gustafn in OpenACS

Adjusted results for file updates

Many thanks to Khy H.

For details, see https://openacs.org/forums/message-view?message_id=7412487

Fixed snyk vulnerability check (backport from HEAD)

Snyk page has changed, we have to switch the pattern we are looking for.

Bumped version number to flage the change to "upgrade from repository"

    • -2
    • +2
    /openacs-4/packages/acs-tcl/acs-tcl.info
Fixed snyk vulnerability check

Snyk page has changed, we have to switch the pattern we are looking for.

bump version numbers

- update upstream version to 7.6.1

- bump package number to 2.1.8

set focus via HTML "autofocus" attribute

improved comments

added a log message, when login page expires (happens seldomly)

Enhanced security logging and debugging in security-procs.tcl

- Updated the internal log procedure to accept multiple arguments (using join) for more flexible logging.

- Replace several ns_log calls with ::security::log to standardize logging of session_id, login_cookie, timeout, and other events.

- Add additional log statements in critical functions (e.g. sec_handler, sec_setup_session, __ad_verify_signature, and CSRF token handling)

to provide better traceability of session allocation, cookie generation, session invalidation, and signature verification.

- Improve debug output for CSRF token generation and verification, including logging differences in computed hash values.

added debugging hook for tracing CSRF livecyle

improved log messages to pinpoint location and reason

removed manual default entries from the info texts.

The actual default value is displayed by the parameter page, there is no need

to duplicate this information.

New feature: Display defaults together with actual values in parameter page.

This features makes it easier to see, what paramters were changed locally from

the defaults, without relying on the info messages.

fixed variable name

provent passwords from form being logged via ad_log

ad_return_url: provide a positive list and a negative list for selecting included query variables

The new parameters follow the terminology of the "export_vars" command.

ad_return_url: new parameter "-exclude"

This change allows to exclude certain variables (which are e.g. considered as

confidential) from the form, which computes the return_url.

The change is based on a feature request in the OpenACS forums by Josue Cardona.

added tclhttp to system statistics

reapplied post 5-10 release fix

Many thanks to Claudio Pasolini for reporting and identifying the problem!

fixed bug security::validated_host_header

Many thanks to Claudio Pasolini for reporting and identifying the problem!

Fixed 2 bugs: with remote code repository

- fixed repository URL when trying to "install-from-repositry"

on a checkout from the HEAD channel. The code tried to fetch

from a channel "6-0", which does not exist.

- determine the exact repository tag for repository channels

unset temporary variables which would be kept in the in the ::xowiki namespace

    • -1
    • +3
    /openacs-4/packages/xowiki/tcl/xowiki-procs.tcl
streamline spelling

fixed typo

Bumped upstream version of highcharts to 12.1.2

bumped version of fa icons to 6.7.2

Ported essential post-release fixes from oacs-5-10 branch

    • -8
    • +14
    /openacs-4/packages/acs-tcl/tcl/install-procs.tcl
    • -1
    • +1
    /openacs-4/packages/dotlrn/install.xml
improved comments

backport from oacs-head, otherwise the cache viewer is unusuable

fixed page contract for cache viewer

Bumped version number of acs-tcl to 5.10.2d2

    • -2
    • +2
    /openacs-4/packages/dotlrn/dotlrn.info