Commit Graph

165 Commits (f66aac72818c5bd69d8f62cef868b37a2cb44cc1)

Author SHA1 Message Date
xjm 5f9015435b
SA-CORE-2023-005 by benjifisher, Heine, cmlara, mlhess, larowlan, David_Rothstein, xjm, Wim Leers, DamienMcKenna, effulgentsia, pwolanin, mcdruid, poker10, jenlampton, longwave, kim.pepper, alexpott, drumm 2023-04-19 11:14:58 -05:00
mcdruid 0a9c6cc85e Issue #3308929 by poker10, swentel, fago, catch, alexpott, Berdir: [D7] Cron lock time limit is too short and does not prevent multiple, concurrent cron runs 2022-11-28 19:50:13 +00:00
mcdruid 98b92ad931 Issue #3292743 by mcdruid, poker10: Remove FLoC header from D7 as google has abandoned it 2022-11-18 11:58:03 +00:00
Juraj Nemec e15ccfbf6a
Issue #3293649 by mcdruid: drupal_http_request() fails to strip Cookie or Authorization headers on HTTP downgrade 2022-09-06 23:29:55 +02:00
mcdruid 24afdc00f5 SA-CORE-2022-012 by cmlara, GuyPaddock, larowlan, mondrake, effulgentsia, xjm, longwave, Dave Reid, lauriii, David Strauss, benjifisher, alexpott, mcdruid, Fabianx 2022-07-20 16:30:44 +01:00
mcdruid be2c0763de Issue #1232572 by deviantintegral, mcdruid, joachim, cweagans, Lennard Westerveld, kenorb, hanoii, webflo, bleen, esod, johnennew, Elijah Lynn, ron_s, csmdgl, sriharsha.uppuluri, cman9090, Berdir, catch, q0rban, alexpott, anavarre: Backport skip_permissions_hardening 2021-11-15 15:23:09 +00:00
mcdruid b8685e91a7 Issue #229825 by nod_, mcdruid, sun, ApacheEx, lightsurge, legovaer, pounard, RobLoach, Frederikvho, Robin Monks, cburschka, yched, keith.smith, Kiphaas7, treksler, jbrauer, catch, Dave Reid, aspilicious, Damien Tournoud, Wim Leers, giupenni, ressa, Fabianx, webchick: backport "$_COOKIE['has_js'] must die" patch to 7.x 2021-11-08 17:45:44 +00:00
mcdruid eb66609d55 Issue #3209976 by mcdruid, DamienMcKenna, Maeglin, antiorario, effulgentsia, gapple, rachel_norfolk, rootwork, phenaproxima, neclimdul, larowlan, longwave: Add Permissions-Policy header to block Google FLoC 2021-05-26 17:25:25 +01:00
mcdruid 7ba88d9d4f Issue #3170525 by mcdruid, nullkernel, simonholt83, MustangGB, Znak, axle_foley00, Fabianx, akorkot, cilefen, thalemn, Ayesh, ressa, finne: Set samesite cookie attribute for PHP sessions 2021-03-23 21:33:42 +00:00
mcdruid 975e9c6040 Issue #2470619 by mcdruid, pounard, hosef, heddn, DamienMcKenna, boyan.borisov, joelpittet, Fabianx, joseph.olstad, MustangGB, izmeez, oadaeh, joshmiller, marcingy, mikeytown2, discipolo, amateescu, Jordan Samouh, das-peter, ndobromirov, quietone, Ronino, mxr576, David_Rothstein, potop, dreamer777, btully: Do not attempt field storage write when field content did not change 2021-03-23 21:26:17 +00:00
mcdruid 6cc9596664 Issue #3098058 by mcdruid, SAVEL, alexpott, alexandra.vecher, nikolas.tatianenko, kiamlaluno, sjerdo, RobLoach, catch, cburschka, carlos8f, penyaskito, gdud, theborg, pillarsdotnet, olamaekle, naxoc: [D7] Use site name in From: header for system e-mails 2020-11-30 16:43:29 +00:00
mcdruid 92112208cd Issue #973436 by catch, joseph.olstad, beejeebus, karschsp, pillarsdotnet, mcdruid, DamienMcKenna, carlos8f, sun, dsobon, kentr, Damien Tournoud, pounard, Fabianx, xjm, fgm, Steven Jones, David_Rothstein, donquixote, amateescu, MustangGB, Lars Toomre, basicmagic.net, Jeremy, DanPir, nnewton, yonailo, Peter Bowey, RobLoach, gdaw, dsutter, joel_osc, nareshp, izmeez, joelpittet, torgosPizza, crea, tim.plunkett, YesCT, stefan.r, rwohleb: Overzealous locking in variable_initialize() 2020-11-25 15:15:38 +00:00
