aboutsummaryrefslogtreecommitdiffstats
path: root/lib/private
Commit message (Collapse)AuthorAgeFilesLines
* allow streamed responses in http clientRobin Appelman2015-08-292-4/+14
|
* Merge pull request #18511 from owncloud/downgrad-sharing-error-logs-to-debugJoas Schilling2015-08-281-22/+22
|\ | | | | Change log level of debugging logs to debug
| * Change log level of debugging logs to debugJoas Schilling2015-08-241-22/+22
| |
* | Merge pull request #18423 from owncloud/occ_encrypt_allBjörn Schießle2015-08-281-29/+15
|\ \ | | | | | | occ command line tool to encrypt all files
| * | copy always file by file to encrypt/decrypt it if neededBjoern Schiessle2015-08-261-29/+15
| | |
* | | Remove last occurence of `forcessl`Lukas Reschke2015-08-261-2/+2
| | | | | | | | | | | | This shoudl have been adjusted as well, now it's consistent with `setMagicInCookie`. While it does not have a security impact directly some automated scanners reported this all the time.
* | | Merge pull request #18553 from owncloud/write-l10n-on-loginThomas Müller2015-08-261-4/+12
|\ \ \ | | | | | | | | Save detected l10n of browser on login
| * | | Save detected l10n of browser on loginMorris Jobke2015-08-251-4/+12
| | | | | | | | | | | | | | | | * fixes owncloud/activity#373
* | | | Merge pull request #17662 from owncloud/locking-dbThomas Müller2015-08-266-43/+292
|\ \ \ \ | | | | | | | | | | Database backend for locking
| * | | | Adding path to log messageThomas Müller2015-08-251-1/+1
| | | | |
| * | | | log a warning while trying to acquire a db lock from within a transactionRobin Appelman2015-08-102-5/+17
| | | | |
| * | | | add method to check if we're inside a transactionRobin Appelman2015-08-102-0/+19
| | | | |
| * | | | cleanup empty locksRobin Appelman2015-08-101-0/+14
| | | | |
| * | | | more phpdocRobin Appelman2015-08-031-1/+1
| | | | |
| * | | | more phpdocRobin Appelman2015-08-031-1/+9
| | | | |
| * | | | rename path field to keyRobin Appelman2015-08-031-8/+13
| | | | |
| * | | | initialize unused (for now) ttl field to 0Robin Appelman2015-08-031-1/+1
| | | | |
| * | | | Fix db schemaRobin Appelman2015-08-032-10/+8
| | | | |
| * | | | use the database backend for locking if no memcache is configured for itRobin Appelman2015-08-031-4/+2
| | | | |
| * | | | Add database backend for high level lockingRobin Appelman2015-08-031-0/+131
| | | | |
| * | | | split off keeping track of acquire locksRobin Appelman2015-08-032-36/+100
| | | | |
* | | | | Explicitly specify status code 200 as response codeLukas Reschke2015-08-251-0/+1
| |/ / / |/| | | | | | | | | | | Potentially fixes https://github.com/owncloud/core/issues/17586
* | | | Merge pull request #18523 from owncloud/crazy-scannerThomas Müller2015-08-251-4/+14
|\ \ \ \ | | | | | | | | | | Prevent bkg scanner going crazy with unavailable storages (ajax/scan.php)
| * | | | Prevent scanner going crazy with unavailable storagesVincent Petry2015-08-241-4/+14
| | | | |
* | | | | Remove DEBUG constant and use config valueMorris Jobke2015-08-243-10/+4
|/ / / / | | | | | | | | | | | | | | | | * introduces config.php option 'debug' that defaults to false * migrate DEBUG constant to config value
* | | | Fix master againLukas Reschke2015-08-241-0/+1
| | | | | | | | | | | | | | | | Caused due to merge of two PRs
* | | | Merge pull request #18482 from owncloud/encrypt-session-dataMorris Jobke2015-08-243-1/+283
|\ \ \ \ | |_|_|/ |/| | | Add a session wrapper to encrypt the data before storing it on disk
| * | | Handle failures gracefully, remove switchLukas Reschke2015-08-213-22/+97
| | | |
| * | | Add a session wrapper to encrypt the data before storing it on diskJoas Schilling2015-08-213-28/+235
| | | |
* | | | Merge pull request #18486 from owncloud/use-client-service-to-work-behind-proxyVincent Petry2015-08-241-0/+5
|\ \ \ \ | | | | | | | | | | Use client service to work behind proxy for checks for remote ownCloud instances
| * | | | Use IClientService to check for remote ownCloud instancesLukas Reschke2015-08-221-0/+5
