Commit message (Collapse) | Author | Age | |
---|---|---|---|
* | img: force common Web formats to be interpreted according to extension | Simon McVittie | 2016-05-05 |
| | | | | | | | | A site administrator might unwisely set allowed_attachments to something like '*.jpg or *.png'; if they do, an attacker could attach, for example, a SVG file named attachment.jpg. This mitigates CVE-2016-3714. | ||
* | HTML-escape error messages (OVE-20160505-0012) | Simon McVittie | 2016-05-05 |
| | | | | | | | | | | | | The instance in cgierror() is a potential cross-site scripting attack, because an attacker could conceivably cause some module to raise an exception that includes attacker-supplied HTML in its message, for example via a crafted filename. (OVE-20160505-0012) The instances in preprocess() is just correctness. It is not a cross-site scripting attack, because an attacker could equally well write the desired HTML themselves; the sanitize hook is what protects us from cross-site scripting here. | ||
* | all good | https://id.koumbit.net/anarcat | 2016-05-04 |
| | |||
* | (no commit message) | smcv | 2016-05-04 |
| | |||
* | response: confirmation it's a bug in MMD and Discount doesn't have ↵ | https://id.koumbit.net/anarcat | 2016-05-04 |
| | | | | footnotes, and request for workaround | ||
* | discount (as used on this wiki) can do footnotes, but they aren't enabled by ↵ | smcv | 2016-05-04 |
| | | | | ikiwiki | ||
* | response | smcv | 2016-05-04 |
| | |||
* | response | Joey Hess | 2016-05-02 |
| | |||
* | (no commit message) | https://id.koumbit.net/anarcat | 2016-04-29 |
| | |||
* | response | https://id.koumbit.net/anarcat | 2016-04-28 |
| | |||
* | Merge branch 'master' of ssh://git.ikiwiki.info | Joey Hess | 2016-04-28 |
|\ | |||
| * | (no commit message) | https://id.koumbit.net/anarcat | 2016-04-28 |
| | | |||
| * | http/https issue | https://id.koumbit.net/anarcat | 2016-04-28 |
| | | |||
* | | response | Joey Hess | 2016-04-28 |
| | | |||
* | | Merge remote-tracking branch 'origin/master' | Joey Hess | 2016-04-28 |
|\| | |||
| * | smaller is too small for large blocks | Antoine Beaupré | 2016-04-26 |
| | | |||
| * | fix typo and comment | Antoine Beaupré | 2016-04-26 |
| | | |||
| * | new CSS bug | Antoine Beaupré | 2016-04-26 |
| | | |||
| * | explain footnotes | https://id.koumbit.net/anarcat | 2016-04-26 |
| | | |||
| * | Changed the expired domain and added question | desci | 2016-04-18 |
| | | |||
| * | Fixed dead link. | RickHanson | 2016-04-17 |
| | | |||
| * | add screenshot | Antoine Beaupré | 2016-04-15 |
| | | |||
| * | fix typos | Antoine Beaupré | 2016-04-15 |
| | | |||
| * | announce the admonition plugin | Antoine Beaupré | 2016-04-15 |
| | | |||
| * | elaborate copyright investigation. ugh. | Antoine Beaupré | 2016-04-15 |
| | | |||
| * | response | Antoine Beaupré | 2016-04-15 |
| | | |||
| * | can't login again | Antoine Beaupré | 2016-04-15 |
| | | |||
| * | escape | smcv | 2016-04-15 |
| | | |||
| * | templates are another way to do this | smcv | 2016-04-15 |
| | | |||
| * | (no commit message) | smcv | 2016-04-15 |
| | | |||
| * | a weird authentication bug | Antoine Beaupré | 2016-04-15 |
| | | |||
| * | admonitions proposal | Antoine Beaupré | 2016-04-15 |
| | | |||
| * | Arguing more | desci | 2016-04-15 |
| | | |||
| * | Added systemd for nginx | desci | 2016-04-15 |
| | | |||
| * | (no commit message) | desci | 2016-04-14 |
| | | |||
| * | Document new feature. | spalax | 2016-04-14 |
| | | |||
| * | clarify that theme and css is not only to change stylesheets, but the look ↵ | https://id.koumbit.net/anarcat | 2016-04-13 |
| | | | | | | | | in general | ||
| * | link to localstyle after a user struggled for hours to figure out exactly that | https://id.koumbit.net/anarcat | 2016-04-13 |
| | | |||
| * | explain why multiple page.tmpl is a showstopper for upstream even if not for ↵ | smcv | 2016-04-12 |
| | | | | | | | | local themes | ||
| * | (no commit message) | desci | 2016-04-11 |
| | | |||
| * | Updated link | desci | 2016-04-11 |
| | | |||
| * | Updated link | desci | 2016-04-11 |
| | | |||
| * | Edited old sentence to reference the forum | desci | 2016-04-11 |
| | | |||
| * | (no commit message) | desci | 2016-04-11 |
| | | |||
| * | Asked Joey to reconsider | desci | 2016-04-11 |
| | | |||
| * | Added yet another bootstrap theme | desci | 2016-04-11 |
| | | |||
| * | Added question | desci | 2016-04-11 |
| | | |||
| * | There's also a config file option. | spwhitton | 2016-04-09 |
| | | |||
| * | Marketing | desci | 2016-04-09 |
| | | |||
| * | Delivering what I've promised | desci | 2016-04-09 |
| | |