summaryrefslogtreecommitdiff
path: root/lib
Commit message (Collapse)AuthorAge
* cache JavaScript per templateAnika Henke2015-05-04
|
* Revert "use nav+ul element for "you are here""Andreas Gohr2015-05-02
| | | | | This reverts commit 3940c519db432ec22e8c587504d86191631f9bfb as discussed in #1082.
* Merge branch 'languagecleanup' of git://github.com/ptbrown/dokuwiki into ↵Andreas Gohr2015-05-02
|\ | | | | | | | | | | | | | | | | | | pull-request-1105 * 'languagecleanup' of git://github.com/ptbrown/dokuwiki: Remove no longer needed language string Delete unused div (Fixes #1098) Remove unused language strings Move language string to authad plugin
| * Merge branch 'authpwdexpire' into languagecleanupPatrick Brown2015-04-04
| |\
| | * Move language string to authad pluginPatrick Brown2015-03-31
| | |
* | | translation updateHudson FAS2015-04-28
| | |
* | | translation updateAlex P2015-04-24
| | |
* | | Add comment to explain purpose of folliwing linesMichael Große2015-04-23
| | |
* | | Move cursor to the end of the text in inputMichael Große2015-04-23
| | |
* | | 2 typo fixesYoven2015-04-19
| | |
* | | translation updateTomas Darius Davainis2015-04-17
| | |
* | | translation updateSchplurtz le Déboulonné2015-04-14
|/ /
* | Merge pull request #1097 from dokuwiki-translate/lang_update_35Andreas Gohr2015-04-02
|\ \ | | | | | | Translation update (pt)
| * | translation updateRomulo Pereira2015-03-31
| | |
* | | add plugin groups to config plugin testChristopher Smith2015-04-01
| | |
* | | add more plugin groups to authplain testChristopher Smith2015-04-01
|/ /
* | Merge pull request #1089 from dokuwiki-translate/lang_update_27Andreas Gohr2015-03-31
|\ \ | | | | | | Translation update (ko)
| * | translation updateMyeongjin2015-03-28
| |/
* | Merge pull request #1090 from dokuwiki-translate/lang_update_28Andreas Gohr2015-03-31
|\ \ | | | | | | Translation update (cs)
| * | translation updateJaroslav Lichtblau2015-03-28
| |/
* / translation updateAlejandro Nunez2015-03-31
|/
* Update toolbar.jschang-zhao2015-03-21
| | | When the picker button is near the border of the screen, then an opening panel of picker buttons can go over the screen edge. That's not convenient. So we should add a check in a `function pickerToggle()` and shift picker buttons position if needed.
* Merge pull request #1022 from cdwertmann/patch-1Andreas Gohr2015-03-19
|\ | | | | indexer.php: slow page loads on lighttpd due to missing ob_flush()
| * Speed up indexer on lighttpd by using tpl_flush()Christoph Dwertmann2015-03-17
| |
| * Add ob_flush() to sendGIFChristoph Dwertmann2015-02-05
| | | | | | | | | | | | | | I'm running this dokuwiki docker container: https://registry.hub.docker.com/u/mprasil/dokuwiki/ It uses lighttpd and fastcgi. For some reason, the ignore_user_abort() feature where the browser should close the connection after the GIF has been received is not working on lighty. The browser keeps loading the page until the indexer run is complete, which leads to extremely slow load times with a larger page index. Adding ob_flush() to sendGIF fixes the issue.
* | SECURITY escape user properties in user manager #1081Andreas Gohr2015-03-18
| | | | | | | | | | | | | | | | | | The user properties (login, real name, etc) where not properly escaped in the user manager's edit form. This allowed a XSS attack on the superuser by registered users. Thanks to Filippo Cavallarin from www.segment.technology for discovering this bug.
