summaryrefslogtreecommitdiffstats
path: root/attachment.cgi
AgeCommit message (Expand)AuthorFilesLines
2015-08-19Bug 1195544 - Information Disclosure Vulnerability Permits Attacker Obtains T...Byron Jones1-0/+2
2015-07-21Bug 1175985 - Bugzilla Sensitive Information Disclosure VulnerabilityDylan William Hardison1-1/+17
2015-07-21Bug 1180572 - create attachment_storage parameterByron Jones1-4/+1
2015-04-01remove debugging codeByron Jones1-1/+0
2015-03-30Bug 1125987: asking for review in a restricted bug doesn't work as expected (...Byron Jones1-1/+1
2015-03-24Bug 1096798: prototype modal show_bug viewByron Jones1-0/+1
2014-10-16Bug 1082887: comments made when setting a flag from the attachment details pa...Byron Jones1-4/+9
2014-10-06merged with upstream 4.2David Lawrence1-12/+11
2014-10-06Bug 1075578: [SECURITY] Improper filtering of CGI argumentsFrédéric Buclin1-4/+6
2014-04-02Bug 986590: Confusing error message when not finding reviewerByron Jones1-0/+2
2014-03-31Bug 989650 - backport bug 294021 to bmo/4.2 to allow requestees to set attach...David Lawrence1-3/+27
2014-01-07Bug 956052 - backport upstream bug 945535 to bmo/4.2 for performance improvem...Dave Lawrence1-3/+2
2013-10-17merged with bugzilla/4.2Dave Lawrence1-8/+11
2013-10-16Bug 913904: (CVE-2013-1734) [SECURITY] CSRF when updating attachmentsFrédéric Buclin1-8/+11
2013-10-15Bug 916906: attaching a file which just contains a github url should automati...Byron Jones1-0/+4
2013-07-16Bug 888939: patches created by pasting the attachment content should use unix...Byron Jones1-3/+13
2012-11-28Bug 814411: Add a caching mechanism to Bugzilla::Object to avoid querying the...Byron Jones1-3/+3
2012-10-23Bug 803600: Operators email address is exposed to anons on attachment deletionFrédéric Buclin1-1/+0
2012-09-09Merge from bugzilla/4.2Reed Loden1-2/+1
2012-09-09Bug 671612: Send "X-Content-Type-Options: nosniff" with every responseMatt Selsky1-2/+1
2012-07-24Bug 771107 - List of attachments in attachment details screen does not distin...Dave Lawrence1-2/+0
2011-11-22merged with bmo/4.2Dave Lawrence1-28/+5
2011-11-21Bug 703983 - CSRF vulnerability in attachment.cgi allows possible unauthorize...Reed Loden1-28/+5
2011-10-05more porting workDavid Lawrence1-1/+8
2011-08-04Bug 637981: (CVE-2011-2379) [SECURITY] "Raw Unified" patch diffs can cause XS...Byron Jones1-30/+99
2011-04-28Bug 653404: Misleading error message when file to be attached is not readable...Frédéric Buclin1-1/+4
2011-03-09Bug 633776: Automatic charset detection for text attachmentsByron Jones1-1/+7
2010-10-26Bug 607361: Creating an attachment without a "comment" param in the URL cause...Frédéric Buclin1-1/+2
2010-10-03Bug 414509: offer View All (non obsolete) attachmentsGuy Pyrzak1-0/+5
2010-08-04Bug 584110: Don't name attachment files "attachment.txt" by default, because ...Frédéric Buclin1-1/+1
2010-08-03Bug 453425 - Send "X-Content-Type-Options: nosniff" header when displaying at...Reed Loden1-1/+2
2010-07-18Bug 119703: Create an attachment by pasting it into a text fieldFrédéric Buclin1-3/+2
2010-07-08Bug 490930: Always store attachments locally if they are over X size (and bel...Frédéric Buclin1-1/+0
2010-06-03Bug 567846: Modify set_status, set_resolution, and set_dup_id to useMax Kanat-Alexander1-1/+1
2010-05-20Bug 565879: Merge ThrowCodeError("action_unrecognized"), ThrowUserError("no_v...Frédéric Buclin1-1/+1
2010-05-17Bug 560281: Do not display deleted attachments in "View All"Frédéric Buclin1-0/+2
2010-05-07Bug 395451 - "Bugzilla::BugMail needs to use Bug objects internally instead o...Reed Loden1-3/+3
2010-04-22Bug 560009: Use firstidx from List::MoreUtils instead of lsearchMax Kanat-Alexander1-4/+2
2010-04-06Bug 556429: Stop sending bugmail from inside the templateMax Kanat-Alexander1-4/+9
2010-03-28Bug 365926: Serve attachments without an explicit charset, and let the browserMax Kanat-Alexander1-0/+8
2009-12-30Bug 532518: Credentials are not checked correctly when viewing one attachment...lpsolit%gmail.com1-21/+28
2009-12-18Bug 162060: Remove the relationship between "votestoconfirm" and whether or n...mkanat%bugzilla.org1-1/+2
2009-12-13Bug 526734: Allow localization of the "From update of attachment" string in c...mkanat%bugzilla.org1-7/+5
2009-12-04Bug 452919: Allow the "created an attachment" message in comments to be local...mkanat%bugzilla.org1-5/+4
2009-10-24Bug 523495: Re-work attachment.cgi and the general attachment_base-checking c...mkanat%bugzilla.org1-11/+12
2009-10-01Bug 509053: Implement Bugzilla->feature (feature_enabled in the templates), a...mkanat%bugzilla.org1-6/+0
2009-09-30Bug 328628: When attachments have UTF-8 characters in their name, they will n...mkanat%bugzilla.org1-0/+7
2009-09-28Bug 140999: Users without edit permissions for an attachment should still be ...lpsolit%gmail.com1-37/+45
2009-08-11Bug 509045: Make "use_keywords" a global template variable instead of having ...mkanat%bugzilla.org1-3/+0
2009-08-06Bug 305993: The requestee field may be omitted even when a requestee is alrea...lpsolit%gmail.com1-2/+8