| ae27e120 | 30-Jul-2013 |
Michael Hamann <michael@content-space.de> |
Use a new, truly random secret for cookie encryption |
| 9c6747f2 | 30-Jul-2013 |
Michael Hamann <michael@content-space.de> |
Fix and add type declarations for the auth system |
| b40098c3 | 30-Jul-2013 |
Michael Hamann <michael@content-space.de> |
Add truly random numbers and use them in places where randomness matters |
| 2586f61f | 31-Jul-2013 |
Christopher Smith <chris@jalakai.co.uk> |
add html5 attributes to email fields of the config manager |
| 7b3674bd | 31-Jul-2013 |
Christopher Smith <chris@jalakai.co.uk> |
add html5 'email' type to the user manager forms |
| 71422fc8 | 31-Jul-2013 |
Christopher Smith <chris@jalakai.co.uk> |
Change error message shown for incorrect current password on update profile form.
The current message confusingly mentions bad 'username' when username is not involved. The new message is the same
Change error message shown for incorrect current password on update profile form.
The current message confusingly mentions bad 'username' when username is not involved. The new message is the same as that introduced for an incorrect current password on the self delete profile form (FS#2751)
show more ...
|
| 3b1338ff | 31-Jul-2013 |
Christopher Smith <chris@jalakai.co.uk> |
add html5 attributes to update profile form |
| a669bfe0 | 31-Jul-2013 |
Christopher Smith <chris@jalakai.co.uk> |
add html5 attributes to register form |
| 020ea9e1 | 31-Jul-2013 |
Christopher Smith <chris@jalakai.co.uk> |
unit tests for self deleting of user accounts |
| 2a7abf2d | 31-Jul-2013 |
Christopher Smith <chris@jalakai.co.uk> |
FS#2751 - self deletion of user account |
| 0320882f | 31-Jul-2013 |
Michael Hamann <michael@content-space.de> |
Remove search_references() and the refshow configuration option
The refshow configuration option wasn't used as described anymore already in the latest release and after the introduction of the medi
Remove search_references() and the refshow configuration option
The refshow configuration option wasn't used as described anymore already in the latest release and after the introduction of the media usage index the parameter is also no longer relevant for internal optimization. The only place where it was still used is the no longer used search_references()-function which is removed here, too.
show more ...
|
| ffec1009 | 31-Jul-2013 |
Michael Hamann <michael@content-space.de> |
Index media file usage in the metadata index and use it in ft_mediause() |
| 0e1777cb | 31-Jul-2013 |
Anika Henke <anika@selfthinker.org> |
added aria attributes to tree and show/hide functions |
| 07ff0bab | 31-Jul-2013 |
Michael Hamann <michael@content-space.de> |
Fix the useheading cache invalidation for hidden pages, add tests
This adds a new parameter to ft_backlinks() to ignore permissions which is needed for invalidating the cache of linking pages with u
Fix the useheading cache invalidation for hidden pages, add tests
This adds a new parameter to ft_backlinks() to ignore permissions which is needed for invalidating the cache of linking pages with useheading enabled. This also adds various test cases for ft_backlinks().
show more ...
|
| cd997f93 | 31-Jul-2013 |
Andreas Gohr <andi@splitbrain.org> |
include updateVersion in CSS/JS tseed to force reload on update |
| fd975da7 | 31-Jul-2013 |
Anika Henke <anika@selfthinker.org> |
removed possibility to have rtl.less files in plugins |
| e8e5221c | 31-Jul-2013 |
Anika Henke <anika@selfthinker.org> |
switched to LESS variables in rest of template's css files |
| b25974c4 | 31-Jul-2013 |
Guy Brand <gb@unistra.fr> |
Fixed instructions on PHPunit |
| 7b650cef | 31-Jul-2013 |
Michael Hamann <michael@content-space.de> |
auth_en/decrypt: Add explanation and more efficient decryption
Added an explanation that what we do is like normal CBC but that we additionally encrypt the IV which is actually suggested by the NIST
auth_en/decrypt: Add explanation and more efficient decryption
Added an explanation that what we do is like normal CBC but that we additionally encrypt the IV which is actually suggested by the NIST for non-random (but unique) IVs. In the decryption process it's not necessary to decrypt the IV, this should save some time.
show more ...
|
| 8269996a | 31-Jul-2013 |
Michael Hamann <michael@content-space.de> |
auth_random: remove exception comment as there is no exception |
| 21134337 | 31-Jul-2013 |
Anika Henke <anika@selfthinker.org> |
updated intro text on wiki:dokuwiki |
| f2bbf30b | 31-Jul-2013 |
Guy Brand <gb@unistra.fr> |
Simple test cases for code and file token fix |
| 04369c3e | 30-Jul-2013 |
Michael Hamann <michael@content-space.de> |
Add AES from phpseclib and use it for cookie encryption
This replaces the deprecated and broken Blowfish implementation that has previously been used and should provide a lot more security. |
| 30d544a4 | 30-Jul-2013 |
Michael Hamann <michael@content-space.de> |
Use a new, truly random secret for cookie encryption |
| 27058a05 | 30-Jul-2013 |
Michael Hamann <michael@content-space.de> |
Fix and add type declarations for the auth system |