- 07 Dec, 2011 2 commits
-
-
Benni Mack authored
When editing a translated record in the TCEforms backend, the original language label is shown below, in a green box. The green box is definitively from the old skin (3.x) and should be changed. Change-Id: I9a85f1daac7b41a1a6d1e3cd9663c67abc917c44 Resolves: #28012 Releases: 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/7123 Reviewed-by: Georg Ringer Tested-by: Georg Ringer
-
Georg Ringer authored
Currently explode() is used for pageOverLayFields which requires a list without any whitespaces. Using t3lib_div::trimExplode() improves the usability for integrators and reduces possibilities of not working configurations Change-Id: I65ba837ac2bb8370de6e79e6c7cef820afc9063d Resolves: #28916 Releases: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/7132 Reviewed-by: Georg Ringer Tested-by: Georg Ringer
-
- 29 Nov, 2011 1 commit
-
-
Marco Bresch authored
Fix XSS at column 'workspace membership'. How to test: * choose a workspace title like "<b>test</b>" * assign a user as member to the workspace * select the BE-module "Admin Tools->User Admin" * select the checkbox "Workspace membership" * press update * take a look at column "Workspace membership" Change-Id: I7036eb070d94beb73c539091135b188f588e171d Fixes: #32040 Releases: 4.7, 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/6961 Reviewed-by: Georg Ringer Tested-by: Georg Ringer
-
- 22 Nov, 2011 3 commits
-
-
TYPO3 v4 Release Team authored
Change-Id: I87c8c5c848353c9f0f71a9aaf15f63bd353b8120 Reviewed-on: http://review.typo3.org/6857 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
TYPO3 v4 Release Team authored
Change-Id: I5ff0d2c0a39593d64dc2cd183dc9b5b27fd56ee0 Reviewed-on: http://review.typo3.org/6856 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
TYPO3 v4 Release Team authored
Change-Id: Ia90ea04d65ced0756ce6f6c74e598f48bd234849 Reviewed-on: http://review.typo3.org/6848 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
- 18 Nov, 2011 1 commit
-
-
Francois Suter authored
The date picker in the Admin Tools > Log when selecting a user-defined time range is broken. Adapt it to new skinning API for the JS to act on it properly again. Change-Id: I26e34b312bf411b20bb8671278a6099e45accbe1 Resolves: #31450 Releases: 4.7, 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/6396 Reviewed-by: Tomita Militaru Reviewed-by: Francois Suter Tested-by: Francois Suter
-
- 17 Nov, 2011 1 commit
-
-
Marc Bastian Heinrichs authored
Change-Id: I3c4f9390e13bebfae861565c482877f5563f9442 Resolves: #28835 Releases: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/6697 Reviewed-by: Simon Schaufelberger Reviewed-by: Georg Ringer Tested-by: Georg Ringer Reviewed-by: Dmitry Dulepov Tested-by: Dmitry Dulepov
-
- 09 Nov, 2011 1 commit
-
-
Back ported code from task #31501 breaks the the configuration page of the saltedpasswords extension in EM. Change-Id: Ie2d2a4c4bb8050e6b474095c816af6ae9a2ef555 Fixes: #31501 Relates: #31178 Releases: 4.5, 4.4 Reviewed-on: http://review.typo3.org/6612 Reviewed-by: Steffen Gebert Tested-by: Steffen Gebert
-
- 04 Nov, 2011 1 commit
-
-
Markus Klein authored
The options field is hidden in the BE user form if the user is admin. This is a problem if the admin has assigned groups with db_mounts, as the default value for the options is to mount also the group's mounts, which is undesired for most instances. Change-Id: Ie1931a9531acf073e18548c56d454e958c22b531 Fixes: #30492 Releases: 4.7, 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/6529 Reviewed-by: Markus Klein Tested-by: Markus Klein Reviewed-by: Georg Ringer Tested-by: Georg Ringer
-
- 26 Oct, 2011 1 commit
-
-
Helmut Hummel authored
