Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Merge pull request #18730 from owncloud/appframework_proper_304 | Vincent Petry | 2015-09-01 | 1 | -1/+1 |
|\ | | | | | Properly return 304 in AppFramework | ||||
| * | Properly return 304 | Roeland Jago Douma | 2015-09-01 | 1 | -1/+1 |
| | | | | | | | | | | | | | | | | The ETag set in the IF_NONE_MODIFIED header is wraped in quotes ("). However the ETag that is set in response is not (yet). Also we need to cast the ETag to a string. * Added unit test | ||||
* | | Merge pull request #18635 from ↵ | Vincent Petry | 2015-08-31 | 1 | -1/+13 |
|\ \ | |/ |/| | | | | | owncloud/stickify-files-and-sharing-notification-types Sticky the notification types of files and sharing | ||||
| * | Sticky the notification types of files and sharing | Joas Schilling | 2015-08-28 | 1 | -1/+13 |
| | | |||||
* | | Merge pull request #17899 from owncloud/enc_make_key_storage_root_configurable | Vincent Petry | 2015-08-31 | 6 | -30/+133 |
|\ \ | | | | | | | Make root of key storage configurable | ||||
| * | | don't read certificates if ownCloud is not installed | Bjoern Schiessle | 2015-08-30 | 3 | -3/+17 |
| | | | |||||
| * | | make system root of key storage configurable | Bjoern Schiessle | 2015-08-30 | 4 | -29/+118 |
| | | | |||||
* | | | Merge pull request #18691 from owncloud/request-no-read | Morris Jobke | 2015-08-31 | 1 | -34/+49 |
|\ \ \ | | | | | | | | | Decode request content only on getContent | ||||
| * | | | Decode request content only on getContent | Robin McCorkell | 2015-08-31 | 1 | -34/+49 |
| | |/ | |/| | |||||
* | | | Merge pull request #10149 from owncloud/storage-wrapper-check | Morris Jobke | 2015-08-30 | 1 | -0/+3 |
|\ \ \ | |_|/ |/| | | Check result of storage wrappers | ||||
| * | | Check result of storage wrappers | Robin Appelman | 2015-08-30 | 1 | -0/+3 |
| | | | |||||
* | | | Merge pull request #18651 from owncloud/ocs_share_create_with_expire | Vincent Petry | 2015-08-30 | 1 | -0/+15 |
|\ \ \ | |/ / |/| | | Allow to directly set the expireDate on a new (link)share | ||||
| * | | Actually validate the expire date on share | Roeland Jago Douma | 2015-08-30 | 1 | -0/+15 |
| |/ | | | | | | | * Added more intergration tests | ||||
* | | Merge pull request #18620 from owncloud/add-public-interface-for-factory | Vincent Petry | 2015-08-29 | 3 | -16/+26 |
|\ \ | | | | | | | Add a public interface for the language factory so apps can use it | ||||
| * | | Deprecate OC_L10N::get() | Joas Schilling | 2015-08-28 | 1 | -6/+3 |
| | | | |||||
| * | | Add a public interface for the language factory so apps can use it | Joas Schilling | 2015-08-27 | 2 | -10/+23 |
| | | | |||||
* | | | Merge pull request #18511 from owncloud/downgrad-sharing-error-logs-to-debug | Joas Schilling | 2015-08-28 | 1 | -22/+22 |
|\ \ \ | | | | | | | | | Change log level of debugging logs to debug | ||||
| * | | | Change log level of debugging logs to debug | Joas Schilling | 2015-08-24 | 1 | -22/+22 |
| | | | | |||||
* | | | | Merge pull request #18423 from owncloud/occ_encrypt_all | Björn Schießle | 2015-08-28 | 1 | -29/+15 |
|\ \ \ \ | |_|_|/ |/| | | | occ command line tool to encrypt all files | ||||
| * | | | copy always file by file to encrypt/decrypt it if needed | Bjoern Schiessle | 2015-08-26 | 1 | -29/+15 |
| | | | | |||||
* | | | | Remove last occurence of `forcessl` | Lukas Reschke | 2015-08-26 | 1 | -2/+2 |
| |_|/ |/| | | | | | | | | This shoudl have been adjusted as well, now it's consistent with `setMagicInCookie`. While it does not have a security impact directly some automated scanners reported this all the time. | ||||
* | | | Merge pull request #18553 from owncloud/write-l10n-on-login | Thomas Müller | 2015-08-26 | 1 | -4/+12 |
|\ \ \ | | | | | | | | | Save detected l10n of browser on login | ||||
| * | | | Save detected l10n of browser on login | Morris Jobke | 2015-08-25 | 1 | -4/+12 |
| | | | | | | | | | | | | | | | | * fixes owncloud/activity#373 | ||||
* | | | | Merge pull request #17662 from owncloud/locking-db | Thomas Müller | 2015-08-26 | 6 | -43/+292 |
|\ \ \ \ | | | | | | | | | | | Database backend for locking | ||||
| * | | | | Adding path to log message | Thomas Müller | 2015-08-25 | 1 | -1/+1 |
| | | | | | |||||
| * | | | | log a warning while trying to acquire a db lock from within a transaction | Robin Appelman | 2015-08-10 | 2 | -5/+17 |
| | | | | | |||||
