Commit Graph

736 Commits (postfixadmin-2.3)
 

Author SHA1 Message Date
Christian Boltz ea2103f594 CHANGELOG.TXT, debian/changelog:
- 2.3.7 release


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1651 a1433add-5e2c-0410-b055-b7f2511e0802
10 years ago
Christian Boltz 584583c9d8 functions.inc.php:
- fix SQL injection in show_gen_status()
  (backport of trunk r1639)
- update version number to 2.3.7

(+ CHANGELOG.TXT update)


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1650 a1433add-5e2c-0410-b055-b7f2511e0802
10 years ago
Christian Boltz 95f73e2a10 functions.inc.php:
- check_domains(): raise TLD limit to 13 chars - even if I seriously
  doubt someone wants to use such a long TLD ;-)
  ( https://sourceforge.net/p/postfixadmin/bugs/310/ again)



git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1638 a1433add-5e2c-0410-b055-b7f2511e0802
10 years ago
Christian Boltz 11f9f3b88c functions.inc.php
- check_domain(): update regex for new, longer TLDs like .photography
  https://sourceforge.net/p/postfixadmin/bugs/310/

(+ Changelog update)


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1636 a1433add-5e2c-0410-b055-b7f2511e0802
10 years ago
Christian Boltz 5bf296db44 functions.inc.php:
- check_email(): don't trim() mail address to avoid that aliases 
  starting with a space are allowed. This fixes 
  http://sourceforge.net/p/postfixadmin/bugs/210/ and 
  https://sourceforge.net/p/postfixadmin/feature-requests/113/

create-mailbox.php:
- revert r1520 - changing check_email() to not trim the mail address 
  is better than trim()ing the localpart

CHANGELOG.TXT:
- update for the changes above


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1622 a1433add-5e2c-0410-b055-b7f2511e0802
11 years ago
Christian Boltz e923f5842c vacation.pl:
- disable TLS by default due to a bug in Mail::Sender 0.8.22
  (https://rt.cpan.org/Public/Bug/Display.html?id=85438)
  Actually, due to a bug in Mail::Sender 0.8.21, it was never enabled ;-)
- add new config option $smtp_tls_allowed to allow enabling TLS



git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1616 a1433add-5e2c-0410-b055-b7f2511e0802
11 years ago
Christian Boltz ae2ed69138 vacation.pl:
- encode subject
  https://sourceforge.net/p/postfixadmin/bugs/272/
  https://sourceforge.net/p/postfixadmin/patches/119/



git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1598 a1433add-5e2c-0410-b055-b7f2511e0802
11 years ago
Christian Boltz 8e3c1822a6 upgrade.php:
- upgrade_318_mysql(): mark vacation_notification.notified field as
  latin1 to avoid overlong index (no upgrade function needed - if it
  broke before, upgrade.php bailed out)
  http://sourceforge.net/p/postfixadmin/discussion/676076/thread/0c919cfd/


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1521 a1433add-5e2c-0410-b055-b7f2511e0802
11 years ago
Christian Boltz 48ebe9c317 create-mailbox.php:
- trim() localpart to avoid mailbox names with leading space

CHANGELOG.TXT:
- also add forgetten entry for setup.php r1498



git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1520 a1433add-5e2c-0410-b055-b7f2511e0802
11 years ago
Christian Boltz d08d29caff - explicitely specify (empty) values for description and transport when
creating the "ALL" domain to fix problems with strict SQL mode in MariaDB
  https://sourceforge.net/p/postfixadmin/bugs/288/


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1498 a1433add-5e2c-0410-b055-b7f2511e0802
11 years ago
Christian Boltz a264e34d15 da.lang
- Translation update by Titanus <titanus AT aptget.dk>, via mailinglist


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1480 a1433add-5e2c-0410-b055-b7f2511e0802
11 years ago
Christian Boltz 0bcde914a1 edit-mailbox.php:
- when enabling/disabling a mailbox, also update the corresponding alias
  Patch by Paolo Stancato, https://sourceforge.net/p/postfixadmin/bugs/289/


