Age | Commit message (Collapse) | Author | Files | Lines | |
---|---|---|---|---|---|
2016-07-26 | [ci skip] Mark the start of 3.1.1 development | Andrey Andreev | 1 | -1/+1 | |
2016-07-26 | Prepare for 3.1.0 release | Claudio Galdiolo | 1 | -1/+1 | |
2016-07-25 | Merge pull request #4725 from tianhe1986/develop_url_encode_case_insensitive | Andrey Andreev | 1 | -2/+2 | |
Fix remove_invisible_characters() for URL-encoded characters in upper case | |||||
2016-07-25 | Merge pull request #4724 from tianhe1986/develop_is_https_strtolower | Andrey Andreev | 1 | -1/+1 | |
Compare X-Forwarded-Proto case-insensitively | |||||
2016-07-19 | Fix #4679 | Andrey Andreev | 1 | -2/+2 | |
2016-05-20 | Merge pull request #4638 from kasimtan/phpdoc_fixes | Andrey Andreev | 4 | -4/+4 | |
[ci skip] Fixed PHPDoc parameter name and type discrepancies | |||||
2016-04-28 | Fix #4605 | Andrey Andreev | 1 | -6/+3 | |
2016-04-04 | Fix #4563 | Andrey Andreev | 1 | -12/+14 | |
2016-03-22 | random_bytes()-related improvements | Andrey Andreev | 1 | -4/+22 | |
See #4260 | |||||
2016-03-22 | [ci skip] Fix CI_VERSION | Andrey Andreev | 1 | -1/+1 | |
2016-03-21 | [ci skip] Mark the start of 3.0.7 development | Andrey Andreev | 1 | -1/+1 | |
2016-03-21 | [ci skip] Prepare for 3.0.6 release | Andrey Andreev | 1 | -1/+1 | |
2016-03-11 | [ci skip] Mark the start of 3.0.6 development | Andrey Andreev | 1 | -1/+1 | |
2016-03-11 | [ci skip] Prepare for 3.0.5 release | Andrey Andreev | 1 | -1/+1 | |
2016-03-11 | Add a defensive check in CI_Loader::_ci_load() | Andrey Andreev | 1 | -0/+8 | |
Prevents possible internal variable overwrites when loading views | |||||
2016-03-07 | Merge pull request #4472 from vibbow/patch-1 | Andrey Andreev | 1 | -1/+1 | |
[ci skip] Update get_instance() return type in docblock | |||||
2016-03-07 | Fix #4475 | Andrey Andreev | 1 | -1/+8 | |
2016-03-01 | [ci skip] Move flock() call in CI_Log::write_log() immediately after fopen() | Andrey Andreev | 1 | -2/+2 | |
2016-02-24 | Merge pull request #4480 from versalle88/develop | Andrey Andreev | 1 | -1/+1 | |
Changed class_exists() calls to ignore __autoload() | |||||
2016-02-15 | Merge pull request #4453 from EpicKris/feature/Autoload-Driver-Object-Name | Andrey Andreev | 1 | -6/+10 | |
Autoload Driver Object Names | |||||
2016-02-09 | Merge pull request #4323 from ↵ | Andrey Andreev | 1 | -3/+20 | |
jspreddy/sai/log_line_formatting_extensibility_change Refactored CI_Log line formatting to allow extensibility | |||||
2016-01-20 | [ci skip] Fix a documentation error on output cache times | Andrey Andreev | 1 | -1/+1 | |
2016-01-13 | [ci skip] Mark the start of 3.0.5 development | Andrey Andreev | 1 | -1/+1 | |
2016-01-11 | [ci skip] Update ellislab.com links to https too | Andrey Andreev | 21 | -21/+21 | |
2016-01-11 | [ci skip] Update codeigniter.com links to https | Andrey Andreev | 21 | -42/+42 | |
2016-01-11 | [ci skip] Bump year to 2016 | Andrey Andreev | 21 | -42/+42 | |
2016-01-04 | Fix #4350 | Andrey Andreev | 1 | -1/+31 | |
2015-12-07 | Merge pull request #4291 from b-kaxa/fix-phpdoc | Andrey Andreev | 2 | -1/+2 | |
[ci skip] phpdoc adjustments in CI_Router and CI_URI | |||||
2015-11-24 | Use PHP7's random_bytes() when possible | Andrey Andreev | 1 | -0/+16 | |
Close #4260 | |||||
2015-11-09 | Merge pull request #4217 from natesilva/fix-ipv6-base_url | Andrey Andreev | 1 | -1/+10 | |
Build base_url correctly if SERVER_ADDR is IPv6 | |||||
2015-11-04 | [ci skip] Start of 3.0.4 development | Andrey Andreev | 1 | -1/+1 | |
2015-10-31 | [ci skip] Update changelog, version & upgrade instructions | Andrey Andreev | 1 | -1/+1 | |
2015-10-31 | Prevent Host header injections | Andrey Andreev | 1 | -4/+2 | |
2015-10-31 | Harden xss_clean() | Andrey Andreev | 1 | -27/+39 | |
2015-10-30 | Fix #3201 | Andrey Andreev | 1 | -1/+6 | |
2015-10-12 | [ci skip] This is 3.0.3-dev | Andrey Andreev | 1 | -1/+1 | |
2015-10-08 | [ci skip] Prepare 3.0.2 release | Andrey Andreev | 1 | -1/+1 | |
2015-10-05 | Some more intrusive XSS cleaning | Andrey Andreev | 1 | -5/+11 | |
2015-10-02 | More XSS stuff | Andrey Andreev | 1 | -1/+1 | |
2015-09-24 | Fix #4137 | Andrey Andreev | 1 | -1/+1 | |
2015-09-21 | More XSS stuff | Andrey Andreev | 1 | -3/+3 | |
2015-09-17 | Don't allow open-ended tags to pass through xss_clean() | Andrey Andreev | 1 | -4/+9 | |
This was a regression caused by the previous commit | |||||
2015-09-17 | Refactor 'evil attributes' sanitization logic | Andrey Andreev | 1 | -92/+66 | |
Turned out pretty much impossible to do remove 'evil attributes' with just one pattern - it either breaks something else, hits pcre.backtrack_limit or causes PHP to segfault. No benchmarks made, but there shouldn't be any performance regressions since we're now trying to strip attributes only after it is determined that they are inside a tag; up until now this was done seprately for _sanitize_naughty_html() and _remove_evil_attributes(). | |||||
2015-09-15 | Missing character in the evil attributes pattern | Andrey Andreev | 1 | -1/+1 | |
2015-09-14 | Another addition to tag detection patterns in xss_clean() | Andrey Andreev | 1 | -1/+4 | |
2015-09-14 | Close #4098 | Andrey Andreev | 1 | -2/+18 | |
2015-09-14 | Fix #4109 | Andrey Andreev | 1 | -20/+22 | |
2015-09-14 | Add 'eval' to a JS blacklist in xss_clean() | Andrey Andreev | 1 | -7/+10 | |
2015-09-14 | Move _remove_evil_attributes() call | Andrey Andreev | 1 | -4/+3 | |
2015-09-11 | Harden xss_clean() more | Andrey Andreev | 1 | -5/+37 | |
This time eliminate false positives for the 'naughty html' logic. |