Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Bug 1071317: Remove unused variables | Frédéric Buclin | 2014-09-29 | 1 | -1/+0 |
| | | | | r=gerv a=sgreen | ||||
* | Bug 996893: Perl 5.18 and newer throw tons of warnings about deprecated modules | Frédéric Buclin | 2014-08-13 | 5 | -0/+5 |
| | | | | r=dkl a=sgreen | ||||
* | Bug 1044701: "Uninitialized value $token_type" when passing an invalid ↵ | David Lawrence | 2014-07-31 | 1 | -1/+4 |
| | | | | | | Bugzilla_api_token value r=sgreen,a=glob | ||||
* | Bug 726696 - All authenticated WebServices methods should require ↵ | Simon Green | 2014-07-27 | 2 | -1/+65 |
| | | | | | | username/pass, token or a valid API key for authentication r=dkl, a=sgreen | ||||
* | Bug 1001497: User.login incorrectly returns id = 0 when the login or ↵ | Frédéric Buclin | 2014-04-25 | 1 | -1/+1 |
| | | | | | | password is missing r=dkl a=justdave | ||||
* | Bug 713926: (CVE-2014-1517) [SECURITY] Login form lacks CSRF protection | Frédéric Buclin | 2014-04-17 | 1 | -4/+37 |
| | | | | r=dkl a=justdave | ||||
* | Bug 987205: Bugzilla crashes because it tries to import a non-exported ↵ | Frédéric Buclin | 2014-04-14 | 1 | -1/+2 |
| | | | | | | login_token() subroutine from Bugzilla::Auth::Login::Cookie r=dkl a=justdave | ||||
* | Bug 907438 - In MySQL, login cookie checking is not case-sensitive, reducing ↵ | Dave Lawrence | 2013-10-16 | 1 | -3/+3 |
| | | | | | | total entropy and allowing easier brute force r=LpSolit,a=sgreen | ||||
* | Bug 917669 - invalid or expired authentication tokens and cookies should ↵ | Dave Lawrence | 2013-09-26 | 1 | -8/+13 |
| | | | | | | throw errors, not be silently ignored r/a=glob | ||||
* | Bug 893195 - Allow token based authentication for webservices | Dave Lawrence | 2013-08-26 | 1 | -14/+54 |
| | | | | r=glob,a=sgreen | ||||
* | Bug 787668: Use |use parent| instead of |use base| | Matt Selsky | 2012-12-01 | 3 | -3/+3 |
| | | | | r/a=LpSolit | ||||
* | Bug 787529: Use |use 5.10.1| everywhere | Frédéric Buclin | 2012-09-01 | 4 | -0/+12 |
| | | | | r=wicked a=LpSolit | ||||
* | Bug 680131: Replace the MPL 1.1 license by the MPL 2.0 one in all files, and ↵ | Frédéric Buclin | 2012-01-11 | 4 | -82/+20 |
| | | | | | | add it to files which miss one r=kiko r=mkanat r=mrbball a=LpSolit | ||||
* | Make Login/Stack.pm refuse to continue down the stack if an Auth method ↵ | Gervase Markham | 2011-11-18 | 1 | -2/+8 |
| | | | | | returns an explicit failure. r=dkl, a=mkanat. https://bugzilla.mozilla.org/show_bug.cgi?id=698423 | ||||
* | Bug 423612 - Allow editing extern_id for users from the admin interface | Jochen Wiedmann | 2011-04-27 | 2 | -0/+7 |
| | | | | r=mkanat, a=mkanat | ||||
* | Bug 550732: Allow read-only JSON-RPC methods to be called with GET | Max Kanat-Alexander | 2010-04-22 | 3 | -0/+7 |
| | | | | r=dkl, a=mkanat | ||||
* | Bug 553770: Make the JSON-RPC WebService throw a proper error when you don't | Max Kanat-Alexander | 2010-03-23 | 1 | -4/+2 |
| | | | | | | provide login credentials on a LOGIN_REQUIRED page. (Before this, it was attempting to display the HTML login page to JSON-RPC clients.) r=dkl, a=mkanat | ||||
* | Bug 527586: Use X-Forwarded-For instead of REMOTE_ADDR for trusted proxies | mkanat%bugzilla.org | 2009-12-31 | 1 | -1/+1 |
| | | | | Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=dkl, a=mkanat | ||||
* | Bug 385606: Logincookies are recreated at each HTTP request when using the ↵ | lpsolit%gmail.com | 2009-12-31 | 1 | -0/+1 |
