Aleksander Machniak
554a20fe49
Fix security issue where it was possible to bypass the CSS jail in HTML messages using :root pseudo-class ( #6897 )
5 years ago
Aleksander Machniak
c0c42d1075
Fix bug where some strict remote URIs in url() style were unintentionally blocked ( #6899 )
5 years ago
Aleksander Machniak
d0d8c1ace5
Fix security issue where it was possible to bypass the position:fixed CSS check in received messages ( #6898 )
5 years ago
Thomas Bruederli
f2e610dbe5
Bump version to 1.3.10
5 years ago
Jack Cherng
45e099b0be
Fix implode() wrong parameter order ( #6866 )
...
It has been deprecated in PHP 7.4.
Such as PHP deprecated: implode(): Passing glue string after array is deprecated. Swap the parameters in /var/www/roundcubemail/program/lib/Roundcube/rcube_db.php on line 917
Signed-off-by: Jack Cherng <jfcherng@gmail.com>
5 years ago
Aleksander Machniak
42c473aedd
Fix wrong messages order after returning to a multi-folder search result ( #6836 )
5 years ago
Aleksander Machniak
c25a6cf09b
Fix bug in miemetype name comparator
...
The code was removing the first matching prefix (x- or x-ms-), which
caused 'x-ms-bmp' to end up as 'ms-bmp'. It should be 'bmp'. Fixed by
reverting the order of tokens in the regexp.
5 years ago
Aleksander Machniak
22375170df
Fix bug in converting multi-page Tiff images into Jpeg ( #6824 )
...
When using 'convert' binary we have to use -flatten argument (the same
as we do with thumbnails) otherwise it will produce multiple output files
with -0, -1, etc. suffix. This way we make sure to generate only one image
until we support multi-page Tiff properly.
6 years ago
Aleksander Machniak
77c2c8155a
Fix bug where selection of columns on messages list wasn't working
6 years ago
Aleksander Machniak
70622c37e6
Fix bug where Next/Prev button in mail view didn't work with multi-folder search result ( #6793 )
6 years ago
Aleksander Machniak
d6f9b79be5
Update changelog
6 years ago
Aleksander Machniak
1cd1990053
Fix PHP error when using Net_LDAP3 from master
...
get_entry() method signature has changed. We don't really needed
that override in rcube_ldap_generic, so it's now removed.
6 years ago
Aleksander Machniak
37f4c7df77
Update changelog, add some tests for rcube_utils::parse_host()
6 years ago
Amir Caspi
06c5a20331
Update rcube_utils::parse_host, fixes #6746
...
Updated regexps used in parse_host to ensure that %t, %d, %z do not cut off domain and return only tld when underlying host has no subdomain (i.e., is just domain.tld rather than mail.domain.tld). Update fixes #6746 , now returns nothing shorter than domain.tld.
Also removed backslash from character class, period does not need to be escaped within character class.
6 years ago
Aleksander Machniak
55ebae3c1e
Fix bug where bold/strong text was converted to upper-case on html-to-text conversion (6758)
6 years ago
Aleksander Machniak
de25226d31
Enigma: Fix "decryption oracle" bug [CVE-2019-10740] ( #6638 )
...
When composing mail (on reply/forward/edit) we decrypt content only
in the first "content part" of the message.
6 years ago
Aleksander Machniak
8b649420ff
Fix regexp
6 years ago
Aleksander Machniak
f8afd18713
Enigma: Fix error message when trying to encrypt with a revoked private key ( #6607 )
6 years ago
Aleksander Machniak
0c828a254e
Enigma: Fix bug where revoked users/keys were not greyed out in key info
...
The 'deleted' class was assigned to the wrong (next) row in a table.
It also didn't work in Elastic skin at all because of the missing style.
6 years ago
Aleksander Machniak
cfd3d4ad38
Fix PHP Deprecated: idn_to_ascii(): INTL_IDNA_VARIANT_2003 is deprecated
...
Use rcube_utils::idn_to_ascii() instead of idn_to_ascii().
