Commit Graph

779 Commits

Author SHA1 Message Date
Laurent Destailleur
2f3105d884 Add CSRF protection 2021-08-04 13:05:07 +02:00
Laurent Destailleur
6f449cfd6c Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop 2021-07-31 16:33:38 +02:00
Laurent Destailleur
f02dee2e21 Fix test on missing install.lock 2021-07-29 23:47:59 +02:00
Laurent Destailleur
7533c9e3a5 Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/langs/fr_FR/interventions.lang
2021-07-12 12:01:53 +02:00
Laurent Destailleur
802ac58f9a Clean v14 2021-07-11 18:56:15 +02:00
Laurent Destailleur
e1e410ce91 Fix error message if file corrupted 2021-07-11 03:04:06 +02:00
Laurent Destailleur
93083e39c7 Fix using zip for integrity file 2021-07-11 02:58:18 +02:00
Laurent Destailleur
3fadd5cda5 NEW Add $dolibarr_main_db_readonly in conf.php for readonly access. 2021-07-09 19:37:12 +02:00
Laurent Destailleur
407ad4d84d Fix bad value 2021-07-06 02:15:52 +02:00
Laurent Destailleur
6e24ee48d4 Debug security page 2021-07-06 02:07:58 +02:00
Laurent Destailleur
3ac72fe73c Fix 2021-07-05 18:19:02 +02:00
Laurent Destailleur
38d272e31a Better position of fields 2021-07-05 18:16:52 +02:00
Laurent Destailleur
a14c68e996 Fix Hide sensitive key on info page 2021-07-05 18:14:52 +02:00
Laurent Destailleur
6e27ae6029 Fix path 2021-06-20 01:56:26 +02:00
Laurent Destailleur
4b6427f920 Fix menu entry 2021-06-20 01:55:56 +02:00
Laurent Destailleur
2efd432946 Fix list of security events enabled 2021-06-20 01:54:55 +02:00
Laurent Destailleur
61bd572a9c Fix token for ajax call 2021-06-17 03:37:52 +02:00
Laurent Destailleur
d4ca6bf42a Clean code 2021-06-09 13:56:03 +02:00
Laurent Destailleur
458ef9f8da Fix security test 2021-06-09 13:31:00 +02:00
Laurent Destailleur
14e3d04e25 Add more info on security page 2021-06-09 13:02:17 +02:00
Laurent Destailleur
c375668ab6 Clean code 2021-06-09 12:41:53 +02:00
Laurent Destailleur
2dc9ca334f CSS 2021-05-31 23:36:37 +02:00
Laurent Destailleur
2f969f154e More examples 2021-05-30 17:10:38 +02:00
Laurent Destailleur
1834d642b3 Fix phpcs 2021-05-30 17:04:12 +02:00
Laurent Destailleur
240ca50a84 Merge branch 'develop' of git@github.com:Dolibarr/dolibarr.git into develop 2021-05-27 01:53:06 +02:00
Laurent Destailleur
7983ce941e Fix performance page 2021-05-27 01:52:52 +02:00
Laurent Destailleur
5372912b0b
Merge pull request #17642 from Givriz/dev
Compatibility phpv8
2021-05-26 18:22:46 +02:00
Laurent Destailleur
673eb73d0a
Merge branch 'develop' into dev_1 2021-05-25 19:55:31 +02:00
Laurent Destailleur
9d6e93fd01
Update security.php 2021-05-25 19:50:53 +02:00
Laurent Destailleur
d4310f49c4 FIX CWE-79 - huntr - Fix option MAIN_ALLOW_SVG_FILES_AS_IMAGES 2021-05-24 19:46:19 +02:00
Givriz
0c5a934e10 Compatibility phpv8 2021-05-20 17:40:44 +02:00
Laurent Destailleur
