Commit Graph

11630 Commits (c3148e173a1a24b9a35427378a7dcba8e3981b4d)

Author SHA1 Message Date
mcdruid c3148e173a
Issue #3384397 by poker10, Fabianx: [D7] When adding a new menu link, restrict the available parents to the current menu 2023-12-05 11:30:06 +00:00
mcdruid 7bfe25f63c
Issue #764408 by poker10, sgtpep, acrollet, David_Rothstein, checker, Fabianx, bkouchi: [D7] Drupal.t() does not respect locale_custom_strings 2023-12-05 11:28:27 +00:00
mcdruid 6380331eb0
Issue #691932 by BTMash, Shellingfox, jhedstrom, dinarcon, AndyF, zhangtaihao, catch, MustangGB, wamilton, Barry_Fisher, brad.bulger, yched, xjm, Sylvain Lecoy, 5n00py, chx, droplet, tim.plunkett, ohthehugemanatee, parasolx, cilefen, andypost, poker10, Fabianx: Add hook_field_schema_alter() 2023-12-05 11:22:06 +00:00
mcdruid 68ca415ff6
Issue #3396440 by poker10, joelpittet, tibezh, Fabianx: [D7 PHP 8.1] html_entity_decode(): Passing null to parameter #1 ($string) of type string is deprecated in decode_entities() 2023-12-05 11:03:17 +00:00
mcdruid fd71fedd65
Issue #2345695 by poker10, formatC'vt, frodri, quietone, mgifford, mondrake, thirdender, james.williams: Users are able to upload 0-byte images 2023-12-05 10:46:41 +00:00
mcdruid dcf3c1404e
Issue #3386936 by poker10: Remove unused/non-working function getSchemaUpdates() 2023-12-01 22:22:36 +00:00
mcdruid bdb7dd4353
Issue #3326994 by klonos, poker10, BramDriesen: Username enumeration via one time login route 2023-12-01 22:18:50 +00:00
mcdruid 72c4d548f6
Issue #3383556 by poker10, BramDriesen, cussack: Username disclosure in /user/password 2023-12-01 21:41:58 +00:00
mcdruid 4884d1551b
Issue #2677118 by Chi, poker10: Wrong usage of watchdog in system.api.php 2023-12-01 14:21:22 +00:00
mcdruid 9b894d6e07
Issue #2801329 by gianani, poker10, MustangGB: Remove system.cron.js 2023-12-01 14:19:29 +00:00
mcdruid 4c0e15a792
Issue #2978218 by heilop, poker10, langelhc: Add "delete" link on node Translate tab Operations 2023-12-01 13:56:40 +00:00
mcdruid 80cc744787
Issue #2880910 by tatarbj, joseph.olstad, vijaycs85, poker10, klausi, oadaeh, mahalingam_cs, David_Rothstein, mcdruid: [D7] Nothing clears the "5 failed login attempts" security message when a user resets their own password 2023-11-13 10:27:12 +00:00
mcdruid c868605197
Issue #3348669 by Chase., poker10: system.mail.inc: strpos(): Passing null to parameter #1 ($haystack) of type string is deprecated 2023-11-10 11:54:23 +00:00
mcdruid 5ea9bbef7c
Issue #3372666 by hadsie, poker10, ayushmishra206, jibran, larowlan, amietpatial, alexpott, aalamaki, afox, mark_fullmer, mohit_aghera, Wim Leers, wroxbox, tanubansal, rteijeiro, NikolaAt, rakesh.gectcr, richardbporter: D7 Backport: Links with "@" are converted into email addresses even if there is no domain suffix present 2023-11-10 11:50:01 +00:00
mcdruid 1acc41ae01
Issue #2540830 by swarad07, mikemadison, jhodgdon, poker10, David_Rothstein, cilefen: Sanitize watchdog() link in dblog_event() 2023-11-10 11:38:17 +00:00
Juraj Nemec 6a020fca83
Issue #3380876 by poker10: [D7 PHP 8.3] unserialize(): Extra data starting at offset 2023-10-20 19:52:39 +02:00
mcdruid 5fa9cc2ddc
Issue #3393147 by fjgarlin, mcdruid, poker10: Exceptions ignored in errorHandler for DrupalTestCase 2023-10-11 11:44:41 +01:00
Juraj Nemec 96a9946c34
Issue #3373222 by Gábor Hojtsy, mcdruid: Fallback to feed item description does not strip HTML, only takes 40 chars even though field allows 255 2023-09-15 18:55:55 +02:00
Juraj Nemec 605b36bde2
Issue #3386055 by fjgarlin: Cookie base path not check in the test but set in code 2023-09-12 00:12:54 +02:00
mcdruid 8d31dcfe39
Issue #3381481 by mcdruid, poker10: add tests for PHP Gadget Chain Drupal7/RCE1 protection 2023-08-21 19:19:13 +01:00
mcdruid 353a22fcae
Issue #1705618 by sun, nod_, mgifford, hanoii, clemens.tolboom, poker10, torotil, Wim Leers, Matt V., helmo, mcdruid, joseph.olstad, JvE, tim.plunkett, Bojhan, fawwad.nirvana, GuyPaddock, Dries, David_Rothstein: Double click prevention on form submission 2023-06-06 20:18:15 +01:00
mcdruid b280556110
Issue #3007538 by poker10, torotil, DamienMcKenna, Jorrit, Fabianx: Cron.php does not check for maintenance mode correctly 2023-06-06 19:32:35 +01:00
Juraj Nemec 18157eae5b
Issue #2164025 by skipyT, mcdruid, pwolanin: Improve security of session ID against DB exposure or SQL injection 2023-06-06 17:32:55 +02:00
Juraj Nemec 0e01f46498
Issue #3293648 by mcdruid, poker10: [D7 backport] Update status does not verify the identity or authenticity of the release history URL 2023-06-06 17:12:39 +02:00
