Commit Graph

2343 Commits

Author SHA1 Message Date
Laurent Destailleur
4d563651fa Add a mode MAIN_SECURITY_CSRF_WITH_TOKEN = 2 2021-09-19 14:49:11 +02:00
Laurent Destailleur
5c8fb38426 Fix add del* action into list of sensitive actions 2021-09-19 14:41:46 +02:00
Laurent Destailleur
e92a24d5f1 Fix test 2021-09-19 13:49:21 +02:00
Laurent Destailleur
4253b564ba Fix add reopen as sensitive actions 2021-09-18 22:55:23 +02:00
Laurent Destailleur
89e8f24e15 Fix CSRF protection for all massactions 2021-09-18 22:38:25 +02:00
Laurent Destailleur
c3e88579ab Fix add remove_* action as sensitive action 2021-09-18 22:24:51 +02:00
Laurent Destailleur
d760686239 Fix case of newtoken() 2021-09-18 22:24:00 +02:00
Laurent Destailleur
0749d01c5a Fix add action delete* as sensitive action 2021-09-18 22:04:41 +02:00
Laurent Destailleur
8bdc53f469 Fix Add action classify as sensitive actions 2021-09-18 20:49:24 +02:00
Laurent Destailleur
6390f2de6f Fix add all confirm_* action as sensitive actions 2021-09-18 19:47:51 +02:00
Laurent Destailleur
7dfedd242a Fix add confirm_deleteline as sensitive action 2021-09-18 19:43:38 +02:00
Laurent Destailleur
62b721a904 Add deletecontact as sentitive action
Replace dol_buildpath with DOL_URL_ROOT
2021-09-18 19:34:46 +02:00
Laurent Destailleur
858a5ab188 Add confirm_validate and confirm_close as sensitive actions 2021-09-18 18:36:45 +02:00
Laurent Destailleur
fa28621709 Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/reception/list.php
2021-09-09 16:11:29 +02:00
Laurent Destailleur
5d5b7c3af4 Merge branch '13.0' of git@github.com:Dolibarr/dolibarr.git into 14.0
Conflicts:
	htdocs/comm/action/peruser.php
	htdocs/main.inc.php
2021-09-09 15:15:26 +02:00
Laurent Destailleur
70f22f2648 # WARNING: head commit changed in the meantime
Merge
2021-09-09 15:12:02 +02:00
Frédéric FRANCE
456f25d57e fix #17634 2021-09-04 11:30:03 +02:00
Laurent Destailleur
e4cbc2140e Fix doc and token renewal with NOSESSION 2021-08-24 21:48:38 +02:00
Laurent Destailleur
c6774505d8 FIX #18465 2021-08-24 14:05:02 +02:00
Laurent Destailleur
58fa0740c3 Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/core/lib/functions.lib.php
	htdocs/langs/en_US/errors.lang
2021-08-22 01:41:18 +02:00
Laurent Destailleur
4cd5a53b63 FIX Recommended session.cookie_samesite must be 'Lax' not 'Strict'. 2021-08-22 00:44:51 +02:00
Laurent Destailleur
335e1ff405 Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop 2021-08-20 12:45:37 +02:00
Laurent Destailleur
10ddd621ca Fix escape error message 2021-08-20 12:40:49 +02:00
Gurvan Kervern
d2e2dcf27e fix warnings 2
Fixing PHP8 warnings
2021-08-16 18:10:04 +08:00
Laurent Destailleur
354d88df23 Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop 2021-08-06 18:50:39 +02:00
Laurent Destailleur
591b8acd51 FIX show info of company into user dropdown 2021-08-05 15:57:51 +02:00
Laurent Destailleur
841176fdfd Fix set cookie with tag "secure" when https is forced. 2021-08-04 14:38:05 +02:00
Laurent Destailleur
afa6ced6c9 Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/main.inc.php
2021-07-21 01:29:22 +02:00
Laurent Destailleur
23f708c0d4 Fix phpcs 2021-07-21 01:27:14 +02:00
Laurent Destailleur
dbed6bc0da Fix #yogosha6678 2021-07-21 01:18:48 +02:00
Laurent Destailleur
e02fbadcd7 Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/main.inc.php
2021-07-21 00:41:40 +02:00
Laurent Destailleur
e4bb5ed008 Fix phpcs 2021-07-21 00:35:08 +02:00
Laurent Destailleur
c2f1781fae Fix #huntr5bb5a52-3b1c-40ad-9c64-61735f886736 2021-07-21 00:14:03 +02:00
Laurent Destailleur
219a2a860b Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/langs/en_US/main.lang
	htdocs/main.inc.php
2021-07-20 23:59:33 +02:00
Laurent Destailleur
dc7ff07517 Fix #huntr7144bb4b-338f-45f0-a70e-088ef1f4c037 2021-07-20 23:54:22 +02:00
Laurent Destailleur
08e06f9789 Fix #hunter2c606116-f212-49e0-967c-11f8666be43b 2021-07-20 23:28:57 +02:00
Laurent Destailleur
0e18bd4be1 Fix #hunter2cd3fc73-65a1-4615-9143-9e7febd81a15 2021-07-20 23:15:31 +02:00
Laurent Destailleur
a916f668f9 Fix param of include js 2021-07-08 22:16:47 +02:00
Laurent Destailleur
ddc37ef38c Fix missing lang param 2021-07-08 20:58:19 +02:00
Laurent Destailleur
1380344fdb Fix PHP 8 2021-07-08 12:17:32 +02:00
Laurent Destailleur
16ee47b12c Fix warning.
Reduce memory need for getmin/max on large graphs.
2021-07-08 11:13:15 +02:00
Laurent Destailleur
2f25079981 Fix CSRF token generation must be fast, can have low entropy. 2021-07-07 14:40:47 +02:00
Laurent Destailleur
d97a95aa2a Fix CSRF token generation must be fast, can have low entropy. 2021-07-07 14:38:52 +02:00
Francis Appels
5d824899e5 Fix php 8 warning on home page 2021-07-05 13:44:05 +02:00
Laurent Destailleur
0f020d5b20 Fix for phpv8 2021-06-29 19:05:18 +02:00
Laurent Destailleur
796b2d201a Enhance the sanitizing. 2021-06-29 18:17:27 +02:00
Laurent Destailleur
cc65e4bb38 FIX #18030 2021-06-26 12:00:25 +02:00
Laurent Destailleur
720ea16bb1 css 2021-06-26 02:00:30 +02:00
Laurent Destailleur
c4e9e1c8df Comment 2021-06-25 10:50:58 +02:00
Laurent Destailleur
46ae7180f8 Fix phpunit. Refused @@ char in sql. 2021-06-25 10:47:31 +02:00