mcdruid e189264330 Issue #2978575 by mcdruid, Ayesh, Ronino, fietserwin, emilcarpenter, elijahoyekunle, berenddeboer, Mixologic, almaudoh, tfranz, izmeez, TR, Charlie ChX Negyesi, joseph.olstad, mmjvb, gisle, MustangGB, ronlee, pyQlo, TrevorBradley, alexpott, mfb, Fabianx, Andrés Chandía, buddym, rjt1224, saxmeister, Pol, shenzhuxi, sjerdo, aparna_kondala, seamus_lee, andrew_rs, bernig, andyrandom, xpiku, Kevin Morse, SivaprasadC, lakshmi_a, vensires, waqarit, joergM: Mysql 8 Support on Drupal 7 2020-11-25 13:19:13 +00:00
mcdruid 51d6e29626 Issue #2989985 by mcdruid, colorfulCoder, tatarbj, Fabianx, paulocs: User module's flood controls should do better logging, plus add new hook_user_flood_control() 2020-11-24 21:01:59 +00:00
Pol Dellaiera bf635f9f04
Issue #3035772 by Pol: [Regression] Fix default.settings.php permission 2019-02-26 09:04:27 +01:00
Pol Dellaiera a0983925ed
Issue #2482549 by Pol, marcelovani, ndf, drupal@guusvandewal.nl, jenlampton, ufku, kaidjohnson, MiSc, David_Rothstein, RobLoach, SebCorbin, geerlingguy, pablo.guerino, JohnAlbin, joelpittet, afoster: Ignore node_module folder in core to use Drupal with npm/grunt/nodejs 2019-01-07 21:06:16 +01:00
David Rothstein 96753f64a2 Issue #2091511 by Cameron Tod, mcdruid, mpdonadio, David_Rothstein, lokapujya, stefan.r, Berdir, alexpott, damiankloip, cosmicdreams, das-peter, heddn, xjm, catch, tstoeckler, anavarre, naveenvalecha, tim.plunkett, dawehner: Make cache_form expiration configurable, to mitigate runaway cache_form tables 2017-10-04 17:33:24 -04:00
stefan.r d4d7a73eaa Issue #2009584 by hgoto, jtwalters, rteijeiro, ry5n, emattias, Fabianx: Allow double underscores to pass through drupal_clean_css_identifier as per new CSS standards 2016-09-29 17:58:59 +01:00
stefan.r 8b79f437f5 Issue #2766537 by bhavikshah9, mforbes: Missing asterisk in one line of default.settings.php documentation block 2016-07-18 11:37:49 +02:00
David Rothstein bc60c9298a Issue #2488180 by stefan.r, stovak, pwolanin, David_Rothstein, Noe_, typhonius, KhaledBlah, joelpittet, Fabianx, geerlingguy, nithinkolekar, mikeytown2, jduhls, scuba_fly, travelvc, hass: Support full UTF-8 (emojis, Asian symbols, mathematical symbols) on MySQL and other database drivers when they are configured to allow it 2016-07-06 00:34:23 -04:00
David Rothstein 8b0f1c71c5 Issue #2115737 by darol100, owenpm3, rhuffstedtler, andythomnz, jemandy, ijf8090, zealfire, er.pushpinderrana, jhodgdon, corbacho, spitcher, abenamer, holingpoon, ay1n: Make the text in modules, themes, and profiles README.txt files more user-friendly 2015-10-14 18:12:49 -04:00
David Rothstein c2d06db123 Issue #2538640 by rrrob, dawehner: Add theme_debug to default.settings.php 2015-10-12 18:32:44 -04:00
David Rothstein 6e6c3dba67 Issue #2455057 by michaellenahan, jhodgdon, jelo: Fix fast 404 settings for private image files 2015-10-12 17:53:46 -04:00
Jennifer Hodgdon dc84091add Issue #2500101 by David_Rothstein: sites/all/modules/README.txt should not imply that clearing caches always works after moving a module to a new subdirectory 2015-06-04 07:31:10 -07:00
David Rothstein 49908edcf7 Issue #667058 followup by TwoD: Fix "JavaScript" typo in sites/all/libraries/README.txt. 2015-06-01 18:30:21 -04:00
David Rothstein 2a3cf926af Issue #667058 by greggles, DamienMcKenna, cweagans, travelertt, Dave Reid, tstoeckler, geerlingguy: Add a sites/all/libraries folder and encourage people to use it properly 2015-05-04 16:30:31 -04:00
Jennifer Hodgdon 4d1840e620 Issue #2407175 by zealfire: Documentation error in default.settings.php 2015-02-17 16:32:33 -08:00
