Commit Graph

1499 Commits

Author SHA1 Message Date
Remi 611e41a31b bug fix: set success class to alert-success insted of alert-error after successful mailbox parameters update 2017-02-07 10:20:33 +01:00
Remi 4a2d1dcbdf bug fix undelete mail 2017-01-24 18:29:13 +01:00
Remi 20dab5677a bug fixes variable $dom_id et non $domain_id 2017-01-24 17:52:29 +01:00
John Soros bec836f87b latest security update of phpmyadmin seems to have disabled the indexes so we need to explicitely redirect to .../index.php 2017-01-20 17:41:52 +01:00
thms cb56e77093 m_dom now refuses cname on its apex 2016-11-04 12:00:24 +01:00
Benjamin Sonntag 1dc41d5530 [fix] missing csrf on mail_manage_catchall.php 2016-10-27 16:32:49 +02:00
Benjamin Sonntag fc068bc938 [fix] invalid token at login time 2016-08-29 16:55:05 +02:00
Benjamin Sonntag 4f3604e717 [FIX] #83 issue with FTP file with wrong rights. 2016-08-26 16:31:19 +02:00
Benjamin Sonntag 1d9e478f2e [FIX] Undefined variable: res at upgrade time 2016-08-26 15:51:01 +02:00
Benjamin Sonntag 5ef516e0ba Merge branch 'stable-3.1' of github.com:AlternC/AlternC into stable-3.1 2016-08-09 16:44:34 +02:00
Benjamin Sonntag 16bd8278a4 [fix] allow HTTPS on any panel (you'd better use letsencrypt then, but that's a valid choice. Fixes #106 2016-08-09 16:44:30 +02:00
Benjamin Sonntag 42eac1173d Merge pull request #107 from AlternC/albancrommer-patch-1
Update config.php to allow HTTPS on other VHOSTS
2016-08-09 16:43:37 +02:00
Benjamin Sonntag a35288b91e [fix] the file editor allows an invalid token. Tell the user and give a new one to re-submit. Fixes #111 2016-08-09 16:40:11 +02:00
Remi 0c840f9f2e bug fix: remove old references to unknown 'bw_web' quota values linking to not existing stats_show_per_month.php page and menu gadget
(anyone aiming to display custom menu gadget or size based quota could return in_menu=1 and type=size array values in hook_quota_get() function)
2016-07-15 18:40:29 +02:00
Alban Crommer 04c36baa77 Update config.php
See Issue #106

AlternC should allow HTTPS panel access for different host names
2016-07-13 12:19:33 +02:00
Benjamin Sonntag ade5c51f0f Merge branch 'stable-3.1' of github.com:AlternC/AlternC into stable-3.1 2016-07-12 15:54:30 +02:00
Benjamin Sonntag 3ffa78aa5f [fix] fixing db issue when creating a DB + post/request for SQLRESTORE 2016-07-12 15:54:21 +02:00
Remi 1b73dff3a5 bug fix: sub admin were proposed to install hosting_tld for new user, but the domain creation silently failed 2016-07-07 12:59:56 +02:00
Benjamin Sonntag e381692cbd [fix] deleting a domain didn't work (post/request check) 2016-05-31 12:13:57 +02:00
Benjamin Sonntag 9057254059 [i18n] updating translations 2016-05-26 18:38:16 +02:00
Benjamin Sonntag e806446945 [wip] fixing most found bug during big test at https://pad.lqdn.fr/p/alternc-tests-secu201605 2016-05-26 18:32:17 +02:00
Benjamin Sonntag 93ce8ffd0f htmlentities in sql_getparams + check if db not found 2016-05-23 16:37:32 +02:00
Benjamin Sonntag aef4f58e8a [wip] fixing errors brought by the big security changes... update browser preferences fix + some post/get/request messup + zip not working properly 2016-05-23 16:08:23 +02:00
Benjamin Sonntag d9d73d204c fixing most GET/REQUEST to POST if needed 2016-05-23 15:03:13 +02:00
Benjamin Sonntag b205d6bf8a [wip] CSRF check should work better now... 2016-05-23 13:59:16 +02:00