c561669edf Code comment 2021-05-20 17:02:22 +02:00
Damien BENOIT
e7ac39fe35
Update modules.php
Added $param
2021-05-18 15:23:29 +02:00
Givriz
6bbd6db84b Compatibility phpv8 2021-05-17 18:39:08 +02:00
Laurent Destailleur
d888e4b3bf
Merge pull request #17385 from Givriz/dev_1
Compatibility phpv8
2021-05-17 16:29:49 +02:00
Laurent Destailleur
9eda9c1e21 Enhance setup 2021-05-12 19:55:16 +02:00
Frédéric FRANCE
0d3afb573a
align check code 2021-05-10 14:33:26 +02:00
Laurent Destailleur
a54e60d345 Look and feel v14 2021-05-02 13:13:55 +02:00
Laurent Destailleur
e99355a0c2 Clean html 2021-04-30 15:22:17 +02:00
Laurent Destailleur
195163b81a Enhance security center 2021-04-30 11:45:45 +02:00
Laurent Destailleur
1166dfb458
Merge pull request #17365 from Givriz/dev
Compatibility phpv8
2021-04-28 17:01:22 +02:00
Laurent Destailleur
367a6b15a6
Update modules.php 2021-04-28 17:00:29 +02:00
Laurent Destailleur
d138e7410b Clean code 2021-04-26 19:12:23 +02:00
Givriz
a451fee68f Compatibility phpv8 2021-04-23 18:01:11 +02:00
Givriz
3c49a2b49a Compatibility phpv8 2021-04-21 18:59:25 +02:00
Laurent Destailleur
474bf5cfd9 Show MAIN_SECURITY_ANTI_SSRF_SERVER_IP option into security page 2021-04-19 15:26:24 +02:00
Laurent Destailleur
0537fdd1c6 Add local ip into excluded IP for external URL download.
Fix #yogosha5861
2021-04-19 13:52:12 +02:00
Laurent Destailleur
8b2304ec8e Better warning 2021-04-15 19:28:13 +02:00
Laurent Destailleur
195d3b578b Fix phpcs 2021-04-14 20:44:34 +02:00
Laurent Destailleur
8bfb69cdba Fix security check 2021-04-14 18:56:31 +02:00
Laurent Destailleur
3893c69dc1 Enhance perf and security page 2021-04-11 21:30:41 +02:00
Laurent Destailleur
59c8e70fd2 Fix #yogosha4510 2021-04-07 23:43:10 +02:00
Laurent Destailleur
6c4f5b851d Use all param of getURLContent 2021-04-07 23:31:16 +02:00
Laurent Destailleur
1e1b963ca7 Restriction on name of files 2021-04-07 19:38:54 +02:00
Laurent Destailleur
10fb793fb1 Enhance the security page 2021-04-06 13:56:33 +02:00
Laurent Destailleur
767aa605a2 Enhance security page 2021-04-06 13:09:00 +02:00
Laurent Destailleur
6c521073ea Fix perm id and sort of modules by id. 2021-04-05 13:52:19 +02:00
Laurent Destailleur
15440917b1 Fix #ygosha5698 2021-03-22 11:30:18 +01:00
Frédéric FRANCE
7878f3cba0
fix php8 warning 2021-03-18 08:08:37 +01:00
Laurent Destailleur
8246eb814b Enhance the page for security advices 2021-03-16 16:02:15 +01:00
Laurent Destailleur
c0e0300eb3 Enhance the page security 2021-03-08 11:08:58 +01:00
Frédéric FRANCE
608b933ef5
code syntax admin dir 2021-02-26 22:04:03 +01:00
Laurent Destailleur
f6080d45fa Merge branch '13.0' of git@github.com:Dolibarr/dolibarr.git into develop 2021-02-22 16:21:26 +01:00
Laurent Destailleur
0d01041166 css 2021-02-21 12:10:07 +01:00
Laurent Destailleur
8f91dd48c9 Fix file integrity message 2021-02-20 11:46:48 +01:00
