Age | Commit message (Collapse) | Author |
|
|
|
HTTP headers X_FORWARDED_* and X_REAL_IP are only evaluated when
received from an IP listed in proxy_whitelist. Furthermore, only the
last non-trusted IP from X-Forwarded-For is used in place of the real
ip.
Without this, an attacker can easily spoof the headers and control the
result of the ip or ssl check.
This fixes several problems with [3a4c9f42], [4d480b36] and [a520f331] as
mentioned in #1489729.
|
|
|
|
of current folder, even if it does not exist
|
|
|
|
Make modcss.inc work with allow_url_fopen = Off
|
|
|
|
|
|
browser (#1489569)
|
|
|
|
for all empty file uploads (#1489685)
|
|
|
|
skip_deleted = true.
|
|
- Display alert if no file is chosen
- Unlock the UI if form is not submitted
- Avoid duplicate error messages
- Fix javascript error due to missing attachments list widget
|
|
|
|
|
|
|
|
|
|
|
|
'uibutton'
|
|
|
|
as array
|
|
CSS class for autocomplete list items
|
|
|
|
|
|
|
|
|
|
by wrapping the clickable content in <span> tag
|
|
|
|
(#1489627)
|
|
|
|
|
|
Alternatively use the PHP cURL extension
|
|
|
|
various user properties there
|
|
Added rcube_utils::is_absolute_path() method
|
|
|
|
|
|
|
|
in the main window with enoough space and better UI integration
|
|
|
|
|
|
|
|
mouse click on a record after the focus was put on preview frame.
|
|
|
|
|
|
|
|
|
|
that includes touch events (#1489431)
|
|
|