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1479 a1433add-5e2c-0410-b055-b7f2511e0802
11 years ago
Christian Boltz 108e4546f0 lt.lang:
- translation update by Nerijus Baliunas <nerijus @SF>
  https://sourceforge.net/p/postfixadmin/patches/118/


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1435 a1433add-5e2c-0410-b055-b7f2511e0802
11 years ago
Christian Boltz cff1cc753d 2.3.6 release - update version at various places
git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1417 a1433add-5e2c-0410-b055-b7f2511e0802
12 years ago
Christian Boltz dc86351af6 fetchmail.php:
- fix bool and date handling for pgsql
  (patch from Christian Eberl)


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1411 a1433add-5e2c-0410-b055-b7f2511e0802
12 years ago
Christian Boltz e0f8d2d8b4 setup.php:
- fix double inclusion of config.inc.php
  https://sourceforge.net/tracker/?func=detail&atid=937964&aid=3539027&group_id=191583


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1405 a1433add-5e2c-0410-b055-b7f2511e0802
12 years ago
Christian Boltz df777553d9 templates/login.php:
- typo fix - focus the username input field
  https://sourceforge.net/tracker/?func=detail&atid=937964&aid=3538192&group_id=191583

templates/users_login.php:
- focus username input field in login form


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1404 a1433add-5e2c-0410-b055-b7f2511e0802
12 years ago
Christian Boltz 26b136ae8e templates/footer.php:
- replace footer link with link to postfixadmin.sf.net


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1402 a1433add-5e2c-0410-b055-b7f2511e0802
12 years ago
Christian Boltz c7d48cbf55 templates/list-virtual, templates/admin_list-domain:
- display domain and mailbox description with correct encoding
  This fixes a regression in 2.3.5
  https://sourceforge.net/projects/postfixadmin/forums/forum/676076/topic/4977778


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1342 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
David Goodwin fd0063bb6a fix these to aid future building
git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1340 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz 339d585ac2 functions.inc.php
- update release number to 2.3.5

CHANGELOG.TXT:
- add 2.3.5 release headline


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1335 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Norman Messtorff 894d83d3e1 Merged debian/* stuff from trunk to postfixadmin-2.3 branch
git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1334 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz fac93bf28b functions.inc.php:
- pacrypt(): escape_string() $salt for mysql_encrypt to be on the safe side


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1333 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz bf0892aa9c More XSS fixes:
create-alias.php, edit-alias.php:
- fix XSS in error message
    
templates/admin_list-domain.php:
- fix XSS (by values stored in the database) in "description" field

templates/fetchmail.php:
- fix XSS (by values stored in the database) in any field

templates/list-virtual.php:
- fix XSS (by values stored in the database) in "name" field

+ CHANGELOG.TXT update

Again, thanks to Filippo Cavallarin for pointing out those issues.


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1330 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz d60276e864 functions.inc.php:
- PHP around 5.3.8 includes hex2bin as native function - http://php.net/hex2bin
  therefore we have to wrap our function (which fortunately gives the same
  results) with function_exists().
  Reported by MadOtis on #postfixadmin


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1329 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz 71f7b03801 update CHANGELOG.TXT with latest commits/fixes
git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1325 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz 638f2755eb edit-vacation.php, templates/edit-vacation.php:
- only urlencode() $fDomain, not the whole fCanceltarget (otherwise
  the ? is also encoded, which results in a 404 error)


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1324 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz 8f5047cb20 templates/admin_create-domain.php:
- fix XSS in domain and description field
  (Thanks to Filippo Cavallarin!)


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1323 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
David Goodwin 5c4d9e48bd escape provided url better (fix XSS vuln) - thanks to Flippo Cavallarin for reporting this
git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1322 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
David Goodwin 9fb0f040c9 fix xss from poor sanitisation/checking of $_GET[domain], thanks to Flippo Cavallarin for reporting this
git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1321 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
David Goodwin 9dd00fb0a7 fix sql injection hole where value fields were not being escaped in the stored file - (thanks to Filippo Cavallarin)
git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1320 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
David Goodwin d8895ccdc2 fix sql injection hole in pacrypt if $CONF[encrypt] == mysql_encrypt (thanks to Filippo Cavallarin)
git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1319 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz ef0c84283f list-virtual.php:
- delivery to mailbox with a recipient delimiter (mailbox+foo@domain)
  was marked as "forward only"

