Changeset 2742:8382f97c65e2
- Timestamp:
- 08/27/14 23:23:43 (11 years ago)
- Branch:
- default
- Parents:
- 2741:014e6f1fedce (diff), 2735:7483b223ed79 (diff)
Note: this is a merge changeset, the changes displayed below correspond to the merge itself.
Use the (diff) links above to see all the changes relative to each parent. - Files:
-
- 8 edited
Legend:
- Unmodified
- Added
- Removed
-
.hgsubstate
r2730 r2742 1 187bfdeb25f8169132d5fd4e7a6dd5948abe7a21inc/libs/clearbricks1 db7d5fa1b5fbf48444f782857a53091aadf24c68 inc/libs/clearbricks -
.hgtags
r2734 r2742 19 19 185f7650c1d86e4a5680c2d3b1da5628253091f5 2.6.1 20 20 1f8978ee39fc70bf9a6c345cf3b550722b819173 2.6.2 21 121f94747a10af7f58a88c00537eafc4e0d29685 2.6.3 21 22 80d565483595acca5b1d9e149aa8a2a9fe5983a6 2.6.4 -
.hgtags
r2714 r2742 20 20 1f8978ee39fc70bf9a6c345cf3b550722b819173 2.6.2 21 21 121f94747a10af7f58a88c00537eafc4e0d29685 2.6.3 22 80d565483595acca5b1d9e149aa8a2a9fe5983a6 2.6.4 -
CHANGELOG
r2732 r2742 6 6 Dotclear 2.6.3 - 2014-05-16 7 7 =========================================================== 8 * Security fix: Streng hened xmlrpc auth. Thanks to Egidio Romano9 * Security fix: Streng hened categories ordering. Thanks to Egidio Romano8 * Security fix: Strengthened xmlrpc auth. Thanks to Egidio Romano 9 * Security fix: Strengthened categories ordering. Thanks to Egidio Romano 10 10 11 11 Dotclear 2.6.2 - 2014-01-20 -
CHANGELOG
r2718 r2742 1 Dotclear 2.6.4 - 2014-08-18 2 =========================================================== 3 * Security fix: Sanitize search request. Thanks to Takayuki Uchiyama 4 * Security fix: Strenghened xmlrpc (see http://www.breaksec.com/?p=6362) 5 1 6 Dotclear 2.6.3 - 2014-05-16 2 7 =========================================================== -
admin/search.php
r2727 r2742 72 72 73 73 if ($qtype == 'p') { 74 $posts_actions_page = new dcPostsActionsPage($core, 'search.php',array('q'=>$q,'qtype'=>$qtype));74 $posts_actions_page = new dcPostsActionsPage($core,$core->adminurl->get("admin.search"),array('q'=>$q,'qtype'=>$qtype)); 75 75 76 76 if ($posts_actions_page->process()) { … … 78 78 } 79 79 } else { 80 $comments_actions_page = new dcCommentsActionsPage($core, 'search.php',array('q'=>$q,'qtype'=>$qtype));80 $comments_actions_page = new dcCommentsActionsPage($core,$core->adminurl->get("admin.search"),array('q'=>$q,'qtype'=>$qtype)); 81 81 82 82 if ($comments_actions_page->process()) { … … 94 94 95 95 echo 96 '<form action=" search.php" method="get">'.96 '<form action="'.$core->adminurl->get("admin.search").'" method="get">'. 97 97 '<div class="fieldset"><h3>'.__('Search options').'</h3>'. 98 98 '<p><label for="q">'.__('Query:').' </label>'.form::field('q',30,255,$q).'</p>'. … … 118 118 119 119 $post_list->display($page,$nb_per_page, 120 '<form action=" search.php" method="post" id="form-entries">'.120 '<form action="'.$core->adminurl->get("admin.search").'" method="post" id="form-entries">'. 121 121 122 122 '%s'. … … 146 146 147 147 $comment_list->display($page,$nb_per_page, 148 '<form action=" search.php" method="post" id="form-comments">'.148 '<form action="'.$core->adminurl->get("admin.search").'" method="post" id="form-comments">'. 149 149 150 150 '%s'. -
admin/search.php
