Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Merge pull request #18925 from owncloud/change-risky-test | Morris Jobke | 2015-09-09 | 1 | -2/+2 |
|\ | | | | | Rename data provider to avoid risky test warning | ||||
| * | Rename data provider to avoid risky test warning | Lukas Reschke | 2015-09-09 | 1 | -2/+2 |
| | | | | | | | | | | | | | | | | | | ``` 06:49:56 There was 1 risky test: 06:49:56 06:49:56 1) OC\AppFramework\Http\JSONResponseTest::testRenderProvider 06:49:56 This test did not perform any assertions ``` | ||||
* | | Write to session in batch at the end of the request | Lukas Reschke | 2015-09-09 | 1 | -9/+0 |
| | | |||||
* | | Write session data to single key | Lukas Reschke | 2015-09-09 | 1 | -4/+4 |
|/ | | | | This prevents decrypting values multiple times. | ||||
* | Merge pull request #18684 from owncloud/explicit-upgrade-version | Morris Jobke | 2015-09-09 | 1 | -10/+64 |
|\ | | | | | Explicit upgrade version + prevent downgrades | ||||
| * | Restrict upgrades to explicit allowed version | Vincent Petry | 2015-08-30 | 1 | -10/+64 |
| | | | | | | | | | | | | version.php now contains the previous ownCloud version from which upgrades are allowed. Any other upgrades will show a message that the upgrade/downgrade is not supported. | ||||
* | | Load all enabled apps in test bootstrap | Robin McCorkell | 2015-09-07 | 1 | -3/+2 |
| | | |||||
* | | Merge pull request #18748 from owncloud/files-versions-tab | Morris Jobke | 2015-09-07 | 1 | -0/+10 |
|\ \ | | | | | | | Add versions tab to files sidebar | ||||
| * | | Add versions tab to files sidebar | Vincent Petry | 2015-09-03 | 1 | -0/+10 |
| | | | | | | | | | | | | | | | | | | | | | - move versions to a tab in the files sidebar - added mechanism to auto-update the row in the FileList whenever values are set to the FileInfoModel given to the sidebar - updated tags/favorite action to make use of that new mechanism | ||||
* | | | Merge pull request #18742 from owncloud/mimetype-updatedb | Roeland Douma | 2015-09-06 | 3 | -15/+291 |
|\ \ \ | | | | | | | | | Introduce mimetype DB update occ command | ||||
| * | | | Unit tests for mimetype loader | Robin McCorkell | 2015-09-04 | 2 | -0/+277 |
| | | | | |||||
| * | | | Split mimetype handling to new class | Robin McCorkell | 2015-09-04 | 1 | -15/+14 |
| | | | | |||||
* | | | | Merge pull request #18799 from owncloud/appconfig-with-one-request | Morris Jobke | 2015-09-03 | 1 | -204/+247 |
|\ \ \ \ | |_|/ / |/| | | | Only query the appconfig once per request | ||||
| * | | | Only query the appconfig once | Joas Schilling | 2015-09-03 | 1 | -204/+247 |
| | | | | |||||
* | | | | Encode HTML tags in JSON | Lukas Reschke | 2015-09-03 | 1 | -6/+20 |
|/ / / | | | | | | | | | | While not encoding the HTML tags in the JSON response is perfectly fine since we set the proper mimetype as well as disable content sniffing a lot of automated code scanner do report this as security bug. Encoding them leads to less discussions and a lot of saved time. | ||||
* | | | use config.php value instead of version string | Morris Jobke | 2015-09-02 | 1 | -0/+28 |
| | | | |||||
* | | | Merge pull request #18730 from owncloud/appframework_proper_304 | Vincent Petry | 2015-09-01 | 1 | -0/+8 |
|\ \ \ | | | | | | | | | Properly return 304 in AppFramework | ||||
| * | | | Properly return 304 | Roeland Jago Douma | 2015-09-01 | 1 | -0/+8 |
| |/ / | | | | | | | | | | | | | | | | | | | | | | The ETag set in the IF_NONE_MODIFIED header is wraped in quotes ("). However the ETag that is set in response is not (yet). Also we need to cast the ETag to a string. * Added unit test | ||||
* / / | verify the path in the autoloader | Robin Appelman | 2015-09-01 | 3 | -37/+39 |
|/ / | |||||
* | | don't read certificates if ownCloud is not installed | Bjoern Schiessle | 2015-08-30 | 1 | -1/+5 |
| | | |||||
* | | make system root of key storage configurable | Bjoern Schiessle | 2015-08-30 | 4 | -13/+456 |
|/ | |||||
* | Merge pull request #14856 from rullzer/remote_avatars | Morris Jobke | 2015-08-29 | 1 | -12/+17 |
|\ | | | | | Allow Remote avatars | ||||
| * | Allow remote avatars | Roeland Jago Douma | 2015-08-29 | 1 | -12/+17 |
| | | |||||
* | | Merge pull request #18620 from owncloud/add-public-interface-for-factory | Vincent Petry | 2015-08-29 | 1 | -0/+1 |
|\ \ | |/ |/| | Add a public interface for the language factory so apps can use it | ||||
| * | Add a test for the interface | Joas Schilling | 2015-08-28 | 1 | -0/+1 |
| | | |||||
* | | Merge pull request #18423 from owncloud/occ_encrypt_all | Björn Schießle | 2015-08-28 | 3 | -55/+141 |
