| Commit message (Expand) | Author | Age | Files | Lines |
* | Bump the version number for 4.0rc2.release-4.0rc2bugzilla-4.0rc2 | Max Kanat-Alexander | 2011-01-24 | 2 | -4/+4 |
* | Bug 619594: (CVE-2010-4568) [SECURITY] Improve the randomness of | Max Kanat-Alexander | 2011-01-24 | 5 | -5/+78 |
* | Bug 621105 - [SECURITY] Voting lacks CSRF protection | David Lawrence | 2011-01-24 | 3 | -0/+6 |
* | Bug 619588: (CVE-2010-4567) [SECURITY] Safety checks that disallow clicking f... | Frédéric Buclin | 2011-01-24 | 3 | -8/+20 |
* | Bug 621572: (CVE-2010-4572) [SECURITY] chart.cgi vulnerable to header-injecti... | Reed Loden | 2011-01-24 | 1 | -3/+3 |
* | Bug 619648: (CVE-2010-4570) [SECURITY] XSS via summary in "possible duplicate... | Reed Loden | 2011-01-24 | 1 | -1/+2 |
* | Bug 619637: (CVE-2010-4569) [SECURITY] XSS in user autocomplete due to lack o... | Reed Loden | 2011-01-24 | 1 | -1/+8 |
* | Bug 621110: [SECURITY] Quips (adding/approving/deleting) lacks CSRF protection | Frédéric Buclin | 2011-01-24 | 2 | -2/+12 |
* | Bug 621108: [SECURITY] Creating/editing charts lacks CSRF protection | Frédéric Buclin | 2011-01-24 | 3 | -2/+9 |
* | Bug 621107: [SECURITY] Sanity checking lacks CSRF protection | Frédéric Buclin | 2011-01-24 | 4 | -8/+26 |
* | Bug 621090: [SECURITY] Adding saved searches lacks CSRF protection | David Lawrence | 2011-01-24 | 3 | -0/+4 |
* | An optional module was accidentally listed in the "required" section of the | Max Kanat-Alexander | 2011-01-23 | 1 | -2/+2 |
* | Bug 627910: Update Release Notes for Bugzilla 4.0rc2 | Max Kanat-Alexander | 2011-01-23 | 1 | -6/+26 |
* | Bug 621128 - Remove trailing whitespace from '<div id="view_disabled" >' | timeless | 2011-01-22 | 1 | -1/+1 |
* | Bug 621109: Column changing lacks CSRF protection | Frédéric Buclin | 2011-01-22 | 2 | -5/+19 |
* | Bug 627854: Add 'form' hook to create-guided.html.tmpl similar to create.html... | David Lawrence | 2011-01-21 | 1 | -0/+2 |
* | Bug 591165: (CVE-2010-4411) [SECURITY] Bump minimum required version of CGI.p... | Reed Loden | 2011-01-21 | 1 | -2/+2 |
* | Bug 627660 - Rename "Send" button on final create account page to "Create", a... | Reed Loden | 2011-01-21 | 1 | -1/+1 |
* | Bug 626292 - "Make description private" checkbox should set bz_private class ... | David Lawrence | 2011-01-21 | 3 | -6/+8 |
* | Bug 623608 - Add intro/outro extension hooks to footer.html.tmpl | David Lawrence | 2011-01-21 | 1 | -2/+2 |
* | Bug 625190: Typo and Missing FK in Bugzilla::DB::Schema | David Marshall | 2011-01-15 | 1 | -3/+6 |
* | Bug 618841: Bare word "bug" in release notes | A. Shimono | 2011-01-09 | 1 | -3/+3 |
* | Bug 622204: Bugzilla::Migrate crashes trying to create bugs with resolutions | | 2011-01-09 | 1 | -1/+1 |
* | Bug 255524: The duplicates table inherits no CSS classes when viewed in simpl... | Frédéric Buclin | 2011-01-07 | 1 | -0/+4 |
* | Document how to add user settings. r,a=mkanat. | Gervase Markham | 2011-01-05 | 3 | -1/+19 |
