ChangeLog 253 KB
Newer Older
1
2
3
4
2010-10-18  Xavier Perseguers  <typo3@perseguers.ch>

	* Fixed bug #1318: 'removeTag' does not remove closing tags

5
6
7
8
2010-10-06  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #15898: It is (still) possible to download arbitrary files through the jumpurl feature (thanks to Helmut Hummel and Marcus Krause)

Oliver Hader's avatar
Oliver Hader committed
9
10
11
12
2010-08-06  Oliver Hader  <oliver@typo3.org>

	* Release of TYPO3 4.1.15

13
14
15
16
2010-08-05  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #15282: It is impossible to set links to files any more with the link wizard

17
18
19
2010-08-03  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #15311: t3lib_div::sanitizeLocalUrl() leads to fatal error on PHP4 systems
20
	* Fixed bug #15265: InstallTool-login not possible after Update to 4.4.1 due to session_start() in extensions (thanks to Ernesto Baschny and Helmut Hummel)
21

22
23
24
25
2010-08-02  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #15289: Element-Browser page tree has HSC'ed <span> elements

Oliver Hader's avatar
Oliver Hader committed
26
27
28
2010-07-30  Oliver Hader  <oliver@typo3.org>

	* Reverted fix for bug #15260
29
	* Fixed bug #15263: Clearing caches in backend only displays empty frame
Oliver Hader's avatar
Oliver Hader committed
30

31
32
33
34
2010-07-28  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #15260: Use of undefined method t3lib_div::sanitizeLocalUrl()

Oliver Hader's avatar
Oliver Hader committed
35
36
37
38
2010-07-28  Oliver Hader  <oliver@typo3.org>

	* Release of TYPO3 4.1.14

39
40
41
2010-07-28  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #14978: XSS in file tree (thanks to Georg Ringer)
42
	* Fixed bug #13292: TYPO3 error message reveals path to web root (thanks to Xavier Perseguers)
43
	* Fixed bug #11618: XSS vulnerability in install tool / BE login (thanks to Georg Ringer)
44
	* Fixed bug #13961: XSS in impexp (thanks to Georg Ringer)
45
	* Fixed bug #13960: XSS in sys_action (thanks to Georg Ringer)
46
	* Fixed bug #13958: XSS in BE Log (thanks to Georg Ringer)
47
	* Fixed bug #14317: XSS in Extension Manager (thanks to Georg Ringer)
48
	* Fixed bug #14215: XSS in beuser (thanks to Georg Ringer)
49
	* Fixed bug #12458: Session fixation possibility in new sesion machanism of the install tool (thanks to Benjamin Mack, Helmut Hummel and Ernesto Baschny)
50
	* Fixed bug #12736: XSS in setup module (thanks to Georg Ringer)
51
	* Fixed bug #13989: Mitigate PHP's RNG vulnerability (thanks to Marcus Krause and Helmut Hummel)
52
	* Fixed bug #12739: XSS in shortcuts (thanks to Francois Suter and Georg Ringer)
53
	* Fixed bug #13885: XSS in indexed search BE module (thanks to Benjamin Mack)
54
	* Fixed bug #15254: Extension Manager allows to edit arbitrary files if noEdit flag is not set (thanks to Helmut Hummel)
55
	* Fixed bug #14389: phtml is also PHP extension and should be denied editing / uploading via fileadmin (thanks to Ernesto Baschny)
56
	* Fixed bug #1985: XSS vulnerability in wizard classes
57
	* Fixed bug #14712: The GET/POST variable mimeType is used to create the http header content-type without verification (thanks to Rupert Germann)
58
	* Fixed bug #14412: Field value added to foreign_table_where by replacing ###REC_FIELD_THE_FIELD_NAME### is not quoted (thanks to Helmut Hummel and Xavier Perseguers)
59
	* Fixed bug #14114: Core mailform is open to spam abuse (thanks to Lars Houmark)
60
	* Fixed bug #13137: redirect/returnUrl isn't validated in core (thanks to Georg Ringer and Marcus Krause)
61

62
63
64
2010-05-17  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #13394: Information disclosure in sysext:sys_actions (thanks to Georg Ringer)
65
	* Fixed bug #13042: XSS in index.php (thanks to Georg Ringer)
66
	* Fixed bug #11617: XSS in template module (thanks to Georg Ringer)
67
	* Fixed bug #13249: XSS in TS Object Browser (thanks to Marcus Krause)
68
	* Fixed bug #11621: XSS vulnerabilities in workspace module (thanks to Georg Ringer)
69
	* Fixed bug #11620: XSS vulnerability in task center module (thanks to Georg Ringer)
70
	* Fixed bug #12628: XSS in sysext sys_action (thanks to Georg Ringer)
71
	* Fixed bug #12634: XSS in the access module (thanks to Georg Ringer)
72
	* Fixed bug #13558: XSS in t3lib_querygenerator (thanks to Georg Ringer)
73
	* Fixed bug #12630: XSS in filelist module
74

75
76
77
78
2010-04-09  Michael Stucki  <michael@typo3.org>

	* Fixed bug #13959: Security precaution for extensions which use their own autoloader. Note: This is the same fix which has been committed to TYPO3 4.3 where it is marked as a security fix. However, versions prior to TYPO3 4.3 do not ship with an autoloader, so they are not affected by this problem unless an extension provides its own autoloader.

79
80
81
82
2010-02-24  Ernesto Baschny  <ernst@cron-it.de>

	* Fixed bug #13470: Session/Login not working in IE8 across subdomains 

83
84
85
86
2009-11-30  Steffen Kamper  <info@sk-typo3.de>

	* Fixed bug #12467: TYPO3 Inline User Manual is broken

87
88
89
90
2009-11-17  Rupert Germann  <rupi@gmx.li>

	* Fixed bug #11937: Do not show PHP 5.3 E_DEPRECATED messages on productive systems

91
92
93
94
2009-11-09  Stanislas Rolland  <typo3@sjbr.ca>

	* Follow-up to #11847: htmlArea RTE displays empty editing area in Opera 10

95
96
97
98
2009-11-06  Stanislas Rolland  <typo3@sjbr.ca>

	* Fixed bug #12481: AllowClipboard Helper Firefox extension does not work with FF 3.5

99
100
101
102
2009-10-29  Ernesto Baschny  <ernst@cron-it.de>

	* Fixed bug #12371: Warning issued on first load of install tool with open_basedir set

Oliver Hader's avatar
Oliver Hader committed
103
104
105
106
2009-10-22  Oliver Hader  <oliver@typo3.org>

