summaryrefslogtreecommitdiffstats
path: root/lib/redmine
Commit message (Collapse)AuthorAgeFilesLines
* Merged r17763 from trunk to 3.4-stable (#30171).Go MAEDA2018-12-171-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17767 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Updates for 3.4.7 release.Jean-Philippe Lang2018-12-091-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17710 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17645 to 3.4-stable (#29674).Jean-Philippe Lang2018-11-291-0/+10
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17654 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17643 to 3.4-stable (#20788).Jean-Philippe Lang2018-11-291-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17650 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17638 from trunk to 3.4-stable (#30009).Go MAEDA2018-11-261-0/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17639 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17636 from trunk to 3.4-stable (#8395).Go MAEDA2018-11-261-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17637 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17625 from trunk to 3.4-stable (#8317).Go MAEDA2018-11-101-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17627 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17603 from trunk to 3.4-stable (#29756).Go MAEDA2018-10-281-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17604 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17474 from trunk to 3.4-stable (#29413).Go MAEDA2018-08-251-2/+4
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17475 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17450 from trunk to 3.4-stable (#29247).Go MAEDA2018-07-211-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17451 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17377 to 3.4-stable.Jean-Philippe Lang2018-06-101-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17378 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17351 from trunk to 3.4-stable (#28725).Go MAEDA2018-05-281-4/+15
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17352 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17322 from trunk to 3.4-stable (#28469).Go MAEDA2018-05-021-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17323 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17286.Jean-Philippe Lang2018-04-071-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17287 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17266 into 3.4-stable (#25299).Jean-Philippe Lang2018-04-071-8/+6
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17267 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17198 to 3.4-stable (#28119).Go MAEDA2018-03-311-1/+2
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17247 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17162 to 3.4-stable.Jean-Philippe Lang2018-01-081-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17163 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17062 from trunk to 3.4-stable (#27516)Toshi MARUYAMA2017-12-071-13/+14
| | | | | | | | | | | mercurial: work around faulty parsing of early command options Use -sVALUE and --long=VALUE instead of "-s VALUE" and "--long VALUE" respectively. Contributed by Yuya Nishihara. git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17068 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17061 from trunk to 3.4-stable (#27516)Toshi MARUYAMA2017-12-071-5/+5
| | | | | | | | | | | | mercurial: separate command options and positional arguments with "--" We don't have much problems here thanks to hgtarget(path) and CGI.escape(), which prepends a repository path and encodes "=" character respectively, but it's better to not rely on the side effect of these functions. Contributed by Yuya Nishihara. git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17067 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17060 from trunk to 3.4-stable (#27516)Toshi MARUYAMA2017-12-071-0/+15
| | | | | | | | | | | | | | | | | | | | | | | | mercurial: reject malicious command argument We've got a security report from the Phabricator team, which basically says --config and --debugger arguments can be injected anywhere to lead to an arbitrary command execution. https://secure.phabricator.com/rPa7921a4448093d00defa8bd18f35b8c8f8bf3314 This is a fundamental issue of the argument parsing rules in Mercurial, which allows extensions to populate their parsing rules and such extensions can be loaded by "--config extensions.<name>=". There's a chicken and egg problem. We're working on hardening the parsing rules, but which won't come in by default as it would be a behavior change. This patch adds a verification to reject malicious command arguments as a last ditch. The subsequent patches will fix the problem in more appropriate way. Contributed by Yuya Nishihara. git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17066 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17027 to 3.4-stable (#26410).Go MAEDA2017-11-251-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17028 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r17003 and r17004.Jean-Philippe Lang2017-10-151-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17005 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r16948 from trunk to 3.4-stable (#26645)Toshi MARUYAMA2017-08-081-1/+1
| | | | | | git: remove "--no-color" option from "git --version" for git 2.14 compatibility. git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@16949 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r16825.Jean-Philippe Lang2017-07-161-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@16826 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Merged r16779.Jean-Philippe Lang2017-07-091-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@16780 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Set version to 3.4 stable.Jean-Philippe Lang2017-06-251-3/+3