Benjamin Sonntag 23a438de99 [wip] csrf check: moving the check to the right place: before authentication 2016-05-23 08:33:32 +02:00
Benjamin Sonntag aaa3d68697 [wip] adding missing ehe() and eue() for htmlentities or urlencode in form fields 2016-05-23 08:27:58 +02:00
Benjamin Sonntag a956b38c00 [wip] adding missing ehe() and eue() for htmlentities or urlencode in form fields 2016-05-22 20:14:26 +02:00
Benjamin Sonntag de5837750e same random system everywhere : mt_rand() 2016-05-22 17:40:57 +02:00
Benjamin Sonntag 6043e9c3d7 [wip] securing *all* forms through CSRF management (requires a new table) 2016-05-20 14:21:47 +02:00
Benjamin Sonntag d9bdfaf1ac [wip] adding csrf form management, to be added everywhere 2016-05-19 17:04:49 +02:00
Benjamin Sonntag 7b1e5bba94 [wip] m_mail LIMIT shall not be quoted 2016-05-18 18:41:27 +02:00
Benjamin Sonntag 424b2a9ce7 [wip] more PDO fixes 2016-05-18 18:24:40 +02:00
Benjamin Sonntag b1ca1d88ae fixing PDO for MySQL class and spoolsize (adding exec() for direct queries, manage properly query() call without arguments (no prepare, allow show database) 2016-05-18 18:00:04 +02:00
Benjamin Sonntag 8392c1d84f fixing quote + doms + roundcube & squirrelmail's quoting using PDO 2016-05-18 15:39:41 +02:00
Benjamin Sonntag b6eb1e668c fixing get_remote_ip() quoting 2016-05-18 15:12:49 +02:00
Benjamin Sonntag 06076b6fe0 moving https check down to AFTER hook/err initialization 2016-05-18 15:04:19 +02:00
Emmanuel Monbroussou 4e558e5e7c [wip] Passing mysql request params into array arguments for the query method (part 4) 2016-05-18 12:51:03 +02:00
Emmanuel Monbroussou 61b07a257d [wip] Passing mysql request params into array arguments for the query method (part 3) 2016-05-18 11:19:20 +02:00
Emmanuel Monbroussou 86e7bfb6b8 Merge branch '20160515-secu' of github.com:AlternC/AlternC into 20160515-secu 2016-05-17 18:58:25 +02:00
Emmanuel Monbroussou 3665aabc96 [wip] Passing mysql request params into array arguments for the query method (part 2) 2016-05-17 18:57:01 +02:00
Benjamin Sonntag 0c505e8b6c [security] using prepared query in the panel 2016-05-17 18:47:09 +02:00
Emmanuel Monbroussou 262336aadb [wip] Passing mysql request params into array arguments for the query method (part 1) 2016-05-17 17:21:08 +02:00
Emmanuel Monbroussou bc5c8f7e34 Merge branch 'pdo_migration' into 20160515-secu
Conflicts:
	bureau/class/config.php
	bureau/class/db_mysql.php
	bureau/class/m_action.php
	bureau/class/m_variables.php
2016-05-17 15:10:37 +02:00
Remi 28f09e31e1 More explicit message for sql names length limit 2016-04-28 12:54:53 +02:00
root b28b73e913 issue #75: defines length of sql user and database names depending of the local configuration. 2016-04-27 19:04:49 +02:00
Benjamin Sonntag c8353f3f21 initialize , Fixes #56 2016-03-13 13:23:11 +01:00
Remi 6388489d4f bug fix: Quota use was different when switching language
use of str_pad inside get_size_unit() was removing decimal part due to localization issues (coma separator instead of dot)
2016-03-09 10:58:19 +01:00
Remi 06fdadbcd0 bug fix: rediction to https was called inside shell call 2016-03-03 16:20:41 +01:00
Remi d041bcbeca fix test if variables is set 2016-03-03 16:06:38 +01:00
Remi 2bf3f45466 bug fix #40: force_https variable was disabled by commit bbd913e6e6
now redirects peacefully a client when connecting to non SSL panel.
