Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Bug 1259881 - CSV export vulnerable to formulae injection (again) | Frédéric Buclin | 2016-04-25 | 1 | -3/+4 |
| | | | | r=sgreen a=dkl | ||||
* | Bug 1234977: Replace \d+ by [0-9]+ in critical validation places | Frédéric Buclin | 2016-03-09 | 1 | -8/+8 |
| | | | | r=dylan a=dkl | ||||
* | Bug 1232785 - [SECURITY] Buglists in CSV format can be parsed as valid ↵ | Dylan Hardison | 2015-12-22 | 1 | -0/+3 |
| | | | | | | javascript in some browsers r=dkl,a=dkl | ||||
* | Bug 1179160: The login form should not use type="email" when LDAP has ↵ | Frédéric Buclin | 2015-08-06 | 1 | -0/+11 |
| | | | | | | LDAPmailattribute set r=gerv a=dkl | ||||
* | Bug 1160598: url() in concatenated CSS files are incorrect when using ↵ | Frédéric Buclin | 2015-05-05 | 1 | -1/+1 |
| | | | | | | Multiple Bugzilla databases with a single installation r/a=glob | ||||
* | Bug 1143871: Correctly preload bug data when viewing a bug | Frédéric Buclin | 2015-04-05 | 1 | -8/+5 |
| | | | | r=dkl a=sgreen | ||||
* | Bug 880282: Replace |FILTER no_break| by |class="nowrap"| to prevent dashes ↵ | Frédéric Buclin | 2015-03-11 | 1 | -8/+0 |
| | | | | | | (U+002D) from being replaced by non-breaking hyphens/dashes (U+2011) r=dkl a=justdave | ||||
* | Bug 1134743: javascript filter should escape uncode line and paragraph ↵ | Byron Jones | 2015-02-24 | 1 | -0/+2 |
| | | | | | | separators (causes "Unterminated string literal" javascript error) r=dylan,a=glob | ||||
* | Bug 399068: Remove the docs_urlbase parameter. r=LpSolit, a=glob. | Gervase Markham | 2014-12-22 | 1 | -4/+32 |
| | |||||
* | Bug 1100368: css concatenation breaks data: urls | Byron Jones | 2014-11-18 | 1 | -1/+3 |
| | | | | r=dylan,a=glob | ||||
* | Revert Bug 330707 - Add optional support for MarkDown | David Lawrence | 2014-11-04 | 1 | -25/+5 |
| | |||||
* | Bug 1083081 - javascript concatenation should insert a semicolon between files | Dylan William Hardison | 2014-10-27 | 1 | -1/+1 |
| | | | | r=dkl a=glob | ||||
* | Bug 1059723: Reply button should become AJAX-based | Koosha KM | 2014-10-14 | 1 | -5/+7 |
| | | | | r=dkl,a=sgreen | ||||
* | Bug 1054702: CSV export vulnerable to formulae injection | Simon Green | 2014-10-06 | 1 | -1/+3 |
| | | | | r=glob,a=glob | ||||
* | Bug 1072110: _concatenate_js assumes javascript_urls is an array | Byron Jones | 2014-09-26 | 1 | -1/+2 |
| | | | | r=dkl,a=glob | ||||
* | Bug 1064395: concatenate and slightly minify javascript files | Byron Jones | 2014-09-18 | 1 | -1/+50 |
| | | | | r=dkl,a=glob | ||||
* | Bug 1064933: Bugzilla.pm does not compile without Text::Markdown | Koosha KM | 2014-09-11 | 1 | -2/+3 |
| | | | | r=glob,a=sgreen | ||||
* | Bug 330707: Add optional support for MarkDown | Koosha KM | 2014-08-28 | 1 | -0/+17 |
| | | | | r=dkl,a=sgreen | ||||
* | Bug 1054642: quoteUrls() enters an infinite loop with a list of nonexistent ↵ | Koosha KM | 2014-08-25 | 1 | -13/+8 |
| | | | | | | bug ids to be linkified r=glob,a=sgreen | ||||
* | Bug 996893: Perl 5.18 and newer throw tons of warnings about deprecated modules | Frédéric Buclin | 2014-08-13 | 1 | -0/+1 |
| | | | | r=dkl a=sgreen | ||||
* | Bug 897915 - Field lists not sorted alphabetically | Simon Green | 2014-08-10 | 1 | -0/+15 |
| | | | | r=dkl, a=sgreen | ||||
* | Bug 726696 - All authenticated WebServices methods should require ↵ | Simon Green | 2014-07-27 | 1 | -0/+6 |
| | | | | | | username/pass, token or a valid API key for authentication r=dkl, a=sgreen | ||||
* | Bug 1028795: pre-load all related bugs during show_bug initialisation | Byron Jones | 2014-07-03 | 1 | -5/+6 |
| | | | | r=sgreen,a=sgreen | ||||
* | Bug 1020821 - Product drop down orders classifications alphabetically | Simon Green | 2014-07-02 | 1 | -0/+6 |
| | | | | r=gkl, a=glob | ||||
* | Bug 1013209: data/assets: empty generated css-file | Byron Jones | 2014-05-30 | 1 | -1/+1 |