	* Release of TYPO3 4.1.13

107
108
109
2009-10-22  Ernesto Baschny <ernst@cron-it.de>

	* Fixed bug #11586: Potential SQL injection in frontend editing (thanks to Oliver Klee)
110
	* Fixed bug #12309: It was possible to gain access to the Install Tool by only knowing the md5 hash of the password.
111
	* Fixed bug #12310: Encryption key can be recalculated when using normal mailform when [FE][strictFormmail] == 0 (thanks to Oliver Klee)
112
	* Fixed bug #12090: Filenames should be escaped with escapeshellarg before passing them to imagemagick (thanks to Oliver Klee)
113
	* Fixed bug #12303: XSS vulnerability due to not proper sanitizing in function t3lib_div::quoteJSvalue (thanks to Oliver Klee)
114
	* Fixed bug #12304: Frame inclusion in the backend through alt_mod_frameset (thanks to Oliver Klee)
115
	* Fixed bug #12305: XSS vulnerability in view_help.php / tfID parameter (thanks to Oliver Klee)
116
	* Fixed bug #12306: XSS vulnerability in module dispatcher
117
	* Fixed bug #12307: XSS vulnerability in alt_palette (thanks to Oliver Klee)
118
	* Fixed bug #12308: XSS vulnerability in "DB > Full search" functionality
119
	* Fixed bug #10501: XSS vulnerability in the install tool (thanks to Oliver Klee)
120

121
122
123
124
2009-10-21  Rupert Germann  <rupi@gmx.li>

	* Fixed bug #12300 (Follow-up to 11995): Output compression breaks prompt for keyboard input in CLI scripts

125
126
127
128
2009-10-11  Rupert Germann  <rupi@gmx.li>

	* Fixed bug #10971: Fatal error in impexp module: Call to a member function includeLLFile() on a non-object (thanks to Andre Steiling)

129
130
131
132
2009-09-29  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #11433: touch(): Utime failed in install tool (thanks to Steffen Gebert)

133
134
135
136
2009-09-20  Francois Suter  <francois@typo3.org>

	* Fixed bug #11995: Prompt for keyboard input does not get displayed in CLI scripts

137
138
139
140
2009-09-17  Rupert Germann  <rupi@gmx.li>

	* Fixed bug #9270: Editors can´t undelete records in history (thanks to Christian Hernmarck)

141
142
143
2009-09-15  Stanislas Rolland  <typo3@sjbr.ca>

	* Updated htmlArea RTE version to 1.5.10
144
	* Follow-up to bug #11946: htmlArea RTE: reference was made to context menu item after context menu was closed
145

146
147
148
2009-09-13  Stanislas Rolland  <typo3@sjbr.ca>

	* Fixed bug #11847: htmlArea RTE displays empty editing area in Opera 10
149
	* Fixed bug #11946: htmlArea RTE: table properties editing dialogue windows loose focus after opening in IE8
150

151
152
153
154
2009-08-28  Michael Stucki  <michael@typo3.org>

	* Fixed bug #11731: ENABLE_INSTALL_TOOL file check in yellow box does not check the file age (thanks to Moreno Feltscher)

Michael Stucki's avatar
Michael Stucki committed
155
156
157
2009-07-03  Michael Stucki  <michael@typo3.org>

	* Release of TYPO3 4.1.12
158
159
	* Follow-up to issue #11391: Backport of the admin button was only half-way finished, in fact it was never visible due to a missing variable

160
161
162
163
2009-07-03  Oliver Hader  <oliver@typo3.org>

	* Fixed issue #10656: htmlArea RTE: Initialization fails in presence of Firefox extension Ant.com Toolbar 1.3 (patch by Stanislas Rolland)

Ingmar Schlecht's avatar
Ingmar Schlecht committed
164
165
166
167
2009-07-02  Ingmar Schlecht  <ingmar@typo3.org>

	* Release of TYPO3 4.1.11

168
169
170
171
2009-07-01  Stanislas Rolland  <typo3@sjbr.ca>

	* Follow-up to issue #11009: External links get prepended with base url in RTE htmlArea in Firefox 3.0.11/3.5b4

172
173
2009-06-29  Michael Stucki  <michael@typo3.org>

Michael Stucki's avatar
Michael Stucki committed
174
	* Added feature #11391: Add a button to let admins create the file ENABLE_INSTALL_TOOL from the backend (since it is automatically removed after 1 hour since this version) - thanks to Steffen Kamper who wrote this code!
175

176
177
178
179
2009-06-28  Benjamin Mack  <benni@typo3.org>

	* Fixed #10136: tslib_pibase page browser may hurt search engines by the incorrect "Next" link (On behalf of Dmitry Dulepov)

180
181
2009-06-23  Michael Stucki  <michael@typo3.org>

182
	* Fixed bug #11369: jumpUrl should only allow files matching fileDenyPattern (thanks to Ingmar Schlecht)
183
184
	* Fixed bug #11368: Ignore ENABLE_INSTALL_TOOL file if it is older than one hour

185
186
187
188
2009-05-18  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #11009: External Links get prepended with http://typo3 in the RTEhtmlarea in Firefox 3.0.11/3.5b4

189
190
191
192
2009-05-16  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #10165: FlexForms: wrong mm-relations after copy and localize (thanks to Peter Kuehn)

193
194
195
196
2009-05-08  Steffen Kamper  <info@sk-typo3.de>

	* Fixed bug #11040: ENGINE modifier in ext_tables.sql cannot be parsed

197
198
2009-04-24  Christian Kuhn  <lolli@schwarzbu.ch>

Christian Kuhn's avatar
Christian Kuhn committed
199
	* Fixed bug #10977: Copyright in TYPO3 comment still 2006 (Thanks to Johannes Feustel)
200

201
202
203
204
2009-04-21  Patrick Broens  <patrick@patrickbroens.nl>

	* Fixed bug #10939: Wrong nesting of <ul> <li> tags in expanded mount root in module file > filelist

205
206
207
208
2009-04-09  Stanislas Rolland  <typo3@sjbr.ca>

	* Follow-up for issue #10844: htmlArea RTE: IE8 creates erroneous ranges when selection is empty

209
210
211
212
2009-04-08  Christian Kuhn  <lolli@schwarzbu.ch>

	* Fixed bug #10266: No user authentication for >1 TYPO3 installation under one domain (Thanks to Marcus Krause)

213
214
215
2009-04-06  Stanislas Rolland  <typo3@sjbr.ca>

	* Fixed issue #10834: htmlArea RTE: IE8 now uses standard name for DOM class attribute
216
	* Updated htmlArea RTE version to 1.5.8 for TYPO3 4.1.11
217
	* Fixed issue #10837: htmlArea RTE: IE8 reports unknown "complete" attribute on img nodes
218
	* Fixed bug #10844: htmlArea RTE: IE8 creates erroneous ranges when selection is empty
219

220
221
222
223
2009-04-03  Ingo Renner  <ingo@typo3.org>

	* Fixed bug #10838: t3lib_cs->utf8_decode() does not check whether the target charset is utf8

224
225
226
227
2009-03-31  Benjamin Mack  <benni@typo3.org>

	* Fixed bug #10567: Added IE8+ support / Get rid of browser version dependent t3lib_div::clientInfo() (Thanks to Steffen Gebert)

228
229
2009-03-23  Jeff Segars  <jeff@webempoweredchurch.org>

230
	* Fixed bug #10410: Generation of encryption key does not work in IE7 (thanks to Steffen Mueller)
231

232
233
234
235
2009-02-27  Michael Stucki  <michael@typo3.org>

	* Follow-up to #10083: Constant styles.content.imgtext.separateRows has a wrong default value. This was changed accidentally during a bugfix on 2009-01-09. Reverting back to the old bahaviour (4.1.7 and before). Thanks to Adrian Fischer for pointing this out!