|\ \ | | | | | | | occ command line tool to encrypt all files | ||||
| * | | copy always file by file to encrypt/decrypt it if needed | Bjoern Schiessle | 2015-08-26 | 1 | -53/+8 |
| | | | |||||
| * | | occ tool to encrypt all files | Bjoern Schiessle | 2015-08-26 | 3 | -2/+133 |
| | | | |||||
* | | | Use certificates that expire in 10 years | Lukas Reschke | 2015-08-27 | 3 | -33/+48 |
| |/ |/| | | | | | :speak_no_evil: :speak_no_evil: :speak_no_evil: | ||||
* | | Merge pull request #17662 from owncloud/locking-db | Thomas Müller | 2015-08-26 | 2 | -0/+73 |
|\ \ | | | | | | | Database backend for locking | ||||
| * | | log a warning while trying to acquire a db lock from within a transaction | Robin Appelman | 2015-08-10 | 1 | -1/+1 |
| | | | |||||
| * | | Fix db schema | Robin Appelman | 2015-08-03 | 1 | -1/+1 |
| | | | |||||
| * | | Add database backend for high level locking | Robin Appelman | 2015-08-03 | 1 | -0/+43 |
| | | | |||||
| * | | split off keeping track of acquire locks | Robin Appelman | 2015-08-03 | 1 | -0/+30 |
| | | | |||||
* | | | Explicitly specify status code 200 as response code | Lukas Reschke | 2015-08-25 | 1 | -0/+4 |
| | | | | | | | | | | | | Potentially fixes https://github.com/owncloud/core/issues/17586 | ||||
* | | | Merge pull request #18491 from owncloud/expire-token-after-12h-or-login | Lukas Reschke | 2015-08-24 | 1 | -7/+116 |
|\ \ \ | | | | | | | | | Expire token after 12h and if user logged-in again | ||||
| * | | | Expire token after 12h and if user logged-in again | Lukas Reschke | 2015-08-22 | 1 | -7/+116 |
| | | | | | | | | | | | | | | | | As an hardening measure we should expire password reset tokens after 12h and if the user has logged-in again successfully after the token was requested. | ||||
* | | | | Merge pull request #18482 from owncloud/encrypt-session-data | Morris Jobke | 2015-08-24 | 3 | -0/+136 |
|\ \ \ \ | | | | | | | | | | | Add a session wrapper to encrypt the data before storing it on disk | ||||
| * | | | | Handle failures gracefully, remove switch | Lukas Reschke | 2015-08-21 | 1 | -3/+4 |
| | | | | | |||||
| * | | | | Add a session wrapper to encrypt the data before storing it on disk | Joas Schilling | 2015-08-21 | 3 | -0/+135 |
| |/ / / | |||||
* | | | | Merge pull request #18254 from owncloud/mitigate-breach | Morris Jobke | 2015-08-24 | 12 | -16/+130 |
|\ \ \ \ | |/ / / |/| | | | Add mitigation against BREACH | ||||
| * | | | Add mitigation against BREACH | Lukas Reschke | 2015-08-14 | 12 | -16/+130 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | While BREACH requires the following three factors to be effectively exploitable we should add another mitigation: 1. Application must support HTTP compression 2. Response most reflect user-controlled input 3. Response should contain sensitive data Especially part 2 is with ownCloud not really given since user-input is usually only echoed if a CSRF token has been passed. To reduce the risk even further it is however sensible to encrypt the CSRF token with a shared secret. Since this will change on every request an attack such as BREACH is not feasible anymore against the CSRF token at least. | ||||
* | | | | Merge pull request #18426 from owncloud/joblist-next-non-existing | Morris Jobke | 2015-08-21 | 1 | -0/+26 |
|\ \ \ \ | | | | | | | | | | | handle non existing job classes in $jobList->getNext | ||||
| * | | | | handle non existing job classes in $jobList->getNext | Robin Appelman | 2015-08-19 | 1 | -0/+26 |
| | |_|/ | |/| | | |||||
* | | | | Merge pull request #18457 from owncloud/test-traits | Robin McCorkell | 2015-08-20 | 4 | -44/+127 |
|\ \ \ \ | | | | | | | | | | | Move common test logic to re-usable traits | ||||
| * | | | | add test mountprovider logic to a trait | Robin Appelman | 2015-08-20 | 2 | -31/+60 |
| | | | | | |||||
| * | | | | allow moving common test logic into traits | Robin Appelman | 2015-08-20 | 3 | -14/+68 |
| | | | | | |||||
* | | | | | Merge pull request #18372 from ↵ | Joas Schilling | 2015-08-20 | 1 | -1/+196 |
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | | owncloud/issue-18358-object-type-and-id-for-activities Issue 18358 object type and id for activities | ||||
| * | | | | Add test coverage for Activity Event and Manager | Joas Schilling | 2015-08-20 | 1 | -1/+196 |
| | | | | | |||||
* | | | | | Merge pull request #18369 from owncloud/occ-log | Morris Jobke | 2015-08-20 | 2 | -0/+302 |
|\ \ \ \ \ | | | | | | | | | | | | | occ commands to manage logging |