5ee643bbbb
Remove non-English language support
2025-04-22 00:05:23 -07:00
Marc Delisle
e2b6af5a99
Avoid showing the password in phpinfo()'s output
2011-11-21 12:41:13 -05:00
Michal Čihař
571cdc6ff4
Pass token along with swekey auth requests
2011-07-11 14:50:44 +02:00
Herman van Rink
e7bb42c002
[security] Fixed possible session manipulation in swekey authentication, see PMASA-2011-12
2011-07-09 23:10:23 +02:00
Herman van Rink
7ebd958b2b
Fixed possible session manipulation in swekey authentication, see PMASA-2011-5
2011-06-30 12:30:58 +02:00
Marc Delisle
99eb0cde32
bug #3308072 [auth] Version disclosure to anonymous visitors
2011-05-30 16:32:29 -04:00
Michal Čihař
adc6de0685
[auth] Fixed error handling for signon auth method.
...
The message is now stored in caller session data and properly displayed
in example script.
2011-05-23 10:33:14 +02:00
Michal Čihař
8fb267930e
bug #3039384 [auth] Force signon auth on signon URL change.
2011-03-18 16:12:16 +01:00
Michal Čihař
d0d236fd62
rfe #2936155 [auth] Allow to pass additional parameters using signon method.
2011-03-02 11:44:57 +01:00
Michal Čihař
cd74e9fa5d
bug #3175227 [auth] Reset user cache on login.
2011-02-08 13:15:01 +01:00
Michal Čihař
5a2835ec86
Readd redirect login to top frame
2011-02-02 11:44:56 +01:00
Michal Čihař
685e199c16
Use standard javascript loading on login page.
2011-02-01 17:52:14 +01:00
Michal Čihař
67e4994490
Single place to handle redirection.
2011-01-31 15:22:25 +01:00
Michal Čihař
dc0c6938b2
[security] Redirect external links to avoid Referer leakage.
2011-01-28 13:22:41 +01:00
Marc Delisle
b923bb3fbb
Upgrade to jQuery 1.4.4
2011-01-02 08:00:25 -05:00
Michal Čihař
d17fba309c
Fix permissions.
...
Most files were made executable somewhere in ninadsp tree, reverting
this.
2010-08-30 09:53:37 +02:00
ninadsp
a2f78a6d38
Resolve merge conflicts for upstream merge
2010-07-29 19:17:25 +05:30
Michal Čihař
6c3ad9e942
Fix back showing login form in frames.
2010-07-26 17:31:56 +02:00
Michal Čihař
d291827444
No need to require_once footer
...
It is the last thing executed anyway (ends with exit).
2010-07-26 16:20:24 +02:00
ninadsp
e646a2760c
Fixed conflict due to upstream merge
2010-07-23 21:59:15 +05:30
Michal Čihař
eeae8bec21
Get rid of inline javascript in login form.
2010-07-21 09:21:58 +02:00
Michal Čihař
3e57a8eca9
No @uses __('Something').
2010-07-20 15:06:34 +02:00
Michal Čihař
318dc4b650
Drop @version tag from docblocks.
2010-07-20 13:59:17 +02:00
ninadsp
bcbf327139
Merge remote branch 'origin/master'
2010-06-29 23:54:01 +05:30
Dieter Adriaenssens
16ed06531a
remove author names
2010-06-28 20:36:12 +02:00
ninadsp
bed1948d04
testing git setup - no major change made in code yet
...
only added a few comments
2010-05-23 01:22:01 +05:30
Marc Delisle
632211d065
gettext conversion
2010-05-09 16:24:32 -04:00
Michal Čihař
ee776a570c
Convert mcrypt warning to generic function.
2010-05-05 11:35:32 +02:00
Marc Delisle
2182098af6
strings to gettext, second batch
2010-05-04 20:07:19 -04:00
Marc Delisle
f55823f47f
strings to gettext, first batch
2010-05-03 12:57:46 -04:00
Michal Čihař
20925728e7
Replace other usages of deprecated split().
2010-04-22 20:21:07 +02:00
Michal Čihař
d659eeaafd
No longer reference non existing message which is inline.
2010-04-19 14:21:36 +02:00
Michal Čihař
71ff89c2fe
Include non minified version in Git.
...
The JS compression will happen on release.
2010-04-13 11:52:33 +02:00
Marc Delisle
7d106d4aa3
missing jQuery on login page (needed by update-location.js
2010-04-01 16:30:59 -04:00
Michal Čihař
5ecbd6941d
Better name for javascript file.
2010-04-01 11:24:38 +02:00
Michal Čihař
7b754395e9
Provide way for vendors to easily change paths to config files.
2010-03-31 12:29:21 +02:00
Michal Čihař
8781e81c5e
Move some messages to places where they belong.
...
This is bascially just test that everything works as expected, much more
messages should follow.
2010-03-11 23:58:38 +01:00
Marc Delisle
819324ede6
remove author names, as discussed at the 2010 developer meeting and according to the book Producing Open Source Software
2010-03-06 18:04:17 +00:00
Marc Delisle
5d96387808
bug #2961609 Potential information disclosure at login page
2010-03-04 13:00:35 +00:00
Marc Delisle
4ad6f11561
patch #2948421 HTTP Basic auth realm name
2010-02-24 16:48:52 +00:00
Michal Čihař
ecc4913a8c
Reenable bookmarking code.
...
Just disable it for webkit based browsers, because they do not allow to
update any part of location without reload.
bug#2937481
2010-01-25 11:50:48 +00:00
Michal Čihař
b6a7def809
Reloading also on login page.
2010-01-22 21:45:49 +00:00
Michal Čihař
bee928cb75
Fix indentation.
2010-01-21 15:29:35 +00:00
Michal Čihař
ebf948d840
Cleare session error message before login.
2010-01-21 15:24:35 +00:00
Michal Čihař
ac9d23f535
rfe #2936156 [auth] Signon authentication forwards error message through session data.
2010-01-21 15:22:34 +00:00
Michal Čihař
94c2f864ae
[core] Remove config data from session as it brings chicken-egg problem.
...
Configuration data stores PmaAbsoluteUri, which should be accessible
before initiating session. Otherwise there is no way to make
PmaAbsoluteUri work. PmaAbsoluteUri is needed at least for reverse
proxy setups, for example http webserver running behind https proxy.
2010-01-21 11:18:18 +00:00
Marc Delisle
e0579f1b9e
bug #2905629 [auth] Blowfish secret is not hashed
2009-11-29 21:36:13 +00:00
Marc Delisle
6a803f65d3
[auth] Add custom port configuration in signon
2009-10-10 11:33:03 +00:00
Herman van Rink
9df074aad3
patch #2665440 Detect mcrypt initialization failure
2009-05-07 07:56:13 +00:00
Marc Delisle
2647ce6a5e
patch #1863739 [auth] cache control missing (PHP-CGI), thanks to stmfd
2009-04-12 12:19:08 +00:00