summaryrefslogtreecommitdiffstats
path: root/Bugzilla/WebService
AgeCommit message (Collapse)AuthorFilesLines
2014-07-24Bug 1036213 - (CVE-2014-1546) add '/**/' before jsonrpc.cgi callback to ↵Simon Green1-2/+3
avoid swf content type sniff vulnerability r=glob,a=sgreen
2013-12-05Bug 942599: Documentation about possible_duplicates() lists 'products' as ↵Frédéric Buclin1-1/+1
argument instead of 'product' r=dkl a=justdave
2013-07-24Bug 880653 - Add POD for Bug.possible_duplicates webserviceDave Lawrence1-0/+53
r=LpSolit,a=sgreen
2013-07-15Bug 787328 - xmlrpc.cgi doesn't send any security-related headersDave Lawrence1-2/+10
r=glob,a=justdave
2013-05-04Bug 859118 - Bug.search called with no arguments returns all visible bugs, ↵Dave Lawrence2-11/+48
ignoring max_search_results and search_allow_no_criteria r/a=LpSolit
2012-11-20Bug 640756 - Make the documentation clearer that attachments created with ↵Dave Miller1-1/+3
Bug.add_attachment must by of type 'base64' when non-ASCII . r=LpSolit, a=LpSolit
2012-11-13Bug 781850 (CVE-2012-4198): [SECURITY] Do not leak the existence of groups ↵Frédéric Buclin2-6/+21
when using User.get() r=dkl a=LpSolit
2012-10-13Fix typoFrédéric Buclin1-1/+1
2012-10-12Bug 793826: Prevent private web service methods from being calledKoosha Khajeh Moogahi1-1/+3
r=dkl a=LpSolit
2012-08-03Bug 682317 - Bug.create is incorrectly documented as ignoring invalid ↵Koosha Khajeh Moogahi1-2/+3
fields; it should say it produces an error r=dkl, a=LpSolit
2012-05-24Bug 744691: Throw an error early when calling a method from a non-existent classByron Jones1-0/+1
r=dkl, a=LpSolit
2012-03-22Bug 733458: The "creator" argument is listed twice for the Bug.search ↵Matt Selsky1-7/+3
WebService method r/a=LpSolit
2012-02-29Bug 731219: Fix XMLRPC breakage when content-type contains a charsetByron Jones1-1/+4
r=dkl, a=LpSolit
2012-02-22Bug 725663 - (CVE-2012-0453) [SECURITY] CSRF vulnerability in the XML-RPC ↵Dave Lawrence2-0/+16
API when using mod_perl r/a=LpSolit
2012-02-15Bug 724464 - JSON-RPC support shouldn't require SOAP::LiteDave Lawrence1-0/+14
r/a=LpSolit
2012-02-14Bug 727240: The POD for Bug.attachments is wrong about the format of the ↵Frédéric Buclin1-16/+10
returned data r=dkl a=LpSolit
2012-01-31(CVE-2012-0440) [SECURITY] JSON-RPC permits to bypass token checks and can ↵Frédéric Buclin1-1/+13
lead to CSRF (no victim's action required) r=mkanat a=LpSolit https://bugzilla.mozilla.org/show_bug.cgi?id=718319
2012-01-31Bug 714446: Product.create default behavior is broken and inconsistent with PODFrédéric Buclin1-17/+29
r=dkl a=LpSolit
2012-01-05Bug 706753: Bugzilla will not work with newest version of JSON::RPC 1.01 due ↵Frédéric Buclin1-1/+12
to non-backward compatibility r=dkl r=mkanat a=LpSolit
2011-12-28Bug 711714: (CVE-2011-3667) [SECURITY] The User.offer_account_by_email ↵Frédéric Buclin2-19/+8
WebService method lets you create new user accounts independently of the value of Bugzilla::Auth::Verify::*::user_can_create_account r=dkl a=LpSolit
2011-12-06Bug 657290: Bug.add_attachment() stores truncated timestamps in the DB ↵Frédéric Buclin1-1/+4
(seconds are missing) r=dkl a=mkanat
2011-12-05Bug 692354: Incorrect parameter type in WebServices documentation for ↵Matt Selsky1-1/+1
Bug.add_comment r/a=mkanat
2011-10-15Bug 689862: Fix Product.get to only return the Classification name,Tiago Mello1-17/+2
instead of all the classification info. r/a=LpSolit
2011-10-15Bug 691243: Fix typoMatt Selsky1-1/+1
