 Replace $oDocument with empty DocumentItem if access is not allowed 2026-03-09 20:29:59 +09:00
Kijin Sung
a03c33381f Fix error when updating a document with a required file #2685 2026-03-04 18:51:15 +09:00
Kijin Sung
bf0899973a Fix missing validation of xe_run_method 2026-03-03 18:07:56 +09:00
Kijin Sung
cdc713301f Prevent saving layout HTML/CSS if it was not previously edited 2026-03-03 18:02:42 +09:00
Kijin Sung
cdb520d2b1 Preserve module_srl after managing document #2683 2026-03-01 23:32:39 +09:00
Kijin Sung
2392b923b0 Fix reference to potentially undefined config variable 2026-02-27 20:51:30 +09:00
Kijin Sung
6386ddfe27 Fix warnings when user is logged out #2680 2026-02-27 20:51:07 +09:00
Kijin Sung
798b0cd1d6 Fix warnings when user is logged out #2680 2026-02-27 20:46:49 +09:00
Kijin Sung
73e153be60 Fix warnings when logged_info is false #2680 2026-02-27 20:46:32 +09:00
Kijin Sung
2ede904d56 Ensure that the default version of jQuery and jQuery Migrate are always loaded during install 2026-02-26 13:15:12 +09:00
Kijin Sung
d0d1505367 Enable secure session and cookies by default if installed or upgraded in an HTTPS site 2026-02-26 01:25:36 +09:00
Kijin Sung
f0f73c6ac8 Update jQuery to 3.7.1 and recommend updating 2026-02-26 01:21:19 +09:00
Kijin Sung
74b9533281 Merge branch 'security/rve-2026-2' 2026-02-25 20:39:06 +09:00
Kijin Sung
bcda659add Merge branch 'security/rve-2026-1' 2026-02-25 20:39:04 +09:00
Kijin Sung
ed68509c98 Add comment to DocumentItem::getBrowserTitle() 2026-02-24 17:08:28 +09:00
Kijin Sung
4c91040c35 Rename misleading label for list_order sort 2026-02-24 17:05:59 +09:00
Kijin Sung
cb947abb76 Remove unreasonable list_count default 2026-02-23 13:55:37 +09:00
Kijin Sung
47e54bc564 Fix typo in XML filter file #2679 2026-02-23 13:55:17 +09:00
Kijin Sung
37b23341be Fix template path error in mobile document page #2679 2026-02-22 20:18:05 +09:00
Kijin Sung
a53e293a5a Support searching admin memo in member list #2676 2026-02-21 21:51:41 +09:00
Kijin Sung
d47dd2d824 Remove reference to old themes in layout module 2026-02-21 21:45:48 +09:00
Kijin Sung
18401d2688 Remove reference to old theme file #2677 2026-02-21 21:41:35 +09:00
Kijin Sung
91744ec87c Always download SVG as attachment 2026-02-20 21:57:07 +09:00
Kijin Sung
bf2df84d0f Use enshrined\svgSanitize to clean SVG file content 2026-02-20 21:55:29 +09:00
Kijin Sung
f131a616eb Fix RVE-2026-1 arbitrary file association by extra var 2026-02-16 21:56:44 +09:00
Kijin Sung
ad1617b17c Show clickable list of layout instances in "installed layout" page 2026-02-09 21:40:56 +09:00
Kijin Sung
59f95fe099 Remove outdated filter files in admin module 2026-02-08 11:08:37 +09:00
Kijin Sung
ee5418d9d5 Clean up message module config JS 2026-02-08 11:02:50 +09:00
Kijin Sung
b9a512c007 Fix add IP to spamfilter menu not working 2026-02-08 10:56:28 +09:00
Kijin Sung
4339d01a75 Update Daum/Kakao postcode API URL #2672 2026-02-07 21:10:34 +09:00