Skip to content
Snippets Groups Projects
  1. Jul 23, 2012
  2. Jul 22, 2012
  3. Jul 21, 2012
  4. Jul 20, 2012
  5. Jul 16, 2012
  6. Jul 10, 2012
  7. Jul 09, 2012
  8. Jul 08, 2012
  9. Jul 07, 2012
  10. Jul 05, 2012
  11. Jul 02, 2012
  12. Jun 30, 2012
  13. Jun 29, 2012
  14. Jun 28, 2012
  15. Jun 26, 2012
  16. Jun 23, 2012
  17. Jun 21, 2012
    • Jared Hancock's avatar
      Remove SQL injection vulnerabilities · 70aca893
      Jared Hancock authored
      Map each of the inputs from $_POST['ids'] into a separate, sanitized
      database input (via the db_input() function), then implode() the array with
      commas and build the SQL statement.
      70aca893
  18. Jun 20, 2012
    • Jared Hancock's avatar
      Implement simple CSRF protection scheme · ff1d8b9e
      Jared Hancock authored
      Protect againts cross-site request forgery attacks by requiring a special
      form-field or header to be sent with requests that modify ticket system
      data.
      
      This meant a slight change to the AJAX ticket locking mechanism. It was
      defined to lock with a GET request; however, GET requests are defined as
      safe methods and should not modify backend data (such as a lock
      acquisition). Therefore, the the lock acquire AJAX method was changed to
      require a POST method.
      
      Also remove old, no-longer-used staff panel include files
      ff1d8b9e
  19. Jun 18, 2012
Loading