| | | | | 'Env' auth method - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat | ||||
* | Bug 430014: Re-write the code hooks system so that it uses modules instead ↵ | mkanat%bugzilla.org | 2009-11-24 | 1 | -1/+1 |
| | | | | | | of individual .pl files Patch by Max Kanat-Alexander <mkanat@bugzilla.org> (module owner) a=mkanat | ||||
* | Bug 525734: Allow WebService clients to authenticate using Bugzilla_login ↵ | mkanat%bugzilla.org | 2009-11-09 | 1 | -5/+3 |
| | | | | | | and Bugzilla_password Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=dkl, a=mkanat | ||||
* | Bug 399073: Remove the 'loginnetmask' parameter - Patch by Frédéric ↵ | lpsolit%gmail.com | 2009-10-18 | 1 | -17/+8 |
| | | | | Buclin <LpSolit@gmail.com> r/a=mkanat | ||||
* | Bug 514913: Eliminate ssl="authenticated sessions" | mkanat%bugzilla.org | 2009-10-09 | 1 | -11/+0 |
| | | | | Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=dkl, a=mkanat | ||||
* | Bug 488467: Verify and Login auth methods were being called in a random ↵ | mkanat%bugzilla.org | 2009-04-17 | 1 | -1/+1 |
| | | | | | | order, causing sudo sessions to frequently not need the user to re-enter their password. Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit | ||||
* | Partial backout of bug 183665. It's responsible for bug 457719 | lpsolit%gmail.com | 2008-10-05 | 1 | -1/+1 |
| | |||||
* | Bug 428659 â Setting SSL param to 'authenticated sessions' only ↵ | dkl%redhat.com | 2008-08-18 | 1 | -3/+8 |
| | | | | | | | protects logins and param doesn't protect WebService calls at all Patch by David Lawrence <dkl@redhat.com> - r/a=LpSolit/mkanat | ||||
* | Bug 438435: Need code hooks for authentication | mkanat%bugzilla.org | 2008-08-07 | 1 | -4/+12 |
| | | | | Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=mkanat | ||||
* | Backing out these patches as they cause a regression. More information | dkl%redhat.com | 2008-07-29 | 1 | -3/+5 |
| | | | | | | | | | | | in the respective bug reports. Bug 428659 â Setting SSL param to 'authenticated sessions' only protects logins and param doesn't protect WebService calls at all Patch by Dave Lawrence <dkl@redhat.com> - r/a=mkanat Bug 445104: ssl redirects come with a 200 OK HTTP code on mod_perl Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=dkl, a=mkanat | ||||
* | Bug 428659 â Setting SSL param to 'authenticated sessions' only ↵ | dkl%redhat.com | 2008-07-10 | 1 | -5/+3 |
| | | | | | | protects logins and param doesn't protect WebService calls at all Patch by Dave Lawrence <dkl@redhat.com> - r/a=mkanat | ||||
* | Bug 183665: Accessing post_bug.cgi directly gives a weird error message and ↵ | lpsolit%gmail.com | 2007-11-15 | 1 | -1/+1 |
| | | | | should redirect to enter_bug.cgi instead - Patch by Matt Tasker <mtasker@gmail.com> (based on the original patch from victory <spam@bmo2007.rsz.jp>) r/a=LpSolit | ||||
* | Bug 224577: Bugzilla could use a web services interface. | wurblzap%gmail.com | 2006-08-20 | 1 | -0/+7 |
| | | | | | Patch by Marc Schumann <wurblzap@gmail.com>; r=mkanat; a=myk | ||||
* | Bug 340967: The login form appears twice when trying to add an attachment ↵ | lpsolit%gmail.com | 2006-07-06 | 1 | -0/+15 |
| | | | | (due to two consecutive calls to Bugzilla->login) - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=myk | ||||
* | Bug 338375: Use Bugzilla->params everywhere instead of Param(). | mkanat%bugzilla.org | 2006-07-04 | 2 | -2/+0 |
| | | | | Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=justdave | ||||
