Age | Commit message (Collapse) | Author |
|
|
|
HTTP headers X_FORWARDED_* and X_REAL_IP are only evaluated when
received from an IP listed in proxy_whitelist. Furthermore, only the
last non-trusted IP from X-Forwarded-For is used in place of the real
ip.
Without this, an attacker can easily spoof the headers and control the
result of the ip or ssl check.
This fixes several problems with [3a4c9f42], [4d480b36] and [a520f331] as
mentioned in #1489729.
|
|
|
|
|
|
|
|
of current folder, even if it does not exist
|
|
|
|
Make modcss.inc work with allow_url_fopen = Off
|
|
|
|
|
|
browser (#1489569)
|
|
|
|
|
|
for all empty file uploads (#1489685)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
skip_deleted = true.
|
|
|
|
- Display alert if no file is chosen
- Unlock the UI if form is not submitted
- Avoid duplicate error messages
- Fix javascript error due to missing attachments list widget
|
|
|
|
|
|
(#1489546)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
'uibutton'
|
|
|
|
|
|
as array
|
|
CSS class for autocomplete list items
|
|
|
|
Fix default mailbox sort order
|
|
|
|
|
|
https://github.com/roundcube/roundcubemail/pull/169)
|
|
Redirect after HTTP authentication
|
|
|
|
|
|
|