- 24 May, 2012 2 commits
-
-
If persistent connections are not allowed by MySQL the error message "Can only select database if username/password/host is correctly set first." is shown. Add an explanation that $TYPO3_CONF_VARS['SYS']['no_pconnect'] must be set to 1, if persistent connections are not allowed. Change-Id: I1fbe73d84f5a3626f6be32fa6ef4f2721a617b33 Fixes: #29245 Releases: 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/7113 Reviewed-by: Markus Klein Tested-by: Markus Klein Reviewed-by: Stefan Neufeind Tested-by: Stefan Neufeind Reviewed-by: Sebastian Fischer Reviewed-by: Oliver Klee Reviewed-by: Stefan Galinski Tested-by: Stefan Galinski
-
This test makes use of posix_getegid which on Mac OS always returns -1, thus making it useless for getting the effective group ID. Change-Id: I754a0e192b8b9b20a9475c56bf17a9738aa3fa19 Resolves: #28017 Releases: 4.6, 4.5, 4.4, 4.3 Reviewed-on: http://review.typo3.org/7124 Reviewed-by: Markus Klein Tested-by: Markus Klein Reviewed-by: Stefan Neufeind Tested-by: Stefan Neufeind Reviewed-by: Philipp Gampe Reviewed-by: Georg Grossberger Tested-by: Georg Grossberger Reviewed-by: Oliver Klee Reviewed-by: Stefan Galinski Tested-by: Stefan Galinski
-
- 17 Apr, 2012 3 commits
-
-
TYPO3 v4 Release Team authored
Change-Id: I3993b065b557e6024ae43cf6a3345f4282a6492c Reviewed-on: http://review.typo3.org/10571 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
TYPO3 v4 Release Team authored
Change-Id: I27b6756698e0653d665a59172ab1b70b05e3f02e Reviewed-on: http://review.typo3.org/10570 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
Change-Id: I8a8bc19e6ae4e25466570f5c376e018200306730 Releases: 6.0, 4.7, 4.6, 4.5, 4.4 Fixes: #34348 Security-Review: http://review.typo3.org/10313 Security-Commit: de5adb6d314831bafab690af27520d296f853640 Security-Bulletin: TYPO3-CORE-SA-2012-002 Reviewed-on: http://review.typo3.org/10565 Reviewed-by: Oliver Hader Tested-by: Oliver Hader
-
- 05 Apr, 2012 2 commits
-
-
Andreas Wolf authored
For a page with translations, the clickmenu is not shown for these translations in the page module, view "languages". This comes from a missing table name in the clickmenu link generation call. Change-Id: I8f63349bd66d02eddf0c48bf6223f9504aa6e43e Resolves: #27052 Releases: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/4663 Reviewed-by: Markus Klein Tested-by: Markus Klein Reviewed-by: Stefan Neufeind Tested-by: Stefan Neufeind Reviewed-by: Andreas Wolf Tested-by: Andreas Wolf
-
Andreas Wolf authored
The behaviour that causes the error (translated elements are not deleted when deleting parent) is fixed in recent TYPO3 versions; it is better to do that additional check anyways (for old installations). Change-Id: I4daf02f6b60daf2c1a1f7daad1683001deda40e5 Resolves: #17910 Releases: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/6211 Reviewed-by: Markus Klein Tested-by: Markus Klein Reviewed-by: Stefan Neufeind Tested-by: Stefan Neufeind Reviewed-by: Andreas Wolf Tested-by: Andreas Wolf
-
- 28 Mar, 2012 10 commits
-
-
TYPO3 v4 Release Team authored
Change-Id: I6478cd2389441452b95eb5a7bd890d4b3cea42e4 Reviewed-on: http://review.typo3.org/10031 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
TYPO3 v4 Release Team authored
Change-Id: I60c80742e77c66b23f5ff57f93ca33985921c755 Reviewed-on: http://review.typo3.org/10028 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
Andreas Wolf authored
RemoveXSS fails to properly remove non printable characters, especially zero-byte (\x00) chars. Change-Id: Idfd0cdb4a9a27c27d86db9c4339c7227ffe6ae16 Fixes: #30188 Security-Review: http://review.typo3.org/5841 Security-Commit: dd560e6b831ee6825687dd594ddf1702012a6ecd Security-Bulletin: TYPO3-CORE-SA-2012-001 Reviewed-on: http://review.typo3.org/10002 Reviewed-by: Oliver Hader Tested-by: Oliver Hader
-
Christian Kuhn authored