* | Bug 342869: Use Bugzilla->params everywhere except templates | mkanat%bugzilla.org | 2006-07-04 | 2 | -5/+7 |
| | | | | Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=justdave | ||||
* | Spelling in code comments patch: 'cokie' -> 'cookie'; patch by Vlad Dascalu ↵ | vladd%bugzilla.org | 2006-06-19 | 1 | -1/+1 |
| | | | | <vladd@bugzilla.org>. | ||||
* | Bug 340104: Move Bugzilla::Auth::get_netaddr() in Util.pm - Patch by ↵ | lpsolit%gmail.com | 2006-06-03 | 1 | -2/+1 |
| | | | | Frédéric Buclin <LpSolit@gmail.com> r/a=justdave | ||||
* | Bug 339858: Remove useless module dependencies in Bugzilla::Auth::* - Patch ↵ | lpsolit%gmail.com | 2006-06-01 | 3 | -3/+1 |
| | | | | by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=justdave | ||||
* | Bug 300410: Bugzilla::Auth needs to be restructured to not require a BEGIN block | mkanat%bugzilla.org | 2006-05-12 | 8 | -655/+297 |
| | | | | Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=myk | ||||
* | Patch for bug 161369: Strip trailing whitespace from login usernames; patch ↵ | jocuri%softhome.net | 2006-03-03 | 1 | -1/+1 |
| | | | | by Paul <pdemarco@zoominternet.net>, r=vladd, a=justdave. | ||||
* | Bug 327355: Email preferences are not set correctly when the user account is ↵ | lpsolit%gmail.com | 2006-02-22 | 1 | -101/+63 |
| | | | | created by Env.pm - Patch by Frédéric Buclin <LpSolit@gmail.com> r=joel a=justdave | ||||
* | Bug 322620: Logging in with 'Remember my Login' deselected gives: Use of ↵ | lpsolit%gmail.com | 2006-01-10 | 1 | -0/+1 |
| | | | | uninitialized value in string eq at Bugzilla/Auth/Login/WWW/CGI.pm line 83 - Patch by Olav Vitters <bugzilla-mozilla@bkor.dhs.org> r=LpSolit a=justdave | ||||
* | Bug 322244: Cookies are incorrectly detainted when logging out - Patch by ↵ | lpsolit%gmail.com | 2006-01-05 | 1 | -1/+1 |
| | | | | Olav Vitters <bugzilla-mozilla@bkor.dhs.org> r=LpSolit a=justdave | ||||
* | Bug 119524: SECURITY: predictable sessionid (Use a token instead of ↵ | lpsolit%gmail.com | 2006-01-03 | 1 | -4/+6 |
| | | | | logincookie) - Patch by Olav Vitters <bugzilla-mozilla@bkor.dhs.org> r=mkanat a=justdave | ||||
* | Bug 279716: Users have to relogin when changing their own password - Patch ↵ | lpsolit%gmail.com | 2005-11-22 | 1 | -2/+12 |
| | | | | by Marc Schumann <wurblzap@gmail.com> r=wicked a=justdave | ||||
* | Bug 304075: Eliminate use of $::userid from Bugzilla - Patch by Frédéric ↵ | lpsolit%gmail.com | 2005-10-31 | 1 | -4/+0 |
| | | | | Buclin <LpSolit@gmail.com> r=wicked a=justdave | ||||
* | Bug 304583: Remove all remaining need to rederive inherited groups | bugreport%peshkin.net | 2005-08-19 | 1 | -0/+9 |
| | | | | | Patch by Joel Peshkin <bugreport@peshkin.net> r=mkanat, a=justdave | ||||
* | Bug 300403: New Charts errors out, creates new 'add' user, when Env auth ↵ | lpsolit%gmail.com | 2005-07-26 | 1 | -2/+6 |
| | | | | method is used - Patch by A. Karl Kornel <karl@kornel.name> r=wurblzap a=justdave | ||||
* | Bug 301967: Some .pm files have invalid POD syntax - Patch by Frédéric ↵ | lpsolit%gmail.com | 2005-07-26 | 1 | -1/+3 |
| | | | | Buclin <LpSolit@gmail.com> r=wurblzap a=justdave | ||||
* | Bug 298659: setting authentication to LDAP,DB fails | mkanat%kerio.com | 2005-07-08 | 1 | -2/+2 |
| | | | | Patch By A. Karl Kornel <karl@kornel.name> r=glob, a=justdave | ||||
* | Bug 285695: [PostgreSQL] Username checks for login, etc. need to be case ↵ | mkanat%kerio.com | 2005-07-08 | 1 | -1/+2 |
| | | | | | | insensitive Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=justdave |