Commit Graph

6615 Commits (3c0544d7613d7216a7cba382dcb2e685a996f3ac)

Author SHA1 Message Date
Hagen Schink 2f003f9a41 Extract work package attributes to partial 11 years ago
Philipp Tessenow 9db54f08a0 call private methods the right way 11 years ago
Philipp Tessenow eb4a18ea7d do not use ruby 2.1 features so we still support 2.0 inofficially 11 years ago
Philipp Tessenow b26b15ce89 prepend private_class_method to private class methods 11 years ago
Martin Linkhorst 99427f281c re-render everything so there won't be multiple error flash messages on the page 11 years ago
Martin Linkhorst c00771156a do not display successful flash message when in wasn't 11 years ago
Michael Frister 78ab5970a4 Allow plugins to add permitted attributes 11 years ago
Michael Frister 0c338e042a Remove attr_protected on User now that we use strong_parameters 11 years ago
Michael Frister 3c324bdc42 Use strong_parameters for User, remove safe_attribtues 11 years ago
Toshi MARUYAMA 00d60e9583 fix miss fixing 'weigh' 11 years ago
Jean-Philippe Lang b8ffa31e1a Potentiel data leak in "Invalid form authenticity token" error screen (#16511). 11 years ago
Alex Coles 376eca0f72 Fix typos, spelling in helper comments 11 years ago
Alex Coles c409c542c3 Fix typos, spelling in mailer comments 11 years ago
Alex Coles d872d91d0d Fix typos, spelling in model comments 11 years ago
Philipp Tessenow f7fb4f9fd1 WorkPackage model: Improve formatting 11 years ago
Philipp Tessenow 1fe3d6c787 make WorkPackage.count_and_group_by private 11 years ago
Hagen Schink 6e66224fed Fix flash message activation 11 years ago
Philipp Tessenow 13036e909f show matched text in at.who auto-completion in black (the default (white) is hardly visible) 11 years ago
Philipp Tessenow 71ad8de223 fix plugin assets inclusion 11 years ago
Hagen Schink 66ad6d6b76 Make changes a hash with indifferent access 11 years ago
Hagen Schink abe3d9cac9 Remove symbols from journal processing 11 years ago
Martin Linkhorst a83af510cb given openproject runs in a subdirectory we cannot allow redirecting to a different subdirectory. also tries to catch shenanigans to circumvent the check like ".." in the path. 11 years ago
Hagen Schink 77a77bc497 Don't escape selected item twice 11 years ago
Hagen Schink 5403380524 Don't escape results on retrieval 11 years ago
Hagen Schink ce001401ba Mention timeline context in header 11 years ago
Johannes Wollert 36b231d6b3 put timeline name into page title where possible 11 years ago
Hagen Schink 784bf7e6fc Fix code layout 11 years ago
Hagen Schink 88bceae8e8 Add update notice 11 years ago
Hagen Schink 7c8c27d2dd Add deletion notice 11 years ago
Martin Linkhorst dbc75d4263 there was a wrong parenthesis: the last match needs to be ANDed with all the prior checks. instead of changing it, refactored the code to be more clear. still allows redirects to different sub-uris. 11 years ago
Johannes Wollert c8d4e449cc unifies creation/deletion/error notices in user's membership tab 11 years ago
Ion Biziiac ce2f74a37a Fix WP copy without project cross references 11 years ago
Philipp Tessenow b0285751a6 explicitly allow home path in back_url 11 years ago
Philipp Tessenow 7808e82cf1 fix protocol-relative redirection test 11 years ago
jplang 7bb076fa48 [security] fixed back url verification 11 years ago
Alexey Fedorov f4775c6a40 [fix #4928] Made journal notes shown in search. 11 years ago
Philipp Tessenow 70a9715d21 remove gravatar border statements 11 years ago
Ion Biziiac 7bf51e3059 Fixes quote icon in wrong position 11 years ago
Philipp Tessenow 3770c42039 remove border around gravatars 11 years ago
Ion Biziiac 79ccb46ef2 Fixes quotes in versions are not properly HTML-escaped 11 years ago
Ion Biziiac 86f9e7cae9 Fixes Comparison of history versions in wiki pages ignores newlines 11 years ago
Ion Biziiac a1955579f8 Fixes Spent Time not localized 11 years ago
slawa c59a2efc0f override css method for wiki page by adding overflow: visible 11 years ago
slawa 1e94c804c8 Attach event handler for async loaded elements 11 years ago
Jens Ulferts 686da8cecc uses named routes for topics/boards 11 years ago
Markus Kahl d6b215f09e dropped redundant limit 11 years ago
Markus Kahl 7301228d65 don't rely on journal record id to find predecessor and use version instead 11 years ago
Hagen Schink 23d1a51c74 Preview caption reflects the previewed attribute 11 years ago
Hagen Schink 628a8a71a8 Authorize preview object access 11 years ago
Hagen Schink 26213ea3b7 Reset order of preview texts 11 years ago