| * | | | | add method to check if we're inside a transaction | Robin Appelman | 2015-08-10 | 2 | -0/+19 |
| | | | | | |||||
| * | | | | cleanup empty locks | Robin Appelman | 2015-08-10 | 1 | -0/+14 |
| | | | | | |||||
| * | | | | more phpdoc | Robin Appelman | 2015-08-03 | 1 | -1/+1 |
| | | | | | |||||
| * | | | | more phpdoc | Robin Appelman | 2015-08-03 | 1 | -1/+9 |
| | | | | | |||||
| * | | | | rename path field to key | Robin Appelman | 2015-08-03 | 1 | -8/+13 |
| | | | | | |||||
| * | | | | initialize unused (for now) ttl field to 0 | Robin Appelman | 2015-08-03 | 1 | -1/+1 |
| | | | | | |||||
| * | | | | Fix db schema | Robin Appelman | 2015-08-03 | 2 | -10/+8 |
| | | | | | |||||
| * | | | | use the database backend for locking if no memcache is configured for it | Robin Appelman | 2015-08-03 | 1 | -4/+2 |
| | | | | | |||||
| * | | | | Add database backend for high level locking | Robin Appelman | 2015-08-03 | 1 | -0/+131 |
| | | | | | |||||
| * | | | | split off keeping track of acquire locks | Robin Appelman | 2015-08-03 | 2 | -36/+100 |
| | | | | | |||||
* | | | | | Explicitly specify status code 200 as response code | Lukas Reschke | 2015-08-25 | 1 | -0/+1 |
| |/ / / |/| | | | | | | | | | | | Potentially fixes https://github.com/owncloud/core/issues/17586 | ||||
* | | | | Merge pull request #18523 from owncloud/crazy-scanner | Thomas Müller | 2015-08-25 | 1 | -4/+14 |
|\ \ \ \ | | | | | | | | | | | Prevent bkg scanner going crazy with unavailable storages (ajax/scan.php) | ||||
| * | | | | Prevent scanner going crazy with unavailable storages | Vincent Petry | 2015-08-24 | 1 | -4/+14 |
| | | | | | |||||
* | | | | | Remove DEBUG constant and use config value | Morris Jobke | 2015-08-24 | 3 | -10/+4 |
|/ / / / | | | | | | | | | | | | | | | | | * introduces config.php option 'debug' that defaults to false * migrate DEBUG constant to config value | ||||
* | | | | Fix master again | Lukas Reschke | 2015-08-24 | 1 | -0/+1 |
| | | | | | | | | | | | | | | | | Caused due to merge of two PRs | ||||
* | | | | Merge pull request #18482 from owncloud/encrypt-session-data | Morris Jobke | 2015-08-24 | 3 | -1/+283 |
|\ \ \ \ | |_|_|/ |/| | | | Add a session wrapper to encrypt the data before storing it on disk | ||||
| * | | | Handle failures gracefully, remove switch | Lukas Reschke | 2015-08-21 | 3 | -22/+97 |
| | | | | |||||
| * | | | Add a session wrapper to encrypt the data before storing it on disk | Joas Schilling | 2015-08-21 | 3 | -28/+235 |
| | | | | |||||
* | | | | Merge pull request #18486 from owncloud/use-client-service-to-work-behind-proxy | Vincent Petry | 2015-08-24 | 1 | -0/+5 |
|\ \ \ \ | | | | | | | | | | | Use client service to work behind proxy for checks for remote ownCloud instances | ||||
| * | | | | Use IClientService to check for remote ownCloud instances | Lukas Reschke | 2015-08-22 | 1 | -0/+5 |
| |/ / / | | | | | | | | | | | | | | | | | | | | | | | | | 1. Allows to set a timeout (though still not perfect but way better than before) 2. Allows to have unit tests 3. I also added unit tests for the existing controller code 4. Corrected PHPDoc on IClient | ||||
* | | | | Merge pull request #17501 from tbartenstein/patch-1 | Vincent Petry | 2015-08-24 | 1 | -1/+1 |
|\ \ \ \ | | | | | | | | | | | Update fileinfo.php | ||||
| * | | | | Update fileinfo.php | tbartenstein | 2015-07-08 | 1 | -1/+1 |
| | | | | | | | | | | | | | | | Edits isMounted() to remove the check for 'local' prefix, so that folder icons are displayed correctly (see issue #10712) | ||||
* | | | | | Merge pull request #18254 from owncloud/mitigate-breach | Morris Jobke | 2015-08-24 | 3 | -3/+28 |
|\ \ \ \ \ | |_|/ / / |/| | | | | Add mitigation against BREACH | ||||
| * | | | | Add mitigation against BREACH | Lukas Reschke | 2015-08-14 | 3 | -3/+28 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | While BREACH requires the following three factors to be effectively exploitable we should add another mitigation: 1. Application must support HTTP compression 2. Response most reflect user-controlled input 3. Response should contain sensitive data Especially part 2 is with ownCloud not really given since user-input is usually only echoed if a CSRF token has been passed. To reduce the risk even further it is however sensible to encrypt the CSRF token with a shared secret. Since this will change on every request an attack such as BREACH is not feasible anymore against the CSRF token at least. |