Laurent Destailleur
|
7835c1f6bc
|
Debug setup
|
2023-12-02 15:49:29 +01:00 |
|
Laurent Destailleur
|
df6ca57763
|
Debug v19
|
2023-12-02 15:20:42 +01:00 |
|
Laurent Destailleur
|
c417949a7e
|
Fix phpunit
|
2023-11-30 00:06:05 +01:00 |
|
Laurent Destailleur
|
7809b66688
|
Doc
|
2023-11-29 23:18:49 +01:00 |
|
Laurent Destailleur
|
3e1d5b1748
|
Fix for MAIN_RESTRICTHTML_ONLY_VALID_HTML
|
2023-11-29 23:17:22 +01:00 |
|
Laurent Destailleur
|
43f9210ab4
|
SEC: Add option MAIN_RESTRICTHTML_ONLY_VALID_HTML_TIDY
|
2023-11-29 20:19:21 +01:00 |
|
Laurent Destailleur
|
ca3f5eaadf
|
Debug v19
|
2023-11-14 00:56:30 +01:00 |
|
Laurent Destailleur
|
5b15b5c647
|
QUAL Move conf->global into getDolGlobal...
|
2023-10-24 17:00:13 +02:00 |
|
Laurent Destailleur
|
bae75281e3
|
QUAL: Code fix using rector
|
2023-10-11 19:44:06 +02:00 |
|
Jon Bendtsen
|
154ce1329f
|
adding mariadb and mariadb-dump to the list of restricted os commands
|
2023-09-13 22:58:36 +02:00 |
|
Laurent Destailleur
|
7ce9bf6b23
|
Clean code
|
2023-08-05 15:44:28 +02:00 |
|
Laurent Destailleur
|
761565cabb
|
Merge branch '18.0' of git@github.com:Dolibarr/dolibarr.git into develop
|
2023-07-25 23:47:28 +02:00 |
|
Laurent Destailleur
|
2bc6cd20dd
|
Debug v18
|
2023-07-25 13:15:52 +02:00 |
|
Laurent Destailleur
|
01eca1eb47
|
Debug v18
|
2023-07-25 12:56:11 +02:00 |
|
Laurent Destailleur
|
7ccd50d2b8
|
Fix class not initialized
|
2023-07-25 12:38:27 +02:00 |
|
Laurent Destailleur
|
9c62e76c46
|
NEW Disable not used PHP streams
|
2023-07-25 12:30:09 +02:00 |
|
Laurent Destailleur
|
b08d24348c
|
Add 2 more dangerous function to disable
|
2023-07-25 12:00:50 +02:00 |
|
Laurent Destailleur
|
4ba8324a3f
|
Doc
|
2023-07-19 04:22:02 +02:00 |
|
Frédéric FRANCE
|
d55ae5dbd2
|
use isModEnabled
|
2023-06-09 13:53:58 +02:00 |
|
Laurent Destailleur
|
51708f4d70
|
Ad option MAIN_ALLOW_SVG_FILES_AS_EXTERNAL_LINKS in security page
|
2023-06-03 11:31:24 +02:00 |
|
Laurent Destailleur
|
155c52bc30
|
Fix #yogosha16184
|
2023-04-24 13:52:31 +02:00 |
|
Laurent Destailleur
|
869a73befc
|
Add option MAIN_DISALLOW_EXT_URL_INTO_DESCRIPTIONS into security page
|
2023-04-06 13:39:04 +02:00 |
|
Laurent Destailleur
|
3821f5c27c
|
Update security page
|
2023-03-21 01:50:14 +01:00 |
|
Laurent Destailleur
|
72750c3b8d
|
Add notice in security to show if installmodules.lock exists.
|
2023-03-21 01:43:09 +01:00 |
|
Laurent Destailleur
|
29417861db
|
Fix bad var shown
|
2023-03-12 11:54:46 +01:00 |
|
Laurent Destailleur
|
54d1250887
|
Merge + Clean duplicate trigger code. We must use the context.
