Commit message (Collapse) | Author | Age | Lines | |
---|---|---|---|---|
* | Upgrade to Rails 2.3.18 to get fixes for CVE-2013-1855, CVE-2013-1856, ↵hotfix/0.7.0.5 | Louise Crow | 2013-03-18 | -20/+20 |
| | | | | CVE-2013-1857. | |||
* | Merge branch 'hotfix/0.7.0.4' | Louise Crow | 2013-03-14 | -1951/+1977 |
|\ | ||||
| * | Latest translations from transifex.hotfix/0.7.0.4 | Louise Crow | 2013-03-14 | -1951/+1977 |
|/ | ||||
* | Merge branch 'hotfix/0.7.0.2'0.7.0.2 | Louise Crow | 2013-02-16 | -5/+5 |
|\ | ||||
| * | Don't escape public body notes as html.hotfix/0.7.0.2 | Louise Crow | 2013-02-16 | -5/+5 |
|/ | ||||
* | Merge branch 'hotfix/0.7.0.1'0.7.0.1 | Louise Crow | 2013-02-15 | -0/+35 |
|\ | ||||
| * | Handle the case where the subject is not set | Louise Crow | 2013-02-15 | -2/+2 |
| | | ||||
| * | Fix for #808. SafeBuffer and ActionMailer::Quoting.quoted_printable don't ↵ | Louise Crow | 2013-02-15 | -0/+35 |
|/ | | | | play well together, so convert all subject lines to strings before passing them off to actionmailer. | |||
* | Merge branch 'release/0.7'0.7.00.7 | Louise Crow | 2013-02-14 | -53971/+12794 |
|\ | ||||
| * | Silence printing of Erubis version number to stdout - can result in bounces ↵ | Louise Crow | 2013-02-14 | -1/+7 |
| | | | | | | | | to incoming mail depending on your mail config. | |||
| * | Rename spec file so that it's picked up by rake spec. | Louise Crow | 2013-02-14 | -0/+0 |
| | | ||||
| * | Bump Alaveteli version number.release/0.7 | Louise Crow | 2013-02-14 | -1/+1 |
| | | ||||
| * | Latest translations from transifex. | Louise Crow | 2013-02-14 | -377/+380 |
| | | ||||
| * | Remove memcached config for test environment, not using interlock anymore. | Louise Crow | 2013-02-14 | -2/+0 |
| | | ||||
| * | Missing Gemfile.lock from 55eb8c0 | Louise Crow | 2013-02-11 | -17/+17 |
| | | ||||
| * | Upgrade JSON gem to get fix for CVE-2013-0269. Update to latest Rails 2-3 ↵ | Louise Crow | 2013-02-11 | -5/+5 |
| | | | | | | | | series - has fixes for CVE-2013-0277, CVE-2013-0276, although alaveteli does not use attr_protected or serialize. | |||
| * | Merge remote-tracking branch ↵ | Louise Crow | 2013-02-11 | -3/+4 |
| |\ | | | | | | | | | | 'openaustralia_github/various_xss_escaping_fixes' into release/0.7 | |||
| | * | Don't escape link html on foi email display page | Matthew Landauer | 2013-02-11 | -2/+2 |
| | | | ||||
| | * | Don't escape links that are automatically added in user bios | Matthew Landauer | 2013-02-11 | -1/+2 |
| | | | ||||
| * | | Add full stop. | Louise Crow | 2013-02-11 | -1/+1 |
| | | | ||||
| * | | Adding some initial change notes. | Louise Crow | 2013-02-08 | -21/+34 |
| |/ | ||||
| * | Restore old trailing whitespace so no need for any change to translation files. | Louise Crow | 2013-02-08 | -2/+2 |
| | | ||||
| * | Latest translations from transifex | Louise Crow | 2013-02-08 | -236/+3478 |
| | | ||||
| * | Convert .po files to a standard msgmerge format - --no-wrap --sort-output ↵ | Louise Crow | 2013-02-08 | -19190/+8816 |
| | | | | | | | | --no-location. | |||
| * | Simple task for converting .po files to a standard msgmerge format. | Louise Crow | 2013-02-08 | -3/+12 |
| | | ||||
| * | Use helper method which handles external requests without user accounts when ↵ | Louise Crow | 2013-02-08 | -5/+5 |
| | | | | | | | | displaying lists of info request events on a user's wall. | |||
