aboutsummaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Bump the version number for 4.0rc2.release-4.0rc2bugzilla-4.0rc2Max Kanat-Alexander2011-01-242-4/+4
* Bug 619594: (CVE-2010-4568) [SECURITY] Improve the randomness of Max Kanat-Alexander2011-01-245-5/+78
* Bug 621105 - [SECURITY] Voting lacks CSRF protectionDavid Lawrence2011-01-243-0/+6
* Bug 619588: (CVE-2010-4567) [SECURITY] Safety checks that disallow clicking f...Frédéric Buclin2011-01-243-8/+20
* Bug 621572: (CVE-2010-4572) [SECURITY] chart.cgi vulnerable to header-injecti...Reed Loden2011-01-241-3/+3
* Bug 619648: (CVE-2010-4570) [SECURITY] XSS via summary in "possible duplicate...Reed Loden2011-01-241-1/+2
* Bug 619637: (CVE-2010-4569) [SECURITY] XSS in user autocomplete due to lack o...Reed Loden2011-01-241-1/+8
* Bug 621110: [SECURITY] Quips (adding/approving/deleting) lacks CSRF protectionFrédéric Buclin2011-01-242-2/+12
* Bug 621108: [SECURITY] Creating/editing charts lacks CSRF protectionFrédéric Buclin2011-01-243-2/+9
* Bug 621107: [SECURITY] Sanity checking lacks CSRF protectionFrédéric Buclin2011-01-244-8/+26
* Bug 621090: [SECURITY] Adding saved searches lacks CSRF protectionDavid Lawrence2011-01-243-0/+4
* An optional module was accidentally listed in the "required" section of theMax Kanat-Alexander2011-01-231-2/+2
* Bug 627910: Update Release Notes for Bugzilla 4.0rc2Max Kanat-Alexander2011-01-231-6/+26
* Bug 621128 - Remove trailing whitespace from '<div id="view_disabled" >'timeless2011-01-221-1/+1
* Bug 621109: Column changing lacks CSRF protectionFrédéric Buclin2011-01-222-5/+19
* Bug 627854: Add 'form' hook to create-guided.html.tmpl similar to create.html...David Lawrence2011-01-211-0/+2
* Bug 591165: (CVE-2010-4411) [SECURITY] Bump minimum required version of CGI.p...Reed Loden2011-01-211-2/+2
* Bug 627660 - Rename "Send" button on final create account page to "Create", a...Reed Loden2011-01-211-1/+1
* Bug 626292 - "Make description private" checkbox should set bz_private class ...David Lawrence2011-01-213-6/+8
* Bug 623608 - Add intro/outro extension hooks to footer.html.tmplDavid Lawrence2011-01-211-2/+2
* Bug 625190: Typo and Missing FK in Bugzilla::DB::SchemaDavid Marshall2011-01-151-3/+6
* Bug 618841: Bare word "bug" in release notesA. Shimono2011-01-091-3/+3
* Bug 622204: Bugzilla::Migrate crashes trying to create bugs with resolutions2011-01-091-1/+1
* Bug 255524: The duplicates table inherits no CSS classes when viewed in simpl...Frédéric Buclin2011-01-071-0/+4
* Document how to add user settings. r,a=mkanat.Gervase Markham2011-01-053-1/+19
* Bug 622822 - add additional_links hook to front page. r,a=mkanat.Gervase Markham2011-01-051-0/+1
* Bug 622437: Remove 'colchange_columns' hook from the Example extensionTiago Mello2011-01-021-7/+0
* Bug 622105 - Misspelling in setting_info_invalid error messageDavid Lawrence2010-12-301-1/+1
* Bug 621597: Make mod_perl.pl do the INC configuration itself, instead ofMax Kanat-Alexander2010-12-282-2/+8
* Bug 618844: Make clear that the Apache module must be enabled in release notesA. Shimono (himorin)2010-12-271-2/+2
* Bug 618842: Enclose checksetup.pl between <kbd> and </kbd> tags in templatesA. Shimono (himorin)2010-12-275-15/+15
* Bug 599539: Update the mod_perl.pl code for Apache2::SizeLimit 0.93Max Kanat-Alexander2010-12-273-16/+25
* Bug 615574: Make every search done by buglist.cgi create a list_id, so thatMax Kanat-Alexander2010-12-274-25/+61
* Bug 603762: Vertical margins between header, footer, and content are not cons...Christian Legnitto2010-12-272-4/+1
* Bug 588013: Fix typotimeless2010-12-271-1/+1
* Bug 620796: Make Bugzilla::Migrate skip abnormal fields when doingMax Kanat-Alexander2010-12-211-0/+2
* Bug 475894 - Send the 'X-Frame-Options: SAMEORIGIN' header to help protect ag...Reed Loden2010-12-181-0/+6
* Bug 313583: Relnote that long_list.cgi, showattachment.cgi and xml.cgi will b...Frédéric Buclin2010-12-161-0/+4
* Bug 617477: Fix numerous consistency and behavior issues surrounding Bug.updateMax Kanat-Alexander2010-12-135-40/+176
* Bug 618161: Make VERSION into a constant in two included extensions so thatMax Kanat-Alexander2010-12-122-4/+3
* Bug 610182: Support enabling UNCONFIRMED in all products when usingFrank Becker2010-12-101-2/+16
* Bug 617684: Values starting with a dot or an underscore are no longer hidden ...Frédéric Buclin2010-12-081-6/+0
* Bug 567953: Components which exist in several products are duplicated in tabu...miketosh2010-12-081-1/+2
* Bug 617030 - Add an error code for json_rpc_invalid_callback, and fix theMax Kanat-Alexander2010-12-062-1/+2
* Bug 542931: Bug in SOAP::Lite prevents WebService:XMLRPC logins from persistingFrédéric Buclin2010-12-061-3/+3
* Bug 607138: Don't send the Strict-Transport-Security header for theMax Kanat-Alexander2010-12-061-2/+6
* Bug 607675: In Firefox, YAHOO.util.Event.addListener/on events no longer exis...Guy Pyrzak2010-12-021-3/+5
* Bug 416784: In PostgreSQL 8.1 and newer, createuser takes the argument -R ins...Frédéric Buclin2010-11-271-3/+7
* Bug 386600: Implement auto-completion for the requestee fieldGuy Pyrzak2010-11-213-29/+26
* Bug 611891: Don't generate cookies for logins done over GET via the WebServiceMax Kanat-Alexander2010-11-141-1/+6