236
237
238
2009-02-27  Francois Suter  <francois@typo3.org>

	* Fixed bug #10313: Fileadmin-module wrongly allows creation of trailing dot directories on UTF8 FS (Thanks to Steffen Gebert)
239
	* Fixed bug #10417: Remove debugging code from sysext t3skin (thanks to Markus Krause)
240

Michael Stucki's avatar
Michael Stucki committed
241
242
243
2009-02-10  Michael Stucki  <michael@typo3.org>

	* Release of TYPO3 4.1.10
244
	* Fixed bug #10364: Jumpurl feature allows to access arbitrary files on a server (thanks to the TYPO3 Security Team and especially Marcus Krause)
245
	* Fixed bug #10298: Various XSS issues in the BE user admin module (thanks to Jelmer de Hen and Dmitry Dulepov)
246

247
248
249
250
2009-02-05  Francois Suter  <francois@typo3.org>

	* Fixed bug #10346: l10n_display option abusively hides field for "All" languages when set to defaultAsReadonly

251
252
253
254
2009-02-05  Benjamin Mack  <benni@typo3.org>

	* Fixed bug #9266: Bug: strcmp() with array as parameter in t3lib_div::linkThisScript() produces warnings with PHP 5.3 (Thanks to Niels Pardon)

255
256
257
258
2009-02-03  Francois Suter  <francois@typo3.org>

	* Fixed bug #1527: t3lib_svbase: Method init returns wrong value  (thanks to Stefano Kowalke and Michael Miousse)

259
260
2009-01-30  Benjamin Mack  <benni@typo3.org>

261
	* Fixed bug #7123: Select wizard doesn't work in Safari (Thanks to Ismael Bidau)
262

Ingmar Schlecht's avatar
Ingmar Schlecht committed
263
264
265
266
2009-01-24  Ingmar Schlecht  <ingmar@typo3.org>

	* Release of TYPO3 4.1.9

267
268
269
270
2009-01-24  Ingmar Schlecht  <ingmar@typo3.org>

	* Fixed bug #10205: DB session record is only created when user is authenticated (thanks also to Michael Stucki)

271
272
273
274
2009-01-22  Michael Stucki  <michael@typo3.org>

	* Improvement to bugfix #10218: Quote the match-word properly

275
276
2009-01-18  Francois Suter  <francois@typo3.org>

277
	* Fixed bug #10218: For fixing bug #10143 the function str_ireplace was introduced, which does not exist in PHP4 (thanks to Helmut Hummel)
278

279
280
281
282
2009-01-21  Steffen Kamper  <info@sk-typo3.de>

	* Fixed bug #10214: md5's second argument is only valid for PHP5 (thanks to Marcus Krause)

283
284
285
286
2009-01-21  Ingo Renner  <ingo@typo3.org>

	* Fixed bug #10204: PHP error due to "public static" keywords in PHP4 in t3lib_div::generateRandomBytes() (thanks to Marcus Krause)

Ingmar Schlecht's avatar
Ingmar Schlecht committed
287
288
289
290
2009-01-20  Ingmar Schlecht  <ingmar@typo3.org>

	* Release of TYPO3 4.1.8

291
292
293
2009-01-20  Ingmar Schlecht  <ingmar@typo3.org>

	* Fixed bug #10146: Session fixation vulnerability in user authentication (thanks to the TYPO3 Security Team and especially Marcus Krause)
294
	* Fixed bug #10159: XSS vulnerability in workspace module (thanks to the TYPO3 Security Team and especially Marcus Krause)
295

296
297
298
2009-01-20  Ingo Renner  <ingo@typo3.org>

	* Fixed bug #10134: XSS vulnerability in sysext indexed_search (thanks to the TYPO3 Security Team and especially Marcus Krause)
299
	* Fixed bug #10133: Command execution in sysext indexed_search (thanks to the TYPO3 Security Team and especially Marcus Krause)
300
	* Fixed bug #10154: Weak encryption key generation vulnerability in sysext install (thanks to the TYPO3 Security Team, and especially Marcus Krause)
301

302
303
2009-01-18  Francois Suter  <francois@typo3.org>

304
	* Cleanup #10125: Replace deprecated function calls in sysext indexed_search (thanks to Markus Krause)
305

306
307
308
309
2009-01-17  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #7677: Constants are not correctly substituted on some PHP5 distributions

Oliver Hader's avatar
Oliver Hader committed
310
2009-01-16  Steffen Kamper  <info@sk-typo3.de>
311
312
313

	* Fixed bug #10157: t3lib/config_default.php textfile_ext should be updated to include xml and other text types

Oliver Hader's avatar
Oliver Hader committed
314
2009-01-14  Steffen Kamper  <info@sk-typo3.de>
315
316
317

	* Fixed bug #10143 spamProtectEmailAddresses_atSubst does not work correctly if linktext contains email address with uppercase charachters (thanks to Helmut Hummel)

318
319
2009-01-14  Dmitry Dulepov  <dmitry@typo3.org>

Oliver Hader's avatar
Oliver Hader committed
320
	* Fixed bug #10116: Remove/protect adodb testfiles (thanks to Marcus Krause)
321

322
323
324
2009-01-13  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #10109: Google reports duplicate title tag
325
	* Fixed bug #10120: Add .buildpath to svn:ignore
326

Oliver Hader's avatar
Oliver Hader committed
327
2009-01-12  Steffen Kamper  <info@sk-typo3.de>
328
329

	* Fixed bug #7265: Submodules of Web module can't work with mod.php and the _DISPATCH system
330

331
332
333
334
2009-01-09  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #10083: Constant styles.content.imgtext.separateRows is not defined

335
336
337
338
2009-01-08  Benjamin Mack  <benni@typo3.org>

	* Fixed bug #9194: Bug: wrong handling of 'is_in' list in TCA element type 'input' (Thanks to Vladimir Podkovanov)

Oliver Hader's avatar
Oliver Hader committed
339
2009-01-05  Steffen Kamper  <info@sk-typo3.de>
340

Oliver Hader's avatar
Oliver Hader committed
341
	* Fixed bug #10055: Add contrib directory to list of allowed paths (thanks to Dan Osipov)
342
	* Fixed bug #10056: Misspelling english word "guesbooks"
343

344
345
346
347
2009-01-03  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #10047: typo3/contrib is not prefixed with config.absRefPrefix

348
349
350
351
2009-01-01  Benjamin Mack  <benni@typo3.org>

	* Fixed bug #8361: Stage change notification emails not send when publishing from Live workspace (Thanks to Andreas Wolf)

352
353
354
355
2008-12-25  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #10012: TYPO3 generates incorrect ETag

356
357
358
359
2008-12-23  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #9999: Setting [BE][compressionLevel]=true causes problems

360
361
362
363
2008-12-22  Steffen Kamper  <info@sk-typo3.de>

	* Fixed bug #9977: Extensions class.ext_update.php scripts are executed even when extension isn't loaded

