Age | Commit message (Collapse) | Author | Files | Lines | |
---|---|---|---|---|---|
2012-02-08 | Bug 533012 - add the ability to see all the administrative actions performed ↵ | Dave Lawrence | 1 | -0/+2 | |
by a user r=glob | |||||
2012-01-31 | merged with bugzilla/4.2 | Dave Lawrence | 2 | -5/+8 | |
2012-01-31 | (CVE-2012-0440) [SECURITY] JSON-RPC permits to bypass token checks and can ↵ | Frédéric Buclin | 1 | -0/+5 | |
lead to CSRF (no victim's action required) r=mkanat a=LpSolit https://bugzilla.mozilla.org/show_bug.cgi?id=718319 | |||||
2012-01-31 | Bug 714472: (CVE-2012-0448) [SECURITY] utf8 homoglyphs are allowed in email ↵ | Frédéric Buclin | 2 | -5/+3 | |
addresses, which could allow an attacker to be CC'ed to private bugs by accident r=glob a=LpSolit | |||||
2012-01-11 | merged with bugzilla/4.2 | Dave Lawrence | 1 | -0/+3 | |
2012-01-10 | Bug 716283: Clickjacking in the attachment "Details" page allows to bypass ↵ | Frédéric Buclin | 1 | -0/+3 | |
token checks r=dkl a=LpSolit | |||||
2012-01-09 | merge with bugzilla/4.2 | Dave Lawrence | 2 | -2/+2 | |
2012-01-06 | Bug 714664: The content of the "emailregexpdesc" parameter is not escaped ↵ | Frédéric Buclin | 2 | -2/+2 | |
when displayed to the user r=dkl a=LpSolit | |||||
2012-01-03 | bug 714759: fix IE js syntax error | Byron Jones | 1 | -2/+2 | |
2011-11-30 | Bug 301656: Adds a preference to CC flag requestees to bugs | Byron Jones | 1 | -0/+1 | |
2011-11-28 | merged with bugzilla/4.2 | Dave Lawrence | 1 | -0/+4 | |
2011-11-26 | Bug 255606: Do not let buglist.cgi return all bugs by default | Frédéric Buclin | 1 | -0/+4 | |
r/a=mkanat | |||||
2011-11-01 | merged with bugzilla/4.2 | David Lawrence | 4 | -8/+8 | |
2011-11-01 | Fix missing-space bugs in error messages. a=LpSolit. | Gervase Markham | 3 | -6/+6 | |
https://bugzilla.mozilla.org/show_bug.cgi?id=698737 | |||||
2011-10-24 | Bug 685552 - Email auto-completion causes server to thrash | David Lawrence | 1 | -2/+2 | |
r/a=mkanat | |||||
2011-10-05 | merged with bugzilla/4.2 | David Lawrence | 1 | -0/+4 | |
2011-10-05 | more porting work | David Lawrence | 4 | -3/+40 | |
2011-10-01 | Bug 582529: Ambiguous error message "You did not specify a file to attach" ↵ | Frédéric Buclin | 1 | -0/+4 | |
when deleting an existing attachment filename a=LpSolit | |||||
2011-08-29 | Bug 637648 - Rename the "tags" table to "tag" | Stephanie Daugherty | 1 | -1/+1 | |
r=LpSolit, a=LpSolit | |||||
2011-08-16 | Bug 678844: When trying to edit a non-existent classification, the error ↵ | Frédéric Buclin | 1 | -2/+4 | |
message has missing words r=glob a=LpSolit | |||||
2011-08-10 | Bug 677187: If the attachment filename contains a newline, an error is ↵ | Frédéric Buclin | 1 | -2/+3 | |
thrown when trying to download the attachment r/a=mkanat | |||||
2011-08-04 | Bug 637981: (CVE-2011-2379) [SECURITY] "Raw Unified" patch diffs can cause ↵ | Byron Jones | 1 | -0/+5 | |
XSS on this domain in IE 6-8 and Safari r/a=LpSolit | |||||
2011-08-04 | Bug 653477: (CVE-2011-2380) [SECURITY] Group names can be guessed when ↵ | Frédéric Buclin | 1 | -20/+8 | |
creating or editing a bug r=mkanat a=LpSolit | |||||
2011-08-04 | Bug 676237: The traceback in code-error.html.tmpl is displayed on a single line | Frédéric Buclin | 1 | -1/+1 | |
r=glob a=LpSolit | |||||
2011-08-01 | Bug 634812: Having a very large number of custom fields can make displaying ↵ | Frédéric Buclin | 1 | -1/+3 | |
show_bug.cgi slow r=glob a=LpSolit | |||||
2011-08-01 | Bug 674574: When all components or versions are disabled, you cannot enter ↵ | Frédéric Buclin | 1 | -2/+2 | |
bugs into the product but it's listed in enter_bug.cgi anyway r=dkl a=LpSolit | |||||
