Frank Karlitschek
24d14783d7
added a serverProtocol function that correctly returns the used protocol even if the ssl connection is terminated at a reverse_proxy or at a load balancer
2012-06-01 10:38:44 +02:00
Frank Karlitschek
a72e6cc113
fix oc-780
2012-05-31 21:28:58 +02:00
Frank Karlitschek
d4ea853fcf
use our own serverHost call so that ownCloud works with reverse proxy servers
2012-05-31 20:26:09 +02:00
Sam Tuke
ec0c0f3907
Added & improved documentation
2012-05-31 17:57:34 +01:00
Sam Tuke
ef60dcc23e
fixed typo
2012-05-31 17:38:35 +01:00
Sam Tuke
6b3df8ae9c
Improved class comment block
2012-05-31 17:32:34 +01:00
Sam Tuke
8744b09959
added extensive class comment based on icewind's January list email
2012-05-31 17:02:35 +01:00
Sam Tuke
fc400e06c3
fixed typos in var names
2012-05-31 14:53:52 +01:00
Sam Tuke
43fcae0409
clarified comment
2012-05-31 14:50:41 +01:00
Bart Visscher
a33f580db1
Remove OC_App::register function
...
The data supplied is never used in OwnCloud. Removed the call from all the apps, and made the public API function empty.
2012-05-31 13:01:30 +02:00
Bart Visscher
4434016a8b
Whitespace fixes
2012-05-31 13:01:30 +02:00
Frank Karlitschek
22a04d8e93
don´t hardcode /tmp
2012-05-30 14:14:32 +02:00
Michael Gapczynski
fbe58755e5
Restrict requested app to apps directory
2012-05-29 12:31:47 -04:00
Frank Karlitschek
982cde0bb1
check during ownCloud upgrade if all the installed apps are compatible with the new ownCloud version. Disable them if not
2012-05-26 20:37:10 +02:00
Frank Karlitschek
a945fa10a6
update copyright
2012-05-26 19:14:24 +02:00
Frank Karlitschek
dfd5a9759c
only enable compatible apps
2012-05-25 11:31:46 +02:00
Brice Maron
9c2a6fb551
Add HEAD request management for files ajax/download.php
2012-05-24 22:48:10 +00:00
Frank Karlitschek
24318354f2
changed the default from Berlin to UTC.
...
Greetings form Berlin by the way ;-)
2012-05-24 00:49:21 +02:00
Robin Appelman
60fdc13ae6
enable running unit tests from cli
2012-05-22 20:22:53 +02:00
Florian Hülsmann
d2e2a2b2c0
prevent apps from printing output from app.php
2012-05-22 13:10:42 +02:00
Robin Appelman
cb23bae8d9
dont throw errors when apps dont have types configured
2012-05-20 18:52:03 +02:00
Robin Appelman
f00b57f8be
files app is always enabled
2012-05-20 18:52:03 +02:00
Frank Karlitschek
c0db603d29
this is 5 pre alpha now
2012-05-19 18:21:33 +02:00
Frank Karlitschek
7e49a33d64
getStorage belongs to files not to apps.
2012-05-19 10:44:08 +02:00
Frank Karlitschek
08f7d4c552
document the public classes a bit more
2012-05-19 10:36:57 +02:00
Robin Appelman
a2cc772aa5
dont run update scripts for apps that arent enabled
2012-05-19 02:00:46 +02:00
Robin Appelman
b096fd9ed8
log upgrades
2012-05-19 01:55:20 +02:00
Robin Appelman
df64b9b0e9
strict standards fixes for sqlite3
2012-05-19 01:39:41 +02:00
Michael Gapczynski
90cbc32c77
Fix redirect after login, prevent open redirects
2012-05-18 16:56:48 -04:00
Frank Karlitschek
16224e5e8b
"fopen(" interferes with our own classes.
...