|
2023-03-02 02:19:24 +01:00 |
|
Laurent Destailleur
|
14a59483f5
|
Debug v17
|
2023-03-01 23:50:02 +01:00 |
|
Laurent Destailleur
|
6fc473bd71
|
Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop
|
2023-02-28 19:16:29 +01:00 |
|
Laurent Destailleur
|
afae14d914
|
Fix CSP Policy
|
2023-02-28 11:35:40 +01:00 |
|
Laurent Destailleur
|
3354a27a6f
|
css
|
2023-02-25 01:21:12 +01:00 |
|
Laurent Destailleur
|
5aaca18567
|
css
|
2023-02-25 00:48:50 +01:00 |
|
Laurent Destailleur
|
44da230012
|
Clean code
|
2023-02-21 12:57:36 +01:00 |
|
Laurent Destailleur
|
870ac42082
|
Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop
|
2023-02-20 16:20:49 +01:00 |
|
Laurent Destailleur
|
a4c2c671be
|
Fix option example
|
2023-02-20 15:29:17 +01:00 |
|
Laurent Destailleur
|
0300ccebfd
|
Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop
|
2023-02-18 21:09:58 +01:00 |
|
Laurent Destailleur
|
a81510ccd6
|
Better exemple for RCP security string
|
2023-02-18 14:15:39 +01:00 |
|
Laurent Destailleur
|
2168578f2e
|
Fix inline css
|
2023-02-18 14:00:25 +01:00 |
|
Laurent Destailleur
|
183ae35ab7
|
Fix #huntr10e423cd-7051-43fd-b736-4e18650d0172
|
2023-02-13 12:57:35 +01:00 |
|
Laurent Destailleur
|
53be37148b
|
NEW Support option MAIN_SECURITY_MAXFILESIZE_DOWNLOADED #yogosha10660
|
2023-02-04 11:32:38 +01:00 |
|
Laurent Destailleur
|
8f02fb2ab8
|
Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop
|
2022-12-22 20:34:22 +01:00 |
|
Laurent Destailleur
|
d183760841
|
Clean code
|
2022-12-22 13:21:46 +01:00 |
|
Frédéric FRANCE
|
b1b46556be
|
fix stickler
|
2022-12-21 09:17:07 +01:00 |
|
Frédéric FRANCE
|
6c24230d9e
|
fix typo
|
2022-12-20 18:34:50 +01:00 |
|
Frédéric FRANCE
|
172aa02eff
|
fix typo in url
|
2022-12-20 18:30:53 +01:00 |
|
Frédéric FRANCE
|
5a5794b64a
|
fix warnings
|
2022-12-20 18:22:10 +01:00 |
|
Laurent Destailleur
|
981e165c3e
|
Reduce default value from 1000 to 200 for
MAIN_SECURITY_MAX_POST_ON_PUBLIC_PAGES_BY_IP_ADDRESS
|
2022-11-29 10:24:21 +01:00 |
|
Laurent Destailleur
|
427a785fb3
|
Update help on security
|
2022-11-22 21:27:30 +01:00 |
|
Laurent Destailleur
|
767f5db7dc
|
Typo
|
2022-11-20 22:42:35 +01:00 |
|
Laurent Destailleur
|
3041edc013
|
Debug
|
2022-11-20 21:59:35 +01:00 |
|
Laurent Destailleur
|
e5a4824ed2
|
Enhance default WEBSITE_MAIN_SECURITY_FORCECSP
|
2022-11-20 16:12:18 +01:00 |
|
Laurent Destailleur
|
c5459a47eb
|
Enhance default WEBSITE_MAIN_SECURITY_FORCECSP
|
2022-11-20 16:08:32 +01:00 |
|
Laurent Destailleur
|
938bc27917
|
Update sample for fail2ban
|
2022-10-18 12:59:15 +02:00 |
|
lmarcouiller
|
b0d2aa6d9b
|
Fix : php 8.1 warnings
|
2022-09-23 16:05:11 +02:00 |
|
Laurent Destailleur
|
4a17fae9af
|
Add info on mitigation
|
2022-09-11 20:48:23 +02:00 |
|
Laurent Destailleur
|
60c39933d4
|
Clean code
|
2022-09-11 13:26:24 +02:00 |
|
Laurent Destailleur
|
a0dda0ed77
|
NEW Add more advices into the Setup security page
|
2022-09-11 12:35:40 +02:00 |
|
Laurent Destailleur
|
2293d82607
|
NEW Add picto property on sub-module for paswword generation
|
2022-09-11 12:18:43 +02:00 |
|
Frédéric France
|
8d33953142
|
add comment
|
2022-09-07 20:08:59 +02:00 |
|
Laurent Destailleur
|
3b195fa1fb
|
Can add Permissions-Policy on web sites
|
2022-08-16 16:58:28 +02:00 |
|
Laurent Destailleur
|
5ef941311a
|
NEW can set header "Strict-Transport-Security" in web sites
|
2022-08-16 16:06:09 +02:00 |
|
Laurent Destailleur
|
f404eddad0
|
Fix recommended value
|
2022-08-16 15:23:53 +02:00 |
|
Laurent Destailleur
|
94da628cf4
|
Clean code for http header + better support for Content-Security-Policy
|
2022-08-16 15:19:45 +02:00 |
|
Laurent Destailleur
|
524b001f3b
|
Add $dolibarr_main_restrict_os_commands in security center.