Laurent Destailleur
d16276ea2c Clean code 2021-02-16 11:15:42 +01:00
Laurent Destailleur
f301635681 Merge branch '13.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/core/class/html.formmail.class.php
2021-02-03 21:02:32 +01:00
Laurent Destailleur
c9e232f2ff Try to fix import/export timeout by dynamic increase 2021-02-03 18:00:27 +01:00
Laurent Destailleur
4d029194d3 Merge branch '13.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/core/lib/ajax.lib.php
	htdocs/margin/agentMargins.php
	htdocs/margin/customerMargins.php
2021-02-02 13:22:23 +01:00
Laurent Destailleur
f4f9a7c461 Clean page of info tools 2021-02-02 09:44:51 +01:00
Laurent Destailleur
2e9656a5b2 Merge branch '13.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/core/class/html.formactions.class.php
	htdocs/filefunc.inc.php
2021-02-02 03:26:20 +01:00
Laurent Destailleur
daf88944f8 FIX #16118 Timezone problem on some fields 2021-02-02 00:19:41 +01:00
Laurent Destailleur
828f1c8314 Merge branch '13.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/comm/propal/card.php
2021-01-15 14:04:22 +01:00
Laurent Destailleur
c3046326cb Fix help 2021-01-15 12:42:40 +01:00
Laurent Destailleur
5660159a6d Merge branch '13.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/bom/bom_card.php
2021-01-11 13:13:26 +01:00
Laurent Destailleur
c10072ccef Merge branch '12.0' of git@github.com:Dolibarr/dolibarr.git into 13.0 2021-01-11 13:07:31 +01:00
Laurent Destailleur
fe7be8362f Fix td balance 2021-01-11 12:03:28 +01:00
Regis Houssin
e36ae4ac90 Merge branch 'develop' of git@github.com:Dolibarr/dolibarr.git into fix_php_8.0 2021-01-02 13:14:30 +01:00
Laurent Destailleur
e4915d9825 Merge branch '12.0' of git@github.com:Dolibarr/dolibarr.git into 13.0 2020-12-30 22:02:06 +01:00
Laurent Destailleur
40d19e6c36 Fix tooltip on timezone 2020-12-30 22:01:26 +01:00
Regis Houssin
aec01a95fc FIX again and again 2020-12-29 17:48:52 +01:00
Laurent Destailleur
67de45b8d7 Fix responsive 2020-12-21 01:40:15 +01:00
Laurent Destailleur
acb73966f7 Clean code. Removed phpexcel library. 2020-12-13 16:27:44 +01:00
Laurent Destailleur
c2124479c7 Fix missing test on IMAP 2020-12-10 16:05:43 +01:00
Laurent Destailleur
56d56929ec Merge branch '12.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/admin/system/dolibarr.php
2020-12-03 16:39:22 +01:00
Laurent Destailleur
ac29db92cb FIX #15618 2020-12-03 16:35:42 +01:00
Laurent Destailleur
00ad6df395 Fight against $_POST 2020-11-30 14:47:07 +01:00
Laurent Destailleur
7634212811 Merge branch '12.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/admin/system/phpinfo.php
	htdocs/commande/stats/index.php
	htdocs/compta/facture/stats/index.php
2020-11-29 21:35:03 +01:00
Laurent Destailleur
df17c2f26a Removed dead code generating warning.
