summaryrefslogtreecommitdiffstats
path: root/system/core
AgeCommit message (Expand)AuthorFilesLines
2017-03-20Fix Apache header injection vulnerability in set_status_header()Andrey Andreev1-5/+5
2017-02-07Allow to omit trailing slash in config pathsvlakoff3-2/+16
2017-02-06[ci skip] Eliminate a needless array_merge() call from PR #5006 patchAndrey Andreev1-6/+3
2017-02-06Merge pull request #5006 from tianhe1986/develop_commonAndrey Andreev1-8/+8
2017-02-04Removing url encoded 127.tianhe19861-0/+1
2017-02-04Loading global mimes config file first, and then environment file.tianhe19861-8/+7
2017-02-01Fix a CI_Input::set_cookie() bugAndrey Andreev1-9/+7
2017-01-23Merge pull request #4991 from verkhoumov/developAndrey Andreev1-5/+0
2017-01-21Fixed show_error() for check $exit_statusDmitriy Verkhoumov1-5/+0
2017-01-20Don't use each()Andrey Andreev1-2/+2
2017-01-19hash_pbkdf2() byte-safety again ... actually tell mbstring to use 8bitAndrey Andreev1-2/+2
2017-01-19hash_pbkdf2() byte-safetyAndrey Andreev1-4/+13
2017-01-19More byte-safetyAndrey Andreev3-14/+14
2017-01-17[ci skip] Merge pull request #4986 from ka7/feature/spellingAndrey Andreev2-2/+2
2017-01-16spelling fixes(1)klemens1-1/+1
2017-01-16spelling fixesklemens2-2/+2
2017-01-11[ci skip] Merge pull request #4977 from fabiospampinato/fabiospampinato-loade...Andrey Andreev1-1/+1
2017-01-11Fixed regex used for loading helpersFabio Spampinato1-1/+1
2017-01-10Merge branch '3.1-stable' into developAndrey Andreev2-37/+37
2017-01-10Fix Undefined variable: object errorChris Faulkner1-2/+2
2017-01-09[ci skip] Mark the beginning of 3.1.4-devAndrey Andreev1-1/+1
2017-01-09[ci skip] Prepare 3.1.3 releaseAndrey Andreev1-1/+1
2017-01-05[ci skip] || -> ORAndrey Andreev1-1/+1
2017-01-04Close #4904Andrey Andreev1-3/+3
2017-01-04Fix a possible file inclusion vulnerability in CI_Loader::vars()Andrey Andreev1-30/+28
2017-01-04[ci skip] Protect CSRF verification from timing side-channel attacksAndrey Andreev1-6/+8
2017-01-04Fix an XSS vulnerabilityAndrey Andreev1-1/+1
2017-01-03Update copyright data to 2017Master Yoda21-42/+42
2016-12-31Update copyright data to 2017Master Yoda21-42/+42
2016-12-14Move csrf_verify() call out of CI_InputAndrey Andreev3-24/+7
2016-12-14Isolate CI_Security instantiation from CI_Input; improve testsAndrey Andreev3-11/+10
2016-12-14Drop all PHP 5.3-related codeAndrey Andreev9-153/+10
2016-12-14Finally drop CI_Input::_sanitize_globals()Andrey Andreev1-160/+8
2016-12-14Remove 'global_xss_filtering' config settingAndrey Andreev1-23/+9
2016-12-14Remove 'allow_get_array', 'standardize_newlines' config settingsAndrey Andreev1-22/+1
2016-12-14Merge branch '3.1-stable' into developAndrey Andreev1-1/+4
2016-12-14Move 'standardize_newlines' proc out of CI_Input::_clean_input_data()Andrey Andreev1-17/+7
2016-12-01[ci skip] Fix #4928Andrey Andreev1-1/+4
2016-12-01Remove previously deprecated CI_Config::system_url()Andrey Andreev1-14/+0
2016-12-01Remove previously deprecated fetch_*() methods from CI_RouterAndrey Andreev1-43/+0
2016-12-01Remove previously deprecated CI_Input::is_cli_request()Andrey Andreev1-15/+0
2016-12-01Merge branch '3.1-stable' into developAndrey Andreev3-36/+13
2016-12-01Fix #4927Andrey Andreev1-3/+4
2016-11-14Fix #4905Andrey Andreev1-32/+8
2016-11-03Fix #4679, for realAndrey Andreev1-1/+1
2016-10-28Merge branch '3.1-stable' into developAndrey Andreev6-45/+196
2016-10-28[ci skip] Mark the start of 3.1.3-devAndrey Andreev1-1/+1
2016-10-28[ci skip] Prepare for 3.1.2 releaseAndrey Andreev1-1/+1
2016-10-28[ci skip] xss_clean() hardeningAndrey Andreev1-10/+11
2016-10-28Improve byte-safetyAndrey Andreev2-9/+106