Skip to content
Snippets Groups Projects
  1. Jun 30, 2012
  2. Jun 23, 2012
  3. Jun 21, 2012
    • Jared Hancock's avatar
      Remove SQL injection vulnerabilities · 70aca893
      Jared Hancock authored
      Map each of the inputs from $_POST['ids'] into a separate, sanitized
      database input (via the db_input() function), then implode() the array with
      commas and build the SQL statement.
      70aca893
  4. Jun 20, 2012
    • Jared Hancock's avatar
      Implement simple CSRF protection scheme · ff1d8b9e
      Jared Hancock authored
      Protect againts cross-site request forgery attacks by requiring a special
      form-field or header to be sent with requests that modify ticket system
      data.
      
      This meant a slight change to the AJAX ticket locking mechanism. It was
      defined to lock with a GET request; however, GET requests are defined as
      safe methods and should not modify backend data (such as a lock
      acquisition). Therefore, the the lock acquire AJAX method was changed to
      require a POST method.
      
      Also remove old, no-longer-used staff panel include files
      ff1d8b9e
  5. Jun 18, 2012
  6. Jun 14, 2012
  7. Jun 12, 2012
Loading