|
2022-04-06 21:14:35 +02:00 |
|
Laurent Destailleur
|
9bda7ba8c7
|
Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
htdocs/core/class/doleditor.class.php
|
2022-03-03 00:16:55 +01:00 |
|
Laurent Destailleur
|
8051128665
|
Split section experimental and stable
|
2022-03-02 11:37:19 +01:00 |
|
Laurent Destailleur
|
12b2a10865
|
Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop
|
2022-03-01 18:15:13 +01:00 |
|
Laurent Destailleur
|
237b6fc922
|
Fix value recommended
|
2022-03-01 17:07:28 +01:00 |
|
Laurent Destailleur
|
8c61a29051
|
Show value of short_open_tags
|
2022-02-25 01:30:34 +01:00 |
|
Laurent Destailleur
|
bf1dfac629
|
Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
htdocs/langs/en_US/errors.lang
htdocs/product/stock/movement_list.php
|
2021-11-25 21:54:06 +01:00 |
|
Laurent Destailleur
|
b345c2463c
|
Fix warning on security page
|
2021-11-25 00:19:55 +01:00 |
|
Frédéric FRANCE
|
6d9ee78704
|
security page doesnt detect xdebug
|
2021-10-23 21:53:04 +02:00 |
|
Regis Houssin
|
db01fed447
|
FIX error when defining an already existing constant
|
2021-10-19 12:36:33 +02:00 |
|
Laurent Destailleur
|
6d8276c9c8
|
Doc
|
2021-10-04 12:59:53 +02:00 |
|
Laurent Destailleur
|
eada0f468f
|
Set MAIN_SECURITY_CSRF_WITH_TOKEN recommended value to 1
|
2021-10-01 12:39:15 +02:00 |
|
Laurent Destailleur
|
5c8b893877
|
Doc
|
2021-09-27 12:50:51 +02:00 |
|
Laurent Destailleur
|
72be24a835
|
Doc
|
2021-09-27 12:37:10 +02:00 |
|
Laurent Destailleur
|
4a85304572
|
Fix security
|
2021-09-26 21:01:34 +02:00 |
|
Laurent Destailleur
|
6c37836b3e
|
Show value of MAIN_SECURITY_CSRF_WITH_TOKEN in setup page
|
2021-09-18 18:28:02 +02:00 |
|
Laurent Destailleur
|
4cd5a53b63
|
FIX Recommended session.cookie_samesite must be 'Lax' not 'Strict'.
|
2021-08-22 00:44:51 +02:00 |
|
Laurent Destailleur
|
948663deb4
|
Fix deprecated var
|
2021-08-07 13:59:07 +02:00 |
|
Laurent Destailleur
|
1435172405
|
Better help
|
2021-08-06 18:55:41 +02:00 |
|
Laurent Destailleur
|
d437d382d8
|
Fix trans
|
2021-08-06 18:48:05 +02:00 |
|
Laurent Destailleur
|
a7fa238b71
|
Position of option
|
2021-08-06 18:35:16 +02:00 |
|
Laurent Destailleur
|
e26eda3f5f
|
Position of option
|
2021-08-06 18:34:35 +02:00 |
|
Laurent Destailleur
|
458f773baf
|
Fix security options
|
2021-08-06 18:32:40 +02:00 |
|
Laurent Destailleur
|
a5d11a1ccf
|
Fix warning
|
2021-08-04 15:46:00 +02:00 |
|
Laurent Destailleur
|
ba403dd33f
|
Add missing security info
|
2021-08-04 15:21:01 +02:00 |
|
Laurent Destailleur
|
c60927da61
|
Add missing security info
|
2021-08-04 15:16:51 +02:00 |
|
Laurent Destailleur
|
f02dee2e21
|
Fix test on missing install.lock
|
2021-07-29 23:47:59 +02:00 |
|
Laurent Destailleur
|
407ad4d84d
|
Fix bad value
|
2021-07-06 02:15:52 +02:00 |
|
Laurent Destailleur
|
6e24ee48d4
|
Debug security page
|
2021-07-06 02:07:58 +02:00 |
|
Laurent Destailleur
|
6e27ae6029
|
Fix path
|
2021-06-20 01:56:26 +02:00 |
|
Laurent Destailleur
|
4b6427f920
|
Fix menu entry
|
2021-06-20 01:55:56 +02:00 |
|
Laurent Destailleur
|
2efd432946
|
Fix list of security events enabled
|
2021-06-20 01:54:55 +02:00 |
|
Laurent Destailleur
|
d4ca6bf42a
|
Clean code
|
2021-06-09 13:56:03 +02:00 |
|
Laurent Destailleur
|
458ef9f8da
|
Fix security test
|
2021-06-09 13:31:00 +02:00 |
|
Laurent Destailleur
|
14e3d04e25
|
Add more info on security page
|
2021-06-09 13:02:17 +02:00 |
|
Laurent Destailleur
|
c375668ab6
|
Clean code
|
2021-06-09 12:41:53 +02:00 |
|
Laurent Destailleur
|
2f969f154e
|
More examples
|
2021-05-30 17:10:38 +02:00 |
|
Laurent Destailleur
|
1834d642b3
|
Fix phpcs
|
2021-05-30 17:04:12 +02:00 |
|