David Rothstein 9559160204 Issue #1930960 by pounard, iamEAP, pjcdawkins, msonnabaum, David_Rothstein: Fixed Block caching disable hardcoded on sites with hook_node_grant() causes serious performance troubles when not necessary. 2014-11-04 20:07:30 -05:00
David Rothstein 433fe74a81 Issue #1221772 by pounard, colan, jcisio | sivaji: Fixed Transaction database settings is misleading in settings.php. 2014-11-02 15:06:53 -05:00
Jennifer Hodgdon a44bda729f Issue #692366 by mariacha1, hosef, Albert Volkman, xjm, underq, kid_icarus, willmoy, bradweikel: Replace US-centric php.net URLs with language-neutral URLs 2013-09-12 07:52:52 -07:00
Jennifer Hodgdon 3919174433 Issue #1829366 by gcassie: Fix up grammar and caps in default settings.php file 2012-11-10 06:48:59 -08:00
David Rothstein 8a4df80203 Issue #1436814 by gary4gar, kid_icarus, netol, webchick, droplet, andypost: Fixed Fast 404 'Not found' pages are missing a doctype. 2012-11-04 23:30:05 -05:00
Jennifer Hodgdon a5d723152b Issue #1553704 by eddie_c: Fix up fast 404 docs in settings.php 2012-10-15 13:02:06 -07:00
Jennifer Hodgdon e320619e07 Issue #1539940 by jwilson3, ryanissamson, infiniteluke, mrf: Fix up sites readme files 2012-10-09 10:47:47 -07:00
webchick 294e758959 Issue #932110 by Albert Volkman, David_Rothstein, marji, jurgenhaas, dcam: On some servers, the Update Manager allows administrators to directly execute arbitrary code even without the PHP module. (Documentation fix) 2012-09-26 23:12:35 -04:00
webchick 76acfb9b16 Issue #7881 by mikeytown2, effulgentsia, gwynnebaer, Patrizio, sylus, pwolanin, David_Rothstein: Add support to drupal_http_request() for proxy servers. 2012-09-01 22:25:49 -07:00
webchick 3b64ddd963 CHANGELOG.txt entry for #1164682. 2012-09-01 22:10:47 -07:00
Jennifer Hodgdon 3782025a16 Issue #932110 by dcam, Albert Volkman, jurgenhaas, marji, David_Rothstein: Add note to settings.php about updates and security 2012-08-31 08:42:21 -07:00
Jennifer Hodgdon 7043f6d7ab Issue #1018324 by Albert Volkman, webbykat, disasm, jhr, jorap: Fix up documentation for multisite 2012-08-24 11:15:37 -07:00
Jennifer Hodgdon 491ae8b00f Issue #1578590 by ksenzee: Replace references to nonexesitent function drupal_initialize_variables 2012-05-21 07:53:24 -07:00
Jennifer Hodgdon 7d22696b72 Issue #1485810 by nmudgal: Clarify wording for salt variable docs in default.settings.php 2012-03-19 12:49:37 -07:00
webchick 2f6d917af5 Issue #1309278 by basic, Niklas Fiekas: Added Make PDO connection options configurable. 2011-12-25 00:40:22 -08:00
webchick 629a4dea2f Issue #1310250 by joelcollinsdc: Fixed Improve reverse proxy ip address handing commenting and documentation. 2011-10-19 23:38:29 -07:00
webchick e120a6e886 Issue #76824 by geerlingguy, xjm, droplet, kbahey: Change notice for Drupal should not handle 404 for certain files. 2011-09-30 15:00:38 -07:00
webchick bd11d95c33 Issue #1005570 by reglogge: Fixed Document leading dot requirement for () in settings.php. 2011-09-30 14:49:23 -07:00
Dries Buytaert 20ac46d1f0 - Patch #1262064 by michaellenahan: default.settings.php has formatting issue with numbered list. 2011-09-16 17:40:01 -04:00
webchick ee09da916c Issue #999538 by Josh The Geek: default.settings.php still refers to 'aggressive caching'. 2011-04-10 16:18:36 -07:00
The Great Git Migration 79bcdb8b7d Stripping CVS keywords 2011-02-25 02:06:03 +00:00
Angie Byron db7de89756 #1040190 by 1V: Fix typo in comment for cookie_domain in settings.php 2011-01-28 07:03:57 +00:00
Dries Buytaert 563c673ea3 - Patch #101227 by mikeytown2, Owen Barton, grendzy: added Gzip aggregated CSS and JS. 2010-10-11 23:49:48 +00:00