Commit Graph

749 Commits

Author SHA1 Message Date
Benjamin Sonntag e806446945 [wip] fixing most found bug during big test at https://pad.lqdn.fr/p/alternc-tests-secu201605 2016-05-26 18:32:17 +02:00
Benjamin Sonntag 93ce8ffd0f htmlentities in sql_getparams + check if db not found 2016-05-23 16:37:32 +02:00
Benjamin Sonntag aef4f58e8a [wip] fixing errors brought by the big security changes... update browser preferences fix + some post/get/request messup + zip not working properly 2016-05-23 16:08:23 +02:00
Benjamin Sonntag d9d73d204c fixing most GET/REQUEST to POST if needed 2016-05-23 15:03:13 +02:00
Benjamin Sonntag b205d6bf8a [wip] CSRF check should work better now... 2016-05-23 13:59:16 +02:00
Benjamin Sonntag aaa3d68697 [wip] adding missing ehe() and eue() for htmlentities or urlencode in form fields 2016-05-23 08:27:58 +02:00
Benjamin Sonntag a956b38c00 [wip] adding missing ehe() and eue() for htmlentities or urlencode in form fields 2016-05-22 20:14:26 +02:00
Benjamin Sonntag 6043e9c3d7 [wip] securing *all* forms through CSRF management (requires a new table) 2016-05-20 14:21:47 +02:00
Benjamin Sonntag 8392c1d84f fixing quote + doms + roundcube & squirrelmail's quoting using PDO 2016-05-18 15:39:41 +02:00
Benjamin Sonntag 0c505e8b6c [security] using prepared query in the panel 2016-05-17 18:47:09 +02:00
root b28b73e913 issue #75: defines length of sql user and database names depending of the local configuration. 2016-04-27 19:04:49 +02:00
Remi 911250a73f fixes #7: show alert-info instead of alert-error when successfully changins sql users rights 2016-03-03 14:35:57 +01:00
Remi c18e3ca9f3 fixes #37 #68 2016-03-03 13:47:08 +01:00
Remi 5ab6a47862 fixes some PHP warnings 2016-03-03 12:07:38 +01:00
Remi 291572224f cosmetic fix: removed inline CSS and gives nice display for smaller screen
will give better rendering for mainstream modern browsers
2016-02-26 10:17:05 +01:00
Remi a9e057cbd1 bug fix: installed domain list was too slow due to DNS request on self managed records (gesdns=1)
bug fix: do not allow DNS modification of created domains under hosting_tld
2016-02-25 16:13:08 +01:00
Remi 6cb248aec5 Some spanish translations. Replace dutch (nederlands) with spanish in default languages (more translated strings, and larger public) 2016-02-25 14:12:41 +01:00
Remi 1c049f6bc6 bug fix: quota summary was inserted directly on main page without calling the appropriate hook. 2016-02-24 14:49:33 +01:00
Remi 3fa2b9c625 bug fix: call to bad function name (m_admin::mail_all_members() instead of m_admin::mailallmembers()) 2016-02-23 22:29:03 +01:00
Remi 983524b14b bug fix: sort in file browser to respect size and date order 2016-02-23 15:46:27 +01:00
Remi 767044fcb5 bug fixes in file editor (bad encoded file names were blank, can_edit was not called on 2 or 3 columns, also fixes a bug in date display) 2016-02-23 13:35:21 +01:00
Remi f5737e0ee6 bug fixes in adm_list: filter implementation and screen display 2016-02-23 12:02:58 +01:00
Remi 604592eedd bug fixes in ACL, wildcard on vhost, and some sql bug 2016-02-22 15:52:55 +01:00
Benjamin Sonntag 9a6cba4ebb Fix cname error not sent to user interface. Fixes #25 2016-01-14 18:15:25 +01:00
Benjamin Sonntag 6d24bd9739 fixing the Choosing of a (dns hosted only) domain name to be a master when installing a slave. Fixes #28 2016-01-14 18:07:34 +01:00
Benjamin Sonntag 48e71faa88 [fix] autocomplete honeypot field to trick firefox: prevent auto-filing of non-needed form passwords. 2016-01-14 16:24:00 +01:00
Benjamin Sonntag 6398702f74 fixing <? without php for Jessie 2015-12-22 16:56:03 +01:00
Benjamin Sonntag 3e3a9d4e83 fixing <? without php for Jessie 2015-12-22 16:53:45 +01:00
Benjamin Sonntag 3b6d527349 removing unbreakable space in php source code 2015-12-07 11:20:05 +01:00
Benjamin Sonntag 1d4a541243 fixing phpmyadmin sso 2015-11-17 10:45:20 +01:00
Benjamin Sonntag fa5ca54555 We know SHOW the 'protected' files in the browser, so that you understand why you can't edit them 2015-11-11 09:43:57 +01:00
Benjamin Sonntag d4c43a9717 adding information for noerase domains, Fixes #10 2015-09-25 18:02:23 +02:00
Benjamin Sonntag d3ab589e56 REFACTORING: code formatting of the panel + braces on if/while/for + fixe some missing or too many Globals in functions 2015-09-25 17:42:00 +02:00
Benjamin Sonntag a0575e0481 adding sort in quotas_users + update changelog 2015-07-31 15:47:51 +02:00
Benjamin Sonntag 985b23339d fixing error message '1' for locked domains 2015-07-31 15:47:11 +02:00
Benjamin Sonntag 2eadec4ae0 separating in a second table the advanced dns entries 2015-06-17 16:33:09 +02:00
Benjamin Sonntag df31733d28 ftp access security translation 2015-06-16 14:37:22 +02:00
Benjamin Sonntag 3b19a765f4 adding autocomplete='off' to any (non-login) password field, prevents firefox to fill hidden (like in the edit mail form) password field, or even non-hidden, effectively disturbing the user. 2015-06-16 13:48:13 +02:00
Benjamin Sonntag 118da88237 fixing browse for folder not working 2015-06-09 11:23:28 +02:00
Benjamin Sonntag 667bc04316 Fixing Browse For Folder not working on Domaines-type with - in their name 2015-05-12 16:07:39 +02:00
Benjamin Sonntag 1fb006b41a fixing FTP/duplicated variable bug, thanks to jon_d 2015-04-29 14:25:03 +02:00
Benjamin Sonntag 1b0ff0c48f translation to french, starting 2015-04-26 00:23:43 +02:00
Benjamin Sonntag f01accd4c2 fix catchall crappy & with bugguy error messages 2015-04-22 17:32:40 +02:00
Benjamin Sonntag f8c5872c99 fixing unzip/untar/ungzip from panel 2015-04-22 16:09:07 +02:00
Benjamin Sonntag 1ebec32e12 smaller field for languages like spanish & french 2015-04-20 19:16:56 +02:00
Benjamin Sonntag b3a1763839 adding tail log view + order by DATE last files before in logs 2015-02-11 11:29:49 +01:00
Benjamin Sonntag 616306ecc6 adding tail log view + order by DATE last files before in logs 2015-02-11 11:28:15 +01:00
Benjamin Sonntag 6b7b5ee2ba [fix] replacing %%FQDN%% in variables by , if not some things will not work (like shell scripts using mailname_bounce) 2014-11-27 16:15:18 +01:00
Benjamin Sonntag c96f928056 fixing alternc_shutdown bug 2014-08-27 11:20:54 +02:00
Benjamin Sonntag beebd51f37 fixing a bug when deleting file (double directory) 2014-08-21 11:37:48 +02:00