Aleksander Machniak
|
d3f2759a6b
|
Fix missing message-htmlpart1 class breaking inline CSS (#6493)
|
6 years ago |
Thomas Bruederli
|
36043cb7bc
|
Bump version to 1.2.9 and copyright to 2018
|
7 years ago |
Aleksander Machniak
|
8d6d4a5de5
|
Fix regression where IMAP commands with '*' uidset argument wasn't working
|
7 years ago |
Thomas Bruederli
|
c69b851b8a
|
Fix regression in compressMessageSet()
|
7 years ago |
Thomas Bruederli
|
9f91018a16
|
Bump version to 1.2.8
|
7 years ago |
Thomas Bruederli
|
cdeb6234a2
|
Fix possible IMAP command injection vulnerability (#6229)
[CVE-2018-9846]
|
7 years ago |
Aleksander Machniak
|
8e7c2f61a3
|
Fix bug in remote content blocking on HTML image and style tags (#6178)
|
7 years ago |
Thomas Bruederli
|
987856eee2
|
Bump version + add CVE ID
|
7 years ago |
Aleksander Machniak
|
9be2224c77
|
Fix file disclosure vulnerability caused by insuficient input validation in relation with attachment plugins (#6026)
|
7 years ago |
Aleksander Machniak
|
1fd9ad242e
|
Fix (again) bug where image data URIs in css style were treated as evil/remote in mail preview (#5580)
|
7 years ago |
Aleksander Machniak
|
ead587ad59
|
Fix bug where HTML messages could have been rendered empty on some systems (#5957)
Consistently use $nodeName instead of $tagName property.
|
7 years ago |
Aleksander Machniak
|
5f0f579766
|
Ignore rewind() warnings (#5950)
|
7 years ago |
Thomas Bruederli
|
3644b02d0b
|
Bump version to 1.2.6
|
7 years ago |
Aleksander Machniak
|
d265b5756f
|
Bring back rcmail_html_container_id global
|
7 years ago |
Thomas Bruederli
|
54a3712ada
|
Modify links in html messages during Washtml DOM traversal
This is a more safe approach than using regex and mitigates
possible vulnerabilities using malformed html markup.
|
7 years ago |
Thomas Bruederli
|
fb43d2e608
|
Escape textarea contents in Washtml
|
7 years ago |
Aleksander Machniak
|
507a1e9935
|
Don't ignore (global) userlogins/sendmail logs in per_user_logging mode
|
8 years ago |
Aleksander Machniak
|
183f68f387
|
Fix uninitialized string offset in rcube_utils::bin2ascii() and make sure rcube_utils::random_bytes() result has always requested length (#5788)
|
8 years ago |
Aleksander Machniak
|
3d498cd632
|
Fix bug where it wasn't possible to set timezone to auto-detected value (#5782)
|
8 years ago |
Aleksander Machniak
|
913ffcfbbe
|
Fix SQL syntax error on MariaDB 10.2 (#5774)
|
8 years ago |
Aleksander Machniak
|
58d7cdc3fc
|
Fix addressbook searching by gender (#5757)
|
8 years ago |
Aleksander Machniak
|
9bfacb4d3c
|
Fix bug where comment notation within style tag would cause the whole style to be ignored (#5747)
|
8 years ago |
Thomas Bruederli
|
e62a7d0dfa
|
Bump version to 1.2.5
|
8 years ago |
Aleksander Machniak
|
22b34fc44b
|
Fix bug where base_dn setting was ignored inside group_filters (#5720)
|
8 years ago |
Aleksander Machniak
|
b213ee9aa0
|
Merge branch 'release-1.2' of github.com:roundcube/roundcubemail into release-1.2
|
8 years ago |
Aleksander Machniak
|
2f6ca6d672
|
Fix bug where namespace prefix could not be truncated on folders list if show_real_foldernames=true (#5695)
|
8 years ago |
Aleksander Machniak
|
0fffea28c1
|
Fix regression in LDAP fuzzy search where it always used prefix search instead (#5713)
|
8 years ago |
Aleksander Machniak
|
6a178b3a7f
|
Remove redundant spaces from generated contact names
|
8 years ago |
Aleksander Machniak
|
fa62496107
|
Fix so settings/upload.inc could not be used by plugins (#5694)
|
8 years ago |
Thomas Bruederli
|
cbd35626f7
|
Better fix for XSS in style tags (fa2824fdc )
|
8 years ago |
Aleksander Machniak
|
fa2824fdcd
|
Fix XSS issue in handling of a style tag inside of an svg element
|
8 years ago |
Thomas Bruederli
|
85a750a068
|
Bump version to 1.2.4
|
8 years ago |
Aleksander Machniak
|
801f296872
|
Fix bug where it was too easy accidentally move a folder when using the subscription checkbox (#5655)
|
8 years ago |
Aleksander Machniak
|
b1a5b76445
|
Fix update of group name in the contacts list header on group rename (#5648)
|
8 years ago |
Aleksander Machniak
|
4475037023
|
Rename $sql_arr variable to $record as it's not about sql only
|
8 years ago |
Aleksander Machniak
|
f51a101891
|
Fix regression where groups with email address were resolved to its members' addresses
|
8 years ago |
Aleksander Machniak
|
3608e0c666
|
Fix visual glitch when using disabled_actions for items in Settings menu
|
8 years ago |
Aleksander Machniak
|
a336026142
|
Fix bug where signature couldn't be added above the quote in Firefox 51 (#5628)
|
8 years ago |
Aleksander Machniak
|
04025fb297
|
Fix bug where mail content frame couldn't be reset in some corner cases (#5608)
Conflicts:
CHANGELOG
|
8 years ago |
Aleksander Machniak
|
82b826faef
|
Fix PHP error on update of a contact with multiple email addresses when using PHP 7.1 (#5587)
|
8 years ago |
Aleksander Machniak
|
1568bd9e04
|
Fix bug where external content in src attribute of input/video tags was not secured (#5583)
|
8 years ago |
Aleksander Machniak
|
f90f22ffb8
|
Fix bug where image data URIs in css style were treated as evil/remote in mail preview (#5580)
|
8 years ago |
Aleksander Machniak
|
58e63a6e70
|
Fix so group/addressbook selection is retained on page refresh
|
8 years ago |
Aleksander Machniak
|
c9b394bcad
|
Fix some advanced search issues with multiple addressbooks (#5572)
|
8 years ago |
Aleksander Machniak
|
e0d7367f1f
|
Fix adding images to new identity signatures
It already worked only on edits, because the image data for new identity
was stored in the wrong session item.
|
8 years ago |
Aleksander Machniak
|
94feab652c
|
Disable Print button for pdf attachments in Firefox (#5125)
Mozilla's PDF.js viewer does not allow printing from host page.
We try to detect such situation and disable the button to minimize
user confusion.
|
8 years ago |
Aleksander Machniak
|
79613c1e4f
|
Fix variable substitution in ldap host for some use-cases, e.g. new_user_identity (#5544)
|
8 years ago |
Thomas Bruederli
|
f04fc506b0
|
Bump version to 1.2.3
|
8 years ago |
Aleksander Machniak
|
e8fc8888a6
|
Remove leftower code from last few backports
|
8 years ago |
Aleksander Machniak
|
31df33d4e0
|
Fix regression where LDAP results could be counted incorrectly when using VLV
... broken by d08bd0a51f where we added searching in users+groups in one request
|
8 years ago |