364
365
366
2008-12-20  Steffen Kamper  <info@sk-typo3.de>

	* Fixed bug #8952: Flags are missing
Oliver Hader's avatar
Oliver Hader committed
367
368
369
	* Fixed bug #8525: added Korean flag
	* Fixed bug #5628: added Slovak flag

370
371
372
2008-12-18  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #9947: gzip compression does not work in BE at all
373
	* Fixed bug #9741: wrong anchor links with absRefPrefix option enabled (thanks to Stefan Galinski)
374

375
376
377
378
2008-12-11  Steffen Kamper  <info@sk-typo3.de>

	* Fixed bug #9836: RTE TSconfig lost when uploading files or creating folders

379
380
2008-12-09  Steffen Kamper  <info@sk-typo3.de>

Oliver Hader's avatar
Oliver Hader committed
381
	* Fixed bug #9915: Typing error in tslib_content ($gifCreateor => $gifCreator)
382

Martin Kutschker's avatar
Martin Kutschker committed
383
2008-12-03  Martin Kutschker  <masi@typo3.org>
384
385
386

	* Fixed bug #6415: preg_replace error on PHP 5.2 sometimes resulting in empty pages (thanks to Francois Suter)

387
388
389
390
2008-12-01  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #9790: class.gzip_encode.php fails with open_basedir restrictions

391
392
393
394
2008-11-27  Dmitry Dulepov  <dmitry.dulepov@gmail.com>

	* Fixed bug #8944: PHP-Error in class.em_index.php on line 4333

395
396
397
398
2008-11-22  Steffen Kamper  <info@sk-typo3.de>

	* Fixed bug #9798: Don't show fe_users password in page module

399
400
401
2008-11-01  Oliver Hader  <oliver@typo3.org>

	* Follow-up to bug #9664: t3lib_div::strtolower() is not implemented (thanks to Marcus Krause)
402
	* Fixed bug #9632: Multiple fileuploads into folders with special characters (umlauts) not possible (thanks to Marcus Krause)
403

404
405
406
407
2008-10-31  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #9659: TCEmain wrongly tests required input-type fields (thanks to Francois Suter)

408
409
410
411
2008-10-28  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #9664: EM fails on retrieving files of uppercase extension keys (thanks to Marcus Krause)

412
413
414
2008-10-21  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #9553: Form validation script jsfunc.validateform.js sometimes fails in IE (thanks to Vladimir Podkovanov)
415
416
417

2008-10-14  Martin Kutschker  <masi@typo3.org>

418
	* Fixed bug #9501: Titles of content columns in classic page module doesn't take into account backend charset (thanx to Steffen Kamper and Vladimir Podkovanov)
419

420
421
422
423
2008-10-10  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #9522: t3lib_BEfunc::BEenableFields generates invalid SQL

424
425
426
427
2008-10-04  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #9479: Selected items are not visible after saving the form in BE

428
429
430
431
2008-09-20  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #9384: FE session hijacking

432
2008-09-18  Martin Kutschker  <martin.t.kutschker@blackbox.net>
433
434
435

	Fixed bug #8588: Admin tools -> User Admin -> List users online broken when [BE][lockIP] is set to < 4

436
437
438
439
2008-09-10  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #9315: Description of tslib_fe::includeTCA is incorrect

440
441
2008-09-09  Dmitry Dulepov  <dmitry@typo3.org>

Oliver Hader's avatar
Oliver Hader committed
442
	* Fixed bug #9268: TCA is not loaded in FE when config cache is disabled
443

444
445
446
447
2008-09-08  Stanislas Rolland  <typo3@sjbr.ca>

	* Fixed bug #3546: htmlArea RTE: wrong charset used by mb_regex in spell checker

448
449
450
451
2008-09-01  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #9249: Misspelling in Install tool (thanks to Christian Kuhn)

452
453
454
455
456
2008-08-25  Stanislas Rolland  <typo3@sjbr.ca>

	* Fixed issue #9196: In htmlArea RTE, unable to create an external URL containing german umlauts
	* Updated htmlArea RTE version to 1.5.7 for TYPO3 4.1.8

457
458
459
460
2008-08-21  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #8826: calls to ini_set produces warnings

461
462
463
464
2008-08-20  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #5205: pi_loadLL() + no language file == full path disclosure

Dmitry Dulepov's avatar
Dmitry Dulepov committed
465
2008-08-18  Dmitry Dulepov  <dmitry@typo3.org>
466
467

	* Fixed bug #9141: Update Wizard uses wrong scheme to write compat_version to localconf.php
468
	* Fixed bug #9152: Deprecated code into stdgraphic
469

470
471
472
473
2008-08-11  Ingo Renner  <ingo@typo3.org>

	* Reverted Change from 2008-08-06 in t3lib_div leading to nonfunctional clipboard

474
475
476
2008-08-06  Ingo Renner  <ingo@typo3.org>

	* Fixed bug: PHP 5.3 throws a warning in class.t3lib_befunc.php on line 3348: trim() expects parameter 1 to be string, array given
477
478
	* Fixed bug: PHP 5.3 throws a deprecation warning in typo3/mod/tools/em/class.em_soap.php on lines 108, 112, 115, 213, 218: Assigning the return value of new by reference is deprecated
	* Fixed bug: PHP 5.3 throws a warning in class.t3lib_div.php on line 3286: strcmp() expects parameter 1 to be string, array given
479

480
2008-08-05  Dmitry Dulepov  <dmitry@typo3.org>
481

Oliver Hader's avatar
Oliver Hader committed
482
	* Fixed bug #6992: t3ib_refindex requires t3lib_BEfunc but does not include it
483

484
485
486
2008-08-01  Benjamin Mack  <benni@typo3.org>

	* Fixed bug #9099: Wrong path to pages.gif in linkbrowser (Thanks to Xander Damen)
487
488
489
490
491

2008-07-30  Martin Kutschker  <martin.t.kutschker@blackbox.net>

	* Fixed bug #9076: iso-ir-109 detected as iso-8859-2 instead of iso-8859-3

492
493
2008-07-23  Dmitry Dulepov  <dmitry@typo3.org>

Oliver Hader's avatar
Oliver Hader committed
494
	* Changed LICENSE.txt to reference GPL "version 2 or later"
495

496
497
498
2008-07-14  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #8566: Unable to match TS condition when variable is not set
499

500
501
502
503
2008-07-13  Martin Kutschker  <martin.t.kutschker@blackbox.net>

	* Fixed bug #5476: links entered in <th>-tag with the RTE are not parsed on the frontend because parseFunc doesn't recognize <th> as cells (thanks to Daniel Ellermann)

504
505
2008-07-12  Martin Kutschker  <martin.t.kutschker@blackbox.net>

506
	* Fixed bug #8922: setStage operation of t3lib_TCAmain::process_cmdmap() overwrites $id parameter making it inaccessible for post-processing hooks
507

508
509
2008-07-07  Ernesto Baschny  <ernst@cron-it.de>

510
	* Fixed bug #8703: More Options>Access wasn't being shown in the pages click-menus (Thanks to Andreas Wagner)
511