r2720 r2742 29 29 if ($q) 30 30 { 31 $q = html::escapeHTML($q); 32 31 33 $params = array(); 32 34 … … 94 96 '<form action="'.$core->adminurl->get("admin.search").'" method="get">'. 95 97 '<div class="fieldset"><h3>'.__('Search options').'</h3>'. 96 '<p><label for="q">'.__('Query:').' </label>'.form::field('q',30,255, html::escapeHTML($q)).'</p>'.98 '<p><label for="q">'.__('Query:').' </label>'.form::field('q',30,255,$q).'</p>'. 97 99 '<p><label for="qtype1" class="classic">'.form::radio(array('qtype','qtype1'),'p',$qtype == 'p').' '.__('Search in entries').'</label> '. 98 100 '<label for="qtype2" class="classic">'.form::radio(array('qtype','qtype2'),'c',$qtype == 'c').' '.__('Search in comments').'</label></p>'. -
inc/prepend.php
r2735 r2742 11 11 # -- END LICENSE BLOCK ----------------------------------------- 12 12 13 /* Start tick */ 14 define('DC_START_TIME',microtime(true)); 15 13 16 /* ------------------------------------------------------------------------------------------- */ 14 17 # ClearBricks, DotClear classes auto-loader … … 26 29 27 30 require CLEARBRICKS_PATH.'/_common.php'; 28 $__autoload['dcCore'] = dirname(__FILE__).'/core/class.dc.core.php'; 29 $__autoload['dcAuth'] = dirname(__FILE__).'/core/class.dc.auth.php'; 30 $__autoload['dcBlog'] = dirname(__FILE__).'/core/class.dc.blog.php'; 31 $__autoload['dcCategories'] = dirname(__FILE__).'/core/class.dc.categories.php'; 32 $__autoload['dcError'] = dirname(__FILE__).'/core/class.dc.error.php'; 33 $__autoload['dcMeta'] = dirname(__FILE__).'/core/class.dc.meta.php'; 34 $__autoload['dcMedia'] = dirname(__FILE__).'/core/class.dc.media.php'; 35 $__autoload['dcPostMedia'] = dirname(__FILE__).'/core/class.dc.postmedia.php'; 36 $__autoload['dcModules'] = dirname(__FILE__).'/core/class.dc.modules.php'; 37 $__autoload['dcPlugins'] = dirname(__FILE__).'/core/class.dc.plugins.php'; 38 $__autoload['dcThemes'] = dirname(__FILE__).'/core/class.dc.themes.php'; 39 $__autoload['dcRestServer'] = dirname(__FILE__).'/core/class.dc.rest.php'; 40 $__autoload['dcNamespace'] = dirname(__FILE__).'/core/class.dc.namespace.php'; 41 $__autoload['dcSettings'] = dirname(__FILE__).'/core/class.dc.settings.php'; 42 $__autoload['dcTrackback'] = dirname(__FILE__).'/core/class.dc.trackback.php'; 43 $__autoload['dcUpdate'] = dirname(__FILE__).'/core/class.dc.update.php'; 44 $__autoload['dcUtils'] = dirname(__FILE__).'/core/class.dc.utils.php'; 45 $__autoload['dcXmlRpc'] = dirname(__FILE__).'/core/class.dc.xmlrpc.php'; 46 $__autoload['dcLog'] = dirname(__FILE__).'/core/class.dc.log.php'; 47 $__autoload['dcWorkspace'] = dirname(__FILE__).'/core/class.dc.workspace.php'; 48 $__autoload['dcPrefs'] = dirname(__FILE__).'/core/class.dc.prefs.php'; 49 $__autoload['dcStore'] = dirname(__FILE__).'/core/class.dc.store.php'; 50 $__autoload['dcStoreReader'] = dirname(__FILE__).'/core/class.dc.store.reader.php'; 51 $__autoload['dcStoreParser'] = dirname(__FILE__).'/core/class.dc.store.parser.php'; 52 $__autoload['dcFavorites'] = dirname(__FILE__).'/admin/class.dc.favorites.php'; 53 54 $__autoload['rsExtPost'] = dirname(__FILE__).'/core/class.dc.rs.extensions.php'; 55 $__autoload['rsExtComment'] = dirname(__FILE__).'/core/class.dc.rs.extensions.php'; 56 $__autoload['rsExtDates'] = dirname(__FILE__).'