summaryrefslogtreecommitdiffstats
path: root/token.cgi
AgeCommit message (Collapse)AuthorFilesLines
2016-04-27Bug 218917 - Allow the login name to be different from the email addressFrédéric Buclin1-22/+35
Original patch by Gervase Markham r=gerv a=dkl
2016-02-29Bug 1136137: Require Perl 5.14Frédéric Buclin1-1/+1
r=dkl
2016-02-23Bug 1246528 - Use Makefile.PL and allow Bugzilla use cpanm-compatible local ↵Dylan Hardison1-1/+1
dependencies r=dkl,a=dylan
2015-08-23Bug 670669 - Changing the e-mail address under account prefs does not ↵Simon Green1-4/+1
require current password if can_change_password is false r=dkl, a=simon
2014-10-06Bug 1075578: [SECURITY] Improper filtering of CGI argumentsFrédéric Buclin1-1/+1
r=dkl,a=sgreen
2014-10-01Fix bustage due to bug 1061247Frédéric Buclin1-0/+1
2014-10-01Bug 1061247 - Successfully using a password change token should invalidate ↵Reed Loden1-0/+2
all other password change tokens for that user r=gerv a=glob
2014-08-13Bug 996893: Perl 5.18 and newer throw tons of warnings about deprecated modulesFrédéric Buclin1-1/+3
r=dkl a=sgreen
2014-08-06Bug 1046145: It is no longer possible to cancel an email address change when ↵Frédéric Buclin1-1/+1
this one has already been confirmed r=dkl a=sgreen
2014-02-27Bug 947823: Replace gender-specific pronouns with gender-neutral pronounsCharlie Somerville1-2/+2
r=gerv a=justdave
2013-06-06Bug 878035: Do not disclose whether a user account exists or not when a user ↵Frédéric Buclin1-3/+4
clicks "forgot password" r=dkl a=LpSolit
2012-09-01Bug 787529: Use |use 5.10.1| everywhereFrédéric Buclin1-0/+1
r=wicked a=LpSolit
2012-08-06Bug 706271: CSRF vulnerability in token.cgi allows possible unauthorized ↵Frédéric Buclin1-0/+5
password reset e-mail request r=reed a=LpSolit
2012-05-28Bug 355596: Your password should be requested to confirm your email address ↵Koosha Khajeh Moogahi1-5/+11
change r/a=LpSolit
2012-05-18Bug 752303: It is no longer possible to cancel an email address change when ↵Koosha Khajeh Moogahi1-14/+5
this one has already been confirmed r/a=LpSolit
2012-01-23Bug 319953: Missing real email syntax checkFrédéric Buclin1-3/+1
r=glob a=LpSolit
2012-01-11Bug 680131: Replace the MPL 1.1 license by the MPL 2.0 one in all files, and ↵Frédéric Buclin1-20/+5
add it to files which miss one r=kiko r=mkanat r=mrbball a=LpSolit
2011-12-28Bug 711714: (CVE-2011-3667) [SECURITY] The User.offer_account_by_email ↵Frédéric Buclin1-0/+4
WebService method lets you create new user accounts independently of the value of Bugzilla::Auth::Verify::*::user_can_create_account r=glob a=LpSolit
2011-08-16Fix complains from 012throwables.t due to bug 677901Frédéric Buclin1-8/+9
2011-08-16Bug 677901: Bugzilla crashes when no token is passed to token.cgi but the ↵Frédéric Buclin1-161/+101
script expects one, because tokens are incorrectly validated r/a=mkanat
2011-07-05Bug 658929 - User autocomplete is very slow when there are lots of users in ↵David Lawrence1-1/+1
the profiles table r/a=mkanat
2010-05-20Bug 565879: Merge ThrowCodeError("action_unrecognized"), ↵Frédéric Buclin1-5/+2
ThrowUserError("no_valid_action") and ThrowCodeError("unknown_action") r=ghendricks a=LpSolit
2009-10-09Bug 514913: Eliminate ssl="authenticated sessions"mkanat%bugzilla.org1-8/+0
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=dkl, a=mkanat
2009-09-11Bug 508189: (CVE-2009-3166) [SECURITY] Logging in after changing your ↵mkanat%bugzilla.org1-0/+4
password would expose your new password in the URL Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=mkanat
2009-08-11Bug 349336: Automatically log in the user when he chooses his password to ↵lpsolit%gmail.com1-2/+6
create his new account - Patch by Frédéric Buclin <LpSolit@gmail.com> r/a=mkanat
2009-06-12496856 - correct patchbbaetz%acm.org1-1/+1
(original patch r/a=mkanat)
2009-06-10Bug 496856 - Fix token.cgi transaction handlingbbaetz%acm.org1-5/+9
2009-01-08Bug 452519: Fix timezones in emails - Patch by Frédéric Buclin ↵lpsolit%gmail.com1-1/+2
<LpSolit@gmail.com> r=wicked a=LpSolit
2008-09-20Bug 455814: token.cgi should reject password change requests for disabled ↵lpsolit%gmail.com1-0/+6