512
513
514
2008-07-03  Ernesto Baschny  <ernst@cron-it.de>

	* Fixed bug #7711: Element browser ignores "Hide in menu" flag (Thanks to Christian Kuhn)
515
	* Fixed bug #8840: Wrong title of edit icon of "Include basis template" section when editing template records (Thanks to Christian Kuhn)
516

517
518
519
520
2008-06-22  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #8724: getElementsByClassName does not work properly in Firefox 3 and Safari 3.1 (thanks to Helmut Hummel)

521
522
523
524
2008-06-13  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #8239: Wrong parameter order for strpos in t3lib_div::getHostname

Michael Stucki's avatar
Michael Stucki committed
525
526
527
528
529
2008-06-11  Michael Stucki  <michael@typo3.org>

	* Release of TYPO3 4.1.7
	* (security) Fixed a low-severity Cross Site Scripting issue in fe_adminLib.inc. For details, see http://typo3.org/teams/security/security-bulletins/typo3-20080611-1/ - thanks to Christian Seifert, Jeroen van Iddekinge and Arnd Messer for discovering and reporting this issue.

530
531
532
533
2008-06-11  Ingo Renner  <ingo@typo3.org>

	* Fixed bug #7646: Firefox 3.0 mixes up frames (versions before TYPO3 4.2)

534
535
2008-06-11  Ingmar Schlecht  <ingmar@typo3.org>

536
	* Fixed bug #8674: Vulnerability of security bulletin typo3-20080611-1: Default value of fileDenyPattern allows arbitrary code execution on Apache (Patch by Henning Pingel, thanks!)
537

538
539
540
2008-06-06  Ernesto Baschny  <ernst@cron-it.de>

	* Fixed bug #8362: Duplicate entry for [tstamp] and [crdate] in Web->List module for single table in selector-box (thanks to Steffen Kamper)
541
	* Fixed bug #8279: Sorting in fields of type "group", "MM=1" and "multiple=1" was not preserved
542

543
544
545
546
2008-06-05  Benjamin Mack  <benni@typo3.org>

	* Fixed bug #2905: t3skin - Styling of (non-dyn) tab menus is bad

547
548
549
550
2008-05-25  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #4455: pid reset to 10000 in Constant Editor

551
552
2008-05-16  Dmitry Dulepov  <dmitry@typo3.org>

Oliver Hader's avatar
Oliver Hader committed
553
	* Fixed bug #8192: typoLink generates wrong links
554

555
556
557
2008-05-15  Stanislas Rolland  <typo3@sjbr.ca>

	* Fixed bug #8346: rtehtmlarea from TYPO3 4.1.6 does not work with Firefox 3 Beta 5
558
	* Updated htmlArea RTE version to 1.5.6 for TYPO3 4.1.7
559
	* Fixed bug #8431: Incorrect handling of links by htmlaArea RTE in TYPO3 4.1.6 and Firefox 3
560

561
562
563
564
2008-04-22  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #8148: IRRE - Expanded or collapsed state of new child records is not handled correctly

565
566
567
2008-04-22  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #8040: Bug: Wrong check on creating folders in filelist makes them unaccessible (thanks to Moreno Feltscher)
568
569
570
571
572

2008-04-16  Martin Kutschker  <martin.t.kutschker@blackbox.net>

	* Fixed bug #4186 (correction): cropping didn't work for IM4/5 and GM (thanks to Helmut Hummel)

573
574
2008-04-11  Dmitry Dulepov  <dmitry@typo3.org>

575
	* Fixed bug #8078: enhance debug stack trace reporting
576

577
578
579
580
2008-04-12  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #8064: Split does not work with returnKey = 0 (thanks to Dirk Weise)

581
582
583
584
2008-04-09  Jeff Segars  <jeff@webempoweredchurch.org>

	* Fixed bug #6873: Missing icon for not in menu, access-restricted pages

585
586
587
588
2008-04-07  Dmitry Dulepov  <dmitry@typo3.org>

	* Rolled back last three bugfixes because they are seen as new feature and may not appear in maintenace release

589
590
591
592
593
594
2008-04-07  Dmitry Dulepov  <dmitry@typo3.org>

	* Fixed bug #8005: Linking across domains does not work with nested domains
	* Fixed bug #7839: Linking between domains in the pagetree with checkRootline does not work with menus
	* Fixed bug #3491: Linking between domains in the pagetree ignores simulate static documents

595
596
597
598
2008-04-06  Stanislas Rolland  <typo3@sjbr.ca>

	* Fixed bug #7992: rtehtmlarea does not work with Firefox 3 Beta 5

599
600
601
2008-04-03  Ingmar Schlecht  <ingmar@typo3.org>

	* Fixed bug #4575: Changes in alternative page language does not clear cache
602
	* Fixed bug #4768: Missing is_array() check in tslib_fe::getStorageSiterootPids()
603

604
605
606
607
2008-03-31  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #7759: XCLASSing USER_INT objects does not work

608
609
610
611
2008-03-26  Stanislas Rolland  <typo3@sjbr.ca>

	* Fixed bug #7864: htmlArea RTE drag & drop imagebrowser does not work correctly in IE in TYPO3 4.1

612
613
614
615
2008-03-21  Ingmar Schlecht  <ingmar@typo3.org>

	* Fixed bug #7850: error in publish.php if errors in TCE should be shown (thanks to Daniel Pötzinger)

616
617
2008-03-20  Dmitry Dulepov  <dmitry@typo3.org>

618
	* Fixed bug #6907: "Conflicts" check ignores version
619

620
621
2008-03-17  Oliver Hader  <oliver@typo3.org>

Oliver Hader's avatar
Oliver Hader committed
622
	* Fixed bug #4186: GIFBUILDER cropsized images have bad quality (thanks to Steffen Kamper)
623

624
625
626
627
2008-03-12  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #7724: Copying of sysfolders or pages with entries connected via mm database entries fail (thanks to Niels Pardon)

628
629
630
631
2008-03-08  Oliver Hader  <oliver@typo3.org>

	* Fixed bug #7511: IRRE - Issues with expand/collapse of child records

Ingmar Schlecht's avatar
Ingmar Schlecht committed
632
633
634
635
2008-03-03  Ingmar Schlecht  <ingmar@typo3.org>

	* Release of TYPO3 4.1.6

Michael Stucki's avatar
   
Michael Stucki committed
636
637
638
2008-03-03  Michael Stucki  <michael@typo3.org>

	* Fixed bug #6663: Unserialized objects not debugged properly (patch by Francois Suter)
639
640
641
642
643

2008-03-01  Martin Kutschker  <martin.t.kutschker@blackbox.net>

	* Fixed bug #5838: cli_dispatch.phpsh doesn't work on windows platforms

644
645
2008-02-28  Oliver Hader  <oh@inpublica.de>

Oliver Hader's avatar
Oliver Hader committed
646
647
	* Fixed bug #5252: Pages with "Hide in menu" checked use normal page icon in list module (Thanks to Andreas Wagner)
	* Fixed bug #7693: New page wizard ignores "hide in menu" flag for page icons (Thanks to Christian Kuhn)
648