remove it for now and let´s fix this later
2012-05-18 18:22:37 +02:00
Frank Karlitschek
2d3c709163
Merge branch 'master' of gitorious.org:owncloud/owncloud
2012-05-18 15:56:15 +02:00
Frank Karlitschek
db77dc91bc
only try to install apps that are compatible with oC4
2012-05-18 15:54:36 +02:00
Frank Karlitschek
2e9115efe0
increase to RC2
2012-05-18 15:54:17 +02:00
Michiel de Jong
a6ff909911
this code looks wrong to me but i'm putting it back while we find out what the right code should look like
2012-05-18 15:39:28 +02:00
Michiel de Jong
1a874b4c56
make redirect safe by restricting it to current host
2012-05-18 15:32:41 +02:00
Michiel de Jong
9b5e8a2c63
fix redirect to desired page after login
2012-05-18 15:11:01 +02:00
Robin Appelman
48505c5626
improve tar archive backend
2012-05-18 01:54:59 +02:00
Robin Appelman
c1ba4deb72
when scanning a folder that is a mountpoint, use the root of the mount for checking if a folder is writable instead of the folder
2012-05-17 01:47:58 +02:00
Robin Appelman
aac9629e88
add support for custom ports for mysql/pgsql by adding :portnumber to the database host
2012-05-17 01:06:22 +02:00
Robin Appelman
5fe7200a7f
update documentation of oc_user::checkpassword
2012-05-17 00:57:43 +02:00
Robin Appelman
2c99924f7d
make sure the group exists in the backend before adding a user to it
2012-05-17 00:47:43 +02:00
Sam Tuke
22dd155e4d
Merge branch 'unstable' of gitorious.org:owncloud/owncloud into unstable
2012-05-16 18:30:35 +01:00
Sam Tuke
9acd1065b0
made initial testing version of expireAll for version control \ngave some old vars new camelcase names
2012-05-16 18:30:26 +01:00
Bart Visscher
c645a7d0f8
Fix empty jsfiles and cssfiles in layout template
2012-05-16 18:53:46 +02:00
Bart Visscher
ce1e4425c2
Combine and minimize core and default app js files
2012-05-16 18:53:46 +02:00
Bart Visscher
f71fec8cdc
Combine and minimize core and default app css files
2012-05-16 18:53:46 +02:00
Bart Visscher
2faae817f1
Template: Fix var name
2012-05-16 18:53:46 +02:00
Bart Visscher
6d20fe4012
Template: Make getFormFactorExtension function public
2012-05-16 18:53:46 +02:00
Bart Visscher
b39f01fce6
Comment spelling fix
2012-05-16 18:52:40 +02:00
Bart Visscher
5d72681d10
Better place to check caching headers
2012-05-16 18:52:40 +02:00
Arthur Schiwon
01b366df80
avoid corrupt ZIP files on lighttpd, should fix oc-467
2012-05-15 11:57:24 +02:00
Thomas Mueller
583dce5276
removing executable bit - again
2012-05-15 00:52:00 +02:00
Robin Appelman
6779f28af4
cache app types during install or update
2012-05-14 22:49:31 +02:00
Thomas Mueller
bda2dbec1f
Prevent Clickjacking by adding additional headers:
...
header('X-Frame-Options: Sameorigin');
header('X-XSS-Protection: 1; mode=block');
header('X-Content-Type-Options: nosniff');
Thanks to Lukas Reschke for reporting this issue (and many more).
2012-05-14 15:34:28 +02:00
Robin Appelman
e7c106d91e
selective app loading for remote/public
2012-05-14 00:28:28 +02:00
Michael Gapczynski
a332c39472
Check if path_info is empty as well, fixes bug oc-632. Thanks to die3lustigen2.
2012-05-13 15:26:30 -04:00
Robin Appelman
8d475debe0
additional logging when db upgrade fails
2012-05-13 21:21:39 +02:00
Robin Appelman
1a2ab2ef68
prevent user creation with empty password
2012-05-13 20:53:56 +02:00
Thomas Tanghus
3926e2d4f3
VCategories: Made a small check for categories that seems to resolv the problems in Calender. Also reverts the changes from 9e6221b229
.
2012-05-13 15:07:07 +02:00
Thomas Tanghus
9e6221b229
VCategories: Suppress error messages stemming from import from file app.
2012-05-13 09:16:53 +02:00
Frank Karlitschek
af77ce9a9b
This is RC now
2012-05-13 05:11:10 +02:00
Robin Appelman
9eb91a111d
update to jquery 1.7.2
2012-05-12 00:37:19 +02:00
Brice Maron
5b7c69f978
Change sqlite escaping of identifier to double quote. Fixing some issues
2012-05-11 19:45:53 +00:00
Bart Visscher
919681f3e6
Make processed css files cachable
2012-05-11 21:33:02 +02:00
Bart Visscher
97233b77cd
Remove DOCUMENTROOT static var, and make SUBURI var private
2012-05-11 21:31:51 +02:00
Robin Appelman
847832ae77
also set remote/public paths on installing apps
2012-05-11 20:58:23 +02:00
Robin Appelman
d12021e3c4
fix sqlite3 driver against updated MDB2
2012-05-11 20:56:02 +02:00
Robin Appelman
cf3940425f
don't do the initial scanning of the users home folder trough the update system
2012-05-11 20:49:19 +02:00
Robin Appelman
0622fa79ba
add temporary filestorage backend for testing purposed
2012-05-11 20:33:56 +02:00
Robin Appelman
b40f9670ae
allow clearing hooks and fileproxies
2012-05-11 20:33:56 +02:00
Robin Appelman
736739bbbd
load remote and public paths from info.xml during upgrade instead of setting them every time
2012-05-11 20:33:56 +02:00
Michiel de Jong
c99d7dd94f
the ',last' breaks all other rewrite rules and is also not there in the committed .htaccess, so removing it. anybody know why it was there?