| * | Mark constructed URL strings which have been escaped as safe, so that they ↵ | Louise Crow | 2013-02-08 | -4/+5 |
| | | | | | | | | aren't escaped when shown in flash notices. | |||
| * | Mark popup banner as html_safe | Louise Crow | 2013-02-08 | -1/+1 |
| | | ||||
| * | Mark flash string with markup in it as html safe. | Louise Crow | 2013-02-08 | -1/+1 |
| | | ||||
| * | Use raw on text with markup in it. | Louise Crow | 2013-02-08 | -3/+3 |
| | | ||||
| * | Mark flash with markup in it as html safe. | Louise Crow | 2013-02-08 | -1/+1 |
| | | ||||
| * | Merge remote-tracking branch 'openaustralia_github/more_escaping_fixes' into ↵ | Louise Crow | 2013-02-07 | -6/+6 |
| |\ | | | | | | | | | | develop | |||
| | * | Fix escaping of raw email display in admin interface | Matthew Landauer | 2013-02-07 | -1/+1 |
| | | | ||||
| | * | Fix calendar picker on request search page | Matthew Landauer | 2013-02-07 | -5/+5 |
| | | | ||||
| * | | Merge remote-tracking branch ↵ | Louise Crow | 2013-02-07 | -1/+0 |
| |\ \ | | |/ | |/| | | | | 'openaustralia_github/email_fix_on_contact_page' into develop | |||
| | * | Fix email link on contact page after escaping changes | Matthew Landauer | 2013-02-07 | -1/+0 |
| | | | ||||
| * | | Rescue an invalid character exception when handling what appears to be badly ↵ | Louise Crow | 2013-02-06 | -1/+1 |
| | | | | | | | | | | | | encoded data. | |||
| * | | Merge remote-tracking branch ↵ | Louise Crow | 2013-02-01 | -13/+8 |
| |\ \ | | | | | | | | | | | | | 'openaustralia_github/backport_timezone_spec_rails_3_fix' into develop | |||
| | * | | read_attribute does timezone conversion in rails 3. So using ↵ | Matthew Landauer | 2013-01-25 | -13/+8 |
| | | | | | | | | | | | | | | | | attributes_before_type_cast instead | |||
| * | | | Merge remote-tracking branch ↵ | Louise Crow | 2013-02-01 | -7/+7 |
| |\ \ \ | | | | | | | | | | | | | | | | 'openaustralia_github/use_url_helpers_in_redirect_tests' into develop | |||
| | * | | | modernise redirect tests by converting to using url helpers | Matthew Landauer | 2013-01-29 | -7/+7 |
| | | | | | ||||
| * | | | | Merge remote-tracking branch ↵ | Louise Crow | 2013-02-01 | -5/+5 |
| |\ \ \ \ | | | | | | | | | | | | | | | | | | | 'openaustralia_github/backport_rails_3_mailer_fix' into develop | |||
| | * | | | | Rename mailer method to avoid naming conflict in Rails 3 | Matthew Landauer | 2013-01-25 | -5/+5 |
| | | |/ / | | |/| | | ||||
| * | | | | Merge remote-tracking branch 'openaustralia_github/model-deprecations' into ↵ | Louise Crow | 2013-02-01 | -66/+85 |
| |\ \ \ \ | | | | | | | | | | | | | | | | | | | develop | |||
| | * | | | | AboutMeValidator model - Overwriting validate is deprecated in Rails 3 | Henare Degan | 2013-01-25 | -2/+6 |
| | | | | | | ||||
| | * | | | | PublicBody model - Overwriting validate is deprecated in Rails 3 | Henare Degan | 2013-01-25 | -9/+10 |
| | | | | | | ||||
| | * | | | | OutgoingMessage model - Overwriting validate is deprecated in Rails 3 | Henare Degan | 2013-01-25 | -26/+28 |
| | | | | | | ||||
| | * | | | | Indentation and spacing fixes only | Henare Degan | 2013-01-25 | -4/+6 |
| | | | | | | ||||
| | * | | | | Formatting only: Group associations and validations | Henare Degan | 2013-01-25 | -4/+3 |
| | | | | | | ||||
| | * | | | | Comment model - Overwriting validate is deprecated in Rails 3 | Henare Degan | 2013-01-25 | -10/+12 |
| | | | | | |