summaryrefslogtreecommitdiffstats
path: root/system
AgeCommit message (Collapse)AuthorFilesLines
2015-10-06Fix handling of %10 in paste contentFlorian Pritz1-1/+1
CI tries to remove invisible escape chars, but this breaks handling of code like the following: if (m == 2 && (y%4 == 0 && y%100 != 0)|| y%400 == 0) When pasted via the client all is fine, but when pasted in the webui CI strips '%10' from the string and leaves 'y0 != 0'. The second parameter of remove_invisible_characters indicates whether the string is urlencoded so I believe that setting it to false should be fine. This only disables the code that removes % escapes. Signed-off-by: Florian Pritz <bluewind@xinu.at>
2015-09-20postgres: Fix CI's postgres version detectionFlorian Pritz1-1/+2
This broke insert_id() because it expects a 'server' key in the returned array yet no array is returned. This should work just fine for postgres >7.4 now. Signed-off-by: Florian Pritz <bluewind@xinu.at>
2015-08-18Fix redirect URI when using multiple tabsFlorian Pritz1-1/+1
If we store only the last called URI in the session we can't support multiple browser tabs that all need to log in again. Fix this by storing the URI in the URL. Also change a trim() to ltrim() so that the URI string we store keeps it's trailing slash. Signed-off-by: Florian Pritz <bluewind@xinu.at>
2015-08-08Cache/file: Catch unlink exceptionFlorian Pritz1-1/+1
Call delete() which already catches the exception if the file is missing. Signed-off-by: Florian Pritz <bluewind@xinu.at>
2015-05-28Fix error when removing missing entries from file cacheFlorian Pritz1-1/+5
Signed-off-by: Florian Pritz <bluewind@xinu.at>
2014-08-30Merge tag '2.2.0' into workingFlorian Pritz2-8/+9
Signed-off-by: Florian Pritz <bluewind@xinu.at>
2014-07-17Fix comptability with php 5.6Florian Pritz1-1/+2
References: http://ellislab.com/forums/viewthread/244510/#1066558 Signed-off-by: Florian Pritz <bluewind@xinu.at>
2014-06-06Merge remote-tracking branch 'remotes/upstream/2.2-stable' into workingFlorian Pritz118-328/+295
Signed-off-by: Florian Pritz <bluewind@xinu.at> Conflicts: system/libraries/Session.php user_guide/
2014-06-06Update CI_VERSIONAndrey Andreev1-1/+1
2014-06-06Issue #3084Andrey Andreev1-5/+2
2014-06-05Minor style fixes to improve readability in HMAC authenticationQuinn Chrzan1-3/+7
2014-05-31Backport HMAC authentication for CI_SessionAndrey Andreev1-22/+34
2014-05-31Changelog messages, bump year in copyright noticesAndrey Andreev115-212/+195
2014-05-29Removing xor_encode from Encrypt libraryQuinn Chrzan1-62/+15
2014-05-13Fix timing attack on session hashFlorian Pritz1-1/+8
http://seclists.org/fulldisclosure/2014/May/54 Signed-off-by: Florian Pritz <bluewind@xinu.at>
2014-02-27Deleted useless .htaccess file, added missed index.html files.Ender Teszla3-0/+30
2014-01-07Manually apply an improved version of PR #2427Andrey Andreev1-6/+5
2013-12-11Make oci_execute() calls inside num_rows() non-committing. Fixes #696.Aaron Krebs1-2/+2
Fixes bug in Oracle driver. Calls to oci_execute() inside num_rows() of the Oracle driver can be made non-committing to fix bug with transactions. Since calls to oci_execute are only there to reset which row is next in line for oci_fetch() calls, it's fine to not commit.
2013-12-05Fix some spacing issues from PR #2689Andrey Andreev1-9/+4
2013-10-18Revert "Bugfix on the active record join statement with empty conditions"blowdoof1-6/+2
This reverts commit 2cfbfc54dc68d9e7ed7c20af4cf7693736bbd447.
2013-10-18Bugfix on the active record join statement with empty conditionsblowdoof1-2/+6
2013-10-18Bugfix on the sqlsrv forge driver rename_table functionblowdoof1-5/+3
2013-10-18Bugfix on the sqlsrv forge driver create_table functionblowdoof1-11/+9
2013-10-18removed unnecessary assignmentblowdoof1-1/+0
2013-10-18Style correctionblowdoof1-6/+6
2013-10-18Fix on sqlsrv_forge drop_tabletino1-1/+8
2013-10-18Bugfix on truncate commandtino1-1/+1
2013-09-22Merge tag '2.1.4'Florian Pritz5-11/+10
Signed-off-by: Florian Pritz <bluewind@xinu.at> Conflicts: application/config/migration.php user_guide/changelog.html
2013-09-16Remove executable bitsFlorian Pritz130-0/+0
Signed-off-by: Florian Pritz <bluewind@xinu.at>
2013-09-02Allow to override config_item() options; add modification commentsFlorian Pritz2-1/+15
Signed-off-by: Florian Pritz <bluewind@xinu.at>
2013-09-02remove left over security libraryFlorian Pritz1-737/+0
Signed-off-by: Florian Pritz <bluewind@xinu.at>
2013-08-05Suhosin compatible emailsPlamenVasilev1-4/+4
Fix problems with Suhosin and sending emails trough php mail()
2013-07-08Revert "Updating User Guide for 2.1.4."Wes Baker1-1/+1
This reverts commit c5f99fdcc5c4a918b5b8fe3ddbd56ab25ad1c22b. Signed-off-by: Wes Baker <wes@wesbaker.com>
2013-07-08Updating User Guide for 2.1.4.Wes Baker2-2/+2
2013-07-05Added small improvement to the _remove_evil_attributes functionbrian9781-7/+6
Signed-off-by: brian978 <dbrian89@yahoo.com> Signed-off-by: Wes Baker <wes@wesbaker.com> Conflicts: system/core/Security.php
2013-03-15Email library: htmlspecialchars for _header_strmoi901-1/+1
2012-11-05Error on line 1407 of db_active_rec.php traces to mis-named variablesPatrick Zeinert1-1/+1
Corrected variables to $k2 and $v2
2012-10-28Fix language typo in Migrations libraryMichael Brooks1-1/+1
lang and line were out of order
2012-10-08Merge tag '2.1.3'Florian Pritz11-117/+106
Conflicts: user_guide Signed-off-by: Florian Pritz <bluewind@xinu.at>
2012-10-08Really fix #1715Andrey Andreev1-1/+1
2012-10-08Fix issue #1715Andrey Andreev1-4/+4
2012-10-07Bump version number to 2.1.3Andrey Andreev2-3/+3
2012-10-06Backport security fixesAndrey Andreev1-26/+25
2012-10-06Fix issues #227 and #907Andrey Andreev1-32/+31
2012-10-04Backport fix for issue #1699Andrey Andreev1-21/+11
2012-09-05Backport a fix for oci8_result::num_rows()Andrey Andreev1-6/+4
2012-08-01Style fix and changelog entry for pull #1675Andrey Andreev1-1/+1
2012-07-31Fix warning by profiler when userdata has objectsRaul Baldner junior1-1/+1
If session data has objects and profiler is enabled, a warning is trown: > A PHP Error was encountered > Severity: Warning > Message: htmlspecialchars() expects parameter 1 to be string, object given > Filename: libraries/Profiler.php > Line Number: 514
2012-07-24Change is_loaded() to return a referenceAndrey Andreev1-1/+1
2012-07-18Backport fix for issue #1314Andrey Andreev1-2/+5