Commit graph

109 commits

Author SHA1 Message Date
Kijin Sung
aac678de48 Explicitly declare noescape 2018-10-10 13:08:24 +09:00
Kijin Sung
a49f2f5f06 Change Context::isAlwaysSSL() to config('session.use_ssl_cookies')
- Main session cookie is httpOnly if use_ssl is true
- SSO cookie is always httpOnly
2018-08-06 01:23:22 +09:00
Min-Soo Kim
25d2e4892a Revert "Example of the cookie option"
This reverts commit 93a35c251b.
2018-08-02 00:35:52 +09:00
Min-Soo Kim
93a35c251b Example of the cookie option 2018-08-02 00:35:27 +09:00
Min-Soo Kim
b62a1322c9 Revert "Merge branch 'develop' into develop"
This reverts commit ec54bbd415, reversing
changes made to 9b12e0a71c.
2018-07-29 11:54:14 +09:00
Min-Soo Kim
6f981318ca Merge branch 'master' into develop 2018-07-24 23:47:55 +09:00
Min-Soo Kim
3bdc896f4e Fix error on the IDN site javascript..
To handle url on the javascript, convert the url to punycode. If not, `isSameOrigin` and return `false` when we compare `location.href` and `request_uri` even though they are same...

On the normal domain (except IDN), they are not affected by this commit.
2018-05-07 01:04:34 +09:00
Min-Soo Kim
f8edfacde2 Refine secure cookie flag
_use_ssl 대신 site_module_info 를 직접 참조하도록 수정.
함수 이름을 조금 더 자연스럽게 수정.
2018-04-28 11:25:15 +09:00
Min-Soo Kim
c1c9a94623 Improve cookie security; Secure flag
SSL 항상 사용 옵션인 경우 쿠키도 이에 맞추어 SSL 인 경우에만 사용되도록 `secure` flag 를 추가합니다.
선택적 SSL 인 경우 SSL 이 적용되지 않은 구간에서도 쿠키를 읽을 수 있어야 하므로, 적용하지 않습니다.
2018-04-24 19:30:38 +09:00
conory
4520a6a2a4 canonical URL이 출력되지 않는 문제 수정 2018-03-12 21:50:52 +09:00
Kijin Sung
17ca61eed3 Fix #832 make the viewport setting customizable
모바일 접속시 <meta name="viewport"> 태그에 들어가는 내용을
시스템 설정 메뉴에서 커스터마이징할 수 있도록 변경함.
2017-11-23 16:54:06 +09:00
Kijin Sung
9a34341759 Populate CSRF token in some non-member requests as well 2017-03-13 16:41:08 +09:00
Kijin Sung
a3ef122b57 Merge branch 'develop' into pr/csrf-token 2017-03-13 16:35:24 +09:00
Kijin Sung
a2e326a419 Always set xeVid to null 2017-03-13 15:40:03 +09:00
Kijin Sung
e2511a0269 Insert CSRF token using meta tag in common_layout.html
<body> 태그의 속성이나 그 밖의 태그를 사용하지 않는 이유는
<body>가 로딩되기 전에 먼저 AJAX 요청을 시도하는 서드파티 자료가 있기 때문이다.
<head> 상단에 CSRF 토큰을 넣어야 이런 자료에서도 토큰이 누락되지 않는다.

다른 CSM나 프레임워크들도 <head> 상단에 <meta> 태그를 사용하여
CSRF 토큰을 삽입하는 사례가 많으며, csrf-token은 이런 용도로
WHATWG에 공식적으로 등록된 meta name이다.