CSS
2020-11-28 16:48:32 +01:00
Laurent Destailleur
bf94ce6aad Fix warnings 2020-11-21 16:49:54 +01:00
Laurent Destailleur
350d694181 Fix security page 2020-11-12 19:15:44 +01:00
Laurent Destailleur
a804ad4914 css 2020-11-11 16:15:06 +01:00
Laurent Destailleur
741806f47e Clean code 2020-11-11 16:08:00 +01:00
Laurent Destailleur
ad04646c05 Fix must use json_encode/decode instead of dol_json_encode/decode 2020-11-11 15:56:19 +01:00
Laurent Destailleur
779566ef30 Clean page with security summary 2020-11-05 10:03:53 +01:00
Laurent Destailleur
60f55c81bf Fix error if module xml not loaded 2020-11-04 17:45:10 +01:00
Laurent Destailleur
38d88ced0b Debug the security page 2020-11-04 16:07:59 +01:00
Frédéric FRANCE
d9bf49c5dc
phpcs 2020-10-31 21:04:38 +01:00
Scrutinizer Auto-Fixer
ab25e047c0 Scrutinizer Auto-Fixes
This commit consists of patches automatically generated for this project on https://scrutinizer-ci.com
2020-10-31 17:51:30 +00:00
stickler-ci
284c9bc6a8 Fixing style errors. 2020-10-31 13:34:01 +00:00
Scrutinizer Auto-Fixer
7f52920716 Scrutinizer Auto-Fixes
This commit consists of patches automatically generated for this project on https://scrutinizer-ci.com
2020-10-31 13:32:18 +00:00
Laurent Destailleur
80d13e711c More secured getURLContent method. Add PHPUnit on getURLContent 2020-10-27 18:02:05 +01:00
Laurent Destailleur
d750dc48a1 More secured getURLContent method. Add PHPUnit on getURLContent 2020-10-27 15:06:16 +01:00
Laurent Destailleur
fe19eea540
Merge pull request #15007 from hregis/develop_bug2
FIX avoid spaces in file name
2020-10-14 14:45:40 +02:00
Laurent Destailleur
85825a0104 Init page for security info 2020-10-14 00:57:39 +02:00
Regis Houssin
00ee1a7433 FIX compatibility with LF (Line Feed) 2020-10-13 15:08:43 +02:00
Regis Houssin
1348c03ca0 FIX avoid spaces in file name 2020-10-13 14:46:17 +02:00
Laurent Destailleur
cfc3c01815 Factorize code to know if a parameter is used to store a secret 2020-10-05 12:13:06 +02:00
Laurent Destailleur
07e1646b3a Minor fixes 2020-10-04 19:09:25 +02:00
Laurent Destailleur
03ede71989 Clean code 2020-10-02 16:15:24 +02:00
Laurent Destailleur
f066da1811 Minor security fixes 2020-09-24 16:19:24 +02:00
Laurent Destailleur
cda101238d Fix #yogosha4543 2020-09-20 21:17:27 +02:00
Laurent Destailleur
b1985950a6 Use POST to make the ajax set/del constant 2020-09-19 12:50:47 +02:00
Laurent Destailleur
937d656f46 Fix #yogosha4515 2020-09-17 23:02:09 +02:00
Laurent Destailleur
bfbb217607 Fix GETPOST on 'action' 2020-09-16 19:39:50 +02:00
stickler-ci
3de5e0f957 Fixing style errors. 2020-09-14 02:30:37 +00:00
Scrutinizer Auto-Fixer
73915d51c8 Scrutinizer Auto-Fixes
This commit consists of patches automatically generated for this project on https://scrutinizer-ci.com
2020-09-14 02:30:04 +00:00
Laurent Destailleur
59bc8ee07c Merge branch '12.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/adherents/stats/byproperties.php
	htdocs/adherents/stats/geo.php
	htdocs/admin/system/dolibarr.php
	htdocs/core/class/commonobjectline.class.php
	htdocs/core/tpl/objectline_title.tpl.php
	htdocs/langs/en_US/admin.lang
	htdocs/product/class/product.class.php
2020-09-14 02:49:19 +02:00
Laurent Destailleur
a4fb16b4f3 Add a warning to warn about security leak 2020-09-14 00:03:49 +02:00
Laurent Destailleur
803efa7acc Add hidden constant until feature is reliable 2020-09-09 15:39:47 +02:00
