1. 25 Oct, 2004 1 commit
    • justdave%bugzilla.org's avatar
      [SECURITY] Bug 263780: Exporting a bug to XML exposes user comments and… · 53bd4df6
      justdave%bugzilla.org authored
      [SECURITY] Bug 263780: Exporting a bug to XML exposes user comments and attachment summaries which are marked as private to users who are not members of the group allowed to see private comments and attachments.  XML export is not exposed in the user interface, but is available to anyone who knows the correct URL to invoke it.  This only affects sites that use the 'insidergroup' feature.
      Patch by Joel Peshkin <bugreport@peshkin.net>
      r=vladd,justdave, a=justdave
      53bd4df6
  2. 22 Sep, 2004 1 commit
  3. 10 Apr, 2004 1 commit
  4. 02 Apr, 2004 1 commit
  5. 27 Mar, 2004 1 commit
  6. 18 Mar, 2004 1 commit
    • justdave%syndicomm.com's avatar
      Bug 192516: Moving the loose .pm files into the Bugzilla directory, where they… · 3d59b2bd
      justdave%syndicomm.com authored
      Bug 192516: Moving the loose .pm files into the Bugzilla directory, where they belong.  These files pre-date the Bugzilla directory, and would have gone there had it existed at the time.  The four files in question were copied on the CVS server to preserve CVS history in the files.  This checkin deletes them from the old location and modifies everything else to know where they are now.
      r= myk, gerv
      a= justdave
      3d59b2bd
  7. 20 Aug, 2003 1 commit
  8. 05 May, 2003 1 commit
  9. 27 Mar, 2003 1 commit
  10. 15 Jan, 2003 1 commit
  11. 15 Dec, 2002 1 commit
  12. 28 Nov, 2002 1 commit
  13. 26 Aug, 2002 1 commit
  14. 24 Mar, 2002 1 commit
  15. 20 Jan, 2002 1 commit
  16. 11 Sep, 2001 1 commit
  17. 03 Jun, 2001 1 commit
  18. 13 Mar, 2001 1 commit
    • endico%mozilla.org's avatar
      Checking in Jake's <jake@acutex.net> interim patches from bug 30694. Bugzilla… · f9ad3697
      endico%mozilla.org authored
      Checking in Jake's <jake@acutex.net> interim patches from bug 30694. Bugzilla was showing bug summaries to everyone, even if they didn't have permission to view the bug. Jake's quick solution is to not display the bug at all if it is in a group no matter who is viewing it. The correct solution would be display the  summary if the viewer had the proper permissions.
      f9ad3697
  19. 09 Mar, 2001 1 commit
  20. 02 Feb, 2001 1 commit
  21. 15 Jan, 2000 1 commit
  22. 02 Nov, 1999 1 commit
  23. 25 Sep, 1999 1 commit
  24. 15 Jun, 1999 1 commit
  25. 11 May, 1999 2 commits
  26. 28 Jan, 1999 1 commit
  27. 21 Nov, 1998 1 commit
  28. 17 Nov, 1998 1 commit
  29. 16 Sep, 1998 1 commit
  30. 26 Aug, 1998 1 commit