Commit Graph

3078 Commits

Author SHA1 Message Date
franck 9f5ba7ea82 Correction d'un bug empechant le tri par lettre des boites mails 2007-04-19 07:35:36 +00:00
Nahuel Angelinetti 27c70f2047 Comme php5 peut etre installé, nous utilisons le lien php qui pointe soit vers php5 soit vers php4 ( soit php6 ? ).
close: #1042
2007-04-18 16:55:34 +00:00
Antoine Beaupré aba66668b4 skip non-existent directories so that misconfigured backups don't break other user's backups 2007-04-06 18:02:22 +00:00
denis 363aa93f1a Dépendance sur courier-authmysql ou courier-authlib-mysql pour être installable dans Etch:
Aucune version du paquet courier-authmysql n'est disponible, mais il existe dans la base
de données. Cela signifie en général que le paquet est manquant, qu'il est devenu obsolète
ou qu'il n'est disponible que sur une autre source
Cependant les paquets suivants le remplacent :
  courier-authlib-mysql
2007-03-07 14:45:42 +00:00
Nahuel Angelinetti 1e87c80f8b oublis de $this-> pour l'execution de la fonction checkmx
closes: #1031
2007-02-09 12:58:33 +00:00
engelaere 2d275f8001 Traduction effacement d'un compte #687 2007-01-20 09:30:28 +00:00
Antoine Beaupré 977a9425e4 announce 0.9.6.2: a proper repackaging of 0.9.6.1 2007-01-17 21:04:18 +00:00
Antoine Beaupré 7e02add2ca fix the real problem: add postfix to the sasl group in postinst, so that we don't need postfix in pre-depends 2007-01-17 20:58:16 +00:00
Antoine Beaupré df3cc759ac déplacer postfix vers le pre-depends, car on assume que le paquet est
configuré en preinst, close #1022.

trier correctement la dépendance php-mysql, close #1023.
2007-01-14 21:27:57 +00:00
Antoine Beaupré 3bdd72980f remove apache{,-ssl} directories from templates, they're empty. also remove those and /etc/php4 from dirs because we don't install anything there anymore. Closes: #1001. 2007-01-14 20:37:28 +00:00
Antoine Beaupré 005d6379c2 Fix a race condition in update_domaines.sh that could allow users to
bypass open_basedir protections when creating domains. Reported by
jerome.

This required changing basedir_prot's behavior so that it creates the
protection even if the symlink doesn't exist, which might create extra
files that are not necessary, but "better be safe than sorry". We
could also fix this in a subsequent release.
2007-01-12 23:03:33 +00:00
Antoine Beaupré 71e5ccbb4c fix regexp in login conformity checks. Closes: #1018. Pointy hat to nahuel ([1760]) 2007-01-12 21:53:49 +00:00
Antoine Beaupré a5cdc58485 back out part of last commit: apache2 is going to require a lot more work than that and is postponed to another release 2007-01-12 21:19:11 +00:00
Antoine Beaupré 36b0a9a38f try to make alternc work with apache2: depend on apache or apache2. move mod-gzip to recommends, since alternc can perfectly live without it 2007-01-12 21:14:59 +00:00
Antoine Beaupré 8374ad5644 fix format of changelog line, again 2007-01-12 21:06:18 +00:00
Antoine Beaupré 6d355b73c9 fix format of changelog line 2007-01-12 21:05:04 +00:00
Antoine Beaupré b4b3b638d4 prepare changelog for 0.9.6.1 2007-01-12 21:04:01 +00:00
Antoine Beaupré 9ad7199f03 only reset the welcomeconfirm prompt if it gets refused so it shows up only once, on first install. See #737. This prompt should simply go away at some point, or we could modify it to tell the admin where the backups are. 2007-01-12 20:20:35 +00:00
Antoine Beaupré 8cccd4f7bd Close #1005: make sure we have a override_php.conf link in /etc/apache/conf.d 2007-01-12 20:16:20 +00:00
Rémi 3b3341f6dd modification de l'appel systeme à chown, en appel au chown builtin 2007-01-04 16:12:21 +00:00
Antoine Beaupré 7c2a0058f6 fix file deletion when in subdirectory: pass R along. also don't depend on javascript for removal (must be tested on explorer, since we rely on the name of the submit button now 2006-12-24 04:45:57 +00:00
Nahuel Angelinetti 862960c05d Ajout de la possibilité d'avoir des logins à tiret, qui ne correspondait pas avec le message d'erreur
Closes: #783
2006-12-03 20:26:58 +00:00
Antoine Beaupré de174073c2 fix typo in last commit: it the dot that forbidden on start 2006-11-29 04:07:20 +00:00
Antoine Beaupré 354e38675b remove quotemeta everywhere, and make sure variables are safe before using them. Closes: #1003 2006-11-29 04:02:41 +00:00
Nahuel Angelinetti b18b83004e Pb d'acolade bizarre.
Closes: #1002
2006-11-28 20:07:37 +00:00
Antoine Beaupré 5a13fa21d8 add a more meaningful changelog 2006-11-28 05:22:57 +00:00
Antoine Beaupré 2b74348649 put myself maintainer, keep benjamin as uploader 2006-11-28 05:18:49 +00:00
Antoine Beaupré 1952f7c8f5 merge r1751 from 0.9.6: add accent to my name 2006-11-28 05:17:34 +00:00
Antoine Beaupré 9245031133 use reload instead of force-reload since the latter doesn't seem to
work with apache
2006-11-28 03:40:44 +00:00
Antoine Beaupré 7be721c3ff faire que wc marche aussi avec le chemin absolu 2006-11-28 02:20:50 +00:00
Antoine Beaupré 0fb06110c0 rouler le bureau en register_globals
grouper les options php

