Commit Graph

86 Commits

Author SHA1 Message Date
Laurent Destailleur
8000341f84 Fix security 2023-08-06 15:42:14 +02:00
Laurent Destailleur
6c8b5d489f NEW Add option MAIN_ALLOW_LOCAL_LINKS_AS_EXTERNAL_LINKS 2023-06-03 11:20:24 +02:00
Laurent Destailleur
14a59483f5 Debug v17 2023-03-01 23:50:02 +01:00
Laurent Destailleur
afae14d914 Fix CSP Policy 2023-02-28 11:35:40 +01:00
Laurent Destailleur
3354a27a6f css 2023-02-25 01:21:12 +01:00
Laurent Destailleur
a4c2c671be Fix option example 2023-02-20 15:29:17 +01:00
Laurent Destailleur
a81510ccd6 Better exemple for RCP security string 2023-02-18 14:15:39 +01:00
Laurent Destailleur
d183760841 Clean code 2022-12-22 13:21:46 +01:00
Frédéric FRANCE
6c24230d9e fix typo 2022-12-20 18:34:50 +01:00
Laurent Destailleur
981e165c3e Reduce default value from 1000 to 200 for
MAIN_SECURITY_MAX_POST_ON_PUBLIC_PAGES_BY_IP_ADDRESS
2022-11-29 10:24:21 +01:00
Laurent Destailleur
427a785fb3 Update help on security 2022-11-22 21:27:30 +01:00
Laurent Destailleur
767f5db7dc Typo 2022-11-20 22:42:35 +01:00
Laurent Destailleur
3041edc013 Debug 2022-11-20 21:59:35 +01:00
Laurent Destailleur
e5a4824ed2 Enhance default WEBSITE_MAIN_SECURITY_FORCECSP 2022-11-20 16:12:18 +01:00
Laurent Destailleur
c5459a47eb Enhance default WEBSITE_MAIN_SECURITY_FORCECSP 2022-11-20 16:08:32 +01:00
Laurent Destailleur
938bc27917 Update sample for fail2ban 2022-10-18 12:59:15 +02:00
lmarcouiller
b0d2aa6d9b Fix : php 8.1 warnings 2022-09-23 16:05:11 +02:00
Laurent Destailleur
4a17fae9af Add info on mitigation 2022-09-11 20:48:23 +02:00
Laurent Destailleur
60c39933d4 Clean code 2022-09-11 13:26:24 +02:00
Laurent Destailleur
a0dda0ed77 NEW Add more advices into the Setup security page 2022-09-11 12:35:40 +02:00
Laurent Destailleur
2293d82607 NEW Add picto property on sub-module for paswword generation 2022-09-11 12:18:43 +02:00
Frédéric France
8d33953142 add comment 2022-09-07 20:08:59 +02:00
Laurent Destailleur
3b195fa1fb Can add Permissions-Policy on web sites 2022-08-16 16:58:28 +02:00
Laurent Destailleur
5ef941311a NEW can set header "Strict-Transport-Security" in web sites 2022-08-16 16:06:09 +02:00
Laurent Destailleur
f404eddad0 Fix recommended value 2022-08-16 15:23:53 +02:00
Laurent Destailleur
94da628cf4 Clean code for http header + better support for Content-Security-Policy 2022-08-16 15:19:45 +02:00
Laurent Destailleur
524b001f3b Add $dolibarr_main_restrict_os_commands in security center. 2022-04-06 21:14:35 +02:00
Laurent Destailleur
9bda7ba8c7 Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/core/class/doleditor.class.php
2022-03-03 00:16:55 +01:00
Laurent Destailleur
8051128665 Split section experimental and stable 2022-03-02 11:37:19 +01:00
Laurent Destailleur
12b2a10865 Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop 2022-03-01 18:15:13 +01:00
Laurent Destailleur
237b6fc922 Fix value recommended 2022-03-01 17:07:28 +01:00
Laurent Destailleur
8c61a29051 Show value of short_open_tags 2022-02-25 01:30:34 +01:00
Laurent Destailleur
bf1dfac629 Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/langs/en_US/errors.lang
	htdocs/product/stock/movement_list.php
2021-11-25 21:54:06 +01:00
Laurent Destailleur
b345c2463c Fix warning on security page 2021-11-25 00:19:55 +01:00
Frédéric FRANCE
6d9ee78704 security page doesnt detect xdebug 2021-10-23 21:53:04 +02:00
Regis Houssin
db01fed447 FIX error when defining an already existing constant 2021-10-19 12:36:33 +02:00
Laurent Destailleur
6d8276c9c8 Doc 2021-10-04 12:59:53 +02:00
Laurent Destailleur
eada0f468f Set MAIN_SECURITY_CSRF_WITH_TOKEN recommended value to 1 2021-10-01 12:39:15 +02:00
Laurent Destailleur
5c8b893877 Doc 2021-09-27 12:50:51 +02:00
Laurent Destailleur
72be24a835 Doc 2021-09-27 12:37:10 +02:00
Laurent Destailleur
4a85304572 Fix security 2021-09-26 21:01:34 +02:00
Laurent Destailleur
6c37836b3e Show value of MAIN_SECURITY_CSRF_WITH_TOKEN in setup page 2021-09-18 18:28:02 +02:00
Laurent Destailleur
4cd5a53b63 FIX Recommended session.cookie_samesite must be 'Lax' not 'Strict'. 2021-08-22 00:44:51 +02:00
Laurent Destailleur
948663deb4 Fix deprecated var 2021-08-07 13:59:07 +02:00
Laurent Destailleur
1435172405 Better help 2021-08-06 18:55:41 +02:00
Laurent Destailleur
d437d382d8 Fix trans 2021-08-06 18:48:05 +02:00
Laurent Destailleur
a7fa238b71 Position of option 2021-08-06 18:35:16 +02:00
Laurent Destailleur
e26eda3f5f Position of option 2021-08-06 18:34:35 +02:00
Laurent Destailleur
458f773baf Fix security options 2021-08-06 18:32:40 +02:00
Laurent Destailleur
a5d11a1ccf Fix warning 2021-08-04 15:46:00 +02:00