649
650
2008-02-26  Oliver Hader  <oh@inpublica.de>

651
	* Fixed bug #7523: Description of properties is missing in install tool (Thanks to Steffen Kamper)
652

653
654
655
656
2008-02-23  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #6885: Nested USER_INT, COA_INT, etc. objects are not rendered

657
658
659
660
661
2008-02-22  Benjamin Mack  <mack@xnos.org>

	* Fixed bug #7445: Malformed translated locallang causes PHP crash (Thanks to Francois Suter)

2008-02-22  Ingmar Schlecht  <ingmar@typo3.org>
662
663

	* Fixed bug #7158: DBAL fixes to Indexed Search backend module (Thanks to Moreno Feltscher)
664

665
2008-02-17  Martin Kutschker  <martin.t.kutschker@blackbox.net>
666

667
	* Fixed bug #5693: options.additionalPreviewLanguages is showing wrong records for table pages (Thanks to Helmut Hummel)
668

669
670
2008-02-16  Benjamin Mack  <mack@xnos.org>

671
	* Fixed bug #5303: t3skin - pilup.gif not the same style as pildown.gif
672
673
	* Fixed bug #7454: Category Treeview in BE-Forms has gap between 2 lines (Thanks to Stefan Geith)

674
675
676
2008-02-04  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #7029: tslib_cObj uses deprecated function call_user_method
677
	* Fixed bug #7371: Query generator does not accept dates in where condition
678

679
680
2008-01-31  Jeff Segars  <jeff@webempoweredchurch.org>

681
	* Fixed bug #6902: Add an imagespace to Text w/ Image when image width is not available. Thanks to Georg Ringer.
682

683
684
685
686
2008-01-27  Oliver Hader  <oh@inpublica.de>

	* Fixed bug: Overriding TCA properties with TSconfig does not work with array

687
688
689
690
2008-01-15  Benjamin Mack  <mack@xnos.org>

	* Fixed bug #7148: CSV Export Output in List Module

691
692
693
694
2008-01-15  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #7126: IRRE - Child records are shown floated and not as blocks in Safari

695
696
697
698
2008-01-10  Jeff Segars  <jeff@webempoweredchurch.org>

	* Fixed bug #5421: Problem ignoring extension constraints

699
700
701
702
703
2008-01-08  Benjamin Mack  <mack@xnos.org>

	* Followup for bug #1678: limit to language; made the variable names better (Thanks to Helmut Hummel)

2008-01-06  Oliver Hader  <oh@inpublica.de>
704
705
706

	* Post-cleanup of bug #5994: IRRE - RTEhtmlarea is not show in child records if parent has no RTE

707
708
709
710
2007-12-26  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #6651: IRRE - Button for creating new records disappeared on nested child records if a parent record reached the maxitems value

711
712
713
714
2007-12-21  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #6007: IRRE - Child records with image fields are not shown in m:n disposal

715
716
717
718
2007-12-17  Ingmar Schlecht  <ingmar@typo3.org>

	* Fixed bug #6996: Versioning in clickmenu was unavailable for non-admins due to a problem of an earlier bugfix #4160 (Thanks to Helmut Hummel for the correction)

Ingmar Schlecht's avatar
Ingmar Schlecht committed
719
720
721
722
2007-12-14  Ingmar Schlecht  <ingmar@typo3.org>

	* Release of TYPO3 4.1.5

723
724
2007-12-13  Oliver Hader  <oh@inpublica.de>

Michael Stucki's avatar
   
Michael Stucki committed
725
	* (major) Fixed bug #6924: t3lib_div::readLLXMLfile does not use localized content anymore
726

Ingmar Schlecht's avatar
Ingmar Schlecht committed
727
728
729
730
2007-12-10  Ingmar Schlecht  <ingmar@typo3.org>

	* Release of TYPO3 4.1.4

731
732
2007-12-10  Ingmar Schlecht  <ingmar@typo3.org>

Michael Stucki's avatar
   
Michael Stucki committed
733
	* (security) Fixed a low-severity SQL injection in the modfunc2 of indexed_search (only exploitable by BE users, and severity limited because addslashes() was already applied to the value - yet not within a quoted string) (Thanks to Henning Pingel for finding the issue and Andreas Otto for the fix)
734

735
2007-12-09  Martin Kutschker  <martin.t.kutschker@blackbox.net>
Martin Kutschker's avatar
   
Martin Kutschker committed
736
737

	* Fixed bug #5985: PHP warning in t3lib_div::getUrl when safe_mode or open_basedir is set
Ingmar Schlecht's avatar
Ingmar Schlecht committed
738
	* Fixed bugs with option $includeHeaders in t3lib_div::getUrl: Option $requestHeaders was ignored, it didn't work with https and had a wrong default port for https
Martin Kutschker's avatar
   
Martin Kutschker committed
739

740
741
742
743
2007-12-09  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #5994: IRRE - RTEhtmlarea is not show in child records if parent has no RTE

Martin Kutschker's avatar
   
Martin Kutschker committed
744
2007-12-07  Dmitry Dulepov	<dmitry@typo3.org>
745
746
747

	* Fixed bug #6903: Translated language files are not loaded

748
749
2007-12-06  Benjamin Mack  <mack@xnos.org>

Martin Kutschker's avatar
   
Martin Kutschker committed
750
	* Fixed bug #1678: limit to language; still can delete and move content element (Thanks to Helmut Hummel)
751

752
2007-12-02  Dmitry Dulepov  <dmitry@typo3.org>
753
754
755

	* Fixed bug #6844: DB compare fails

756
757
758
2007-12-04  Jeff Segars  <jeff@webempoweredchurch.org>

	* Fixed bug #6114: t3lib_extMgm::addToAllTCATypes ignores type 0
Michael Stucki's avatar
   
Michael Stucki committed
759

760
761
762
763
2007-11-30  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #5602: spamProtectEmailAddresses_atSubst is not recognized correctly

764
765
766
767
2007-11-24  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #6817: Files with extension xml are ignored as resource of a template

768
769
770
771
2007-11-23  Ernesto Baschny  <ernst@cron-it.de>

	* Fixed bug #6240: pageNotFound_handling returns empty page if specified URL cannot be retrieved. Credit to Helmut Hummel for the fix.

