Commit message (Collapse) | Author | Age | |
---|---|---|---|
* | - Patch #266488 by Damien Tournoud: cleanup for user_validate_name(). | Dries Buytaert | 2008-06-27 |
| | |||
* | - Patch #270045 by drewish, Susurrus: clean up return values. | Dries Buytaert | 2008-06-18 |
| | |||
* | - Patch #101543 by webchick: document all constants. | Dries Buytaert | 2008-05-26 |
| | |||
* | - Patch #259463 by dmitrig01: notification e-mail for pending user ↵ | Dries Buytaert | 2008-05-17 |
| | | | | registrations had blank subject line. | ||
* | - Patch #73874 by pwolanin: normalize the permissions table and wrote ↵ | Dries Buytaert | 2008-05-07 |
| | | | | simpletests for the (new) permission handling. At last. | ||
* | - Patch #221964 by chx, dopry, webernet, moshe, webchick, justinrandall, ↵ | Dries Buytaert | 2008-05-06 |
| | | | | | | | | | | | flobruit et al. Can you say 'registry'? Drupal now maintains an internal registry of all functions or classes in the system, allowing it to lazy-load code files as needed (reducing the amount of code that must be parsed on each request). The list of included files is cached per menu callback for subsequent loading by the menu router. This way, a given page request will have all the code it needs but little else, minimizing time spent parsing unneeded code. | ||
* | - Patch #227830 by JohnAlbin: link attributes added to l() incorrectly. | Dries Buytaert | 2008-05-02 |
| | |||
* | - Patch #249546 by pwolanin: rip menu access inheritance -- was already ↵ | Dries Buytaert | 2008-04-23 |
| | | | | committed to D6. | ||
* | - Patch #228594 by catch and flobruit: some code clean-up. | Dries Buytaert | 2008-04-19 |
| | |||
* | - Patch #245115 by kkaefer, John Morahan, JohnAlbin et al: after a long ↵ | Dries Buytaert | 2008-04-14 |
| | | | | discussion we've decided to make the concatenation operator consistent with the other operators. | ||
* | - Patch #216072 by recidive, David Rothstein, ptalindstrom et al: switched ↵ | Dries Buytaert | 2008-04-10 |
| | | | | | | | | | | | from numeric block IDs to string IDs. The short explanation is that Drupal uses a lot of numeric deltas in the block system; blocks are identified by the 'module' and the 'delta'. In early Drupal, delta was numeric, but somewhere along the line it was changed to be possibly a string. In modern Drupal, block overrides are easily done via block-MODULE-DELTA.tpl.php. The primary motivation to switch to string IDs everywhere is to make these deltas friendlier to themers: block-user-0.tpl.php --> block-user-navigation.tpl.php block-user-1.tpl.php --> block-user-login.tpl.php You get the picture. | ||
* | - Patch #244597 by drumm: remove login form text as this can now be ↵ | Dries Buytaert | 2008-04-10 |
| | | | | accomplished using hook form_alter. | ||
* | - Patch #228594 by catch et al: removed access rule functionality from core. | Dries Buytaert | 2008-04-08 |
| | | | | | | | | | | | The access rules capability of user module has been stripped down to a simple method for blocking IP addresses. E-mail and username restrictions are now available in a contributed module. IP address range blocking is no longer supported and should be done at the server level. This patch is partly motiviated by the fact that at the usability testing, it frequently came up that users went to "access rules" when trying to configure their site settings. | ||
* | - Patch #29706 by pwolanin, solardiz, et al: more secure password hashing. | Dries Buytaert | 2008-03-31 |
| | | | | | | | | | | | | | | | | | | | This is a big and important patch for Drupal's security. We are switching to much stronger password hashes that are also compatible with the Portable PHP password hashing framework. The new password hashes defeat a number of attacks, including: - The ability to try candidate passwords against multiple hashes at once. - The ability to use pre-hashed lists of candidate passwords. - The ability to determine whether two users have the same (or different) password without actually having to guess one of the passwords. Also implemented a pluggable password hashing API (similar to how an alternate cache mechanism can be used) to allow developers to readily substitute an alternative hashing and authentication scheme. Thanks all! | ||
* | - Patch #226501 by webchick: permission descriptions were used incorrectly ↵ | Dries Buytaert | 2008-03-19 |
| | | | | at admin/user/user. | ||
* | - Patch #30984 by webchick, keith.smith, kkaefer, Crell et al: provide ↵ | Dries Buytaert | 2008-02-20 |
| | | | | descriptions for permissions on the permission administration page. | ||
* | - Patch #181578 by Moshe: removed distributed authentication code from ↵ | Dries Buytaert | 2008-02-18 |
| | | | | user_save(). Factored the relevant code out to a separate function. | ||
* | - Patch #181411 by Moshe: use schema API for saving and updating user records. | Dries Buytaert | 2008-02-18 |
