summaryrefslogtreecommitdiffstats
path: root/system/libraries
AgeCommit message (Collapse)AuthorFilesLines
2008-07-03re-included URL encoded characters within _remove_invisible_characters() ↵Derek Jones1-1/+3
which were mistakenly pulled out in a previous commit, not released
2008-07-03changed link and image regex to be more precise in matching tags, reducing ↵Derek Jones1-3/+3
false positive matches
2008-07-01Changed regex for onfoo event handlers to prevent unwanted matching of text ↵Derek Jones1-4/+4
such as locatiON, cONtent, etc.
2008-06-30whitespaceDerek Jones1-1/+0
2008-06-30simplified regex for _remove_invisible_characters() - since we ↵Derek Jones1-5/+4
rawurldecode() the string, there's no need to go looking for url encoded characters here
2008-06-27Moved the <label> output ability from the language library to a language ↵Derek Jones1-8/+1
helper (hotfix for 1.6.3)
2008-06-27Fixed a double opening &lt;p&gt; tag in the index pages of each system ↵Derek Allard1-8/+3
directory.
2008-06-26changed your-site.com to example.com doc-wideDerek Jones1-1/+1
2008-06-25fixed accidental removal of $converted_string in xss_clean() for image ↵Derek Jones1-0/+5
comparison
2008-06-25added a bit of leeway for images to avoid the more common false-positives ↵Derek Jones1-2/+11
that using xss_clean() on image files might trigger
2008-06-25Further improvements to xss_clean()Derek Jones1-47/+83
2008-06-20Added the ability to automatically output language items as form labels in ↵Derek Allard1-3/+11
the Language class.
2008-06-20Added get_post() to the Input class.Derek Allard1-0/+22
Documented get() in the Input class.
2008-06-16correcting some docblock commentsDerek Allard5-15/+15
2008-06-06added quoted-printable headers when $this->send_multipart has been manually ↵Derek Jones1-1/+2
changed to FALSE
2008-06-06Removed an unused Router reference in _display_cache().Derek Allard1-3/+1
2008-06-04picky picky Jones adjusts some syntaxDerek Jones1-2/+1
2008-06-04a few tweaks for speedDerek Allard1-3/+4
2008-06-04simplified and refactored input filtering and retrievalDerek Jones1-97/+32
2008-06-04emendation to on* event handler removalDerek Jones1-3/+2
2008-05-30decided just to kill all on*= event handlers, rather than trying to keep up ↵Derek Jones1-2/+2
with (and require users to do the same) with a blacklist.
2008-05-30moved word compacting to a callback for clarity, added a few js event ↵Derek Jones1-3/+20
handlers for removal
2008-05-22Fixed a bug (#4561) where orhaving() wasn't properly passing values.Derek Allard2-2/+0
Removed some unused variables from the code (#4563). Fixed a bug where having() was not adding an = into the statement (#4568).
2008-05-21more complete protection against malformed link tags to protect against hex ↵Derek Jones1-13/+25
entities and href=data:url exploits
2008-05-21customizable query stringDerek Allard1-6/+21
2008-05-21Added support for query strings to the Pagination class, automatically ↵Derek Allard1-2/+11
detected or explicitly declared.
2008-05-20improved security in xss_clean(), added <audio> and <video> tags to naughty ↵Derek Jones1-22/+14
HTML tags, and the HTML5 event handlers onerror and onended
2008-05-16changed foreach() reindexing of segment arrays to array_unshift() - teensy ↵Derek Jones1-15/+2
tiny memory and speed improvement.
2008-05-16fixed regular expression in Image lib, CI bug #4542Derek Jones1-1/+1
2008-05-15addition xss protection against certain data urls, stripping of anything ↵Derek Jones1-2/+12
sent with utf-7 encoding
2008-05-15added ability to use xss_clean() to test images, and improved security for ↵Derek Jones1-37/+49
vectors particular to the Opera family of browsers
2008-05-14Set the mime type check in the Upload class to reference the global mimes ↵Derek Allard1-1/+3
variable.
2008-05-14force closing tag on eval() for servers not running short_open_tagsDerek Jones1-1/+1
2008-05-13Hey you! Yeah, you, that other set of hardcoded arrays in xss_clean(). ↵Derek Jones1-21/+3
You're coming with me, pal!
2008-05-13increased security and performance of xss_clean(), added ↵Derek Jones1-24/+56
_sanitize_naughty_html() callback and removed "never allowed" items to a class property
2008-05-13The Zip class has undergone a substantial re-write for speed and clarityDerek Allard1-120/+101
2008-05-13Some sweeping syntax changes for consistency:Derek Jones32-360/+384
(! foo) changed to ( ! foo) || changed to OR changed newline standardization code in various places from preg_replace to str_replace
2008-05-13adjusted eval() statement in Loader to accommodate servers with ↵Derek Jones1-1/+1
short_open_tag disabled with the new change of removing closing PHP tags from files
2008-05-13minor source formattingDerek Allard2-22/+22
2008-05-13preg_split changed to explodeDerek Allard1-165/+165
2008-05-13substr checks swapped out with strncmpDerek Allard1-16/+72
{ braces } added around if and for statements
2008-05-12fixed a misspelling in the Input library of CDATADerek Allard1-1/+1
2008-05-12removed an ereg from configDerek Allard4-124/+125
added a qualifier to a str_replace for \t in Input changed substr to strncmp in Codeigniter.php and directory_map function added braces in an if statement of unit test Removed "scripts" from the auto-load search path. Scripts were deprecated in Version 1.4.1 (September 21, 2006). If you still need to use them for legacy reasons, they must now be manually loaded in each Controller.
2008-05-12Added protection in xss_clean() for GET variables in URLsDerek Jones1-3/+55
http://codeigniter.com/bug_tracker/bug/4167/
2008-05-12changed $xmlrpcDateTime property to all lowercase 'datetime.iso8601' so it ↵Derek Jones1-3/+3
can be recognized as a valid XML-RPC type http://codeigniter.com/bug_tracker/bug/4153/
2008-05-12fixed a bug that would lead to a PHP notice error of array to string ↵Derek Jones1-2/+4
conversion in prep_for_form() http://codeigniter.com/bug_tracker/bug/4425/
2008-05-12changed overlay_watermark() to check for an alpha value before applying the ↵Derek Jones1-6/+19
image to help support PNG-24s with alpha transparency http://codeigniter.com/bug_tracker/bug/4506/
2008-05-11Removed closing PHP tags, replaced with a comment block identifying the end ↵Derek Jones32-32/+96
of the file
2008-05-11Undoing change committed in r1115Derek Jones32-0/+32
2008-05-11removed closing PHP tag from all framework filesDerek Jones32-32/+0