cf. https://wiki.whatwg.org/wiki/MetaExtensions
2017-03-06 11:46:37 +09:00
Kijin Sung
3fbf94f630 Fix #491 no display of canonical URL on some pages 2016-05-11 15:15:05 +09:00
Kijin Sung
da1b69c6b7 Initial implementation of OpenGraph metadata insertion 2016-05-09 01:36:25 +09:00
Kijin Sung
4290f5110c Add 'finalize' option to getCSSFileList() and getJSFileList(), to be used only by the final layout 2016-05-06 22:01:58 +09:00
Kijin Sung
ac1e86cf39 Fix incorrect passing of SSL action list 2016-02-25 14:26:00 +09:00
Kijin Sung
65517735e0 Clean up common_layout.html and merge with mobile_layout.html 2016-02-17 16:20:57 +09:00
Kijin Sung
373305ab6b Initial implementation of debug panel on web page 2016-02-13 01:33:06 +09:00
Kijin Sung
ac8460d782 Finalize debug data format and allow all statistics to be collected 2016-02-12 21:31:38 +09:00
conory
496dc9ddf5 remove rhymix version 2016-01-26 15:28:23 +09:00
conory
0a89dffa5a XE표기를 Rhymix로 변경 2016-01-25 18:10:15 +09:00
bnu
92594e28fe Merge pull request #1458 from misol/language-code-RFC5646
일본어 언어코드를 HTML 상에서 표준에 맞추는 PR 입니다.
2015-07-06 09:11:04 +09:00
MinSoo Kim
4980677c76 비 IE 브라우저를 위한 조건문 다듬기
비 IE 브라우저 또는 상위 버전의 IE를 위한 조건문을 다듬은 커밋.
참고한 글: http://www.oops4u.com/1823
2015-05-05 22:58:22 +09:00
MinSoo Kim
4d48b29dae Fix language-code typo(?)
http://www.iana.org/assignments/language-subtag-registry/language-subtag-registry
에 따르면, 일본어는 ja로 적어야 합니다. 일본에서 사용하는 일본어를 의미한다면, ja-JP로 적어야 합니다. 어떻게 해도
jp는 표준이 아니기에, 이 커밋을 제안합니다.
2015-05-05 22:30:48 +09:00
jhyeon1010
712541c50c #1156 removed admin bar 2015-03-23 11:21:23 +09:00
bnu
86be308a76 fix #1084 load modernizr 2014-12-24 14:01:55 +09:00
bnu
b72b6344c6 #3 IE 9미만에서 jQuery를 로드하지 못하는 문제 수정 2014-02-03 11:08:12 +09:00
khongchi
5693e340fe issue 3645, php5 대응, 함수 대체
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@13202 201d5d3c-b55e-5fd7-737f-ddc643e51545
2013-11-13 01:40:53 +00:00
bnu
4f4c63ed3d Issue 3640 X-UA-Compatible ie=edge 추가.
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@13198 201d5d3c-b55e-5fd7-737f-ddc643e51545
2013-11-09 15:28:16 +00:00
misol
f70ce644ce Close Connection when there is no connection value.
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@13161 201d5d3c-b55e-5fd7-737f-ddc643e51545
2013-09-25 15:29:32 +00:00
ChanMyeong
c59ca1029a Admin bar height adjust.
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@12748 201d5d3c-b55e-5fd7-737f-ddc643e51545
2013-02-13 09:00:42 +00:00
ChanMyeong
72f81ec07d Popup admin bar UI bugfix.
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@12602 201d5d3c-b55e-5fd7-737f-ddc643e51545
2013-01-29 06:11:11 +00:00
ovclas
dd56711e5a not show admin bar in document management popup
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@12579 201d5d3c-b55e-5fd7-737f-ddc643e51545
2013-01-23 04:58:59 +00:00
nagoon97
2bf9c55a34 UI bug fixes
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@12526 201d5d3c-b55e-5fd7-737f-ddc643e51545
2013-01-10 07:31:18 +00:00
nagoon97
7ec02806be Default alert is overwritten
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@12452 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-12-24 09:08:22 +00:00
nagoon97
67bdda04ec Menu selector
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@12449 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-12-24 05:22:45 +00:00
ChanMyeong
f66e445187 common_layout.html meta tag loop rollback.
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@12288 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-11-22 10:38:12 +00:00
ChanMyeong
695693f66f UI cleaning.
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@12287 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-11-22 10:10:20 +00:00
ovclas
a77219754e hide admin bar in admin dashboard
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@12204 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-11-13 08:56:49 +00:00
ChanMyeong
0732563208 Admin Bar UI bugfix.
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@12193 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-11-13 05:33:11 +00:00
ChanMyeong
45dcea0706 Admin Bar UI enhancement. Welcome page content update.
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@12189 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-11-12 12:37:04 +00:00
ChanMyeong
206f49764e Admin Bar UI added.
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@12178 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-11-12 07:00:25 +00:00
flyskyko
fa8e01bdb5 issue 2588, if stylesheet's media is 'all', not display medit attr.
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@12031 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-11-01 09:34:36 +00:00
flyskyko
5a450211ba Issue 2385: Admin UI Refactoring - Advanced - Widgets
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@11685 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-10-15 02:59:49 +00:00
flyskyko
51bb8d1985 merger from branch luminous (~r11576)
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@11580 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-10-04 05:04:23 +00:00
flyskyko
9f5e25a15e merge from branch 1.5.3.2 (~r11282)
git-svn-id: http://xe-core.googlecode.com/svn/branches/luminous@11380 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-09-19 07:56:40 +00:00
flyskyko
9245557873 issue 2445, added a js variable 'xe.current_lang'
git-svn-id: http://xe-core.googlecode.com/svn/branches/luminous@11269 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-09-17 07:25:00 +00:00