| | |||
* | - Patch #210131 by dvessel, catch, John, et al: updated jQuery library. | Dries Buytaert | 2008-02-06 |
| | |||
* | #216858 by jvandyk, moshe weitzman: fix plain wrong and misleading user ↵ | Gábor Hojtsy | 2008-02-03 |
| | | | | module phpdoc blocks | ||
* | #215335 by jvandyk: fix user_login_submit() phpdoc | Gábor Hojtsy | 2008-01-29 |
| | |||
* | #208888 by jvandyk: set access time when externally authenticated user first ↵ | Gábor Hojtsy | 2008-01-27 |
| | | | | logs in | ||
* | #119038 by ximo, Pancho: user role editing usability: include disabled ↵ | Gábor Hojtsy | 2008-01-22 |
| | | | | checkbox for authenticated role | ||
* | #210211 by chx, theborg: removing the broken admin user search, which would ↵ | Gábor Hojtsy | 2008-01-16 |
| | | | | provide the same as the public facing user search anyway | ||
* | #18954 by kkaefer, Pancho: built-in role names were not translated and some ↵ | Gábor Hojtsy | 2008-01-10 |
| | | | | user_roles() call cleanups | ||
* | #206078 by Pancho, traxer: order roles with system roles first (usability) | Gábor Hojtsy | 2008-01-10 |
| | |||
* | #204705 by pwolanin: abort user_save on SQL errors, to avoid data corruption | Gábor Hojtsy | 2008-01-10 |
| | |||
* | #207569 by ScoutBaker (minor code style): clean up @see usage in phpdoc blocks | Gábor Hojtsy | 2008-01-08 |
| | |||
* | - Patch #204221 by webernet: code style fixes. | Dries Buytaert | 2007-12-28 |
| | |||
* | #152497 by bjaspan, with more docs from myself: user_external_login() was ↵ | Gábor Hojtsy | 2007-12-27 |
| | | | | not updated to latest login process | ||
* | #176748 follow up by pwolanin: fix bad breadcrumbs and missing/wrong titles | Gábor Hojtsy | 2007-12-27 |
| | |||
* | #191914 by chx: admin check was missing from menu user_register_access() | Gábor Hojtsy | 2007-12-27 |
| | |||
* | - Patch #203509 by pwolanin, chx, cwgordon7 et al: fixed menu inheritenace. | Dries Buytaert | 2007-12-26 |
| | |||
* | #203274 by Pasqualle: remove excessive witespace from our code (minor) | Gábor Hojtsy | 2007-12-22 |
| | |||
* | #172993 by drewish, Lynn: remove old user picture even when the newly ↵ | Gábor Hojtsy | 2007-12-20 |
| | | | | uploaded one uses a different format | ||
* | - Patch #201894 by David Rothstein: fixed typo in user output. | Dries Buytaert | 2007-12-18 |
| | |||
* | #199387 by Pancho: revert user login/register/request password page titles ↵ | Gábor Hojtsy | 2007-12-17 |
| | | | | to 'User account' as it was in Drupal 5, instead of the bugos 'Log in' | ||
* | #110474 by dww and keith.smith: passwords are not sent in welcome mails, so ↵ | Gábor Hojtsy | 2007-12-14 |
| | | | | do not mislead our users | ||
* | #200069 by keith.smith: new standard for 'more information' links in module ↵ | Gábor Hojtsy | 2007-12-14 |
| | | | | help texts, as the handbook we referred to before was renamed | ||
* | #131493 by spatz4000, ChrisKennedy, keith.smith: consistent username field ↵ | Gábor Hojtsy | 2007-12-14 |
| | | | | description wording in installer and runtime interface | ||
* | #152497 by JohnAlbin, bdragon, moshe weitzman, chx and myself: several user ↵ | Gábor Hojtsy | 2007-12-13 |
| | | | | login tasks, such as session id regeneration were not performed in all cases, so centralize this | ||
* | #197297 by DanW (as GHOP 17), and keith.smith: clean up lots of help texts, ↵ | Gábor Hojtsy | 2007-12-13 |
| | | | | update to drag and drop functionality, drupal.module removal, etc | ||
* | #198579 by webernet and hswong3i: a huge set of coding style fixes, including: | Gábor Hojtsy | 2007-12-08 |
| | | | | | | | | - whitespaces at end of lines - indentation - control structure usage - whitespace in empty lines - phpdoc comment formatting | ||
* | - Patch #163246 by keith smith, freso, O Govinda, catch, webchick et al: ↵ | Dries Buytaert | 2007-11-26 |
| | | | | fixed minor spelling issues and fixed spacing issues. | ||
* | #111481 by chx and pwolanin: profile categories may contain slashes, but ↵ | Gábor Hojtsy | 2007-11-26 |
| | | | | this was not yet supported by the user object menu loader | ||
* | - Patch #192110 by profix898: fixed hook_profile_alter API. | Dries Buytaert | 2007-11-20 |
| | |||
* | #192692 by jrbeeman and mfer: (security) protect profile category page menu ↵ | Gábor Hojtsy | 2007-11-19 |
| | | | | items with the visibility settings already available | ||
* | - Patch #191914 by chx: you cannot add user/register to a menu. Also ↵ | Dries Buytaert | 2007-11-17 |
| | | | | removed some whitespace. | ||
* | #25605 by Rob Loach et al: disallow editing user data of uid 0 | Gábor Hojtsy | 2007-11-14 |
| | |||
* | #171117 by JirkaRybka: set access time for admin created or edited accounts ↵ | Gábor Hojtsy | 2007-11-06 |
| | | | | so they are exempt from the spam protection we have for accounts never logged in |