Skip to content
Snippets Groups Projects
  1. Mar 20, 2018
  2. Mar 06, 2018
    • JediKev's avatar
      xss: Prevent Agent Directory XSS · 36651b91
      JediKev authored
      This addresses a vulnerability where an Agent can perform XSS via the
      Agent Directory’s REQUEST query string. This sanitizes the request params
      so the code will be escaped and not executed in the browser.
      36651b91
  3. Feb 12, 2018
    • JediKev's avatar
      oops: Prevent Account Takeover · be0133b0
      JediKev authored
      This addresses an issue where someone can “takeover” an account with only
      a User’s email and a User’s previous ticket number. Once they get access
      to a User’s ticket they can go to the Ticket Owner’s profile and change
      the email to whatever they’d like. This adds a check on the profile to see
      if the User is a Guest User. If they are a Guest then it kicks them back
      to the ticket view. If they are the actual User it will let them view the
      profile.
      be0133b0
  4. Feb 07, 2018
  5. Nov 06, 2017
    • JediKev's avatar
      issue: File Upload Bypass · 3eb16147
      JediKev authored
      This addresses an issue where someone can bypass the file restrictions on
      the file upload field in the Client Portal. This adds the allowed
      extensions and file types to the field options so that User’s cannot
      upload anything other than the allowed file types.
      3eb16147
  6. Oct 19, 2017
    • JediKev's avatar
      issue: Httponly Cookies · 5b2dfce9
      JediKev authored
      This addresses issue 4015 where osTicket’s cookies aren’t HttpOnly by
      default. The HttpOnly flag helps prevent client scripts accessing the
      cookie. This updates the method that sets the cookie params to include
      the HttpOnly flag.
      5b2dfce9
  7. Sep 28, 2017
  8. Sep 23, 2017
  9. Sep 14, 2017
  10. Aug 15, 2017
  11. Aug 10, 2017
  12. Aug 08, 2017
    • JediKev's avatar
      tasks: Fix Task Updated Time · d6dfa7a6
      JediKev authored
      This addresses an issue where updating a Task does not change the
      `updated` column in the database. This adds a line to change the `update`
      column when updating a Task.
      d6dfa7a6
  13. Jul 28, 2017
    • JediKev's avatar
      oops: Fix Task Print · 2ddf78a6
      JediKev authored
      This addresses issue 3782 where clicking Print on a Task gives you a blank
      popup that hangs. This is because the Print button was being treated as a
      Task action when it is actually not one. This adds a ternary operator to
      give the proper Task Actions the `task-action` class and gives the Print
      button no class.
      2ddf78a6
  14. Jul 21, 2017
    • JediKev's avatar
      oops: User Phone Search · 00e47272
      JediKev authored
      This addresses issue 3815 where searching by User's phone number doesn't
      work in v1.10. This adds phone number search capabilities for the User
      Directory and User Search popup in v1.10.
      00e47272
  15. Jul 19, 2017
    • JediKev's avatar
      cron: Delete Expired Sessions · 5a8fdeae
      JediKev authored
      This addresses an issue where expired sessions would not be removed from
      the database. This caused the session table to fill up and create
      unnecessary issues. This adds a cleanup method to remove all expired
      sessions from the database.
      5a8fdeae
  16. May 19, 2017
  17. May 13, 2017
  18. May 12, 2017
    • JediKev's avatar
      forms: Proper Field Deletion · ad34072c
      JediKev authored
      This addresses issue where upon deletion of a form field and all its
      entry values, the field record wouldn't be deleted from the `form_field`
      table. This links another issue where you can't delete a list if its
      been a field before. This is due to the list delete() function that
      checks for list field records in the `form_field` table.
      ad34072c
  19. Apr 24, 2017
    • Peter Rotich's avatar
      Add timezone setting to DateTimeField with time. · 06e348dd
      Peter Rotich authored
      This is necessary to force a particular timezone on a DateTimeField entry.
      If timezone is not set then user's timezone is assumed.
      06e348dd
    • Peter Rotich's avatar
      DateTime · 69b85f0d
      Peter Rotich authored
      Address edge cases where timezone mixups happens on DateTimeField
      
      Allow datetime field to be timezone agnostic (not timezone aware) to display
      the timezone used to set the field. The timezone of the last user or agent
      that edited the field is used.
      69b85f0d
  20. Apr 10, 2017
  21. Mar 31, 2017
  22. Mar 23, 2017
  23. Mar 17, 2017
Loading