Commit Graph

131 Commits

Author SHA1 Message Date
Laurent Destailleur
c6040146b2 Add more function to disable. Add preg_quote to avoid false positive. 2023-12-21 19:39:02 +01:00
Laurent Destailleur
b1fa6f596f Add experimental security option
MAIN_SECURITY_FORCE_ACCESS_CONTROL_ALLOW_ORIGIN
2023-12-21 13:01:09 +01:00
Laurent Destailleur
fb083a6cfc Fix warning with rector 2023-12-13 16:33:17 +01:00
Laurent Destailleur
7d109e9419 Fix phpcs 2023-12-13 12:46:23 +01:00
Laurent Destailleur
e040219fdc Fix phpcs 2023-12-13 12:45:07 +01:00
Laurent Destailleur
29dc12dd58 Option MAIN_DISALLOW_URL_INTO_DESCRIPTIONS accept 1 or 2 value.
Value 1 should be ready to be on by default in a next version.
Fix #yogosha18900
2023-12-10 16:19:05 +01:00
Laurent Destailleur
20a9a9d298 Debug v19. dolibarr_main_stream_enabled must be changed into
dolibarr_main_stream_to_disable
2023-12-07 14:56:06 +01:00
Laurent Destailleur
987d6c41b9 Fix with php-cs-fixer 2023-12-04 11:41:14 +01:00
Laurent Destailleur
aa44100cbc Add test to check if a security experimental feature can work 2023-12-03 12:49:52 +01:00
Laurent Destailleur
7835c1f6bc Debug setup 2023-12-02 15:49:29 +01:00
Laurent Destailleur
df6ca57763 Debug v19 2023-12-02 15:20:42 +01:00
Laurent Destailleur
c417949a7e Fix phpunit 2023-11-30 00:06:05 +01:00
Laurent Destailleur
7809b66688 Doc 2023-11-29 23:18:49 +01:00
Laurent Destailleur
3e1d5b1748 Fix for MAIN_RESTRICTHTML_ONLY_VALID_HTML 2023-11-29 23:17:22 +01:00
Laurent Destailleur
43f9210ab4 SEC: Add option MAIN_RESTRICTHTML_ONLY_VALID_HTML_TIDY 2023-11-29 20:19:21 +01:00
Laurent Destailleur
ca3f5eaadf Debug v19 2023-11-14 00:56:30 +01:00
Laurent Destailleur
5b15b5c647 QUAL Move conf->global into getDolGlobal... 2023-10-24 17:00:13 +02:00
Laurent Destailleur
bae75281e3 QUAL: Code fix using rector 2023-10-11 19:44:06 +02:00
Jon Bendtsen
154ce1329f adding mariadb and mariadb-dump to the list of restricted os commands 2023-09-13 22:58:36 +02:00
Laurent Destailleur
7ce9bf6b23 Clean code 2023-08-05 15:44:28 +02:00
Laurent Destailleur
761565cabb Merge branch '18.0' of git@github.com:Dolibarr/dolibarr.git into develop 2023-07-25 23:47:28 +02:00
Laurent Destailleur
2bc6cd20dd Debug v18 2023-07-25 13:15:52 +02:00
Laurent Destailleur
01eca1eb47 Debug v18 2023-07-25 12:56:11 +02:00
Laurent Destailleur
7ccd50d2b8 Fix class not initialized 2023-07-25 12:38:27 +02:00
Laurent Destailleur
9c62e76c46 NEW Disable not used PHP streams 2023-07-25 12:30:09 +02:00
Laurent Destailleur
b08d24348c Add 2 more dangerous function to disable 2023-07-25 12:00:50 +02:00
Laurent Destailleur
4ba8324a3f Doc 2023-07-19 04:22:02 +02:00
Frédéric FRANCE
d55ae5dbd2 use isModEnabled 2023-06-09 13:53:58 +02:00
Laurent Destailleur
51708f4d70 Ad option MAIN_ALLOW_SVG_FILES_AS_EXTERNAL_LINKS in security page 2023-06-03 11:31:24 +02:00
Laurent Destailleur
155c52bc30 Fix #yogosha16184 2023-04-24 13:52:31 +02:00
Laurent Destailleur
869a73befc Add option MAIN_DISALLOW_EXT_URL_INTO_DESCRIPTIONS into security page 2023-04-06 13:39:04 +02:00
Laurent Destailleur
3821f5c27c Update security page 2023-03-21 01:50:14 +01:00
Laurent Destailleur
72750c3b8d Add notice in security to show if installmodules.lock exists. 2023-03-21 01:43:09 +01:00
Laurent Destailleur
29417861db Fix bad var shown 2023-03-12 11:54:46 +01:00
Laurent Destailleur
54d1250887 Merge + Clean duplicate trigger code. We must use the context. 2023-03-02 02:19:24 +01:00
Laurent Destailleur
14a59483f5 Debug v17 2023-03-01 23:50:02 +01:00
Laurent Destailleur
6fc473bd71 Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop 2023-02-28 19:16:29 +01:00
Laurent Destailleur
afae14d914 Fix CSP Policy 2023-02-28 11:35:40 +01:00
Laurent Destailleur
3354a27a6f css 2023-02-25 01:21:12 +01:00
Laurent Destailleur
5aaca18567 css 2023-02-25 00:48:50 +01:00
Laurent Destailleur
44da230012 Clean code 2023-02-21 12:57:36 +01:00
Laurent Destailleur
870ac42082 Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop 2023-02-20 16:20:49 +01:00
Laurent Destailleur
a4c2c671be Fix option example 2023-02-20 15:29:17 +01:00
Laurent Destailleur
0300ccebfd Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop 2023-02-18 21:09:58 +01:00
Laurent Destailleur
a81510ccd6 Better exemple for RCP security string 2023-02-18 14:15:39 +01:00
Laurent Destailleur
2168578f2e Fix inline css 2023-02-18 14:00:25 +01:00
Laurent Destailleur
183ae35ab7 Fix #huntr10e423cd-7051-43fd-b736-4e18650d0172 2023-02-13 12:57:35 +01:00
Laurent Destailleur
53be37148b NEW Support option MAIN_SECURITY_MAXFILESIZE_DOWNLOADED #yogosha10660 2023-02-04 11:32:38 +01:00
Laurent Destailleur
8f02fb2ab8 Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop 2022-12-22 20:34:22 +01:00
Laurent Destailleur
d183760841 Clean code 2022-12-22 13:21:46 +01:00