summaryrefslogtreecommitdiffstats
path: root/system/core
AgeCommit message (Expand)AuthorFilesLines
2017-01-04Close #4904Andrey Andreev1-3/+3
2017-01-04Fix a possible file inclusion vulnerability in CI_Loader::vars()Andrey Andreev1-30/+28
2017-01-04[ci skip] Protect CSRF verification from timing side-channel attacksAndrey Andreev1-6/+8
2017-01-04Fix an XSS vulnerabilityAndrey Andreev1-1/+1
2017-01-03Update copyright data to 2017Master Yoda21-42/+42
2016-12-31Update copyright data to 2017Master Yoda21-42/+42
2016-12-14Move csrf_verify() call out of CI_InputAndrey Andreev3-24/+7
2016-12-14Isolate CI_Security instantiation from CI_Input; improve testsAndrey Andreev3-11/+10
2016-12-14Drop all PHP 5.3-related codeAndrey Andreev9-153/+10
2016-12-14Finally drop CI_Input::_sanitize_globals()Andrey Andreev1-160/+8
2016-12-14Remove 'global_xss_filtering' config settingAndrey Andreev1-23/+9
2016-12-14Remove 'allow_get_array', 'standardize_newlines' config settingsAndrey Andreev1-22/+1
2016-12-14Merge branch '3.1-stable' into developAndrey Andreev1-1/+4
2016-12-14Move 'standardize_newlines' proc out of CI_Input::_clean_input_data()Andrey Andreev1-17/+7
2016-12-01[ci skip] Fix #4928Andrey Andreev1-1/+4
2016-12-01Remove previously deprecated CI_Config::system_url()Andrey Andreev1-14/+0
2016-12-01Remove previously deprecated fetch_*() methods from CI_RouterAndrey Andreev1-43/+0
2016-12-01Remove previously deprecated CI_Input::is_cli_request()Andrey Andreev1-15/+0
2016-12-01Merge branch '3.1-stable' into developAndrey Andreev3-36/+13
2016-12-01Fix #4927Andrey Andreev1-3/+4
2016-11-14Fix #4905Andrey Andreev1-32/+8
2016-11-03Fix #4679, for realAndrey Andreev1-1/+1
2016-10-28Merge branch '3.1-stable' into developAndrey Andreev6-45/+196
2016-10-28[ci skip] Mark the start of 3.1.3-devAndrey Andreev1-1/+1
2016-10-28[ci skip] Prepare for 3.1.2 releaseAndrey Andreev1-1/+1
2016-10-28[ci skip] xss_clean() hardeningAndrey Andreev1-10/+11
2016-10-28Improve byte-safetyAndrey Andreev2-9/+106
2016-10-27Close #4875Andrey Andreev1-1/+20
2016-10-27[ci skip] This is 3.1.2-devAndrey Andreev1-1/+1
2016-10-26Fix #4877Andrey Andreev1-5/+29
2016-10-22[ci skip] Prepare for 3.1.1 releaseAndrey Andreev1-1/+1
2016-10-22Merge branch 'security/entity_decode' into 3.1-stableAndrey Andreev1-17/+22
2016-10-21Fix #4865Andrey Andreev2-1/+1
2016-10-11[ci skip] Add new HTTP status codesAndrey Andreev1-1/+6
2016-09-27Fix entity_decode() issueAndrey Andreev1-17/+22
2016-08-29Merge pull request #4785 from guitarrist/developAndrey Andreev1-1/+1
2016-08-26fix typoAntônio1-1/+1
2016-08-23Merge pull request #4781 from tianhe1986/develop_hash_pbkdf2Andrey Andreev1-1/+1
2016-08-23Move strtolower() inside the is_array() check,tianhe19861-2/+1
2016-08-23Hash: processing algorithm name case-insensitively in hash_pbkdf2():tianhe19861-0/+1
2016-08-22Merge pull request #4780 from tianhe1986/develop_standard_hex2binAndrey Andreev1-1/+1
2016-08-22Standard: filtering "resource" type in hex2bin()tianhe19861-1/+1
2016-08-19Merge pull request #4777 from tianhe1986/develop_error_handlerAndrey Andreev1-1/+1
2016-08-19Common: Adding E_PARSE in error judgment.tianhe19861-1/+1
2016-08-10Merge branch '3.1-stable' into developAndrey Andreev4-219/+3
2016-07-28[ci skip] Use const keyword to define CI_VERSIONAndrey Andreev1-1/+1
2016-07-28Remove dead code written for PHP 5.2Andrey Andreev4-219/+3
2016-07-26Merge branch '3.1-stable' into developAndrey Andreev4-25/+42
2016-07-26[ci skip] Mark the start of 3.1.1 developmentAndrey Andreev1-1/+1
2016-07-26Prepare for 3.1.0 releaseClaudio Galdiolo1-1/+1