| | | | | r=dkl, a=glob | ||||
* | Bug 1016199: move skins/assets to data/assets | Byron Jones | 2014-05-28 | 1 | -3/+3 |
| | | | | r=dkl, a=justdave | ||||
* | fix mod_perl breakage caused by bug 977969 | Byron Jones | 2014-05-14 | 1 | -0/+1 |
| | |||||
* | Bug 977969: concatenate and slightly minify css files | Byron Jones | 2014-05-14 | 1 | -12/+76 |
| | | | | r=gerv, a=glob | ||||
* | Bug 998323 - URLs pasted in comments are no longer displayed | David Lawrence | 2014-04-18 | 1 | -14/+11 |
| | | | | r=LpSolit,a=justdave | ||||
* | Bug 968576: [SECURITY] Dangerous control characters allowed in Bugzilla text | Manish Goregaokar | 2014-04-17 | 1 | -0/+12 |
| | | | | r=glob a=justdave | ||||
* | Bug 713926: (CVE-2014-1517) [SECURITY] Login form lacks CSRF protection | Frédéric Buclin | 2014-04-17 | 1 | -0/+5 |
| | | | | r=dkl a=justdave | ||||
* | Bug 956190 (part 3): Remove IE-fixes.css (Internet Explorer 7 and older are ↵ | Frédéric Buclin | 2014-03-05 | 1 | -6/+4 |
| | | | | | | no longer supported) r/a=justdave | ||||
* | Bug 978619 - Typo in Bugzilla/Template.pm | Matt Selsky | 2014-03-04 | 1 | -1/+1 |
| | | | | r=dkl,a=justdave | ||||
* | Bug 917669 - invalid or expired authentication tokens and cookies should ↵ | Dave Lawrence | 2013-09-26 | 1 | -4/+1 |
| | | | | | | throw errors, not be silently ignored r/a=glob | ||||
* | Bug 105865: Bugzilla should pay attention to linebreaks when linkifying bug ↵ | Frédéric Buclin | 2013-08-15 | 1 | -13/+17 |
| | | | | | | IDs in comments r=dkl a=sgreen | ||||
* | Remove debug code | Frédéric Buclin | 2013-07-25 | 1 | -1/+0 |
| | | | https://bugzilla.mozilla.org/show_bug.cgi?id=895309 | ||||
* | Bug 895309 - comments returned via the REST endpoint shouldn't be wrapped | Dave Lawrence | 2013-07-24 | 1 | -1/+3 |
| | | | | | r/a=glob https://bugzilla.mozilla.org/show_bug.cgi?id=859309 | ||||
* | Bug 842038: (CVE-2013-0785) [SECURITY] XSS in show_bug.cgi when using an ↵ | Frédéric Buclin | 2013-02-19 | 1 | -5/+9 |
| | | | | | | invalid page format r=glob a=LpSolit | ||||
* | Bug 830467: Don't call _wanted_languages() when only one is available | Frédéric Buclin | 2013-01-17 | 1 | -8/+3 |
| | | | | r=glob a=LpSolit | ||||
* | Bug 829939: Only build default_authorizer on request | Frédéric Buclin | 2013-01-14 | 1 | -1/+1 |
| | | | | r=glob a=LpSolit | ||||
* | Bug 829709: Do not load CSS files from all skins by default | Frédéric Buclin | 2013-01-14 | 1 | -36/+13 |
| | | | | r=dkl a=LpSolit | ||||
* | Bug 804343: Implement autolinkification for a list of comment ids | Koosha Khajeh Moogahi | 2012-12-29 | 1 | -1/+15 |
| | | | | r/a=LpSolit | ||||
* | Bug 787668: Use |use parent| instead of |use base| | Matt Selsky | 2012-12-01 | 1 | -1/+1 |
| | | | | r/a=LpSolit | ||||
* | Bug 816747 - Add dummy POD for unPODded methods. | Marc Schumann | 2012-11-30 | 1 | -0/+26 |
| | | | | r/a=LpSolit | ||||
* | Bug 811280: Adds a caching mechanism to Bugzilla::Object to avoid querying ↵ | Byron Jones | 2012-11-22 | 1 | -3/+3 |
| | | | | | | the database repeatedly for the same information r=dkl,a=LpSolit | ||||
* | Bug 797636: Improve performance for buglists | Frédéric Buclin | 2012-11-16 | 1 | -3/+2 |
| | | | | r=dkl a=LpSolit | ||||
* | Bug 213440: quoteUrls() should permit multiple bug numbers to be linkified ↵ | Koosha Khajeh Moogahi | 2012-10-13 | 1 | -0/+17 |
| | | | | | | in comments r/a=LpSolit | ||||
* | Bug 797883: Adds a Bugzilla->process_cache | Byron Jones | 2012-10-05 | 1 | -7/+6 |
| | | | | r=LpSolit, a=LpSolit | ||||
* | Bug 787529: Use |use 5.10.1| everywhere | Frédéric Buclin | 2012-09-01 | 1 | -0/+1 |
| | | | | r=wicked a=LpSolit | ||||
* | Bug 778631: use a persistent Template::Provider to avoid recompiling ↵ | Byron Jones | 2012-08-08 | 1 | -0/+14 |
| | | | | | | templates between page loads on mod_perl r=dkl, a=LpSolit |