Juraj Nemec 1e7ee478ae
Issue #2060235 by lauriii, poker10, gaas: Getting a PDOException when adding new image style named thumbnail, medium and large 2023-05-26 20:32:20 +02:00
Juraj Nemec b32f7ee691
Issue #3358515 by mcdruid: Make phpinfo on the admin status report configurable [D7] 2023-05-26 19:54:13 +02:00
Juraj Nemec f1199f88e5
Issue #1470236 by iamEAP, mstrelan, poker10, divesh.kumar: Array flip error when a taxonomy term field has a NULL value 2023-05-26 18:53:32 +02:00
Juraj Nemec 7c73718bac
Issue #1451072 by David_Rothstein, DuttonMa: Deleting a comment author while the Comment module is disabled leads to an EntityMalformedException error after it's reenabled 2023-05-26 18:37:10 +02:00
Juraj Nemec 5a129b18bb
Issue #998632 by dalin, poker10: drupal_write_record() throws PHP notices if any fields use DB-specific data types 2023-05-26 18:25:59 +02:00
Juraj Nemec 9ce7214b5e
Issue #3308471 by poker10: [D7] Update CommonXssUnitTest::testBadProtocolStripping() to check other allowed / dangerous protocols 2023-05-26 18:07:11 +02:00
mcdruid d8dd20c964
Issue #1821178 by heddn, poker10: Performance tune text_field_load() 2023-05-23 18:54:31 +01:00
mcdruid b71063cf23
Issue #1621334 by SebCorbin, poker10, szt, larowlan, swentel, salvis: Notice: Undefined property: stdClass::$forum_tid in forum_node_view() 2023-05-23 18:30:16 +01:00
mcdruid 06438b6ac3
Issue #2177335 by drintios, idebr, czigor, therealssj, oo0shiny, bdimaggio, samiullah, shashank5563, Rinku Jacob 13, poker10, alexpott: Selecting "None" does not move the block to the disabled region when there are no disabled blocks 2023-05-23 18:20:49 +01:00
mcdruid edf413d8dc
Issue #2412151 by poker10, abramm, monika.danielsson: taxonomy_overview_terms undefined index 2023-05-12 14:26:11 +01:00
mcdruid 648c3345e2
Issue #2133309 by pawandubey, tinko, matsbla, ifrik, poker10: Change link for language code identifier when creating custom languages 2023-05-12 13:08:58 +01:00
mcdruid e24f6d3efd
Issue #1777166 by gyuhyon, mandclu, poker10, jhodgdon, mradcliffe, catch: hook_comment_publish() docs are completely wrong 2023-05-12 12:59:42 +01:00
mcdruid 76c552b64e
Issue #3345570 by dmitrii, poker10: list_allowed_values_setting_validate dies with PHP Fatal error on PHP 8.1 2023-05-12 11:04:39 +01:00
mcdruid de6bcb8375 Issue #3358536 by mcdruid, poker10: Add test(s) for SA-CORE-2023-004 2023-05-08 11:00:25 +01:00
Juraj Nemec 0a51cc79ea
Issue #3325533 by benqwerty: Undefined variables in system.tar.inc 2023-05-03 15:17:32 +02:00
Juraj Nemec 03172b7217
Issue #3064227 by zniki.ru: Add close p tag at clean_url_description in system.admin.inc 2023-04-28 19:11:59 +02:00
Juraj Nemec c355b0b5e8
Issue #2845290 by eiriksm: Missing function comment doc for user_admin_account_validate 2023-04-28 19:06:52 +02:00
Juraj Nemec f988ee75aa
Issue #3004335 by interX: Wrong database table mentioned in the documentation of taxonomy_term_load_multiple 2023-04-28 19:01:59 +02:00
mcdruid dabbad0539 Issue #3355216 by poker10: Fix PHP 5.x regression caused by ::class constant 2023-04-21 10:52:45 +01:00
xjm 5f9015435b
SA-CORE-2023-005 by benjifisher, Heine, cmlara, mlhess, larowlan, David_Rothstein, xjm, Wim Leers, DamienMcKenna, effulgentsia, pwolanin, mcdruid, poker10, jenlampton, longwave, kim.pepper, alexpott, drumm 2023-04-19 11:14:58 -05:00
mcdruid b82f268439 SA-CORE-2023-004 by DamienMcKenna, elarlang, larowlan, effulgentsia, pandaski, mcdruid, jenlampton, quicksketch, greggles 2023-03-15 15:49:31 +00:00
mcdruid b1899315a5 Revert "Issue #2070807 by pounard: book_node_load() ignores the 'book_allowed_types' and does excessive SQL queries"
This reverts commit 9801138304.
2022-12-14 15:56:00 +00:00
mcdruid 8eac033bec Issue #3316901 by poker10, solideogloria, mcdruid: hash(): Passing null to parameter #2 ($data) of type string is deprecated in check_markup() 2022-12-05 13:15:07 +00:00
mcdruid 9801138304 Issue #2070807 by pounard: book_node_load() ignores the 'book_allowed_types' and does excessive SQL queries 2022-12-03 16:08:36 +00:00
mcdruid 67a7e9e74e Issue #3306390 by poker10, catch, Fabianx, pwolanin, rvtraveller: [D7] Changing email address should invalidate one-time login links 2022-12-03 15:30:52 +00:00
mcdruid 62faca623f Issue #2891346 by berliner, Ayesh, jpablus, gapple, Fabianx, poker10, mcdruid: tableheader.js: Source: call to eval() or related function blocked by CSP 2022-12-03 15:08:36 +00:00