This fixes 
https://sourceforge.net/tracker/?func=detail&aid=3420440&group_id=191583&atid=937964
reported by <stderr1> on #postfixadmin

(backport of trunk r1198)


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1199 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz 22fb5c5cb2 de.lang:
- fix typo

(backport of trunk r1182)
(not worth a changelog entry)


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1187 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz dba89ba42e functions.inc.php / create_admin():
- fix SQL injection (only exploitable by superadmins)

Reported by Matthias Bethke (msbethke@SF),
https://sourceforge.net/tracker/?func=detail&atid=937964&aid=3412484&group_id=191583

(+ changelog update for this and the previous commit)


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1185 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz d196f38dde *.lang:
- add missing pAdminDelete_admin_error text
  (already existed in trunk, but was missing in 2.3.x)

Reported by Matthias Bethke (msbethke@SF) 
https://sourceforge.net/tracker/?func=detail&atid=937964&aid=3412476&group_id=191583


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1184 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz 8d16ebdab3 update version numbers etc. for the 2.3.4 release
git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1180 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
David Goodwin 591680764a update debian/changelog in preparation of new release
git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1179 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz 1e766a2b39 CHANGELOG.TXT:
- whitespace fix - tabs vs. spaces


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1178 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz 1c76c35e6c import_users_from_csv.py:
- update FSF address (the openSUSE build check complained ;-)

(Backport of trunk r1158)


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1165 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz 19c65d5441 ADDITIONS/delete-mailq-by-domain.pl,
ADDITIONS/squirrelmail-plugin/**/postfixadmin.po:
- whitespace fix: replace DOS line ends with Linux line ends
  (no other changes)

This commit backports trunk r1160 to the 2.3 branch.


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1161 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz ac3eadc17c functions.inc.php - pacrypt():
- if dovecotpw does not give the expected output, read stderr and write
  it to error_log()
- backported from SVN trunk r1071


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1159 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz 3be1184a9b vacation.pl:
- (really) log to "mail" syslog facility

reported by Johan Meiring (jmeiring) in 
http://sourceforge.net/tracker/index.php?func=detail&aid=3086890&group_id=191583&atid=937964

This is a backport of r1073 to the SVN branch.


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1074 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz 5153b1e5b4 Text change: Logged _in_ as ... (the 'in') was missing.
This is a backport of r1062 from trunk. (Only the real change, 
not all the translator comments.)


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1063 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz 3804413c82 create-domain.php:
- force domain name to lowercase to avoid problems with PgSQL foreign keys

Reported by Munroe Sollog (roe1234@SF),
https://sourceforge.net/tracker/?func=detail&aid=3287965&group_id=191583&atid=937964
after some bughunting on #postfixadmin



git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1037 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz 86aabcfa06 list-domain.php:
- add explicit field list in SELECT to avoid PgSQL problems with custom columns

Reported by ksb (ksb4ever@SF),
https://sourceforge.net/tracker/?func=detail&aid=2859165&group_id=191583&atid=937964


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1029 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz eb8fafbc89 functions.inc.php:
- generate_password(): generate more secure random password

Based on a patch from Pierre Fagrell (mrfrenzy@SF),
https://sourceforge.net/tracker/?func=detail&aid=2958698&group_id=191583&atid=937964
(with some modifications)


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1027 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz 04e743f262 fix typo in variable name
Reported by Gabriele Vivinetto (gabrielev@SF),
https://sourceforge.net/tracker/?func=detail&aid=3266862&group_id=191583&atid=937964


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1025 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
Christian Boltz c106ecab76 de.lang:
- remove half/invalid utf-8 char in $PALANG['pCreate_dbLog_createalias']


git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1014 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago
David Goodwin bf7d3bc783 bump revision number + date to keep cboltz happy ;-)
git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/branches/postfixadmin-2.3@1010 a1433add-5e2c-0410-b055-b7f2511e0802
13 years ago