42ad55c849
page-edit: XSS
2021-09-03 01:23:42 +01:00
3f286b4cda
page-delete: fix XSS
2021-09-03 01:16:29 +01:00
54166c9b79
page-credits: htmlentities *everywhere*
2021-09-03 01:12:49 +01:00
4dda12d195
feaature-watchlist: minor XSS improvements
2021-09-03 01:10:54 +01:00
2844a47f9f
feature-user-table: fix potential obscure XSS attack
2021-09-03 01:08:27 +01:00
2d6bf1df70
feature-user-preferences: fiix potential xss vulnerabilities
2021-09-03 01:01:38 +01:00
227a7ac662
feature-upload: fix potential XSS attacks
2021-09-03 00:42:36 +01:00
6dd3e52a9c
feature-theme-gallery: fill in help text
2021-09-03 00:26:55 +01:00
538f899018
feturee-stats: minor admindetails_name issue
2021-09-03 00:14:53 +01:00
98485e7bd2
feature-search: fix potential XSS
2021-09-03 00:00:49 +01:00
d977d594e6
feture-recent-changes: fix typo
2021-09-02 23:02:01 +01:00
0ff5ab20ec
feature-interwiki-links: fix potential XSS attack
2021-09-02 23:00:50 +01:00
b5b38166ac
feature-history: fix potential XSS attack
2021-09-02 22:58:19 +01:00
3f61c9eac0
feature-guiconfig: fix potential obscure XSS
2021-09-02 22:53:59 +01:00
80f77a93b5
feature-comments: fix potential XSS
2021-09-02 22:50:00 +01:00
a1259ec8d9
action-random: use new slugify() function
2021-09-02 22:39:10 +01:00
bacfc11723
fixup
2021-09-02 22:29:48 +01:00
51be347000
action-protect: fix
2021-09-02 22:29:39 +01:00
f400da6dce
Page renderer: Automatically run htmlentities() on all titles
2021-09-02 21:34:40 +01:00
e0f65c2e65
action-hash: fix potential XSS in string GET param
2021-09-02 21:27:26 +01:00
b6fc5941b7
feature-watchlist: fix format GET parameter
2021-09-02 21:23:31 +01:00
dfe76d1d9b
feature-watchlist: Fix Potential XSS in do GET parameter
2021-09-02 21:21:17 +01:00
96546184dc
Implement simple slugify function
...
I suspect I may have to fix a number of issues here.....
2021-09-02 21:19:31 +01:00
0a77065c3f
Bugfix: Fix stored XSS attack - ref CVE-2021-38600
...
See https://github.com/hmaverickadams/CVE-2021-38600
For some reason the author did not think ti wise to let me know
privately first - instead publicly announcing it via a GitHub repo.....
sigh.
In addition, is this *really* a vulnerability? Since Pepperminty Wiki
requires the site secret to set it up, I can't see that this has a real
impact.
Still, I'll fix it anyway.....
2021-09-02 20:54:06 +01:00
fab1b52882
Bugfix: fix error handling logic
2021-08-15 21:46:19 +01:00
ba70f74a96
Added automatic system requirements indicator to first run
2021-08-06 01:50:08 +01:00
e7b3f5e0d0
feature-upload: add function / class existence checks where functions from php extensions are required
2021-08-06 01:49:59 +01:00
fb9eec2d33
Fix & improve sidebar
2021-07-21 00:44:31 +01:00
86206195b6
Fix crash when using the search bar in recent versions of php
2021-07-20 23:54:56 +01:00
0c9934038c
feature-cli: fix typo
2021-06-10 20:11:53 +01:00
26f5838ce0
Add experimental [display text](./Page Name.md) style internal links
...
This is transparently handled by a wrapper around inlineLink, which
conditionally bails by returning the parent if parsing fails. It then
~~ab~~uses inlineInternalLink to provide proper internal link support.
Fixes #190 .
2021-04-11 21:47:41 +01:00
77880d9410
search: properly apply weightings in titlels and tags
2021-02-10 22:17:38 +00:00
e76eaf5963
feature-stats: bump version
2020-11-20 21:20:05 +00:00
05314c464e
Merge branch 'master' of github.com:sbrl/Pepperminty-Wiki
2020-11-20 21:13:42 +00:00
d29b87eb6d
Make the statistic update system more resilient
2020-11-20 21:13:31 +00:00
Popol
d5e4332652
typo
2020-11-07 13:15:48 +01:00
880c9e3796
Send x-robots-tag: noindex,nofollow
with the login page
...
SemrushBot, you better obey this one
2020-10-26 18:59:53 +00:00
2677bb8143
page-sitemap: add module
2020-10-26 18:26:59 +00:00
7b3f06d539
page-credits: add page-sitemap support
2020-10-26 18:26:52 +00:00
d7128eed0e
api-status: add sitemap_url property if the page-sitemap module is present
2020-10-26 18:26:33 +00:00
6abbdc4d1e
recent-changes: deduplicate in atom
...
feed generation
2020-10-26 18:24:53 +00:00
7dd9bd74c4
Add support for creating pages whose name is not yet known - fixes #194
2020-10-25 22:50:03 +00:00
cfd087d919
Add MPL 2.0 short header to core code files
2020-09-23 23:22:39 +01:00
dfca17d1cf
more of the same - this time in page / tag lists
2020-08-31 21:02:49 +01:00
9fad95035b
Fix inbody:searchterm advanced query syntax - fixes #210 (thanks to @SeanFromIT for the report)
2020-08-19 16:59:54 +01:00
9b109face2
Merge pull request #206 from SeanFromIT/master
...
adding WikiProject Paranormal
2020-08-19 14:43:05 +01:00
b30d70927b
parser-parsedown: bump version
2020-08-18 13:52:44 +01:00
c2e4a04778
Fix #209
2020-08-18 13:49:16 +01:00
Sean Feeney
c598dfbf6d
phrasing fix
2020-08-14 18:55:27 -07:00
8a05d79724
similar pages: tweak text
2020-08-11 18:13:47 +01:00