2016-03-03 15:08:27 +01:00
Remi 911250a73f fixes #7: show alert-info instead of alert-error when successfully changins sql users rights 2016-03-03 14:35:57 +01:00
Remi c18e3ca9f3 fixes #37 #68 2016-03-03 13:47:08 +01:00
Remi 5ab6a47862 fixes some PHP warnings 2016-03-03 12:07:38 +01:00
Remi 9ec0668da5 bug fix: mailman wrappers were not added if mail quota was over 2016-03-03 11:28:26 +01:00
Remi 1fe966f5d8 bug fixes: spf and dmarc record weren't updated for every domain due to loss in mysql result query buffer 2016-03-02 14:17:32 +01:00
Remi 925674cf1e translation fix: el tuteo es mas corriente en los sitios web de nuevas tecnologías 2016-02-26 10:39:07 +01:00
Remi 291572224f cosmetic fix: removed inline CSS and gives nice display for smaller screen
will give better rendering for mainstream modern browsers
2016-02-26 10:17:05 +01:00
Remi a9e057cbd1 bug fix: installed domain list was too slow due to DNS request on self managed records (gesdns=1)
bug fix: do not allow DNS modification of created domains under hosting_tld
2016-02-25 16:13:08 +01:00
Remi 7eb64f08a5 Merge branch 'stable-3.1' of github.com:AlternC/AlternC into stable-3.1 2016-02-25 14:17:43 +01:00
Remi 6cb248aec5 Some spanish translations. Replace dutch (nederlands) with spanish in default languages (more translated strings, and larger public) 2016-02-25 14:12:41 +01:00
Benjamin Sonntag b867d5a4dd Merge pull request #24 from GuillaumeFromage/stable-3.1
Added support for .co, which has the same layout as .cc (need another patch to add it to TLD table)
2016-02-24 16:12:02 +01:00
Benjamin Sonntag 9f8c2a8e1e Merge pull request #58 from asso-infini/patch-1
Update m_bro.php to manager bz2
2016-02-24 16:11:03 +01:00
Remi 1c049f6bc6 bug fix: quota summary was inserted directly on main page without calling the appropriate hook. 2016-02-24 14:49:33 +01:00
Remi 79097f48da bug fix: correct typo in the last commit 2016-02-24 11:15:55 +01:00
Remi 6e3a496f25 bug fixes: some fixes in english translation. didn't modify the original source file as it would have repercussion on other languages
(also modified the translation for España, was using the norwegian "spania" term)
2016-02-24 11:11:15 +01:00
Remi 3fa2b9c625 bug fix: call to bad function name (m_admin::mail_all_members() instead of m_admin::mailallmembers()) 2016-02-23 22:29:03 +01:00
Remi 983524b14b bug fix: sort in file browser to respect size and date order 2016-02-23 15:46:27 +01:00
Remi 767044fcb5 bug fixes in file editor (bad encoded file names were blank, can_edit was not called on 2 or 3 columns, also fixes a bug in date display) 2016-02-23 13:35:21 +01:00
Remi f5737e0ee6 bug fixes in adm_list: filter implementation and screen display 2016-02-23 12:02:58 +01:00
Remi 604592eedd bug fixes in ACL, wildcard on vhost, and some sql bug 2016-02-22 15:52:55 +01:00
asso-infini 76895cf5fe Update m_bro.php
Gestion des archives dont l'extension est .bz, .bz2, .Z, .tgz, tbz ou tbz2 
Si on a réussi à traiter l'archive, on n'essaye pas de la traiter une nouvelle fois.