* | translation updateJacob Palm2015-03-17
| |
* | Merge pull request #1073 from sklrrzn/masterAndreas Gohr2015-03-16
|\ \ | | | | | | Add two config options to authldap
| * | Add english description for new authldap optionsSascha Klopp2015-03-16
| | |
| * | Add description for modPass-OptionSascha Klopp2015-03-13
| | |
| * | Two new authldap config options: 'userkey' denotes the LDAPSascha Klopp2015-03-03
| | | | | | | | | | | | | | | attribute holding the username, 'modPass' allows to disable password changing by the user.
* | | Merge pull request #1070 from micgro42/authadGetUserCountAndreas Gohr2015-03-16
|\ \ \ | | | | | | | | Get total number of users in ad, needed for paging
| * | | Escape user strings given to adLDAPMichael Große2015-03-12
| | | |
| * | | Explain functions in docstringsMichael Große2015-03-12
| | | |
| * | | Clean up code, add phpdoc comments, some refactoring, etc.Michael Große2015-03-12
| | | |
| * | | Disable the ``last`` button when filtering groupsMichael Große2015-03-12
| | | | | | | | | | | | | | | | | | | | | | | | Since we cannot effectively filter for groups and have to work with incremental prefetching, the ``last`` button is mostly broken/buggy. Hence it is disabled in this usecase.
| * | | When filtering for group implement prefetchingMichael Große2015-03-12
| | | |
| * | | Create and use ad search for user, name and emailMichael Große2015-03-12
| | | |
| * | | Get total number of users in ad, needed for pagingMichael Große2015-03-11
| | | |
* | | | send JavaScript with correct mimetypeAndreas Gohr2015-03-03
| |/ / |/| | | | | | | | | | | | | | | | | | | | | | | While Browsers (IE of course) still fail to accept the correct application/javascript mimetype in the type attribute of the script element, we should serve the scripts with the correct Content-Type header at least. This is especially important as the default configuration of mod_deflate expects application/javascript and will not compress text/javascript.
* | | Merge pull request #1053 from splitbrain/pageidmobileAndreas Gohr2015-02-25
|\ \ \ | |/ / |/| | simple fix for pageID clash with sidebar in mobile view
| * | remove additional sidebar bottom margin in phone modeAndreas Gohr2015-02-25
| | |
| * | simple fix for pageID clash with sidebar in mobile viewAndreas Gohr2015-02-24
| | | | | | | | | | | | | | | Since the pageid is no longer positioned absolute it clashed with the sidebar since #1027. this introduces a very simplisitc fix.
* | | translation updateSchplurtz le Déboulonné2015-02-24
| | |
* | | check permissions in ACL plugin's RPC API component. #1056Andreas Gohr2015-02-24
|/ / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Security Fix Severity: Medium Type: Remote Priviledge Escalation Remote: yes Vulnerability Details: This fixes a security hole in the ACL plugins remote API component. The plugin failed to check for superuser permissions before executing ACL addition or deletion. This means everybody with permissions to call the XMLRPC API also had permissions to set up their own ACL rules and thus circumventing any existing rules. Risk Assessment: The XMLRPC API in DokuWiki is marked experimental and off by default. It also implements an additional safeguard by giving access to a configured circle of users and groups only. So only a minor number of DokuWiki installations will be affected at all. For affected installations the risk is high if users with access to the API are not to be trusted. Thus the overall severity of medium. Resolution: Installations applying this commit are safe. A hotfix is about to be released. Meanwhile users are advised to disable the XMLRPC API in the config manager.
* | Merge pull request #1027 from splitbrain/issue-1011Andreas Gohr2015-02-24
|\ \ | | | | | | avoid messages pushing down page tools. fixes #1011
| * | fixed the margin for the sidebarAndreas Gohr2015-02-24
| | |
| * | avoid messages pushing down page tools. fixes #1011Andreas Gohr2015-02-09
| | | | | | | | | | | | | | | This moves the message area into content div. The pageid is now aligned by floating instead of absolute positioning.
* | | add bottom margin to tables in print. fixes #1052Andreas Gohr2015-02-24
| | |
* | | translation updateÁlvaro Iradier2015-02-13
| | |