- Apr 09, 2018
-
-
Peter Rotich authored
-
Peter Rotich authored
-
aydreeihn authored
-
Peter Rotich authored
Commit 3944b51d added ability to archive help topics and departments but failed to port changes default data (yaml files) loaded on install. This commits adds the correct bits to flags field for both help topics and departments. It also removes retired 'isactive' field for help topics.
-
- Apr 05, 2018
-
-
aydreeihn authored
-
- Mar 29, 2018
-
-
aydreeihn authored
-
- Mar 28, 2018
-
-
aydreeihn authored
-
- Mar 24, 2018
-
-
Peter Rotich authored
This commit adds var_dump test along with a few enhancements on the test script.
-
Peter Rotich authored
Only ignore visibility constraints on private "searches" when staff is allowed to search the backend. Access control is strictly imposed on ALL queues including inherited private sub-queues.
-
Peter Rotich authored
-
- Mar 23, 2018
-
-
aydreeihn authored
-
- Mar 22, 2018
-
-
aydreeihn authored
-
Peter Rotich authored
-
JediKev authored
This addresses an issue where you can exploit XSS in the help-topic AJAX request. This adds a check for a refferal URL and if none it will return a 403 Forbidden Response.
-
JediKev authored
This addresses an issue where the CSRF Token is displayed in the URL when you preform a search in the Users Tab. This removes the token from the request which removes it from the URL.
-
aydreeihn authored
-
Andrew Peng authored
Updated to fix typo "information" on line 36
-
Peter Rotich authored
* Dont't fetch templates while in a loop * Tidy up the code
-
Peter Rotich authored
-
Peter Rotich authored
Commit c4579277 introduced an extra administrative security feature to restrict files access to signed in users only, even if a user has a valid & signed download URL. The feature, however, did not take into account public images & files associated with FAQs and pages such as landing/thank-you pages. This commit addresses the shortcoming by adding a reference ID (attachment ID) to the download/access URL, that can be used to deduce the model/object type that the file request is associated with. The technique will allow us in the future to enforce ACL at the file level depending on privacy settings and the security clearance of the user (agent).
-
Peter Rotich authored
-
Peter Rotich authored
Account for the possibility of agents being deleted
-
Peter Rotich authored
-
Peter Rotich authored
This commit adds user's account username as one of the field to scan on quick lookup;
-
Peter Rotich authored
-
Peter Rotich authored
Conflicts: include/upgrader/streams/core/934b8db8-ad9d0a5f.task.php
-
Peter Rotich authored
Make selection fields play well with Advanced Search
-
Peter Rotich authored
Commit 5be0de0d introduced the idea of moving-up old saved searches to make room for Custom Queues but failed to account for cases where the system has more than 30 saved searches. This commit addresses the issue by just re-inserting the old records after queues are imported. It also adds validates & reformat the search criteria to make the expected format.
-
- Mar 21, 2018
-
-
JediKev authored
This updates the Phone Field name back to `phone` and changes the flags to make the variable name non-editable. This also adds a check for the phone field on the User Form and if one exists adds it to the search.
-
aydreeihn authored
-
aydreeihn authored
-
aydreeihn authored
-
aydreeihn authored
-
aydreeihn authored
-
Peter Rotich authored
Commit 5be0de0d introduced the idea of moving up old saved searches to make room for custom queues - but failed to account for cases where the system has more than 30 saved searches. This commit addresses the issue by just re-inserting the old records after queues are imported.
-
- Mar 20, 2018
-
-
Peter Rotich authored
Unify ticket visibility as a routine to make sure it's applied uniformly.
-
Peter Rotich authored
Add thread entry action to create a new ticket. The entry is used to seed ticket data like user, message (issue details) and attachments
-
Peter Rotich authored
-
Peter Rotich authored
-
Peter Rotich authored
Add thread entry action to create a new ticket. The entry is used to seed ticket data like user, message (issue details) and attachments
-