• last updated 11 hours ago
Constraints
Constraints: committers
 
Constraints: files
Constraints: dates
Use existing api to tell whether a formfield is disabled or not and to set/unset disabled on a field, handle the case of checkboxes and select fields, where the attribute should not be set whe it is false (e.g. disabled=0 == disabled)

This fixes upstream automated tests on xowiki and xowf

    • -21
    • +31
    ./xowiki/tcl/form-field-procs.tcl
Fix typo

    • -1
    • +1
    ./acs-tcl/tcl/test/doc-check-procs.tcl
fix bug in db_multirow_group_last_row_p

The bug showed up in bug-tracker usage of multirows,

where db_multirow_group_last_row_p was still expecting the

dict structure

    • -3
    • +10
    ./acs-tcl/tcl/01-database-procs.tcl
Give admins the possibility to deactivate pagination actions in the answer workflow of the inclass exam.

As default the pagination actions are shown in the answer workflow.

    • -0
    • +2
    ./xowf/catalog/xowf.de_DE.ISO-8859-1.xml
    • -0
    • +2
    ./xowf/catalog/xowf.en_US.ISO-8859-1.xml
use icanuse "ns_parsehtml" and new interface

    • -5
    • +4
    ./acs-tcl/tcl/test/doc-check-procs.tcl
added icanuse rule for ns_parsehtml

Give people the chance to use OpenACS with WithDeprecatedCode set to 0

When OpenACS is configured with loading of deprecated procs

deactivated, files like deprecated-procs.tcl are not

loaded. Therefore, these files should only contain code, which was

deprecated at LEAST ONE RELEASE EARLIER, such that site admins have one

release time to fix calls to deprecated code.

This change reverts in part Antonio's commit from 26 Aug 2022 which

causes errors like the following on openacs.org:

Error in include template "/var/www/openacs.org/packages/news/lib/news":

invalid command name "ad_parameter_all_values_as_list"

    • -22
    • +10
    ./acs-tcl/tcl/deprecated-procs.tcl
fix documentation

Deprecate ad_parameter_all_values_as_list: it does not provide much value and was also often use improperly

    • -2
    • +0
    ./acs-tcl/tcl/test/html-conversion-procs.tcl
tmpfile page contract filter reform:

do not allow acs-subsite TmpDir parameter to define where the tmpfolder is located anymore. This MUST be the one configured in the server-wide configuration. Tmpfiles cannot be in a subfolder of the tmpfolder, they MUST be direct children instead. A tmpfile MUST exist beforehand and be owned, be readable and writable by the user running the nsd process. This complies with the definition of a tmpfile by AolServer/NaviServer when they are created to store content coming from a file upload.

    • -24
    • +10
    ./acs-tcl/tcl/tcl-documentation-procs.tcl
    • -28
    • +0
    ./acs-tcl/tcl/test/security-procs.tcl
Extend tmpfile filter to behave in the "old way" (default), or in strict mode e.g. tmpfile(strict), enforcing the behavior for tmpfile in Aolserver/Naviserver when a form is processed

    • -12
    • +30
    ./acs-tcl/tcl/tcl-documentation-procs.tcl
Reimplement ad_page_contract_filter_proc_tmpfile using security::safe_tmpfile_p

Some of the features implemented by this filter have been ported into the api, namely the possibility to fetch the valid temp folders from the subsite TmpDir parameter and the possibility to relax the check and allow also files deeper in the tmpfolder hierachy.

Notably, the hardcoded tmpfolders "/var/tmp" and "/tmp" have NOT been ported. One should configure these values via the many available options. security::safe_tmpfile_p is also more restrictive when a file exists, because it checks for ownership and read and write permissions on the file.

    • -17
    • +8
    ./acs-tcl/tcl/tcl-documentation-procs.tcl
    • -1
    • +30
    ./acs-tcl/tcl/test/security-procs.tcl
Comment WIP

Declare proc coverage

    • -0
    • +2
    ./acs-tcl/tcl/test/http-client-procs.tcl
    • -0
    • +1
    ./acs-templating/tcl/test/file-procs.tcl
Factor the payload building behavior in util::http::post into its own proc, so that it can be reused elsewhere

    • -69
    • +170
    ./acs-tcl/tcl/http-client-procs.tcl
Make also sure the tmpfile from the widget exists beforehand, when validating: we don't want users to "explore" our tmpdir with bogus values that just look sane

    • -11
    • +24
    ./acs-templating/tcl/test/data-procs.tcl
Add must_exist flag to enforce a safe tmpfile to already exist

Fixed bug in util_convert_line_breaks_to_html

The code deleted spaces around certain tags, while - according to the

documentation, only line breaks should be removed from there.

Extended regression test.

    • -5
    • +14
    ./acs-tcl/tcl/test/html-conversion-procs.tcl
Improve doc

Revert to previous template::widget::file behavior of accepting input in a form of a list of 3 elements (e.g. without a .tmpfile in the request), but introduce validation so that we enforce all widget values to be in the proper format and the files to be "safe"

    • -0
    • +1
    ./acs-templating/catalog/acs-templating.en_US.ISO-8859-1.xml
    • -42
    • +83
    ./acs-templating/tcl/file-procs.tcl
    • -7
    • +14
    ./acs-templating/tcl/test/data-procs.tcl
    • -0
    • +244
    ./acs-templating/tcl/test/file-procs.tcl
file file-procs.tcl was initially added on branch oacs-5-10.

    • -0
    • +0
    ./acs-templating/tcl/test/file-procs.tcl
Bring test closer to reality

    • -6
    • +14
    ./file-storage/tcl/test/webtest-procs.tcl
Introduce security::safe_tmpfile_p checking whether a file belongs to the configured tmpfolder and respects other constraints

The plan is to use it to improve input validations

    • -0
    • +45
    ./acs-tcl/tcl/test/security-procs.tcl
Fixed serious bug killing at least short-text questions in inclass exam

The bug was introduced in [1], by testing for the existence of the

disabled attribute, and when it exists, it was omitting values

reading. The problem is that when form-fields are reset, the

"disabled" attribute is set to 0, leading the exists check to

succeed. In essence, This change sets now the default value of the

form-field to "0", such that it is safe to test it everywhere.

Originally, it was not set by default to save resources (memory and

processing power), but this requires a more careful analysis when

changes happen.

[1] https://fisheye.openacs.org/browse/OpenACS/openacs-4/packages/xowiki/tcl/xowiki-www-procs.tcl?r1=1.368.2.125&r2=1.368.2.126

    • -12
    • +11
    ./xowiki/tcl/xowiki-www-procs.tcl
Tighten test for is_wf_instance

Previously, the test was based on setting of state and FormPage.

In cases, where plain FormPages are used inside an xowf package

this test was leading to wrong results.

base all timings on NavigationTiming plugin to get closer to previous behavior

    • -5
    • +13
    ./boomerang/tcl/boomerang-procs.tcl
file navtiming.js was initially added on branch oacs-5-10.

    • -0
    • +0
    ./boomerang/www/resources/plugins-1.737.0/navtiming.js
improved error message

make clear, what the name and what the item_id in the message are

use new path xowiki/lib/portlets/ instead of .../www/...

comment method

    • -1
    • +4
    ./xowiki/tcl/xowiki-uploader-procs.tcl