| |/ / / | | | | | | | | | | | | | | | | | | | | | | | | 1. Allows to set a timeout (though still not perfect but way better than before) 2. Allows to have unit tests 3. I also added unit tests for the existing controller code 4. Corrected PHPDoc on IClient
* | | | Merge pull request #17501 from tbartenstein/patch-1Vincent Petry2015-08-241-1/+1
|\ \ \ \ | | | | | | | | | | Update fileinfo.php
| * | | | Update fileinfo.phptbartenstein2015-07-081-1/+1
| | | | | | | | | | | | | | | Edits isMounted() to remove the check for 'local' prefix, so that folder icons are displayed correctly (see issue #10712)
* | | | | Merge pull request #18254 from owncloud/mitigate-breachMorris Jobke2015-08-243-3/+28
|\ \ \ \ \ | |_|/ / / |/| | | | Add mitigation against BREACH
| * | | | Add mitigation against BREACHLukas Reschke2015-08-143-3/+28
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | While BREACH requires the following three factors to be effectively exploitable we should add another mitigation: 1. Application must support HTTP compression 2. Response most reflect user-controlled input 3. Response should contain sensitive data Especially part 2 is with ownCloud not really given since user-input is usually only echoed if a CSRF token has been passed. To reduce the risk even further it is however sensible to encrypt the CSRF token with a shared secret. Since this will change on every request an attack such as BREACH is not feasible anymore against the CSRF token at least.
* | | | | Merge pull request #18426 from owncloud/joblist-next-non-existingMorris Jobke2015-08-211-2/+15
|\ \ \ \ \ | | | | | | | | | | | | handle non existing job classes in $jobList->getNext
| * | | | | handle non existing job classes in $jobList->getNextRobin Appelman2015-08-191-2/+15
| | |_|_|/ | |/| | |
* | | | | Merge pull request #18372 from ↵Joas Schilling2015-08-202-39/+343
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | owncloud/issue-18358-object-type-and-id-for-activities Issue 18358 object type and id for activities
| * | | | | Expand the doc blocks on the new methodsJoas Schilling2015-08-201-0/+15
| | | | | |
| * | | | | Remove unnecessary codeJoas Schilling2015-08-201-7/+0
| | | | | |
| * | | | | Add test coverage for Activity Event and ManagerJoas Schilling2015-08-201-6/+6
| | | | | |
| * | | | | Use an IEvent object instead of a huge parameter listJoas Schilling2015-08-192-24/+315
| | | | | |
| * | | | | Extend the interfaces IManager and IConsumer to allow passing in the objectJoas Schilling2015-08-191-25/+30
| |/ / / /
* | | | | Merge pull request #18439 from owncloud/fix-appmanagement-installMorris Jobke2015-08-201-1/+1
|\ \ \ \ \ | | | | | | | | | | | | [app management] fix dependency check on install
| * | | | | [app management] fix dependency check on installMorris Jobke2015-08-191-1/+1
| | | | | |
* | | | | | Merge pull request #17434 from owncloud/update-showappnameonappupdateMorris Jobke2015-08-201-0/+69
|\ \ \ \ \ \ | |/ / / / / |/| | | | | Display app names in update page for app updates
| * | | | | Additions to update pageVincent Petry2015-08-201-2/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Apps to update and to disable will always be shown. Main title changes only when apps need updated, not core. Added bullet style. Exclude incompatible apps from updated apps list.
| * | | | | Display app names in update page for app updatesVincent Petry2015-08-191-0/+67
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Whenever the update page is displayed for apps, show app names instead of the core update text.
* | | | | | Merge pull request #18432 from owncloud/ext-backends.simpleMorris Jobke2015-08-192-6/+5
|\ \ \ \ \ \ | | | | | | | | | | | | | | Migrate simple external storage backends to new registration API [part 1]
| * | | | | | Revert "Fix mounting wrapped storages resulting in many-layered wrapping"Robin McCorkell2015-08-191-6/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This reverts commit 75a5e6e12b18a9f5b7b113cd7e2c9c56c204084d.