summaryrefslogtreecommitdiffstats
path: root/attachment.cgi
AgeCommit message (Collapse)AuthorFilesLines
2014-10-24Bug 1073264 - allow attachment download to be offloaded to the webserver ↵Damien Nozay1-1/+17
using X-SendFile or equivalent. r=gerv, a=glob.
2014-10-16Bug 1068494: Remove CVS/Bonsai/LXR-specific bits of Patch ViewerFrédéric Buclin1-18/+2
r=gerv a=glob
2014-10-16Bug 1082887: comments made when setting a flag from the attachment details ↵Byron Jones1-53/+59
page are not included in the "flag updated" email r=dkl,a=glob
2014-10-06Bug 1075578: [SECURITY] Improper filtering of CGI argumentsFrédéric Buclin1-4/+6
r=dkl,a=sgreen
2014-08-13Bug 996893: Perl 5.18 and newer throw tons of warnings about deprecated modulesFrédéric Buclin1-1/+3
r=dkl a=sgreen
2014-03-21Bug 294021: Allow requestees to set attachment flags even if they don't have ↵Frédéric Buclin1-3/+25
editbugs privs r=gerv a=justdave
2013-10-16Bug 913904: (CVE-2013-1734) [SECURITY] CSRF when updating attachmentsFrédéric Buclin1-7/+10
r=dkl a=sgreen
2012-11-22Bug 811280: Adds a caching mechanism to Bugzilla::Object to avoid querying ↵Byron Jones1-3/+3
the database repeatedly for the same information r=dkl,a=LpSolit
2012-10-19Bug 803600: Clean up the comment generated when deleting attachmentsFrédéric Buclin1-1/+0
r=justdave a=LpSolit
2012-09-01Bug 787529: Use |use 5.10.1| everywhereFrédéric Buclin1-12/+1
r=wicked a=LpSolit
2012-07-24Bug 771107 - List of attachments in attachment details screen does not ↵Dave Lawrence1-2/+0
distinguish obsolete attachments r=glob, a=LpSolit
2012-06-26Bug 138546: Add a checkbox to add himself to the CC list when creating or ↵Reed Loden1-0/+4
editing an attachment r/a=LpSolit
2012-05-29Bug 671612: Send "X-Content-Type-Options: nosniff" with every responseMatt Selsky1-2/+1
r/a=LpSolit
2012-03-062nd part of bug 731559: fix get_attachments_by_bug() everywhereFrédéric Buclin1-3/+2
a=LpSolit
2012-01-11Bug 680131: Replace the MPL 1.1 license by the MPL 2.0 one in all files, and ↵Frédéric Buclin1-28/+5
add it to files which miss one r=kiko r=mkanat r=mrbball a=LpSolit
2011-12-14Bug 169752: Activity log should fuse data fields split because they didn't fitFrédéric Buclin1-2/+1
r=glob a=LpSolit
2011-12-08Bug 684225: The removal of locally stored attachments should be done from ↵c1541@hotmail.com1-4/+0
Bugzilla::Attachment->remove_from_db r/a=LpSolit
2011-11-21Bug 703983 - CSRF vulnerability in attachment.cgi allows possible ↵Reed Loden1-28/+5
unauthorized attachment creation [r=LpSolit a=LpSolit]
2011-09-02Bug 682822: Hide 'obsolete attachments' section when there are none to displayByron Jones1-30/+41
r=LpSolit, a=LpSolit
2011-08-04Bug 637981: (CVE-2011-2379) [SECURITY] "Raw Unified" patch diffs can cause ↵Byron Jones1-30/+99
XSS on this domain in IE 6-8 and Safari r/a=LpSolit
2011-04-28Bug 653404: Misleading error message when file to be attached is not ↵Frédéric Buclin1-1/+4
readable by browser r/a=LpSolit
2011-03-09Bug 633776: Automatic charset detection for text attachmentsByron Jones1-1/+7
r=mkanat, a=mkanat
2010-10-26Bug 607361: Creating an attachment without a "comment" param in the URL ↵Frédéric Buclin1-1/+2
causes an internal error a=LpSolit
2010-10-03Bug 414509: offer View All (non obsolete) attachmentsGuy Pyrzak1-0/+5
r=LpSolit, a=LpSolit
2010-08-04Bug 584110: Don't name attachment files "attachment.txt" by default, because ↵Frédéric Buclin1-1/+1
this confuses IE a=LpSolit
2010-08-03Bug 453425 - Send "X-Content-Type-Options: nosniff" header when displaying ↵Reed Loden1-1/+2
attachments so IE8 doesn't try to sniff the content type. [r=LpSolit a=LpSolit]
2010-07-18Bug 119703: Create an attachment by pasting it into a text fieldFrédéric Buclin1-3/+2
r/a=mkanat
2010-07-08Bug 490930: Always store attachments locally if they are over X size (and ↵Frédéric Buclin1-1/+0
below some threshold!), don't ever display "Big File" checkbox r=mkanat a=LpSolit
2010-06-03Bug 567846: Modify set_status, set_resolution, and set_dup_id to useMax Kanat-Alexander1-1/+1
VALIDATOR_DEPENDENCIES, so that they don't need custom code in set_all.