When registering an extbase backend module, it should be possible to grant permissions to it for users in the access list backend user groups. Add the missing API calls to enable this for extbase modules. Change-Id: Ie856c061da1139f4e9c790ee8a4ce1a88033487f Releases: 4.4 Fixes: #24122 Reviewed-on: http://review.typo3.org/6354 Reviewed-by: Christian Kuhn Tested-by: Christian Kuhn Reviewed-by: Helmut Hummel Tested-by: Helmut Hummel
-
- 24 Oct, 2011 2 commits
-
-
When suggest wizard is used in a form open from the wizard_edit popup wizard, javascript cannot access to "top.TS.PATH_typo3" value. Change-Id: I344001893718ea4c5b2a54b77cc602f76eaa98fd Resolves: #28930 Related: #23789 Releases: 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/6251 Reviewed-by: Xavier Perseguers Tested-by: Xavier Perseguers
-
The Extension Manager shows the results of some checks in the Configuration section of the extension "saltedpasswords", whether "rsaauth" is loaded and whether it is enabled. However, it lacks a check for "rsaauth" being really able to work. If "rsaauth" fails, tell the user that OpenSSL extension is not available or not working correctly. Change-Id: Ie68b0f7dca4ceef9752cec44b1ff651e77f5f1d8 Resolves: #31178 Releases: 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/6268 Reviewed-by: Xavier Perseguers Tested-by: Xavier Perseguers
-
- 23 Oct, 2011 1 commit
-
-
Steffen Gebert authored
Change-Id: If303f704ffa8d5d1a4c9df28c9e4c3759ef9ebfc Resolves: #31062 Releases: 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/6195 Reviewed-by: Steffen Gebert Tested-by: Steffen Gebert
-
- 22 Oct, 2011 1 commit
-
-
Helmut Hummel authored
Checking if the superglobal $_SESSION is an array is not reliable. Change the check to use session_id() which is an empty string if the session has not been started. Change-Id: Iac913beee5af40d28c17ade6a8bfa17df4da2374 Resolves: #30270 Releases: 4.3, 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/6189 Reviewed-by: Helmut Hummel Tested-by: Helmut Hummel
-
- 19 Oct, 2011 1 commit
-
-
Tolleiv Nietsch authored
Commit cf834344 wrongly introduced a debug() statement instead of a call to the deprecationLog() method. Change-Id: I79bad0449509675e3660081ed727799e0ad0353b Resolves: #30759 Branches: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/5697 Reviewed-by: Oliver Hader Tested-by: Oliver Hader Reviewed-by: Oliver Klee Reviewed-by: Tolleiv Nietsch Tested-by: Tolleiv Nietsch
-
- 18 Oct, 2011 1 commit
-
-
Markus Klein authored
Any zero length string value is replaced with the current timestamp. (Just like the default value for the second parameter of date/gmdate.) Change-Id: I0d4cef574028668b0736c8a13db0687f0be62b0e Fixes: #30931 Releases: 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/5971 Reviewed-by: Simon Schaufelberger Tested-by: Simon Schaufelberger Reviewed-by: Jigal van Hemert Tested-by: Jigal van Hemert
-
- 10 Oct, 2011 1 commit
-
-
The copyright year in the HTML comment is hardcoded as 1998-2009. This should be changed to using the constant. Change-Id: Ia4caba20944bec95b0169712fa5f12258e038ec9 Resolves: #30725 Releases: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/5669 Reviewed-by: Xavier Perseguers Tested-by: Xavier Perseguers
-
- 05 Oct, 2011 1 commit
-
-
Andreas Bouche authored
Adds a negative lookahead for trailing slash to the regular Expressions in method "cssFixRelativeUrlPaths" to exclude absolute paths from being rewritten. Change-Id: I1c52b2c4f39a8d4c3316ece0c4ca0284956e4743 Resolves: #29904 Releases: 4.4 Reviewed-on: http://review.typo3.org/5124 Reviewed-by: Dmitry Dulepov Tested-by: Dmitry Dulepov
-
- 04 Oct, 2011 2 commits
-
-
Stanislas Rolland authored
Variable is not initialized leading to incorrect transformation on way to RTE. Change-Id: Iefc0d8368c9b33cb24c701e2277f888104afe7d1 Resolves: #29782 Releases: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/5540 Reviewed-by: Stanislas Rolland Tested-by: Stanislas Rolland
-
Stanislas Rolland authored