Closes: #563
2006-11-28 02:19:25 +00:00
Antoine Beaupré b1dbde9d23 corriger un typo stupide 2006-11-28 01:48:50 +00:00
Antoine Beaupré 6e63ed701b use same regexp for allowed usernames as in the php code
(m_admin::add_mem())

do not quote_meta in shell command, since all variables are now
considered safe

see #998
see #427
2006-11-28 00:56:51 +00:00
Antoine Beaupré c6109e63ea use absolute path otherwise this fails on install, see #998 2006-11-28 00:49:12 +00:00
Antoine Beaupré 4404569e2b My stab at #563: stop overwriting php.ini.
Most parameters different from the factory default are now set for the
whole /var/alternc, apart from those very notable exceptions, which
are not set by Alternc anymore:

 * precision = 12 ; The number of significant digits displayed in floating point numbers.
 * y2k_compliance = On ; Enforce year 2000 compliance (will cause problems with non-compliant browsers)
 * safe_mode_allowed_env_vars = PHP_,LANG,LC_
 * highlight.*
 * max_input_time = 60 ; Maximum amount of time each script may spend parsing request data
 * log_errors_max_len = 1024 ; Do not log repeated messages. Repeated errors must occur in same file on same
 * ignore_repeated_errors = Off ; line until ignore_repeated_source is set true. * ignore_repeated_source = Off
 * report_memleaks = On
 * warn_plus_overloading = Off
 * register_globals = On ; enfin!
 * default_charset = "iso-8859-1" (see #381)
 * upload_max_filesize = 5M ; left to admin's discretion
 * default_socket_timeout = 60
 * mysql.*
 * pgsql.*
 * sybase.*
 * dbx.*
 * session.*
 * mssql.*
 * extension=mysql.so ; we assume the php-mysql packages does this properly

The cgi/ subdir was never really changed, afaict.
2006-11-27 23:52:50 +00:00
Antoine Beaupré bd8b73bf16 permettre l'utilisation de chemins complets vers des fichiers dans
convertabsolute()

utiliser seulement convertabsolute() pour verifier les fichiers dans
CreateFile... le fix de sécurité de nahuel ([1738]) empêchait toute
création de fichier.

ainsi, tout fichier passé au travers du filtre convertabsolute() va le
rendre sain pour le browser
2006-11-27 23:05:17 +00:00
Antoine Beaupré 976a0321f3 check for errors in file browser handlers, see #68 2006-11-27 22:18:57 +00:00
Antoine Beaupré 1158621261 next release is 0.9.6, not 0.9.5.2. we're heading for a release today, document a bit more things. set myself as the documentor 2006-11-27 21:29:07 +00:00
Nahuel Angelinetti b8fd27cd06 Correction de l'affichage des noms de fichiers/repertoires qui permettait d'executer du code Javascript dans le brouteur 2006-11-27 18:58:53 +00:00
Nahuel Angelinetti 7ce09ce35b Correction d'une faille permettant de creer des fichiers dans d'autres repertoires que le home du membre. 2006-11-27 18:29:23 +00:00
Nahuel Angelinetti 3f648fcf1e Corrige une faille critique permettant de creer un sous domaine pointant sur / du systÚme 2006-11-27 18:21:17 +00:00
Rémi 5f50bbaf41 correction du test "toujours vrai" qui renvoyait une erreur pour l'ajout des sous-domaines.
mais que fument-ils au Québec? ;-)
2006-11-09 20:11:16 +00:00
Nahuel Angelinetti 3857dc9ad0 On passe le path d'install d'alternc en priority low, et on rajoute un warning, il faudrait rajouter de la couleur si c'est possible pour attirer l'oeil et montrer qu'il faut faire attention
Close: #785
2006-09-15 17:16:42 +00:00
Nahuel Angelinetti 64c85bff5e Changement du path de bunzip selon les infos du package debian
Closes: #788
2006-09-15 16:46:07 +00:00
Benjamin Sonntag 87872a25a7 removing the checkdir function (useless) 2006-08-28 14:41:42 +00:00
Benjamin Sonntag e2cf5f71b2 Closes #1723 with a more elegant solution 2006-08-28 12:13:38 +00:00
Antoine Beaupré db7fe71e68 experimental feature: a harsh mass-redirection script that can be used to
temporarly turn off (by redirecting them) a user's subdomains (all of them)

temporarly, because a SQL dump is showed to allow the admin to restore the
previous state. 

experimental, because the SQL dump should probably be hidden from the admin and
that this whole thing should probably be called something else than
"deactivate" and might be better somewhere else than in adm_list.php.

harsh, because there could be other ways to deal with evil users. this is the
best solution I have found for accounts that are victims of spambots.
2006-08-12 00:04:12 +00:00
Camille Lafitte 204117ff9e suppresion d'un controle de debug dans dir_local 2006-07-22 09:39:09 +00:00
Camille Lafitte a462fdbc45 modification de dir_local afin de prendre en compte des suffixe du genre /../../chemin
see #738.
2006-07-22 03:13:41 +00:00
Camille Lafitte 39985f4de4 see #738
Ajout d'une méthode dir_local() dans functions.php. Permet de supprimer les préfixes ../ et /, ne vérifie pas si le chemin est du genre */../*.
2006-07-21 21:59:16 +00:00