* | Bug 622822 - add additional_links hook to front page. r,a=mkanat. | Gervase Markham | 2011-01-05 | 1 | -0/+1 |
* | Bug 622437: Remove 'colchange_columns' hook from the Example extension | Tiago Mello | 2011-01-02 | 1 | -7/+0 |
* | Bug 622105 - Misspelling in setting_info_invalid error message | David Lawrence | 2010-12-30 | 1 | -1/+1 |
* | Bug 621597: Make mod_perl.pl do the INC configuration itself, instead of | Max Kanat-Alexander | 2010-12-28 | 2 | -2/+8 |
* | Bug 618844: Make clear that the Apache module must be enabled in release notes | A. Shimono (himorin) | 2010-12-27 | 1 | -2/+2 |
* | Bug 618842: Enclose checksetup.pl between <kbd> and </kbd> tags in templates | A. Shimono (himorin) | 2010-12-27 | 5 | -15/+15 |
* | Bug 599539: Update the mod_perl.pl code for Apache2::SizeLimit 0.93 | Max Kanat-Alexander | 2010-12-27 | 3 | -16/+25 |
* | Bug 615574: Make every search done by buglist.cgi create a list_id, so that | Max Kanat-Alexander | 2010-12-27 | 4 | -25/+61 |
* | Bug 603762: Vertical margins between header, footer, and content are not cons... | Christian Legnitto | 2010-12-27 | 2 | -4/+1 |
* | Bug 588013: Fix typo | timeless | 2010-12-27 | 1 | -1/+1 |
* | Bug 620796: Make Bugzilla::Migrate skip abnormal fields when doing | Max Kanat-Alexander | 2010-12-21 | 1 | -0/+2 |
* | Bug 475894 - Send the 'X-Frame-Options: SAMEORIGIN' header to help protect ag... | Reed Loden | 2010-12-18 | 1 | -0/+6 |
* | Bug 313583: Relnote that long_list.cgi, showattachment.cgi and xml.cgi will b... | Frédéric Buclin | 2010-12-16 | 1 | -0/+4 |
* | Bug 617477: Fix numerous consistency and behavior issues surrounding Bug.update | Max Kanat-Alexander | 2010-12-13 | 5 | -40/+176 |
* | Bug 618161: Make VERSION into a constant in two included extensions so that | Max Kanat-Alexander | 2010-12-12 | 2 | -4/+3 |
* | Bug 610182: Support enabling UNCONFIRMED in all products when using | Frank Becker | 2010-12-10 | 1 | -2/+16 |
* | Bug 617684: Values starting with a dot or an underscore are no longer hidden ... | Frédéric Buclin | 2010-12-08 | 1 | -6/+0 |
* | Bug 567953: Components which exist in several products are duplicated in tabu... | miketosh | 2010-12-08 | 1 | -1/+2 |
* | Bug 617030 - Add an error code for json_rpc_invalid_callback, and fix the | Max Kanat-Alexander | 2010-12-06 | 2 | -1/+2 |
* | Bug 542931: Bug in SOAP::Lite prevents WebService:XMLRPC logins from persisting | Frédéric Buclin | 2010-12-06 | 1 | -3/+3 |
* | Bug 607138: Don't send the Strict-Transport-Security header for the | Max Kanat-Alexander | 2010-12-06 | 1 | -2/+6 |
* | Bug 607675: In Firefox, YAHOO.util.Event.addListener/on events no longer exis... | Guy Pyrzak | 2010-12-02 | 1 | -3/+5 |
* | Bug 416784: In PostgreSQL 8.1 and newer, createuser takes the argument -R ins... | Frédéric Buclin | 2010-11-27 | 1 | -3/+7 |
* | Bug 386600: Implement auto-completion for the requestee field | Guy Pyrzak | 2010-11-21 | 3 | -29/+26 |
* | Bug 611891: Don't generate cookies for logins done over GET via the WebService | Max Kanat-Alexander | 2010-11-14 | 1 | -1/+6 |