Skip to content

Conversation

@coneheadusa
Copy link

No description provided.

blizzz and others added 30 commits August 16, 2016 21:08
CI uses an older PHPUnit
File has been renamed only on master
nickvergessen and others added 28 commits September 8, 2016 09:21
…rmissions-for-webdav-move-and-copy

[stable10] Fix required permissions for webdav move and copy
…f-file-types-a-bit

[stable10] Fix detection of file types a bit
…rkflows

[stable10] Add a docs link when given
[10] fix setting quota to default or unlimited
…te-password-policy

Allow to validate the password_policy app
…utton-for-updates-atm

[stable10] Show an download button instead of the updater
Some user agents are notorious and don't really properly follow HTTP
 specifications. For those, have an automated opt-out. Since the protection
for remote.php is applied in base.php as starting point we need to opt out
here.
OVH has implemented load balancing in a very questionable way where the reverse proxy actually internally adds some cookies which would trigger a security exception. To work around this, this change only checks for the session cookie.
[stable10] Fix OS X and OVH problems
There's no need to allow more than those defined mimetypes for images.
The exception message is potentially influenced by user input and could thus be confusing (e.g. somebody could try to open a file like "Please send a mail to support@foo.com", and then the message would include that string.

It is thus reasonable to not show the exception message by default. Also for the browser view I added an `exit()` at the end, as otherwise the XML exception would be attached.
… shouldn't touch files owned by a different user.
…-mimetypes

[stable10] Filter more mimetypes
…-printable

[stable10] Don't print exception message in HTML
…stable10

[stable10] skip shared files, if files get decrypted only for a specific user
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.