- 31 Jan, 2019 1 commit
-
-
Perl Tidy authored
-
- 06 Oct, 2014 1 commit
-
-
Frédéric Buclin authored
r=dkl,a=sgreen
-
- 01 Oct, 2014 2 commits
-
-
Frédéric Buclin authored
-
Reed Loden authored
Bug 1061247 - Successfully using a password change token should invalidate all other password change tokens for that user r=gerv a=glob
-
- 13 Aug, 2014 1 commit
-
-
Frédéric Buclin authored
r=dkl a=sgreen
-
- 05 Aug, 2014 1 commit
-
-
Frédéric Buclin authored
Bug 1046145: It is no longer possible to cancel an email address change when this one has already been confirmed r=dkl a=sgreen
-
- 27 Feb, 2014 1 commit
-
-
Charlie Somerville authored
r=gerv a=justdave
-
- 06 Jun, 2013 1 commit
-
-
Frédéric Buclin authored
Bug 878035: Do not disclose whether a user account exists or not when a user clicks "forgot password" r=dkl a=LpSolit
-
- 01 Sep, 2012 1 commit
-
-
Frédéric Buclin authored
r=wicked a=LpSolit
-
- 06 Aug, 2012 1 commit
-
-
Frédéric Buclin authored
Bug 706271: CSRF vulnerability in token.cgi allows possible unauthorized password reset e-mail request r=reed a=LpSolit
-
- 28 May, 2012 1 commit
-
-
Koosha Khajeh Moogahi authored
r/a=LpSolit
-
- 18 May, 2012 1 commit
-
-
Koosha Khajeh Moogahi authored
Bug 752303: It is no longer possible to cancel an email address change when this one has already been confirmed r/a=LpSolit
-
- 23 Jan, 2012 1 commit
-
-
Frédéric Buclin authored
r=glob a=LpSolit
-
- 11 Jan, 2012 1 commit
-
-
Frédéric Buclin authored
Bug 680131: Replace the MPL 1.1 license by the MPL 2.0 one in all files, and add it to files which miss one r=kiko r=mkanat r=mrbball a=LpSolit
-
- 28 Dec, 2011 1 commit
-
-
Frédéric Buclin authored
Bug 711714: (CVE-2011-3667) [SECURITY] The User.offer_account_by_email WebService method lets you create new user accounts independently of the value of Bugzilla::Auth::Verify::*::user_can_create_account r=glob a=LpSolit
-
- 16 Aug, 2011 2 commits
-
-
Frédéric Buclin authored
-
Frédéric Buclin authored
Bug 677901: Bugzilla crashes when no token is passed to token.cgi but the script expects one, because tokens are incorrectly validated r/a=mkanat
-
- 05 Jul, 2011 1 commit
-
-
David Lawrence authored
r/a=mkanat
-
- 20 May, 2010 1 commit
-
-
Frédéric Buclin authored
Bug 565879: Merge ThrowCodeError("action_unrecognized"), ThrowUserError("no_valid_action") and ThrowCodeError("unknown_action") r=ghendricks a=LpSolit
-
- 09 Oct, 2009 1 commit
-
-
mkanat%bugzilla.org authored
Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=dkl, a=mkanat
-
- 11 Sep, 2009 1 commit
-
-
mkanat%bugzilla.org authored
Bug 508189: (CVE-2009-3166) [SECURITY] Logging in after changing your password would expose your new password in the URL Patch by Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=mkanat
-
- 11 Aug, 2009 1 commit
-
-
lpsolit%gmail.com authored
Bug 349336: Automatically log in the user when he chooses his password to create his new account - Patch by FrÃ
dà ric Buclin <LpSolit@gmail.com> r/a=mkanat
-
- 12 Jun, 2009 1 commit
-
-
bbaetz%acm.org authored
(original patch r/a=mkanat)
-
- 10 Jun, 2009 1 commit
-
-
bbaetz%acm.org authored
-
- 08 Jan, 2009 1 commit
-
-
lpsolit%gmail.com authored
Bug 452519: Fix timezones in emails - Patch by FrÃ
dà ric Buclin <LpSolit@gmail.com> r=wicked a=LpSolit
-
- 20 Sep, 2008 1 commit
-
-
lpsolit%gmail.com authored
Bug 455814: token.cgi should reject password change requests for disabled accounts - Patch by FrÃ
dà ric Buclin <LpSolit@gmail.com> r=ghendricks a=LpSolit
-
- 19 Sep, 2008 1 commit
-
-
lpsolit%gmail.com authored
Bug 455815: Remove global variables from token.cgi - Patch by FrÃ
dà ric Buclin <LpSolit@gmail.com> r/a=mkanat
-
- 18 Aug, 2008 1 commit
-
-
dkl%redhat.com authored
doesn't protect WebService calls at all Patch by David Lawrence <dkl@redhat.com> - r/a=LpSolit/mkanat
-
- 29 Jul, 2008 1 commit
-
-
dkl%redhat.com authored
in the respective bug reports. Bug 428659 â Setting SSL param to 'authenticated sessions' only protects logins and param doesn't protect WebService calls at all Patch by Dave Lawrence <dkl@redhat.com> - r/a=mkanat Bug 445104: ssl redirects come with a 200 OK HTTP code on mod_perl Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=dkl, a=mkanat
-
- 10 Jul, 2008 1 commit
-
-
dkl%redhat.com authored
Bug 428659 â Setting SSL param to 'authenticated sessions' only protects logins and param doesn't protect WebService calls at all Patch by Dave Lawrence <dkl@redhat.com> - r/a=mkanat
-
- 02 Apr, 2008 1 commit
-
-
lpsolit%gmail.com authored
Bug 405946: Some emails are not sent in the language chosen by the addressee - Patch by FrÃ
dà ric Buclin <LpSolit@gmail.com> r=wurblzap a=LpSolit
-
- 19 Nov, 2007 1 commit
-
-
lpsolit%gmail.com authored
Bug 403834: Replace table locks with database transactions in tokens, votes, and sanitycheck - Patch by Emmanuel Seyman <eseyman@linagora.com> r/a=mkanat
-
- 19 Oct, 2007 1 commit
-
-
mkanat%bugzilla.org authored
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=LpSolit
-
- 23 Jul, 2007 1 commit
-
-
timeless%mozdev.org authored
r=lpsolit a=lpsolit
-
- 10 Jul, 2007 1 commit
-
-
timeless%mozdev.org authored
r=lpsolit a=lpsolit
-
- 11 Mar, 2007 1 commit
-
-
reed%reedloden.com authored
-
- 21 Oct, 2006 1 commit
-
-
wurblzap%gmail.com authored
Bug 340538: Insecure dependency in exec while running with -T switch at /usr/lib/perl5/site_perl/5.8.6/Mail/Mailer/sendmail.pm line 16. Patch by Marc Schumann <wurblzap@gmail.com>, r=LpSolit, a=myk
-
- 15 Oct, 2006 1 commit
-
-
lpsolit%gmail.com authored
Bug 281181: [SECURITY] It's way too easy to delete versions/components/milestones etc... - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat a=myk
-
- 26 Aug, 2006 1 commit
-
-
mkanat%bugzilla.org authored
Patch By Max Kanat-Alexander <mkanat@bugzilla.org> r=LpSolit, a=myk
-
- 20 Aug, 2006 1 commit
-
-
lpsolit%gmail.com authored
Bug 87795: Creating an account should send token and wait for confirmation (prevent user account abuse) - Patch by Frédéric Buclin <LpSolit@gmail.com> r=mkanat r=bkor a=myk
-