| | | | git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@16696 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Update copyright.Jean-Philippe Lang2017-06-2571-71/+71
| | | | git-svn-id: http://svn.redmine.org/redmine/trunk@16685 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Removes plugins_path from configuration file (#24007).Jean-Philippe Lang2017-06-171-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/trunk@16675 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Render all possible inline textile images even if an invalid one exists ↵Jean-Philippe Lang2017-06-171-1/+1
| | | | | | | | (#26157). Patch by Holger Just. git-svn-id: http://svn.redmine.org/redmine/trunk@16668 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Removes duplicate shell_quote method (#26149).Jean-Philippe Lang2017-06-172-16/+18
| | | | | | Patch by Jens Krämer. git-svn-id: http://svn.redmine.org/redmine/trunk@16667 e93f8b46-1217-0410-a6f0-8f06a7374b81
* gannt: not show %done if the field is disabled for the tracker (#25876)Toshi MARUYAMA2017-06-151-1/+4
| | | | | | Contributed by Jens Krämer. git-svn-id: http://svn.redmine.org/redmine/trunk@16663 e93f8b46-1217-0410-a6f0-8f06a7374b81
* remove is_binary_data? from String (#25563)Toshi MARUYAMA2017-06-103-5/+9
| | | | git-svn-id: http://svn.redmine.org/redmine/trunk@16644 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Generate markup for uploaded image dropped into wiki-edit textarea (#26071).Jean-Philippe Lang2017-06-073-0/+7
| | | | | | Patch by Felix Gliesche. git-svn-id: http://svn.redmine.org/redmine/trunk@16643 e93f8b46-1217-0410-a6f0-8f06a7374b81
* New permission: view news (#7068).Jean-Philippe Lang2017-06-071-0/+4
| | | | | | Patch by Felix Schäfer. git-svn-id: http://svn.redmine.org/redmine/trunk@16639 e93f8b46-1217-0410-a6f0-8f06a7374b81
* New Permission: View Forum (#4866).Jean-Philippe Lang2017-06-071-0/+4
| | | | | | Patch by Felix Schäfer. git-svn-id: http://svn.redmine.org/redmine/trunk@16637 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Link to user in wiki syntax (#4179).Jean-Philippe Lang2017-06-072-3/+7
| | | | | | Patch by Marius BALTEANU. git-svn-id: http://svn.redmine.org/redmine/trunk@16636 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Use stored ref. to array holding supported languages symbols via a constant ↵Jean-Philippe Lang2017-06-061-2/+3
| | | | | | | | (#26055). Patch by Mischa The Evil. git-svn-id: http://svn.redmine.org/redmine/trunk@16624 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Pull-up retrieve_supported_languages private class method (#26055).Jean-Philippe Lang2017-06-061-4/+10
| | | | | | Patch by Mischa The Evil. git-svn-id: http://svn.redmine.org/redmine/trunk@16623 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Remove internal CodeRay scanners (#26055).Jean-Philippe Lang2017-06-061-1/+2
| | | | | | Patch by Mischa The Evil. git-svn-id: http://svn.redmine.org/redmine/trunk@16622 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Make sure we can call #values.Jean-Philippe Lang2017-06-031-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/trunk@16604 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Errors#get is deprecated in Rails 5.Jean-Philippe Lang2017-06-011-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/trunk@16595 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Cusotom field label should not be associated to the first input (#25760).Jean-Philippe Lang2017-05-271-4/+2
| | | | git-svn-id: http://svn.redmine.org/redmine/trunk@16574 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Highlight language aliases are no more supported (#25634).Jean-Philippe Lang2017-05-271-1/+4
| | | | | | Patch by Go MAEDA. git-svn-id: http://svn.redmine.org/redmine/trunk@16568 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Updates for 3.3.3 release.Jean-Philippe Lang2017-04-091-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/trunk@16532 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Filter arbitrary class names and ids in rendered HTML output (#25503).Jean-Philippe Lang2017-04-063-5/+19
| | | | | | | | | * Disallow setting arbitrary classes and ids via Textile syntax * Only allow valid/supported languages for syntax highlighted code blocks Patch by Jan Schulz-Hofen. git-svn-id: http://svn.redmine.org/redmine/trunk@16502 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Helper methods to find out if a given language is supported (#25503).Jean-Philippe Lang2017-04-061-0/+16
| | | | | | Patch by Jan Schulz-Hofen. git-svn-id: http://svn.redmine.org/redmine/trunk@16501 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Add kbd to ALLOWED_TAGS (#25503).Jean-Philippe Lang2017-04-061-1/+1
| | | | | | Patch by Jan Schulz-Hofen. git-svn-id: http://svn.redmine.org/redmine/trunk@16500 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Don't hardcode the groups on My page.Jean-Philippe Lang2017-04-041-0/+6
| | | | git-svn-id: http://svn.redmine.org/redmine/trunk@16475 e93f8b46-1217-0410-a6f0-8f06a7374b81
* Makes Attachments column available on the issue list (#25515).Jean-Philippe Lang2017-04-041-1/+4
| | | | git-svn-id: http://svn.redmine.org/redmine/trunk@16473 e93f8b46-1217-0410-a6f0-8f06a7374b81
* spelling fixes (#25495)Toshi MARUYAMA2017-04-021-1/+1
| | | | git-svn-id: http://svn.redmine.org/redmine/trunk@16445 e93f8b46-1217-0410-a6f0-8f06a7374b81