772
773
774
775
2007-11-23  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #5956: TCA eval required on date field does not work

776
777
2007-11-09  Benjamin Mack  <mack@xnos.org>

778
	* Fixed image generation bug: Call in t3lib_div now uses the IM wrapper to render gifs/pngs
779

780
781
782
2007-11-07  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #5772: IRRE - Combination mode doesn't save new child records correctly
783
	* Fixed bug #6456: IRRE - Palettes are not rendered correctly on nesting records using the same table
784

785
786
787
788
2007-11-02  Ingmar Schlecht  <ingmar@typo3.org>

	* Bug #6561 revised: Registers IMAGE_NUM and IMAGE_NUM_CURRENT contained incorrect array indizes (Thanks to Helmut Hummel)

789
790
791
792
2007-11-02  Stanislas Rolland  <stanislas.rolland@fructifor.ca>

	* Fixed bug 6640: htmlArea RTE tool bar is not updated in IE when up or down arrow is pressed

793
794
795
796
797
2007-11-01  Stanislas Rolland  <stanislas.rolland@fructifor.ca>

	* Fixed bug 6476: htmlArea RTE incorrectly nests tags on return key in FF
	* Update version number of rtehtmlarea to 1.5.5

798
799
800
801
802
803
2007-10-30  Jeff Segars  <jeff@webempoweredchurch.org>

	* Fixed bug #6618: Web->List: Add title to versioning symbol in extended view	(Thanks to Christian Kuhn)

2007-10-29  Jeff Segars  <jeff@webempoweredchurch.org>

804
805
	* Fixed bug #5338: Error installing suggested extensions

806
2007-10-29  Dmitry Dulepov  <dmitry@typo3.org>
807
808
809
810
811
812

	* Fixed bug #6581: Fatal error in TCEForms: Fatal error: Cannot use string offset as an array
	* Fixed bug #6565: T3DataStructure with sheet references will not show sheetTitle,sheetDescription and sheetShortDescr
	* Fixed bug #5347: Flexforms dosen't resolve sheets
	* Fixed bug #3969: Missing sheets inclusion in flexforms?

813
814
815
2007-10-27  Ingmar Schlecht  <ingmar@typo3.org>

	* Fixed bug #1940: "OPEN DOCUMENTS" causes 404 error (Thanks to Christian Trabold)
816
	* Fixed bug #5082: Clean up a nested htmlspecialchars() in class.db_list_extra.inc (Thanks to Christian Kuhn)
817
	* Fixed bug #6561: imgMax and imgStart (IMGTEXT) not working properly (Thanks to Helmut Hummel)
818

819
820
821
822
2007-10-26  Stanislas Rolland  <stanislas.rolland@fructifor.ca>

	* Fixed bug 5031: htmlArea RTE incorrectly processes col tags and default proc options disallow col and colgroup tags

Ingmar Schlecht's avatar
Ingmar Schlecht committed
823
824
825
826
2007-10-22  Ingmar Schlecht  <ingmar@typo3.org>

	* Release of TYPO3 4.1.3

827
828
829
830
831
2007-10-22  Andreas Otto  <andreas.otto@dkd.de>

	* Fixed bug #6340: JS errors with dividers2tabs and rtehtmlarea

2007-10-21  Thomas Hempel  <thomas@typo3-unleashed.net>
Michael Stucki's avatar
   
Michael Stucki committed
832

833
	* Fixed bug: #6531: Function getUpdateJS doesn't work properly (Thanks to Philip Almeida)
Michael Stucki's avatar
Michael Stucki committed
834
835
	* Fixed bug: #434: Function getUpdateJS produces JS error messages

836
837
2007-10-20  Ingmar Schlecht  <ingmar@typo3.org>

838
839
840
	* Fixed bug #5949: BE-Shortcut to Tools->User Admin returns error. (By Oliver Hader)
	* Fixed bug #6210: UserTSConfig value "options.moduleMenuCollapsable=0" does not work.
	* Fixed bug #6071: Switch to User does not work from context menu in List Module. (Thanks to Christian Kuhn all patches above!)
841
	* Fixed bug #6553: Remove hardcoded strip_tags() from image altText and replacing it with TS stripHtml = 1 (Thanks to Georg Ringer)
842
	* Fixed bug: stdWrap for imgMax is not taken into account. (Thanks to Helmut Hummel)
843

844
845
846
847
2007-10-19  Stanislas Rolland  <stanislas.rolland@fructifor.ca>

	* Fixed bug 6546: Remove htmlArea RTE acronym from Insert-Record object

848
849
850
851
2007-10-17  Michael Stucki  <michael@typo3.org>

	* Fixed bug #6121: Reply-To field in formmails can contain invalid characters if formMailCharset different from site charset (patch by Wolfgang Zenker)

852
853
854
855
2007-10-17  Sebastian Kurfuerst  <sebastian@typo3.org>

	* Fixed bug #6202: Company field is missing for table fe_users in "View Item" (Thanks to Christian Kuhn)

856
857
858
859
2007-10-16  Michael Stucki  <michael@typo3.org>

	* Fixed bug #3552: Fatal error during backend edit

860
861
862
2007-10-16  Stanislas Rolland  <stanislas.rolland@fructifor.ca>

	* Fixed bug 4183: Incorrect display in htmlArea RTE of utf-8 labels for colors, classes and fonts defined in PageTSConfig
863
	* Fixed bug 4525: In htmlArea RTE, disabling personal dictionaries in UserTSConfig not honored
864

865
866
2007-10-15  Stanislas Rolland  <stanislas.rolland@fructifor.ca>

867
868
	* Fixed bug 5855: Missing unlink icon in htmlArea RTE
	* Fixed bug 5839: In htmlArea RTE, paragraph & text dropdown boxes inactive when using @media clause in stylesheet
869
	* Fixed bug 6152: AllowClipboard helper offered by htmlArea RTE doesn't work with 2.0.0.x Firefox
870
	* Fixed bug 6340: rtehtmlarea not working with "Editforms on page" option
871
	* Fixed bug 6152: Nullify default value AllowClipboard helper and use TYPO3-specific Firefox extension
872
	* Update version number of rtehtmlarea to 1.5.4
873

874
875
876
877
878
879
880
881
2007-10-08  Martin Kutschker  <martin.t.kutschker@blackbox.net>

	* Fix bug #6420: access key generation wrong with HTML tags in menu titles (TMENU)

2007-10-07  Martin Kutschker  <martin.t.kutschker@blackbox.net>

	* Fixed bug #5911: GIFBUILDER setting quality not honoured

882
883
884
2007-10-06  Martin Kutschker  <martin.t.kutschker@blackbox.net>

	* Fixed bug #6462: Wrong default locale charset on Windows
885
	* Fixed bug #6252: rteHTMLarea acronyms are not DBAL compatible
886
	* Fixed bug #5189: images with uppercase file extension aren't displayed in drag-n-drop listing
887

888
889
890
891
2007-09-24 Andreas Otto <andreas.otto@dkd.de>

	* Fixed bug #1471: Check if exif functions are available before using them.