2011-07-26 | Bug 674089: Add a new hook 'end_object_name' in user-error.html.tmpl template | Tiago Mello | 1 | -0/+1 | |
r/a=mkanat | |||||
2011-07-26 | Bug 674117: Add a new hook 'auth_failure_object' in user-error.html.tmpl ↵ | Tiago Mello | 1 | -0/+2 | |
template r/a=mkanat | |||||
2011-07-25 | Bug 642388: Description of field days_elapsed missing from ↵ | Frédéric Buclin | 1 | -0/+1 | |
global/field-descs.none.tmpl r=wurblzap a=LpSolit | |||||
2011-07-25 | Bug 589128: Adds a preference allowing users to choose between text or html | Byron Jones | 1 | -0/+3 | |
for bugmail. r=LpSolit, a=LpSolit | |||||
2011-07-05 | Bug 658929 - User autocomplete is very slow when there are lots of users in ↵ | David Lawrence | 1 | -0/+2 | |
the profiles table r/a=mkanat | |||||
2011-07-01 | Revert wrong indentation, see bug 652427 | Frédéric Buclin | 1 | -1/+1 | |
2011-06-29 | Bug 652427: Going back to the new bug page loses the description if possible ↵ | Guy Pyrzak | 1 | -1/+2 | |
duplicates have been searched for r=mkanat, r=mkanat | |||||
2011-05-30 | Bug 660464: Linkify the tag name in the confirmation message when tagging bugs | Frédéric Buclin | 1 | -1/+2 | |
r=glob a=LpSolit | |||||
2011-05-10 | Bug 28849: Block users from CCing other users if they do not have editbugs privs | Byron Jones | 1 | -0/+4 | |
r=LpSolit, a=LpSolit | |||||
2011-05-06 | Bug 653341: Bug.create() fails to error out if an invalid group is passed | Frédéric Buclin | 1 | -0/+7 | |
r/a=mkanat | |||||
2011-04-29 | Bug 653406: fix escaping of url vars in error messages | Byron Jones | 1 | -8/+8 | |
r=LpSolit, a=LpSolit | |||||
2011-04-28 | Bug 423612 - Allow editing extern_id for users from the admin interface | Jochen Wiedmann | 2 | -0/+10 | |
r=mkanat, a=mkanat | |||||
2011-04-25 | Bug 652405: All user fields (assignee, QA contact, Add CC) have the page ↵ | Frédéric Buclin | 1 | -3/+3 | |
title as the "title" attribute r=dkl a=LpSolit | |||||
2011-04-02 | Bug 647466: Allow Search.pm to take the new URL syntax for custom search | Max Kanat-Alexander | 1 | -0/+7 | |
r=mkanat, a=mkanat (module owner) | |||||
2011-03-09 | Bug 634310: Remove WCAG 2.0 violations from the index.cgi to make it | Francisco Donalisio | 2 | -2/+2 | |
W3C WAI compliant. r=timello, a=LpSolit | |||||
2011-03-09 | Bug 639371: Include the charset into HTML pages when the utf8 param is true | Bjoern Jacke | 1 | -0/+4 | |
r/a=mkanat | |||||
2011-03-03 | Bug 638489 - Make all boolean charts work with longdescs.isprivate | Max Kanat-Alexander | 1 | -0/+4 | |
r=mkanat, a=mkanat (module owner) | |||||
2011-03-02 | Bug 624414: BUGZILLA.value_descs was always empty in the JS, and display_value | Max Kanat-Alexander | 4 | -21/+41 | |
wasn't translating values. r=glob, a=mkanat | |||||
2011-03-01 | Bug 616341: Make "tag" a valid search field in Search.pm, for the new | Max Kanat-Alexander | 1 | -0/+1 | |
tagging system r=mkanat, a=mkanat (module owner) | |||||
2011-02-18 | Bug 580490 - Quicksearch should optionally not search comments | David Lawrence | 1 | -0/+1 | |
r/a=mkanat | |||||
2011-02-16 | Bug 624522: Add support for SourceForge URLs in "see also" | Tiago Mello | 1 | -0/+1 | |
r/a=mkanat | |||||
2011-02-15 | Bug 634243: Stop confirm-match.html.tmpl from sending extra, empty values for | Max Kanat-Alexander | 1 | -1/+6 | |
each field being confirmed. This fixes a bug where confirming would fail, displaying a value with an extra comma at the end. r=LpSolit, a=LpSolit | |||||
2011-02-14 | Bug 621122: Add support for MantisBT URLs in "see also". | Reed Loden | 1 | -0/+1 | |
[r=timello a=mkanat] | |||||
2011-02-14 | Bug 543667: Add support for Trac URLs in "see also". | Matt Selsky | 1 | -0/+1 | |