r/a=LpSolit
2011-09-27Bug 655652: Remove "internals" field from Product.getFrédéric Buclin1-9/+35
r=glob a=LpSolit
2011-09-18Fix typo in commentsFrédéric Buclin1-2/+2
2011-09-16Fix typo in PODFrédéric Buclin1-2/+2
2011-08-04Bug 653477: (CVE-2011-2380) [SECURITY] Group names can be guessed when ↵Frédéric Buclin1-2/+1
creating or editing a bug r=mkanat a=LpSolit
2011-07-20Bug 600810: Use XMLRPC::Transport::HTTP:Apache as base class under mod_perlTeemu Mannermaa1-1/+5
r/a=mkanat
2011-07-05Bug 658929 - User autocomplete is very slow when there are lots of users in ↵David Lawrence1-2/+2
the profiles table r/a=mkanat
2011-05-17Bug 655229: Adds components, versions and milestones to Product.get Byron Jones2-36/+233
r=mkanat, a=mkanat
2011-05-06Bug 653341: Bug.create() fails to error out if an invalid group is passedFrédéric Buclin2-4/+11
r/a=mkanat
2011-04-17Bug 469195: New WebService function, Group.create.Carole Pryfer2-1/+149
r=mkanat, a=mkanat
2011-04-08Improve the POD for Product.create.Max Kanat-Alexander1-11/+17
https://bugzilla.mozilla.org/show_bug.cgi?id=469193
2011-04-07Bug 469193: WebService function to create new products (Product.create)Julien Heyman2-0/+124
r/a=mkanat
2011-03-08Bug 622513 - Email-related regexp checking should be case-insensitive. a=mkanat.Gervase Markham1-1/+1
2011-03-06Bug 639151: Fix the webservice Bug.get method to return the correct seeTiago Mello1-1/+2
also url list. r/a=mkanat
2011-02-14Bug 633055: Make Bug.legal_values explicitly throw an error if you pass "undef"Max Kanat-Alexander1-0/+4
for the "field" parameter r=dkl, a=mkanat
2011-02-14Bug 609538: Make the JSON-RPC interface support UTF-8 when a recent versionMax Kanat-Alexander1-1/+16
of LWP is installed r=dkl, a=mkanat
2011-02-14Bug 633422: Fix the documentation for User.get's include_disabled parameterMax Kanat-Alexander1-2/+9
and make User.get check that its required parameters are passed. r=LpSolit, a=mkanat
2011-02-11Fix a POD compilation error.Max Kanat-Alexander1-1/+1
https://bugzilla.mozilla.org/show_bug.cgi?id=633041
2011-02-11Fix the POD of Bug.add_attachment to reflect that it now automaticallyMax Kanat-Alexander1-3/+2
picks the content_type of text/plain when you set is_patch to true. https://bugzilla.mozilla.org/show_bug.cgi?id=633041
2011-02-11Bug 633041: Add an error code for zero_length_file and fill in content_typeMax Kanat-Alexander2-0/+5
for patches when content_type is missing in Bug.add_attachment in the WebService r=LpSolit, a=LpSolit
2011-01-27Bug 622679 - Autocomplete suggests inactive/disabled accounts as matchesDavid Lawrence1-1/+11
r/a=mkanat
2010-12-27Bug 588013: Fix typotimeless1-1/+1
r/a=mkanat
2010-12-13Bug 617477: Fix numerous consistency and behavior issues surroudning Bug.updateMax Kanat-Alexander3-17/+127
and Bugzilla::Bug. See https://bugzilla.mozilla.org/show_bug.cgi?id=617477#c2 for details. r=LpSolit, a=LpSolit
2010-12-06Bug 617030 - Add an error code for json_rpc_invalid_callback, and fix theMax Kanat-Alexander2-1/+2
regex used by _bz_callback in Bugzilla::WebService::Server::JSONRPC to accept numbers other than 0 or 1. r=LpSolit, a=mkanat
2010-11-04Bug 605573: List all available WebService methods at the top of the PODFrédéric Buclin5-77/+35
r/a=mkanat
2010-10-28Bug 607966: Use of qw(...) as parentheses is deprecated since Perl 5.13.5Frédéric Buclin1-1/+1
r=gerv a=LpSolit
2010-10-27Bug 602458: Add is_mandatory to Bug.fields output.Max Kanat-Alexander1-0/+9
r=timello, a=mkanat