892
893
2007-09-18  Oliver Hader  <oh@inpublica.de>

Martin Kutschker's avatar
   
Martin Kutschker committed
894
	* Fixed bug #65: Thumbnails in Element Browser are only displayed if fileSuffix is lowercase
895

896
897
898
2007-09-09  Martin Kutschker  <martin.t.kutschker@blackbox.net>

	* fixed bug 5701: linkHandler Hook Not Initialized Properly , patch supplied by Jeff Segars
899
900
901

2007-09-09  Martin Kutschker  <martin.t.kutschker@blackbox.net>

902
	* Require PHP 4.3 explicitely in init.php
903

904
905
906
907
2007-09-07  Ingmar Schlecht  <ingmar@typo3.org>

	* Bugfix: Highlight root page in pagetree

908
909
910
2007-09-05  Thorsten Kahler  <thorsten.kahler@dkd.de>

	* Fixed bug #4160: Moving content elements in frontent editing mode causes crash
911
	* Disable versioning in clickMenu if BE user doesn't have access to the versioning module
912

913
914
2007-09-03  Oliver Hader  <oh@inpublica.de>

Martin Kutschker's avatar
   
Martin Kutschker committed
915
916
	* Fixed bug #6104: IRRE - IE7: Strange behaviour with hover event of nested Tabs/IRRE-levels with relative positioned HTML elements
	* Fixed bug #5906: IRRE - Default values defined in TCA are not used for children (thanks to Joscha Feth and Jeff Segars)
917

918
919
2007-08-15  Wolfgang Klinger  <wk@plan2.net>

Martin Kutschker's avatar
   
Martin Kutschker committed
920
	* Added is_array checks in extension manager code (committed by Stucki)
921

922
2007-08-23  Dmitry Dulepov  <dmitry@typo3.org>
923
924
925

	* Fixed: hanging recordset in t3lib_BEfunc

926
2007-08-23  Andreas Otto  <andreas.otto@dkd.de>
927

Martin Kutschker's avatar
   
Martin Kutschker committed
928
	* Fixed bug #4888: Invalid argument supplied for foreach()
929

930
931
932
933
2007-08-06  Martin Kutschker  <martin.t.kutschker@blackbox.net>

	* Fixed bug #5941: Log reason of failure on DB connect

Michael Stucki's avatar
   
Michael Stucki committed
934
935
2007-07-16  Michael Stucki  <michael@typo3.org>

Michael Stucki's avatar
Michael Stucki committed
936
	* Release of TYPO3 4.1.2
Michael Stucki's avatar
   
Michael Stucki committed
937
938
939
	* Fixed possible XSS in workspace/version modules (requires valid BE login / patch by Christian Kuhn)
	* Removed possible display of phpinfo() (requires bug in extension to be unveiled)

940
941
942
2007-07-16  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #5556: IRRE - RTE in child elements overwrites field in parent element
943
944
945
946

2007-07-16  Martin Kutschker  <martin.t.kutschker@blackbox.net>

	* Fixed bug #3834: possible abuse of t3lib_formmail
947
	* t3lib_div::getHostname() used $_SERVER instead of t3lib_div::getIndpEnv()
948
	* IPmaskList check is triggered in CLI mode (thanks to Tobias Rohrle)
949

950
951
952
2007-07-14  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #5704: IRRE - Children on the table pages get the pid of the parent page in pagetree
953
	* Fixed bug #5718: IRRE - Copying a page with related child records leads to duplicates of each children
954
	* Fixed bug #5907: RTE-Plugins: Use record specific RTEtsConfigParams
955

956
957
958
2007-07-13  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #5913: RTEhtmlarea not correctly displayed in IRRE child form-fields and tabs (continuance of bug #5177)
959
	* Fixed bug #5948: IRRE - Parent record is not shown after saving the first time to a table on a TYPO3 system
960

961
962
963
2007-07-11  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #5331: Remove the caption wrap on images if no caption is set (thanks to Georg Ringer)
964
	* Fixed bug #5945: Missing right parenthesis in RTEhtmlarea user element module (thanks to Markus Lange)
965

966
967
2007-07-07  Oliver Hader  <oh@inpublica.de>

Oliver Hader's avatar
Oliver Hader committed
968
	* Fixed bug #5053: imgNameNotRandom on TMENU/GMENU could break rollover behaviour (thanks to Ralf Hettinger)
969
	* Fixed bug #5048: JSMENU produces error if using baseurls (thanks to Jens Koester)
970

971
972
973
2007-07-06  Michael Stucki  <michael@typo3.org>

	* Fix in indexed search: List of indexed pages could be broken if mutli-byte chars are cut in the middle (patch by Karsten Dambekalns)
974
	* Fixed bug #5094: Record alt_label was not processed (patch by Volker Graubaum and Thomas Hempel)
975

976
977
978
2007-07-02  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #4623: Content encoding with x-gzip not possible in IE7
979
	* Fixed bug #5789: JS error in new content element wizard with a single item
980

981
982
983
984
2007-06-13  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #5778: Missleading comment in TCEmain::copyRecord_procBasedOnFieldType()

985
986
987
988
2007-06-08  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #5755: XCLASS inclusion part for class.t3lib_tceforms_inline.php is missing

989
990
991
992
2007-06-05  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #4226: New content elements wizard removes CE from array if tt_content_defValues property is zero

993
994
995
996
2007-05-23  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #5564: IRRE - foreign_selector/foreign_unique on click issue

Oliver Hader's avatar
Oliver Hader committed
997
2007-05-21  Dmitry Dulepov  <dmitry@typo3.org>
998
999

	* Added $GLOBALS['TYPO3_DB']->sql_free_result() to TCEmain::recordInfo() to avoid resource waste
1000

Oliver Hader's avatar
Oliver Hader committed
1001
2007-05-18  Martin Kutschker  <martin.t.kutschker@blackbox.net>
1002
1003
1004

	* Fixed bug #5578: config setting SYS[requestURIvar] doesn't work

1005
1006
1007
1008
2007-05-12  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #5074: IRRE - Hook processDatamap_afterDatabaseOperations executed early

1009
1010
2007-05-10  Thorsten Kahler  <thorsten.kahler@dkd.de>

Oliver Hader's avatar
Oliver Hader committed
1011
	* Fixed bug #209: require field URL in page-type "External URL"
1012

1013
1014
1015
1016
2007-05-09  Andreas Otto  <andreas.otto@dkd.de>

	* Fixed bug #2052: Color picker does not work properly in flex forms. Thanks to David Bruehlmeier for providing a patch and a testcase.

1017
1018
1019
2007-05-03  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #5177: RTEhtmlarea not correctly displayed in IRRE child form-fields and tabs
1020
1021
1022

2007-05-01  Martin Kutschker  <martin.t.kutschker@blackbox.net>

Martin Kutschker's avatar
Martin Kutschker committed
1023
	* Fixed bug #2515: jsfunc.validateform.js does not verify password fields (thanks to Joerg Wagner)
1024
	* Fixed bug #5522: 1-2-3 wizard does not accept host name with socket option
1025

Michael Stucki's avatar
Michael Stucki committed
1026
1027
2007-04-28  Andreas Otto  <andreas.otto@dkd.de>

1028
1029
	* Fixed bug #3649: Call to a member function formWidth() on object $GLOBALS['TBE_TEMPLATE'] instead on $GLOBALS['SOBE'].

1030
1031
1032
1033
2007-04-28  Oliver Hader  <oh@inpublica.de>

	* Fixed bug #5519: EM - Some input fields don't have real labels yet (thanks to Oliver Klee)

1034
1035
2007-04-28  Michael Stucki  <michael@typo3.org>

1036
1037
	* Fixed bug in TypoScript object browser: New keys were not added when pressing the return key in the update form instead of clicking the submit button.
	* Fixed bug in class.em_terconnection.php: Need to base64_encode upload data for some NuSOAP implementations (patch by Karsten Dambekalns)
<