- Mar 05, 2015
-
-
Peter Rotich authored
fixes #1777 Reviewed-By:
Peter Rotich <peter@osticket.com>
-
Peter Rotich authored
access: Allow empty staff banner. Show update errors Reviewed-By:
Peter Rotich <peter@osticket.com>
-
Peter Rotich authored
file drop: Support Firefox down to v6 Reviewed-By:
Peter Rotich <peter@osticket.com>
-
- Mar 02, 2015
-
-
Jared Hancock authored
This partially reverts commit bff191b6. The hasSpecialSearch() method can be retired in `develop-next` — NOT in the `develop` branch
-
- Feb 27, 2015
-
-
Luke Drummond authored
-
Jared Hancock authored
Allow the staff banner to be set to empty (which is the default). Also display the update errors back on the dialog for failed updated.
-
Jared Hancock authored
Also, give a "Browser not supported" error for browsers which do not support the Blob constructor.
-
- Feb 26, 2015
-
-
Jared Hancock authored
[FIX] Missing icon before "Add New Filter" Reviewed-By:
Jared Hancock <jared@osticket.com>
-
- Feb 18, 2015
-
-
Jared Hancock authored
-
Jared Hancock authored
-
- Feb 17, 2015
-
-
Peter Rotich authored
filter: Fix filtering by list item properties Reviewed-By:
Peter Rotich <peter@osticket.com>
-
Jared Hancock authored
-
Jared Hancock authored
-
- Feb 16, 2015
-
-
Chefkeks authored
Fixes the missing icon before "Add new filter" in scp at the filters.php page
-
- Feb 13, 2015
-
-
Jared Hancock authored
-
- Feb 11, 2015
-
-
Peter Rotich authored
login: Require CSRF token to login Reviewed-By:
Peter Rotich <peter@osticket.com>
-
Jared Hancock authored
-
Jared Hancock authored
This patch fixes a vulnerable scenario, where sequential login attempts can be made without an existing session, and without a valid CSRF token. This scenario lends itself well for brute force password attempts, because attackers can avoid using a session and still send requests to determine if a set of credentials are valid. This vector also avoids the authentication lockout mechanism, because it requires an ongoing session to shutdown the requests. This patch addresses the issue by requiring a session and a valid CSRF token generated by the server and placed in the session to be submitted with the credentials. Therefore, an existing session and a Cookie header are required to process a login attempt. Secondly, the CSRF token will be changed on the server after each login processed. Therefore, for each session, a subsequent GET request would be necessary before submitting another login attempt.
-
- Feb 10, 2015
-
-
Peter Rotich authored
email: Message-Id header with user and thread ID Reviewed-By:
Peter Rotich <peter@osticket.com>
-
Peter Rotich authored
Session never expires Reviewed-By:
Peter Rotich <peter@osticket.com>
-
Peter Rotich authored
logo: Allow customized SCP logo Reviewed-By:
Peter Rotich <peter@osticket.com>
-
- Feb 06, 2015
-
-
Jared Hancock authored
-
Jared Hancock authored
-
Jared Hancock authored
-
Peter Rotich authored
Fix very predictable random data on some platforms Reviewed-By:
Peter Rotich <peter@osticket.com>
-
Jared Hancock authored
Revert "Disable auto-responses on staff created tickets"
-
Peter Rotich authored
thread: Remove collaborators when removing the thread Reviewed-By:
Peter Rotich <peter@osticket.com>
-
Jared Hancock authored
charset: Normalize charsets Reviewed-By:
Jared Hancock <jared@osticket.com>
-
- Feb 03, 2015
-
-
Jared Hancock authored
References: https://bugs.php.net/bug.php?id=43200 http://stackoverflow.com/a/22521203
-
Jared Hancock authored
-
- Feb 02, 2015
-
-
Jared Hancock authored
-
- Jan 30, 2015
-
-
Jared Hancock authored
-
- Jan 24, 2015
-
-
Peter Rotich authored
-
- Jan 23, 2015
-
-
Jared Hancock authored
Also try harder to send a relevant In-Reply-To and References header back to the client with the email message.
-
Peter Rotich authored
This pull request adds a cleanup util for bogus and invalid charsets, mostly added by a nameless company out of Redmond, WA.
-
- Jan 15, 2015
-
-
Peter Rotich authored
Fix SLA link in help tips Reviewed-By:
Peter Rotich <peter@osticket.com>
-
- Jan 14, 2015
-
-
Jared Hancock authored
This patch sends updated session cookies to the browser when the session is refreshed on the server. This allows the session cookie to expire on the browser at the same time the session timeout occurs at the server. In the event the session timeout is configured in osTicket not to expire, the cookie will expire after seven days on the client browser, and will expire in PHP when it is garbage collected sometime after 86400 seconds after the time last refresh time. Using this method, the session will never expire if the session timeout in osTicket is configured to 0, and the session is refreshed at least daily.
-
- Jan 13, 2015
-
-
Chefkeks authored
Fixes https://github.com/osTicket/osTicket-1.8/issues/1673
-
Jared Hancock authored
Misc::randCode does not generate significantly random data for Windows platforms with a local database. This stems from the random seed using the milliseconds from the current time of day and the database connection time, in microseconds. Because Windows has especially poor sub-second time resolution via the microtime() function, the seed does not have many variations. This patch addresses the issue by using the included Crypto::random() function as a source of random data rather than the mt_rand() function, as it uses native cryptographic random data generators if possible to generate the data, and uses microtime() as a fallback if no other source of random data is available on the platform.
-
- Jan 12, 2015
-
-
Chefkeks authored
Tested with 1.9.4 - found no other / related / new issues due to this change of the z-index. Fixes: https://github.com/osTicket/osTicket-1.8/issues/980 Fixes: https://github.com/osTicket/osTicket-1.8/issues/1411
-