Commit Graph

9551 Commits (554a20fe49fe5e4b4e835edaf3d7158df7d6c6af)
 

Author SHA1 Message Date
Aleksander Machniak 554a20fe49 Fix security issue where it was possible to bypass the CSS jail in HTML messages using :root pseudo-class (#6897) 5 years ago
Aleksander Machniak c0c42d1075 Fix bug where some strict remote URIs in url() style were unintentionally blocked (#6899) 5 years ago
Aleksander Machniak d0d8c1ace5 Fix security issue where it was possible to bypass the position:fixed CSS check in received messages (#6898) 5 years ago
Thomas Bruederli f2e610dbe5 Bump version to 1.3.10 5 years ago
Jack Cherng 45e099b0be Fix implode() wrong parameter order (#6866)
It has been deprecated in PHP 7.4.

Such as PHP deprecated:  implode(): Passing glue string after array is deprecated. Swap the parameters in /var/www/roundcubemail/program/lib/Roundcube/rcube_db.php on line 917

Signed-off-by: Jack Cherng <jfcherng@gmail.com>
5 years ago
Aleksander Machniak 42c473aedd Fix wrong messages order after returning to a multi-folder search result (#6836) 5 years ago
Aleksander Machniak c25a6cf09b Fix bug in miemetype name comparator
The code was removing the first matching prefix (x- or x-ms-), which
caused 'x-ms-bmp' to end up as 'ms-bmp'. It should be 'bmp'. Fixed by
reverting the order of tokens in the regexp.
5 years ago
Aleksander Machniak 22375170df Fix bug in converting multi-page Tiff images into Jpeg (#6824)
When using 'convert' binary we have to use -flatten argument (the same
as we do with thumbnails) otherwise it will produce multiple output files
with -0, -1, etc. suffix. This way we make sure to generate only one image
until we support multi-page Tiff properly.
6 years ago
Aleksander Machniak 77c2c8155a Fix bug where selection of columns on messages list wasn't working 6 years ago
Aleksander Machniak 70622c37e6 Fix bug where Next/Prev button in mail view didn't work with multi-folder search result (#6793) 6 years ago
Aleksander Machniak d6f9b79be5 Update changelog 6 years ago
Aleksander Machniak 1cd1990053 Fix PHP error when using Net_LDAP3 from master
get_entry() method signature has changed. We don't really needed
that override in rcube_ldap_generic, so it's now removed.
6 years ago
Aleksander Machniak 37f4c7df77 Update changelog, add some tests for rcube_utils::parse_host() 6 years ago
Amir Caspi 06c5a20331 Update rcube_utils::parse_host, fixes #6746
Updated regexps used in parse_host to ensure that %t, %d, %z do not cut off domain and return only tld when underlying host has no subdomain (i.e., is just domain.tld rather than mail.domain.tld).  Update fixes #6746, now returns nothing shorter than domain.tld.