Problem: Fixed JS scripts may not be loaded when a new version of TYPO3 is released. This may happen if the version of htmlArea RTE was not incremented. This is an error-prone situation. Solution: Add TYPO3 version to hash of cached scripts Change-Id: Ib340552c094c2284162f7f85c54c5a2f5bc02467 Resolves: #30534 Releases: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/5513 Reviewed-by: Stanislas Rolland Tested-by: Stanislas Rolland
-
- 19 Sep, 2011 1 commit
-
-
Helmut Hummel authored
Because of an information disclosure problem in the backend login we moved the session_start() in t3lib_userauth in a place which caused unwanted side effects with 3rd party extensions. Revert that change to avoid compatibility and performance problems and instead send no cache headers earlier in t3lib_userauth to also fix the information disclosure. Releases: 4.3, 4.4, 4.5, 4.6 Resolves: #29274 Related: #24456, #28694 Change-Id: I87226a21d9b1955773ceb3c377fa1b4c9938e6b2 Reviewed-on: http://review.typo3.org/5071 Reviewed-by: Helmut Hummel Tested-by: Helmut Hummel
-
- 18 Sep, 2011 1 commit
-
-
Sebastian Fischer authored
As in typo3/init.php the TYPO3_mainDir is set to 'typo3/' the replacement in renderForeignRecord could not work because it uses the TYPO3_mainDir . '%2Fajax.php' which results in typo3//ajax.php By this the backpath of the add wizard in IRRE foreign records is fixed. Change-Id: Ia634781269f1329fd79c914dae5e3e6855531a16 Resolves: #29770 Releases: 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/5016 Reviewed-by: Steffen Ritter Tested-by: Steffen Ritter
-
- 14 Sep, 2011 3 commits
-
-
TYPO3 v4 Release Team authored
Change-Id: I79c4d90534b167301a58989f5fe58b7f549f1965 Reviewed-on: http://review.typo3.org/4965 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
TYPO3 v4 Release Team authored
Change-Id: Ie85e0686bb8e92bc3f960976ae723edecf57d098 Reviewed-on: http://review.typo3.org/4964 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
Daniel Pötzinger authored
Change-Id: I6b2d069a61185290ee902d1222d62d6edbb15ffd Releases: 4.6, 4.5, 4.4, 4.3 Resolves: #29366 Reviewed-on: http://review.typo3.org/4943 Reviewed-by: Oliver Hader Tested-by: Oliver Hader
-
- 12 Sep, 2011 1 commit
-
-
Fix a regression, while trying to parse the old time when opening the datepicker would fail on a previously empty datetime field. Add a check for a valid Date object. Change-Id: Ic8580a78d52fb4896dd2d4cbd293e0927ec62166 Resolves: #26674 Relates: #25043 Reviewed-on: http://review.typo3.org/4927 Reviewed-by: Steffen Gebert Tested-by: Steffen Gebert
-
- 09 Sep, 2011 1 commit
-
-
Dmitry Dulepov authored
The fix for #M13740 (revision 3a3a8d81) breaks FE session transfer across top level domains. Method tslib_fe::initFEuser() checks if there is a special URL parameter named FE_SESSION_KEY. If that exists, it sets $_COOKIE[$this->fe_user->name] to the passed session value. This is very useful when using RealURL's feature to make different language domains but use the same user for all domains (multilanguage countries like Switzerland or Belgium love that). However this is broken by using $_SERVER['HTTP_COOKIE'] for FE session cookie. tslib_fe has to be adjusted to set the same cookie. Change-Id: I029c555a35d95895fc9aecf82c6f649df6fd4ca4 Resolves: #27740 Releases: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/3035 Reviewed-by: Stefan Neufeind Reviewed-by: Dmitry Dulepov Tested-by: Dmitry Dulepov
-
- 04 Sep, 2011 1 commit
-
-
Stanislas Rolland authored
Solution: Use same height setting method as for Chrome 7+. Change-Id: I26e1777b8ec5d616d623699b409070e8a3629022 Resolves: #29211 Releases: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/4736 Reviewed-by: Peter Kraume Tested-by: Peter Kraume Reviewed-by: Helmut Hummel Tested-by: Helmut Hummel
-
- 30 Aug, 2011 1 commit
-
-
Stanislas Rolland authored