accounts - Patch by Frédéric Buclin <LpSolit@gmail.com> r=ghendricks a=LpSolit
2008-09-19Bug 455815: Remove global variables from token.cgi - Patch by Frédéric ↵lpsolit%gmail.com1-65/+70
Buclin <LpSolit@gmail.com> r/a=mkanat
2008-08-18Bug 428659 – Setting SSL param to 'authenticated sessions' only ↵dkl%redhat.com1-2/+3
protects logins and param doesn't protect WebService calls at all Patch by David Lawrence <dkl@redhat.com> - r/a=LpSolit/mkanat
2008-07-29Backing out these patches as they cause a regression. More informationdkl%redhat.com1-3/+5
in the respective bug reports. Bug 428659 – Setting SSL param to 'authenticated sessions' only protects logins and param doesn't protect WebService calls at all Patch by Dave Lawrence <dkl@redhat.com> - r/a=mkanat Bug 445104: ssl redirects come with a 200 OK HTTP code on mod_perl Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=dkl, a=mkanat
2008-07-10Bug 428659 – Setting SSL param to 'authenticated sessions' only ↵dkl%redhat.com1-5/+3
protects logins and param doesn't protect WebService calls at all Patch by Dave Lawrence <dkl@redhat.com> - r/a=mkanat
2008-04-03Bug 405946: Some emails are not sent in the language chosen by the addressee ↵lpsolit%gmail.com1-11/+7
- Patch by Frédéric Buclin <LpSolit@gmail.com> r=wurblzap a=LpSolit
2007-11-19Bug 403834: Replace table locks with database transactions in tokens, votes, ↵lpsolit%gmail.com1-8/+4
and sanitycheck - Patch by Emmanuel Seyman <eseyman@linagora.com> r/a=mkanat
2007-10-19Bug 399954: Make Bugzilla able to hold its dependencies in a local directorymkanat%bugzilla.org1-1/+1
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit
2007-07-23Bug 238651 (a&b) Include the login name (in <code>) for "account_inexistent" ↵timeless%mozdev.org1-1/+1
error r=lpsolit a=lpsolit
2007-07-10Bug 365472 rename 'token_inexistent' to 'token_does_not_exist' or somethingtimeless%mozdev.org1-1/+1
r=lpsolit a=lpsolit
2007-03-11Bug 366466 - "flag notification mail has canceled spelled incorrectly" ↵reed%reedloden.com1-5/+5
[p=reed r=timeless a=mkanat]
2006-10-21Bug 340538: Insecure dependency in exec while running with -T switch at ↵wurblzap%gmail.com1-20/+20
/usr/lib/perl5/site_perl/5.8.6/Mail/Mailer/sendmail.pm line 16. Patch by Marc Schumann <wurblzap@gmail.com>, r=LpSolit, a=myk
2006-10-15Bug 281181: [SECURITY] It's way too easy to delete ↵lpsolit%gmail.com1-1/+1
versions/components/milestones etc... - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=myk
2006-08-26Bug 349349: Use ->create from Bugzilla::Object instead of insert_new_user ↵mkanat%bugzilla.org1-25/+7
for Bugzilla::User Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=myk
2006-08-20Bug 87795: Creating an account should send token and wait for confirmation ↵lpsolit%gmail.com1-0/+87
(prevent user account abuse) - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat r=bkor a=myk
2006-07-06Bug 173629: Clean up "my" variable scoping issues for mod_perlmkanat%bugzilla.org1-3/+3
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=myk
2006-06-21Bug 282121: Remove globals.pl from scripts that no longer use it - Patch by ↵lpsolit%gmail.com1-9/+3
Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=myk
2006-06-20Spelling in code comments patch: 'methids' -> 'methods'; patch by Vlad ↵vladd%bugzilla.org1-1/+1
Dascalu <vladd@bugzilla.org>.
2006-05-12Bug 300410: Bugzilla::Auth needs to be restructured to not require a BEGIN blockmkanat%bugzilla.org1-1/+1
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=myk
2006-05-08Bug 332598: Move ValidatePassword() and DBNameToIdAndCheck() from globals.pl ↵lpsolit%gmail.com1-2/+2
into User.pm - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=myk
2005-10-25Bug 312157: Remove $::template and $::vars from globals.pl - Patch by Olav ↵lpsolit%gmail.com1-4/+4
Vitters <bugzilla-mozilla@bkor.dhs.org> r=LpSolit a=justdave
2005-10-24Bug 312307: Misused Throw*Error tags in code and templates - Patch by Dennis ↵lpsolit%gmail.com1-4/+2
Melentyev <dennis.melentyev@infopulse.com.ua> r=LpSolit a=justdave