• last updated 3 hours ago
Constraints
Constraints: committers
 
Constraints: files
Constraints: dates
- use simpler error message generation

- add missing curly brace

- move adp templates from xowiki/www to xowiki/resources/templates

- improve validity checking on tags (e.g. in path notation) to avoid

potential pg errors on invalid UTF-8

  1. … 10 more files in changeset.
file edit.adp was initially added on branch oacs-5-9.

    • -0
    • +0
    /openacs-4/packages/xowiki/resources/templates/edit.adp
file view-book.adp was initially added on branch oacs-5-9.

file view-book-no-ajax.tcl was initially added on branch oacs-5-9.

file view-book-no-ajax.adp was initially added on branch oacs-5-9.

file revisions.adp was initially added on branch oacs-5-9.

file oacs-view3.adp was initially added on branch oacs-5-9.

file oacs-view3-bootstrap.adp was initially added on branch oacs-5-9.

file oacs-view2.adp was initially added on branch oacs-5-9.

file oacs-view.adp was initially added on branch oacs-5-9.

file error-template.adp was initially added on branch oacs-5-9.

file view-plain.adp was initially added on branch oacs-5-9.

file view-page.tcl was initially added on branch oacs-5-9.

file view-page.adp was initially added on branch oacs-5-9.

file view-modal-content.adp was initially added on branch oacs-5-9.

file view-mobile.adp was initially added on branch oacs-5-9.

    • -0
    • +0
    /openacs-4/packages/xowiki/resources/templates/view-mobile.adp
file view-links.adp was initially added on branch oacs-5-9.

file view-default.adp was initially added on branch oacs-5-9.

    • -0
    • +0
    /openacs-4/packages/xowiki/resources/templates/view-default.adp
file view-book.tcl was initially added on branch oacs-5-9.

- fix stupid cut&paste bug

- simplify script

- improve error handling of closed connections

- add csrf protection (bulk-delete, save operations in FormPages)

- add input checking for optional query-parameter "master"

- bump version number to 5.9.1d8

    • -3
    • +3
    /openacs-4/packages/xowiki/xowiki.info
    • -1
    • +1
    /openacs-4/packages/xowiki/tcl/folder-procs.tcl
- added tdom command "::html::CSRFToken" similar to html::div etc. for easy generation of csrf token in tdom contexts

- output more detail for errors

- only subst value, when it was provided explicitely in the "- -export" list. (see also change in www/register/user-new.tcl in http://cvs.openacs.org/changelog/OpenACS?cs=oacs-5-9%3Agustafn%3A20160525130725)

- protect against certain characters in return_url (the real solution is probably a fix in ad_form, which could cause some collateral damage)

- protect against manipulated hidden input fields

- hardening page contracts (invalid values for color_filter_value could cause postgres errors; example color_filter_value=1%00%c0%a7%c0%a2%252527%252522)