Change-Id: I74b66e63015571472c1c3930067abd015991c5d6 Fixes: #29397 Security-Review: http://review.typo3.org/5857 Security-Commit: c3f1e88586a15b67c2fc2ba49ed45cb521cd1478 Security-Bulletin: TYPO3-CORE-SA-2012-001 Reviewed-on: http://review.typo3.org/10001 Reviewed-by: Oliver Hader Tested-by: Oliver Hader
-
Georg Ringer authored
Add escaping to description and file name of file link content element. Warning: There is no longer HTML possible in description! Change-Id: Ie9de8b12d52a4ccf95eacae4352490aa43e95756 Fixes: #25246 Security-Review: http://review.typo3.org/5838 Security-Commit: e543cb17ed7ef9d478e2c933a102fe656eb0964e Security-Bulletin: TYPO3-CORE-SA-2012-001 Reviewed-on: http://review.typo3.org/10000 Reviewed-by: Oliver Hader Tested-by: Oliver Hader
-
Oliver Klee authored
Change-Id: Ice808f1a8f5ef2ddc1c48dbb6e55dac26f4c4942 Releases: 6.0, 4.7, 4.6, 4.5, 4.4 Fixes: #30969 Security-Commit: 254542e63e81ae5ce0754cd3a4ed08e7be7e7bbd Security-Bulletin: TYPO3-CORE-SA-2012-001 Reviewed-on: http://review.typo3.org/9999 Reviewed-by: Oliver Hader Tested-by: Oliver Hader
-
Georg Ringer authored
A proper escaping is missing for field "frequency" Sanitize submitted uid Change-Id: Id811514d4dba2c3732bbbc4b03decdea1a9719ca Fixes: #24474 Security-Commit: 6305b094b7f165e24ed3748ce6ec3dbf2a85b750 Security-Bulletin: TYPO3-CORE-SA-2012-001 Reviewed-on: http://review.typo3.org/9998 Reviewed-by: Oliver Hader Tested-by: Oliver Hader
-
Christian Kuhn authored
Change-Id: I77b3c33e07a6ee6695c15566c14c7cb67053f587 Fixes: #30940 Security-Commit: a395345b246dd1aedb79890de03d6428f98a4b80 Security-Bulletin: TYPO3-CORE-SA-2012-001 Reviewed-on: http://review.typo3.org/9997 Reviewed-by: Oliver Hader Tested-by: Oliver Hader
-
Georg Ringer authored
sys_notes misses an escaping in info module, not in page/list module Change-Id: I302b3c4cdb13e5e1aafb7f35608a9484d59854f9 Fixes: #22748 Releases: 6.0, 4.7, 4.6, 4.5, 4.4 Security-Commit: b58d50c11bc6014bb54477ad13ad3bb775c72464 Security-Bulletin: TYPO3-CORE-SA-2012-001 Reviewed-on: http://review.typo3.org/9996 Reviewed-by: Oliver Hader Tested-by: Oliver Hader
-
Georg Ringer authored
By accessing a cli script in the frontend, it is possible that the DB name is shown. Change-Id: Ib99342fbc80859c1963ab342ff2f07642db3c1aa Fixes: #29060 Security-Commit: e5d79402eddb1e23b437344a72c91ad5ffb0d022 Security-Bulletin: TYPO3-CORE-SA-2012-001 Reviewed-on: http://review.typo3.org/9995 Reviewed-by: Oliver Hader Tested-by: Oliver Hader
-
- 25 Mar, 2012 1 commit
-
-
Jigal van Hemert authored
In groupfields the title attribute of options must also be handled when moving items. Change-Id: I5ef76f6648a3e62140ef8984dd7a8b1e8de9bcd8 Fixes: #35176 Releases: 6.0, 4.7, 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/9863 Reviewed-by: Jigal van Hemert Tested-by: Jigal van Hemert
-
- 12 Mar, 2012 1 commit
-
-
Alexander Stehlik authored
Adjust headers sent by t3lib_userauth to prevent caching, if Internet Explorer is used when downloading files through PHP. Change-Id: I823f72c143d9e5666db2426a5818b96a76d4c39f Fixes: #24125 Releases: 4.4, 4.5, 4.6, 4.7, 4.8 Reviewed-on: http://review.typo3.org/6699 Reviewed-by: Georg Grossberger Tested-by: Georg Grossberger Reviewed-by: Sebastian Fischer Reviewed-by: Steffen Ritter Tested-by: Steffen Ritter
-
- 07 Mar, 2012 1 commit
-
-
Ernesto Baschny authored
Change-Id: Ie3b58bca2de4db7a56b79fd0c07e926876941d53 Resolves: #34600 Releases: 4.4, 4.5, 4.6, 4.7, 4.8 Reviewed-on: http://review.typo3.org/9443 Reviewed-by: Ernesto Baschny Tested-by: Ernesto Baschny
-
- 06 Mar, 2012 1 commit
-
-
Stefan Neufeind authored
Cleanup for an E_NOTICE on exploding the bitmask. Replaced (correct working, but "unreadable") strcmp(). Add testcases. Change-Id: Idc28b66ce714ec26fc6cab68576e440f76421b4c Resolves: #27230 Releases: 4.3, 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/7131 Reviewed-by: Markus Klein Tested-by: Markus Klein Reviewed-by: Stefan Neufeind Tested-by: Stefan Neufeind Reviewed-by: Tolleiv Nietsch Tested-by: Tolleiv Nietsch