Also removed backslash from character class, period does not need to be escaped within character class.
6 years ago
Aleksander Machniak 55ebae3c1e Fix bug where bold/strong text was converted to upper-case on html-to-text conversion (6758) 6 years ago
Aleksander Machniak de25226d31 Enigma: Fix "decryption oracle" bug [CVE-2019-10740] (#6638)
When composing mail (on reply/forward/edit) we decrypt content only
in the first "content part" of the message.
6 years ago
Aleksander Machniak 8b649420ff Fix regexp 6 years ago
Aleksander Machniak f8afd18713 Enigma: Fix error message when trying to encrypt with a revoked private key (#6607) 6 years ago
Aleksander Machniak 0c828a254e Enigma: Fix bug where revoked users/keys were not greyed out in key info
The 'deleted' class was assigned to the wrong (next) row in a table.
It also didn't work in Elastic skin at all because of the missing style.
6 years ago
Aleksander Machniak cfd3d4ad38 Fix PHP Deprecated: idn_to_ascii(): INTL_IDNA_VARIANT_2003 is deprecated
Use rcube_utils::idn_to_ascii() instead of idn_to_ascii().
6 years ago
Aleksander Machniak 8b706775f3 Fix bug in parsing vCard data using PHP 7.3 due to an invalid regexp (#6744)
Looks like \R is not allowed in character class, but \r\n is fine.
On PHP 7.3.5 it throws warnings and empty result from preg_replace(),
though I couldn't reproduce.
6 years ago
Aleksander Machniak 9cb1912553 Fix bug where bmp images couldn't be displayed on some systems (#6728) 6 years ago
Aleksander Machniak 02631baf9e Managesieve: Fix so "Create filter" option does not show up when Filters menu is disabled (#6723) 6 years ago
Aleksander Machniak 7b8a183e9f Bump version to 1.3.9 6 years ago
Aleksander Machniak c4bc3341cb Merge branch 'release-1.3' of github.com:roundcube/roundcubemail into release-1.3 6 years ago
Aleksander Machniak 2b4beca128 Fix composer warning - don't use uppercase in package names 6 years ago
Aleksander Machniak 4227860adf Update tinymce languages url 6 years ago
Aleksander Machniak 0bf17668b6 Fix TinyMCE download location (#6694) 6 years ago
Aleksander Machniak 27b9448d6c Fix bug where next row wasn't selected after deleting a collapsed thread (#6655) 6 years ago
Aleksander Machniak 1dbf187a45 Fix bug when aborting dragging with ESC key didn't stop the move action (#6623)
+ small code improvements
+ focus the list on drag start to make sure it's focused state is up-to-date
  which is needed for proper keypress handling (e.g. ESC key on drag action)
6 years ago
Aleksander Machniak 5b6b1133dc Update changelog 6 years ago
Mario Harjac d87d628601 Fix missing CSRF token in message download (#6621) 6 years ago
Aleksander Machniak 52d80f2467 Fix so mime_content_type check in Installer uses files that should always be available (i.e. from program/resources) (#6599) 6 years ago
Aleksander Machniak 7db6906e37 Make "0.9 or newer" a default selection for db schema update box 6 years ago
Aleksander Machniak 1d7b488841 Fix so ANY record is not used for email domain validation, use A, MX, CNAME, AAAA instead (#6581) 6 years ago
Aleksander Machniak b7b2afc6be Fix PHP 7.2 compatibility in debug_logger plugin (#6586) 6 years ago
Aleksander Machniak 1418812c89 Fix bug in parsing some IMAP command responses that include unsolicited replies (#6577) 6 years ago
Aleksander Machniak eec0d76360 Fix regression in vcard parser 6 years ago
Aleksander Machniak 8dec8fb60a Fix handling of empty entries in vCard import (#6564) 6 years ago
Aleksander Machniak 4619f030f2 Fix bug where a message/rfc822 part without a filename wasn't listed on the attachments list (#6494) 6 years ago
Thomas Bruederli 82ebdcb3be Update copyright year 6 years ago
Thomas Bruederli b1a8a4b627 Bump version to 1.3.8 6 years ago
Aleksander Machniak a34a206b60 Fix session issue on long running requests (#6470) 6 years ago
Aleksander Machniak b11a0ed4d4 Update changelog 6 years ago
Stefanos Petrakis e3f6d4184f Fix multiple VCard field search (#6466) 6 years ago
Aleksander Machniak c22c177e53 Fix bug where valid content between HTML comments could have been skipped in some cases (#6464) 6 years ago
Aleksander Machniak d310ee5bf4 Update changelog 6 years ago
Fedor A. Fetisov 4f683c26e1 Fix support for "allow-from X" in "x_frame_options" config option (#6449) 6 years ago
Aleksander Machniak 4303c59467 New_user_identity: Fix %fu/%u vars substitution in user specific LDAP params (#6419) 6 years ago
Aleksander Machniak 0304f7c75b Managesieve: Fix bug where show_real_foldernames setting wasn't respected (#6422) 6 years ago