/core/class.dc.rs.extensions.php'; 57 $__autoload['rsExtUser'] = dirname(__FILE__).'/core/class.dc.rs.extensions.php'; 58 59 $__autoload['dcMenu'] = dirname(__FILE__).'/admin/class.dc.menu.php'; 60 $__autoload['dcPage'] = dirname(__FILE__).'/admin/lib.dc.page.php'; 61 $__autoload['adminGenericList'] = dirname(__FILE__).'/admin/lib.pager.php'; 62 $__autoload['adminPostList'] = dirname(__FILE__).'/admin/lib.pager.php'; 63 $__autoload['adminPostMiniList'] = dirname(__FILE__).'/admin/lib.pager.php'; 64 $__autoload['adminCommentList'] = dirname(__FILE__).'/admin/lib.pager.php'; 65 $__autoload['adminUserList'] = dirname(__FILE__).'/admin/lib.pager.php'; 66 $__autoload['dcPager'] = dirname(__FILE__).'/admin/lib.pager.php'; 67 $__autoload['dcAdminCombos'] = dirname(__FILE__).'/admin/lib.admincombos.php'; 68 $__autoload['adminModulesList'] = dirname(__FILE__).'/admin/lib.moduleslist.php'; 69 $__autoload['adminThemesList'] = dirname(__FILE__).'/admin/lib.moduleslist.php'; 70 71 $__autoload['dcTemplate'] = dirname(__FILE__).'/public/class.dc.template.php'; 72 $__autoload['context'] = dirname(__FILE__).'/public/lib.tpl.context.php'; 73 $__autoload['dcUrlHandlers'] = dirname(__FILE__).'/public/lib.urlhandlers.php'; 74 $__autoload['dcPostsActionsPage'] = dirname(__FILE__).'/admin/actions/class.dcactionposts.php'; 75 $__autoload['dcCommentsActionsPage'] = dirname(__FILE__).'/admin/actions/class.dcactioncomments.php'; 76 $__autoload['dcActionsPage'] = dirname(__FILE__).'/admin/actions/class.dcaction.php'; 31 $__autoload['dcCore'] = dirname(__FILE__).'/core/class.dc.core.php'; 32 $__autoload['dcAuth'] = dirname(__FILE__).'/core/class.dc.auth.php'; 33 $__autoload['dcBlog'] = dirname(__FILE__).'/core/class.dc.blog.php'; 34 $__autoload['dcCategories'] = dirname(__FILE__).'/core/class.dc.categories.php'; 35 $__autoload['dcError'] = dirname(__FILE__).'/core/class.dc.error.php'; 36 $__autoload['dcMeta'] = dirname(__FILE__).'/core/class.dc.meta.php'; 37 $__autoload['dcMedia'] = dirname(__FILE__).'/core/class.dc.media.php'; 38 $__autoload['dcPostMedia'] = dirname(__FILE__).'/core/class.dc.postmedia.php'; 39 $__autoload['dcModules'] = dirname(__FILE__).'/core/class.dc.modules.php'; 40 $__autoload['dcPlugins'] = dirname(__FILE__).'/core/class.dc.plugins.php'; 41 $__autoload['dcThemes'] = dirname(__FILE__).'/core/class.dc.themes.php'; 42 $__autoload['dcRestServer'] = dirname(__FILE__).'/core/class.dc.rest.php'; 43 $__autoload['dcNamespace'] = dirname(__FILE__).'/core/class.dc.namespace.php'; 44 $__autoload['dcSettings'] = dirname(__FILE__).'/core/class.dc.settings.php'; 45 $__autoload['dcTrackback'] = dirname(__FILE__).'/core/class.dc.trackback.php'; 46 $__autoload['dcUpdate'] = dirname(__FILE__).'/core/class.dc.update.php'; 47 $__autoload['dcUtils'] = dirname(__FILE__).'/core/class.dc.utils.php'; 48 $__autoload['dcXmlRpc'] = dirname(__FILE__).'/core/class.dc.xmlrpc.php'; 49 $__autoload['dcLog'] = dirname(__FILE__).'/core/class.dc.log.php'; 50 $__autoload['dcWorkspace'] = dirname(__FILE__).'/core/class.dc.workspace.php'; 51 $__autoload['dcPrefs'] = dirname(__FILE__).'/core/class.dc.prefs.php'; 52 $__autoload['dcStore'] = dirname(__FILE__).'/core/class.dc.store.php'; 53 $__autoload['dcStoreReader'] = dirname(__FILE__).'