Skip to content
Snippets Groups Projects
  1. Jun 23, 2012
  2. Jun 20, 2012
    • Jared Hancock's avatar
      Implement simple CSRF protection scheme · ff1d8b9e
      Jared Hancock authored
      Protect againts cross-site request forgery attacks by requiring a special
      form-field or header to be sent with requests that modify ticket system
      data.
      
      This meant a slight change to the AJAX ticket locking mechanism. It was
      defined to lock with a GET request; however, GET requests are defined as
      safe methods and should not modify backend data (such as a lock
      acquisition). Therefore, the the lock acquire AJAX method was changed to
      require a POST method.
      
      Also remove old, no-longer-used staff panel include files
      ff1d8b9e
  3. Jun 18, 2012
  4. Jun 14, 2012
  5. Jun 12, 2012
    • Jared Hancock's avatar
      Fix merge conflicts with ajax.reports.php · 4af91eca
      Jared Hancock authored
      4af91eca
    • Jared Hancock's avatar
      Next iteration of the reports · fe2be7bd
      Jared Hancock authored
      Most things work, still outstanding
        - the table needs to support filtering like the graphs,
        - the bootstrap.css file needs to be culled of what isn't used for now,
        - g.raphael needs to be re-minned after a issue is filed with g.raphael
          for the snapEnds() function not picking reasonable graph axes.
        - split dashboard.php into several smaller js, css, etc., respective files
      fe2be7bd
  6. Jun 04, 2012
Loading