2012-05-11 17:59:21 +02:00
Michiel de Jong
347ce2aafa
match setup script to .htaccess from repo
2012-05-11 17:30:27 +02:00
Michiel de Jong
4462b26160
oops, typo in lib/setup.php
2012-05-11 17:09:10 +02:00
Michiel de Jong
2dff357a4e
add new htaccess things into setup script too
2012-05-11 17:06:04 +02:00
Georg Ehrke
8f2217ca2e
make default app choosable
2012-05-11 13:56:52 +02:00
Tom Needham
709b0a1ddc
Check if app is enabled before exporting its data
2012-05-10 23:06:53 +00:00
Michael Gapczynski
de95bf62a2
Prevent any null bytes related exploits, thanks to Lukas Reschke
2012-05-10 11:44:06 -04:00
Michael Gapczynski
d9fbdae758
Prevent XSS exploit by checking if path-info is set, thanks to Lukas Reschke
2012-05-10 10:26:12 -04:00
Sam Tuke
b055ebc1fc
added documentation to OCP namespace
2012-05-10 14:19:17 +01:00
Bart Visscher
c2230580c1
Remove unused OC static variable CONFIG_DATADIRECTORY_ROOT
2012-05-10 09:14:27 +02:00
Bart Visscher
b022ccb863
Whitespace fixes
2012-05-10 09:14:26 +02:00
Bart Visscher
e77ba0280a
Implement default functions in OC_Group backend
...
Simplifies calling these functions, and makes code simpler
functions:
inGroup
getUserGroups
getGroups
usersInGroup
2012-05-10 09:14:26 +02:00
Bart Visscher
ac2e0cd6e4
Implement default functions in OC_User backend
...
Simplifies calling these functions, and makes code simpler
functions:
deleteUser
getUsers
userExists
2012-05-10 09:14:26 +02:00
Bart Visscher
a9d7c67bf2
The log message is not always shown in html
...
The log message can also be logged with syslog, here we don't want to have html-entities. Also the log messages through json are displayed as text not html.
2012-05-10 09:13:09 +02:00
Michael Gapczynski
798e6aa40b
Merge commit 'refs/merge-requests/100' of git://gitorious.org/owncloud/owncloud into merge-requests/100
2012-05-09 17:50:14 -04:00
Robin Appelman
03f66c6351
also scan new folders when checking for updates
...
it might cause long load times but seems the best for now
2012-05-09 20:35:12 +02:00
Georg Ehrke
bc60b8d87a
fix bug in public api
2012-05-09 18:33:40 +02:00
Philipp Roggan
bba434ca37
fixed typo in lib/public/util.php:106 (varname to )
2012-05-09 15:17:40 +02:00
Michael Gapczynski
051442bc76
Sanitize redirect urls
2012-05-08 17:41:50 -04:00
Tom Needham
9c47346373
Protect admin from evil log messages
2012-05-08 19:41:31 +00:00
Georg Ehrke
52717d2a1b
remove comments
2012-05-08 17:07:50 +02:00
Brice Maron
9921ca11b5
Add protection for non-authorized char in installation form
2012-05-07 22:12:30 +00:00
Frank Karlitschek
43978abd80
increase to 4 beta
2012-05-07 22:58:22 +02:00
Frank Karlitschek
10d291d6b3
Merge branch 'master' of gitorious.org:owncloud/owncloud
2012-05-07 22:56:34 +02:00
Frank Karlitschek
40b823bc8b
some more docu fixes
2012-05-07 22:55:44 +02:00
Bart Visscher
4dbc2093c6
Create a function for linking to remote.php
2012-05-07 21:47:14 +02:00
Georg Ehrke
5b7cefb1e5
make ampache work with remote.php
2012-05-07 20:26:09 +02:00
Georg Ehrke
d032345191
fix validation of getfile parameter - i hate this bloody merge conflicts
2012-05-07 13:23:55 +02:00
Thomas Tanghus
cde60dba0f
Fix typo.
2012-05-07 04:46:09 +02:00