/core/class.dc.store.reader.php'; 54 $__autoload['dcStoreParser'] = dirname(__FILE__).'/core/class.dc.store.parser.php'; 55 $__autoload['dcFavorites'] = dirname(__FILE__).'/admin/class.dc.favorites.php'; 56 57 $__autoload['rsExtPost'] = dirname(__FILE__).'/core/class.dc.rs.extensions.php'; 58 $__autoload['rsExtComment'] = dirname(__FILE__).'/core/class.dc.rs.extensions.php'; 59 $__autoload['rsExtDates'] = dirname(__FILE__).'/core/class.dc.rs.extensions.php'; 60 $__autoload['rsExtUser'] = dirname(__FILE__).'/core/class.dc.rs.extensions.php'; 61 62 $__autoload['dcMenu'] = dirname(__FILE__).'/admin/class.dc.menu.php'; 63 $__autoload['dcPage'] = dirname(__FILE__).'/admin/lib.dc.page.php'; 64 $__autoload['adminGenericList'] = dirname(__FILE__).'/admin/lib.pager.php'; 65 $__autoload['adminPostList'] = dirname(__FILE__).'/admin/lib.pager.php'; 66 $__autoload['adminPostMiniList'] = dirname(__FILE__).'/admin/lib.pager.php'; 67 $__autoload['adminCommentList'] = dirname(__FILE__).'/admin/lib.pager.php'; 68 $__autoload['adminUserList'] = dirname(__FILE__).'/admin/lib.pager.php'; 69 $__autoload['dcPager'] = dirname(__FILE__).'/admin/lib.pager.php'; 70 $__autoload['dcAdminCombos'] = dirname(__FILE__).'/admin/lib.admincombos.php'; 71 $__autoload['adminModulesList'] = dirname(__FILE__).'/admin/lib.moduleslist.php'; 72 $__autoload['adminThemesList'] = dirname(__FILE__).'/admin/lib.moduleslist.php'; 73 $__autoload['dcThemeConfig'] = dirname(__FILE__).'/admin/lib.themeconfig.php'; 74 75 $__autoload['dcTemplate'] = dirname(__FILE__).'/public/class.dc.template.php'; 76 $__autoload['context'] = dirname(__FILE__).'/public/lib.tpl.context.php'; 77 $__autoload['dcUrlHandlers'] = dirname(__FILE__).'/public/lib.urlhandlers.php'; 78 $__autoload['dcAdminURL'] = dirname(__FILE__).'/admin/lib.dc.adminurl.php'; 79 $__autoload['dcPostsActionsPage'] = dirname(__FILE__).'/admin/actions/class.dcactionposts.php'; 80 $__autoload['dcCommentsActionsPage'] = dirname(__FILE__).'/admin/actions/class.dcactioncomments.php'; 81 $__autoload['dcActionsPage'] = dirname(__FILE__).'/admin/actions/class.dcaction.php'; 77 82 78 83 # Clearbricks extensions … … 135 140 # Constants 136 141 define('DC_ROOT',path::real(dirname(__FILE__).'/..')); 137 define('DC_VERSION','2. 6.5');142 define('DC_VERSION','2.7-dev'); 138 143 define('DC_DIGESTS',dirname(__FILE__).'/digests'); 139 144 define('DC_L10N_ROOT',dirname(__FILE__).'/../locales'); 140 145 define('DC_L10N_UPDATE_URL','http://services.dotclear.net/dc2.l10n/?version=%s'); 141 define('DC_DISTRIB_PLUGINS','aboutConfig,akismet,antispam,attachments,blogroll,blowupConfig,dclegacy,fairTrackbacks,importExport,maintenance,pages,pings,simpleMenu,tags,themeEditor,userPref,widgets'); 142 define('DC_DISTRIB_THEMES','blueSilence,blowupConfig,customCSS,default,ductile'); 146 define('DC_DISTRIB_PLUGINS','aboutConfig,akismet,antispam,attachments,blogroll,blowupConfig,dclegacy,fairTrackbacks,importExport,maintenance,pages,pings,simpleMenu,tags,themeEditor,userPref,widgets,dcLegacyEditor,dcCKEditor'); 147 define('DC_DISTRIB_THEMES','berlin,blueSilence,blowupConfig,customCSS,default,ductile'); 148 define('DC_DEFAULT_TPLSET','mustek'); 143 149 144 150 if (!defined('DC_VENDOR_NAME')) {
Note: See TracChangeset
for help on using the changeset viewer.