When all classes allowed on an element have been assigned to a single element, the block/text style selector becomes disabled. It is then not possible to remove the assigned classes from this element. Change-Id: I22db8b9d15214aa9fbbebb636bc8deb9e03b138a Resolves: #27801 Releases: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/4576 Reviewed-by: Stanislas Rolland Tested-by: Stanislas Rolland
-
- 29 Aug, 2011 1 commit
-
-
Markus Klein authored
HTMLparser_tags fixAttrib.unset is documented to be boolean, but is currently treated as string. This patch corrects for the expected behavior. Change-Id: I716580d9a6fa9b5909f53e870afb4029a28598af Resolves: #29246 Releases: 4.6, 4.5, 4.4, 4.3 Reviewed-on: http://review.typo3.org/4645 Reviewed-by: Markus Klein Tested-by: Markus Klein Reviewed-by: Jigal van Hemert Tested-by: Jigal van Hemert
-
- 24 Aug, 2011 1 commit
-
-
Georg Ringer authored
PHPdoc states that return value is either FALSE if something strange happened or integer with the count of records. MySql returns strings, so an intval is needed to have integers Change-Id: Ic831b59eaacaa40124e6688d81cb97a1c0b7fbb1 Resolves: #29169 Releases: 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/4569 Reviewed-by: Susanne Moog Tested-by: Susanne Moog
-
- 21 Aug, 2011 2 commits
-
-
Solution: Avoid wrapping the a tag with span tag when style attribute is set when rteerror attribute is also set. Change-Id: I025670f54fd8e78e8d06b03edf926470f8dce76a Resolves: #25302 Releases: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/4353 Reviewed-by: Christian Kuhn Tested-by: Christian Kuhn
-
Only change the object property to something different than "superchallenged" if the configuration is not set to a "standard" security level. Resolves: #29130 Releases: 4.6, 4.5, 4.4, 4.3 Change-Id: Ibf1194d04a7159ade9ef33701e92930f98cfb90e Reviewed-on: http://review.typo3.org/4454 Reviewed-by: Susanne Moog Tested-by: Susanne Moog Reviewed-by: Christian Kuhn Tested-by: Christian Kuhn
-
- 16 Aug, 2011 2 commits
-
-
TYPO3 v4 Release Team authored
Change-Id: Ie1cba79916ad306fb751ad3dba1ff1641b694980 Reviewed-on: http://review.typo3.org/4367 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
TYPO3 v4 Release Team authored
Change-Id: I501f6fe2ed4de49eabb5a101eb38870e7577dd32 Reviewed-on: http://review.typo3.org/4366 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
- 12 Aug, 2011 2 commits
-
-
Oliver Hader authored
Since security fixes in July 2011 introduced a better encoding of URL arguments, checks in the unit tests have to be modified as well. Change-Id: Ibc958c3c51d0b4f3dacfff3ca1e4638783e1b143 Resolves: #28946 Releases: 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/4286 Reviewed-by: Oliver Hader Tested-by: Oliver Hader
-
Helmut Hummel authored
If the fontTag property is set and the dataWrap property is set to the default value, replace the dataWrap with the fontTag property value and disable insertData on this level (if set). This is to retain compatibility with versions before 4.5.4 while compatibility with modified templates (before and after 4.5.4) is still provided. Change-Id: I6f05005e30c63ec2cf81eed1d9adeeb4f9828e82 Resolves: #28847 Related: #26876 Releases: 4.5, 4.4, 4.3 Reviewed-on: http://review.typo3.org/4282 Reviewed-by: Oliver Hader Tested-by: Oliver Hader Reviewed-by: Michael Stucki Tested-by: Michael Stucki
-
- 11 Aug, 2011 1 commit
-
-
If we want to use Ext.encodeURL() here, we have to change many other things, too. Better use encodeURIComponent() here. Ext.encodeURL() was introduced with #25350. Change-Id: Ie4500ae8a60322262aafa15f66ba532e2a16c31b Resolves: #27028 Releases: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/4274 Reviewed-by: Eric Chavaillaz Tested-by: Eric Chavaillaz Reviewed-by: Xavier Perseguers Tested-by: Xavier Perseguers
-
- 03 Aug, 2011 1 commit
-
-
Helmut Hummel authored
Change-Id: Ib3b496a8738107b123a2be0a9221e0fe5c76facd Resolves: #26876 Reviewed-on: http://review.typo3.org/4058 Reviewed-by: Oliver Hader Tested-by: Oliver Hader
-