-
- 18 Feb, 2012 1 commit
-
-
Stefan Neufeind authored
getAllowedItems() is called with two parameters. However the second one is not in the function-definition and not used. Change-Id: I69cd3c4362c36adc3e6f1e2bc1ae1ba7bfb38c77 Fixes: #34030 Releases: 4.4, 4.5, 4.6, 4.7 Reviewed-on: http://review.typo3.org/9088 Reviewed-by: Stanislas Rolland Tested-by: Stanislas Rolland
-
- 24 Jan, 2012 2 commits
-
-
TYPO3 v4 Release Team authored
Change-Id: I25d69f3737a35a3f3cca7136ab55508b4db94e85 Reviewed-on: http://review.typo3.org/8668 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
TYPO3 v4 Release Team authored
Change-Id: I632a05b9ea6d86d0598e1c3e21fe9c8f59c53313 Reviewed-on: http://review.typo3.org/8667 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
- 18 Jan, 2012 1 commit
-
-
Stefan Neufeind authored
Current implementation of md5.js only considers a very limited range of characters. The implementation from webtoolkit.info uses correct unicode-representation. Change-Id: Ib7b983340f2fd82698fd48967c0be61a8fc822b8 Releases: 4.4, 4.5, 4.6 Resolves: #22328 Reviewed-on: http://review.typo3.org/5692 Reviewed-by: Xavier Perseguers Tested-by: Xavier Perseguers Reviewed-by: Stefan Neufeind Tested-by: Stefan Neufeind Reviewed-by: Oliver Hader Tested-by: Oliver Hader
-
- 14 Jan, 2012 1 commit
-
-
Marcus Krause authored
The backend script alt_doc.php even considers deleted pages_language_overlay records when determining in which language a record can be/is localized. This patch improves method documentation and applies t3lib_BEfunc::deleteClause() on the respective database query. Change-Id: Ibea4e3f8cd5ec9d104d52091e66d69faf48bea9d Fixes: #31379 Releases: 4.3, 4.4, 4.5, 4.6, 4.7 Reviewed-on: http://review.typo3.org/6373 Reviewed-by: Markus Klein Tested-by: Markus Klein Reviewed-by: Georg Ringer Tested-by: Georg Ringer Reviewed-by: Simon Schaufelberger Tested-by: Simon Schaufelberger Reviewed-by: Stefan Neufeind Reviewed-by: Tolleiv Nietsch Tested-by: Tolleiv Nietsch
-
- 20 Dec, 2011 1 commit
-
-
Xavier Perseguers authored
Comparator != was supported before. But <> is ANSI SQL and therefore should be supported as well. Change-Id: I56e86bfda550036e31d5bec4e8430c47ff0b9b56 Fixes: #32626 Releases: 4.4, 4.5, 4.6, 4.7 Reviewed-on: http://review.typo3.org/7418 Reviewed-by: Xavier Perseguers Tested-by: Xavier Perseguers
-
- 19 Dec, 2011 1 commit
-
-
Oliver Hader authored
Each page can have a target defined, which can also be a typeNum that gets added to the generated URL. Now if RealURL is used, the "&type=" part will be just added to the final URL which looks like "page.html&type=1". A question mark is missing here to get a valid query part. Change-Id: I5404dde8963f2d5fea6a7e680cbe0f1d1f709d86 Fixes: #31622 Releases: 4.7, 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/6960 Reviewed-by: Stefan Neufeind Reviewed-by: Simon Schaufelberger Tested-by: Simon Schaufelberger Reviewed-by: Oliver Hader Tested-by: Oliver Hader
-
- 18 Dec, 2011 1 commit
-
-
Markus Klein authored
CSS files must comply to http://www.w3.org/TR/CSS21/syndata.html#charset which requires @charset to be "the 10 characters '@charset "' (lowercase, no backslash escapes)". Also the CSS compressor looks for the lowercase version. Change-Id: Ie63eea0c4b6ed5089ea3e8d5291271c627674e24 Fixes: #32163 Releases: 4.7, 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/7351 Reviewed-by: Georg Ringer Tested-by: Georg Ringer
-
- 16 Dec, 2011 1 commit
-
-
Albrecht Koehnlein authored