2010-05-20Bug 565879: Merge ThrowCodeError("action_unrecognized"), ↵Frédéric Buclin1-1/+1
ThrowUserError("no_valid_action") and ThrowCodeError("unknown_action") r=ghendricks a=LpSolit
2010-05-17Bug 560281: Do not display deleted attachments in "View All"Frédéric Buclin1-0/+2
a=LpSolit
2010-05-07Bug 395451 - "Bugzilla::BugMail needs to use Bug objects internally instead ↵Reed Loden1-3/+3
of direct SQL" [r=mkanat a=mkanat]
2010-04-22Bug 560009: Use firstidx from List::MoreUtils instead of lsearchMax Kanat-Alexander1-4/+2
r=timello, a=mkanat
2010-04-06Bug 556429: Stop sending bugmail from inside the templateMax Kanat-Alexander1-4/+9
r=LpSolit, a=LpSolit
2010-03-28Bug 365926: Serve attachments without an explicit charset, and let the browserMax Kanat-Alexander1-0/+8
decide which charset to use r=LpSolit, a=LpSolit
2009-12-30Bug 532518: Credentials are not checked correctly when viewing one ↵lpsolit%gmail.com1-21/+28
attachment from another bug's alternate host - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=LpSolit
2009-12-18Bug 162060: Remove the relationship between "votestoconfirm" and whether or ↵mkanat%bugzilla.org1-1/+2
not the UNCONFIRMED status is available, by adding a checkbox to enable the UNCONFIRMED status in editproducts.cgi. Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit
2009-12-13Bug 526734: Allow localization of the "From update of attachment" string in ↵mkanat%bugzilla.org1-7/+5
comments Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit
2009-12-04Bug 452919: Allow the "created an attachment" message in comments to be ↵mkanat%bugzilla.org1-5/+4
localized Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit
2009-10-24Bug 523495: Re-work attachment.cgi and the general attachment_base-checking ↵mkanat%bugzilla.org1-11/+12
code to prevent an infinite redirect loop when ssl_redirect is on and Bugzilla has an attachment_base set. Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit
2009-10-01Bug 509053: Implement Bugzilla->feature (feature_enabled in the templates), ↵mkanat%bugzilla.org1-6/+0
and use it to detect when PatchReader is available. Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit
2009-09-30Bug 328628: When attachments have UTF-8 characters in their name, they will ↵mkanat%bugzilla.org1-0/+7
now be downloaded with the correct name. Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=Wurblzap, a=mkanat
2009-09-28Bug 140999: Users without edit permissions for an attachment should still be ↵lpsolit%gmail.com1-37/+45
able to make comments - Patch by Frédéric Buclin <LpSolit@gmail.com> a=LpSolit
2009-08-11Bug 509045: Make "use_keywords" a global template variable instead of having ↵mkanat%bugzilla.org1-3/+0
to pass it to templates all the time Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit
2009-08-06Bug 305993: The requestee field may be omitted even when a requestee is ↵lpsolit%gmail.com1-2/+8
already set - Patch by Frédéric Buclin <LpSolit@gmail.com> a=LpSolit
2009-08-05Bug 415541: Implement $bug->set_flags() and $attachment->set_flags() - Patch ↵lpsolit%gmail.com1-34/+15
by Frédéric Buclin <LpSolit@gmail.com> a=LpSolit
2009-04-15Bug 486685: MIME type override for attachments lost in HTTP redirect - Patch ↵lpsolit%gmail.com1-0/+4
by Frédéric Buclin <LpSolit@gmail.com> r=wicked a=LpSolit
2009-04-09Bug 454251: Implement Bugzilla::Attachment->create() and ↵lpsolit%gmail.com1-148/+85
$attachment->update() - Patch by Frédéric Buclin <LpSolit@gmail.com> a=LpSolit (module owner)
2009-03-31Bug 477420 - "Rename some of the token names used in attachment.cgi" [p=reed ↵reed%reedloden.com1-6/+6
r=LpSolit a=LpSolit]
2009-03-30Bug 476603 - "[SECURITY] Editing attachments doesn't have any CSRF ↵reed%reedloden.com1-0/+9
protection" [p=reed r=LpSolit a=LpSolit]