Thu, 26 Feb 2009 01:06:58 -0500 Dan setConfig() will now delete config values if the second parameter is explicitly set to false
Thu, 26 Feb 2009 01:04:27 -0500 Dan HMAC functions are now standards-compliant (not a security issue). This BREAKS 1.1.6-hg passwords!
Thu, 26 Feb 2009 01:03:22 -0500 Dan Added a basic plugin/hook framework for Javascript
Thu, 26 Feb 2009 01:02:50 -0500 Dan [minor] changed heading format in mainpage-default
Thu, 26 Feb 2009 01:02:33 -0500 Dan Fixed default ACLs
Thu, 26 Feb 2009 01:02:00 -0500 Dan Added color specifications on input fields for admin and oxygen
Wed, 25 Feb 2009 13:39:49 -0500 Dan Blah. Wrong type for those getConfig values.
Wed, 25 Feb 2009 13:38:21 -0500 Dan Fixed: no default values in for avatar upload settings
Mon, 16 Feb 2009 17:12:02 -0500 Dan [Oops] removed debug message in install-cli
Mon, 16 Feb 2009 17:01:56 -0500 Dan Damn, forgot to add the version insertion back into schema
Mon, 16 Feb 2009 16:17:25 -0500 Dan Major redesign of rendering pipeline that separates pages saved with MCE from pages saved with the plaintext editor (full description in long commit message)
Mon, 16 Feb 2009 16:04:54 -0500 Dan Made all page_id and namespace columns consistent
Mon, 16 Feb 2009 16:04:31 -0500 Dan Added Unicode support for usernames and passwords (this is probably best considered a JS crypto bug)
Mon, 16 Feb 2009 13:01:35 -0500 Dan Fixed https urls not allowed in user_extra CPs; fixed nonworking password reset in admin CP
Mon, 26 Jan 2009 11:45:48 -0500 Dan Added a few hooks to Admin:GeneralConfig (didn't I do this already?)
Sun, 25 Jan 2009 21:21:07 -0500 Dan Merging Nighthawk (anti-spam work) and Scribus (AJAX work + debugging + CLI installer) branches
Sun, 25 Jan 2009 21:20:14 -0500 Dan Replaced integer checks that used preg_match() to use ctype_digit() instead
Sun, 25 Jan 2009 21:18:05 -0500 Dan Added (very basic) spam filtering plugin support. Plugins can mark a message as spam by hooking into the spam check API, which is documented in functions.php. No spam checking functionality is built-in.
Sun, 25 Jan 2009 20:35:32 -0500 Dan Login: reauth: window.location.hash is now updated to include the new SID so that page reloads will use it
Sun, 25 Jan 2009 20:35:06 -0500 Dan AJAX core library: possible breaking change, readystatechange functions are now called with the XHR instance as the first parameter, to allow requests to run in parallel. This means much better stability but may break some applets (compatibility hack is included)
Sun, 25 Jan 2009 20:27:14 -0500 Dan Oxygen: synced mint style
Sun, 25 Jan 2009 20:26:50 -0500 Dan PageProcessor: fix not setting page_exists to true after create_page() success (todo: move to Namespace_*?); add $visible parameter to create_page()
Sun, 25 Jan 2009 20:24:38 -0500 Dan Change config.new.php and .htaccess.new to have a single newline according to Fedora project guidelines
Fri, 23 Jan 2009 22:03:39 -0500 Dan Installer: add RewriteBase to .htaccess to work properly under aliased Apache setups (generated 404s in QA)
Fri, 23 Jan 2009 21:59:03 -0500 Dan A few bugfixes in CLI installer related to interactivity
Sat, 17 Jan 2009 15:16:36 -0500 Dan SECURITY: Fix XSS under IE in closing tags (shared sanitizer)
Fri, 16 Jan 2009 13:14:08 -0500 Dan Fixed login form being focused too early (caused page to scroll up)
Fri, 16 Jan 2009 13:13:37 -0500 Dan Deprecated old grab_password_hash() functions in session
Fri, 16 Jan 2009 13:13:03 -0500 Dan Whoops! Fixed an SQL injection vulnerability in the CLI installer. (Not like it's a huge deal because the vulnerability was only introduced last commit and if you make it to that stage you already know the database password)
Wed, 14 Jan 2009 23:29:14 -0500 Dan Added already-installed check to cli-core
(0) -300 -100 -50 -30 +30 +50 +100 +300 tip