ImageTTFBBox() randomly returns incorrect negative values. Repeat the operation a number of time if this happens to try to find the correct values. Change-Id: Iec726a3ddbafdb6d2024257e01e63071b566e150 Fixes: #21054 Releases: 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/7120 Reviewed-by: Philipp Gampe Reviewed-by: Simon Schaufelberger Reviewed-by: Jigal van Hemert Tested-by: Jigal van Hemert
-
- 07 Dec, 2011 2 commits
-
-
Benni Mack authored
When editing a translated record in the TCEforms backend, the original language label is shown below, in a green box. The green box is definitively from the old skin (3.x) and should be changed. Change-Id: I9a85f1daac7b41a1a6d1e3cd9663c67abc917c44 Resolves: #28012 Releases: 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/7123 Reviewed-by: Georg Ringer Tested-by: Georg Ringer
-
Georg Ringer authored
Currently explode() is used for pageOverLayFields which requires a list without any whitespaces. Using t3lib_div::trimExplode() improves the usability for integrators and reduces possibilities of not working configurations Change-Id: I65ba837ac2bb8370de6e79e6c7cef820afc9063d Resolves: #28916 Releases: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/7132 Reviewed-by: Georg Ringer Tested-by: Georg Ringer
-
- 29 Nov, 2011 1 commit
-
-
Marco Bresch authored
Fix XSS at column 'workspace membership'. How to test: * choose a workspace title like "<b>test</b>" * assign a user as member to the workspace * select the BE-module "Admin Tools->User Admin" * select the checkbox "Workspace membership" * press update * take a look at column "Workspace membership" Change-Id: I7036eb070d94beb73c539091135b188f588e171d Fixes: #32040 Releases: 4.7, 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/6961 Reviewed-by: Georg Ringer Tested-by: Georg Ringer
-
- 22 Nov, 2011 3 commits
-
-
TYPO3 v4 Release Team authored
Change-Id: I87c8c5c848353c9f0f71a9aaf15f63bd353b8120 Reviewed-on: http://review.typo3.org/6857 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
TYPO3 v4 Release Team authored
Change-Id: I5ff0d2c0a39593d64dc2cd183dc9b5b27fd56ee0 Reviewed-on: http://review.typo3.org/6856 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
TYPO3 v4 Release Team authored
Change-Id: Ia90ea04d65ced0756ce6f6c74e598f48bd234849 Reviewed-on: http://review.typo3.org/6848 Reviewed-by: TYPO3 v4 Release Team Tested-by: TYPO3 v4 Release Team
-
- 18 Nov, 2011 1 commit
-
-
Francois Suter authored
The date picker in the Admin Tools > Log when selecting a user-defined time range is broken. Adapt it to new skinning API for the JS to act on it properly again. Change-Id: I26e34b312bf411b20bb8671278a6099e45accbe1 Resolves: #31450 Releases: 4.7, 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/6396 Reviewed-by: Tomita Militaru Reviewed-by: Francois Suter Tested-by: Francois Suter
-
- 17 Nov, 2011 1 commit
-
-
Marc Bastian Heinrichs authored
Change-Id: I3c4f9390e13bebfae861565c482877f5563f9442 Resolves: #28835 Releases: 4.4, 4.5, 4.6 Reviewed-on: http://review.typo3.org/6697 Reviewed-by: Simon Schaufelberger Reviewed-by: Georg Ringer Tested-by: Georg Ringer Reviewed-by: Dmitry Dulepov Tested-by: Dmitry Dulepov
-
- 09 Nov, 2011 1 commit
-
-
Back ported code from task #31501 breaks the the configuration page of the saltedpasswords extension in EM. Change-Id: Ie2d2a4c4bb8050e6b474095c816af6ae9a2ef555 Fixes: #31501 Relates: #31178 Releases: 4.5, 4.4 Reviewed-on: http://review.typo3.org/6612 Reviewed-by: Steffen Gebert Tested-by: Steffen Gebert
-
- 04 Nov, 2011 1 commit
-
-
Markus Klein authored
The options field is hidden in the BE user form if the user is admin. This is a problem if the admin has assigned groups with db_mounts, as the default value for the options is to mount also the group's mounts, which is undesired for most instances. Change-Id: Ie1931a9531acf073e18548c56d454e958c22b531 Fixes: #30492 Releases: 4.7, 4.6, 4.5, 4.4 Reviewed-on: http://review.typo3.org/6529 Reviewed-by: Markus Klein Tested-by: Markus Klein Reviewed-by: Georg Ringer Tested-by: Georg Ringer
-