Dans le cas de l'utilisation de la commande tar, on utilise plutôt les id proprietaire et groupe des fichiers plutot que le nom des proprietaires et groupes des fichiers avec l'option --numeric-owner
2016-02-15 21:16:22 +01:00
Benjamin Sonntag 02ec16253b Better fix for cname message, Fixes #25 2016-01-18 17:05:35 +01:00
Benjamin Sonntag 1b61e78a11 fixing display of DB Size in MySQL. Fixes #31 2016-01-18 17:02:46 +01:00
Benjamin Sonntag 6c6013e147 spit out a Warning when editing a mailbox without POP OR RECIPIENTS. Fixes #18 2016-01-15 15:13:12 +01:00
Benjamin Sonntag 9a6cba4ebb Fix cname error not sent to user interface. Fixes #25 2016-01-14 18:15:25 +01:00
Benjamin Sonntag 6d24bd9739 fixing the Choosing of a (dns hosted only) domain name to be a master when installing a slave. Fixes #28 2016-01-14 18:07:34 +01:00
Benjamin Sonntag 48e71faa88 [fix] autocomplete honeypot field to trick firefox: prevent auto-filing of non-needed form passwords. 2016-01-14 16:24:00 +01:00
Benjamin Sonntag 5f4b6ebb7b fixing #26: not allowing underscore in domain names (except at the beginning of a domain member, like _tcp) 2016-01-13 17:26:47 +01:00
Benjamin Sonntag 6398702f74 fixing <? without php for Jessie 2015-12-22 16:56:03 +01:00
Benjamin Sonntag 3e3a9d4e83 fixing <? without php for Jessie 2015-12-22 16:53:45 +01:00
Guillaume Barbe 9a4594fd82 Added support for .co, which has the same layout as .cc 2015-12-07 13:24:32 -05:00
Benjamin Sonntag 3b6d527349 removing unbreakable space in php source code 2015-12-07 11:20:05 +01:00
Benjamin Sonntag 1d4a541243 fixing phpmyadmin sso 2015-11-17 10:45:20 +01:00
Benjamin Sonntag fbce91bb39 put comment on the sleep() 2015-11-16 08:27:56 +01:00
Benjamin Sonntag bffd7021c6 update missing FR translations 2015-11-11 09:48:07 +01:00
Benjamin Sonntag fa5ca54555 We know SHOW the 'protected' files in the browser, so that you understand why you can't edit them 2015-11-11 09:43:57 +01:00
Benjamin Sonntag edf639d048 fixing a visual bug when uncompressing a .tar.gz file 2015-11-05 18:31:16 +01:00
Benjamin Sonntag bcf093ffa7 fixing a visual bug when uncompressing a .tar.gz file 2015-11-05 18:25:27 +01:00
Benjamin Sonntag 4cfa74401c fixing missing value2 affectation 2015-11-05 18:07:38 +01:00
Benjamin Sonntag eba60af8b9 fixing #12 eu domain warning from php 2015-11-05 17:40:17 +01:00
Benjamin Sonntag d4c43a9717 adding information for noerase domains, Fixes #10 2015-09-25 18:02:23 +02:00
Benjamin Sonntag d3ab589e56 REFACTORING: code formatting of the panel + braces on if/while/for + fixe some missing or too many Globals in functions 2015-09-25 17:42:00 +02:00
Benjamin Sonntag 3e42567048 REFACTORING: code formatting of the panel + braces on if/while/for + fixe some missing or too many Globals in functions 2015-09-25 00:01:04 +02:00
Benjamin Sonntag d4be9fddbf fixing s in hooks 2015-09-02 12:09:55 +02:00
Benjamin Sonntag b71619c6f5 fixing some missing GLOBAL + issue with variables_set 2015-09-02 11:30:40 +02:00
Benjamin Sonntag 179f4dd580 fixing password policy issue with levensthein 2015-08-03 15:55:05 +02:00
Benjamin Sonntag a0575e0481 adding sort in quotas_users + update changelog 2015-07-31 15:47:51 +02:00
Benjamin Sonntag 985b23339d fixing error message '1' for locked domains 2015-07-31 15:47:11 +02:00
Benjamin Sonntag 5a108d67b9 fixing dmarc subdomain 2015-07-31 11:57:29 +02:00