6 years ago
Aleksander Machniak
8b706775f3
Fix bug in parsing vCard data using PHP 7.3 due to an invalid regexp ( #6744 )
...
Looks like \R is not allowed in character class, but \r\n is fine.
On PHP 7.3.5 it throws warnings and empty result from preg_replace(),
though I couldn't reproduce.
6 years ago
Aleksander Machniak
9cb1912553
Fix bug where bmp images couldn't be displayed on some systems ( #6728 )
6 years ago
Aleksander Machniak
02631baf9e
Managesieve: Fix so "Create filter" option does not show up when Filters menu is disabled ( #6723 )
6 years ago
Aleksander Machniak
7b8a183e9f
Bump version to 1.3.9
6 years ago
Aleksander Machniak
c4bc3341cb
Merge branch 'release-1.3' of github.com:roundcube/roundcubemail into release-1.3
6 years ago
Aleksander Machniak
2b4beca128
Fix composer warning - don't use uppercase in package names
6 years ago
Aleksander Machniak
4227860adf
Update tinymce languages url
6 years ago
Aleksander Machniak
0bf17668b6
Fix TinyMCE download location ( #6694 )
6 years ago
Aleksander Machniak
27b9448d6c
Fix bug where next row wasn't selected after deleting a collapsed thread ( #6655 )
6 years ago
Aleksander Machniak
1dbf187a45
Fix bug when aborting dragging with ESC key didn't stop the move action ( #6623 )
...
+ small code improvements
+ focus the list on drag start to make sure it's focused state is up-to-date
which is needed for proper keypress handling (e.g. ESC key on drag action)
6 years ago
Aleksander Machniak
5b6b1133dc
Update changelog
6 years ago
Mario Harjac
d87d628601
Fix missing CSRF token in message download ( #6621 )
6 years ago
Aleksander Machniak
52d80f2467
Fix so mime_content_type check in Installer uses files that should always be available (i.e. from program/resources) ( #6599 )
6 years ago
Aleksander Machniak
7db6906e37
Make "0.9 or newer" a default selection for db schema update box
6 years ago
Aleksander Machniak
1d7b488841
Fix so ANY record is not used for email domain validation, use A, MX, CNAME, AAAA instead ( #6581 )
6 years ago
Aleksander Machniak
b7b2afc6be
Fix PHP 7.2 compatibility in debug_logger plugin ( #6586 )
6 years ago
Aleksander Machniak
1418812c89
Fix bug in parsing some IMAP command responses that include unsolicited replies ( #6577 )
6 years ago
Aleksander Machniak
eec0d76360
Fix regression in vcard parser
6 years ago
Aleksander Machniak
8dec8fb60a
Fix handling of empty entries in vCard import ( #6564 )
6 years ago
Aleksander Machniak
4619f030f2
Fix bug where a message/rfc822 part without a filename wasn't listed on the attachments list ( #6494 )
6 years ago
Thomas Bruederli
82ebdcb3be
Update copyright year
6 years ago
Thomas Bruederli
b1a8a4b627
Bump version to 1.3.8
6 years ago
Aleksander Machniak
a34a206b60
Fix session issue on long running requests ( #6470 )
6 years ago
Aleksander Machniak
b11a0ed4d4
Update changelog
6 years ago
Stefanos Petrakis
e3f6d4184f
Fix multiple VCard field search ( #6466 )
6 years ago
Aleksander Machniak
c22c177e53
Fix bug where valid content between HTML comments could have been skipped in some cases ( #6464 )
6 years ago
Aleksander Machniak
d310ee5bf4
Update changelog
6 years ago
Fedor A. Fetisov
4f683c26e1
Fix support for "allow-from X" in "x_frame_options" config option ( #6449 )
6 years ago
Aleksander Machniak
4303c59467
New_user_identity: Fix %fu/%u vars substitution in user specific LDAP params ( #6419 )
6 years ago
Aleksander Machniak
0304f7c75b
Managesieve: Fix bug where show_real_foldernames setting wasn't respected ( #6422 )
6 years ago