Laurent Destailleur
3aa921fd0a
Merge pull request #14665 from TobiasSekan/NewCommonFilterForModuleOverview
NEW Add common list function for available app/module page
2020-09-09 15:36:46 +02:00
Sekan, Tobias
37141b577a fix sticker CI, better names, add missing comapres 2020-09-09 08:34:13 +02:00
stickler-ci
2569c792e7 Fixing style errors. 2020-09-08 08:13:56 +00:00
Sekan, Tobias
650bb54051 add common list function for module overview 2020-09-08 10:07:34 +02:00
Laurent Destailleur
198b8d8d2b debugbar ok with php5.6 2020-09-08 02:59:49 +02:00
Laurent Destailleur
fb811a1656 Merge branch '12.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/admin/system/database-tables.php
	htdocs/compta/prelevement/class/bonprelevement.class.php
	htdocs/core/class/commonobject.class.php
	htdocs/langs/fr_FR/withdrawals.lang
	htdocs/societe/class/societe.class.php
2020-08-03 14:44:01 +02:00
Laurent Destailleur
55f3a8b4f8 Fix col size too large by migrating to dynamic format on tables 2020-08-03 11:37:55 +02:00
Laurent Destailleur
81cb5501bc Merge branch '12.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/admin/system/database-tables.php
2020-07-28 10:32:27 +02:00
Laurent Destailleur
4e4f0a4575 Use same case for all sql files 2020-07-28 09:44:48 +02:00
Laurent Destailleur
26c6e2d92e Clean code 2020-07-02 03:34:28 +02:00
Laurent Destailleur
b6c1cdad7c Merge branch '12.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/projet/element.php
2020-06-24 09:59:08 +02:00
Laurent Destailleur
d05c60baf0 Fix css 2020-06-23 14:33:34 +02:00
Laurent Destailleur
8dbc0ff040 Merge branch '12.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/admin/prelevement.php
	htdocs/admin/system/phpinfo.php
	htdocs/modulebuilder/index.php
2020-05-31 00:31:14 +02:00
Laurent Destailleur
b9051bbe22 Fix admin report 2020-05-29 09:50:38 +02:00
Frédéric FRANCE
85625a46bb
add new rule 2020-05-21 09:35:30 +02:00
Frédéric FRANCE
ee6fadd0d5
add new rule 2020-05-21 01:41:27 +02:00
Laurent Destailleur
fe241ea321 Fix removed not reliabled info in PHP info 2020-05-09 21:49:12 +02:00
Laurent Destailleur
b20d85b198 Fix phpcs 2020-04-26 23:06:52 +02:00
Frédéric FRANCE
044a6192b6
doxygen 2020-04-12 16:26:19 +02:00
Scrutinizer Auto-Fixer
444c293c01 Scrutinizer Auto-Fixes
This commit consists of patches automatically generated for this project on https://scrutinizer-ci.com
2020-04-10 08:59:32 +00:00
Laurent Destailleur
5a59f87699
Update phpinfo.php 2020-04-08 14:37:49 +02:00
stickler-ci
6ceb35c5c6 Fixing style errors. 2020-04-08 10:11:06 +00:00
Tobias Sekan
05ec5718bd
Fix overriden PHP POST check 2020-04-08 12:00:47 +02:00
Tobias Sekan
287af6c864
Show better PHP extension info 2020-04-08 11:46:45 +02:00
Scrutinizer Auto-Fixer
e8083e2a65 Scrutinizer Auto-Fixes
This commit consists of patches automatically generated for this project on https://scrutinizer-ci.com
2020-03-23 14:54:02 +00:00
Laurent Destailleur
4e007fe94c Import jommla news 2020-03-20 15:12:50 +01:00
UT from dolibit
8e712c6d0e
Update https for country websites
Update https for country websites
2020-03-16 13:13:11 +01:00
Laurent Destailleur
ffa847bc8e Merge branch '11.0' of git@github.com:Dolibarr/dolibarr.git into develop 2020-02-02 19:32:37 +01:00
Laurent Destailleur
075b1ea744 FIX Log of authentication ko or ko + CVE-2020-7996 2020-02-02 19:05:38 +01:00
Laurent Destailleur
ace43a4227 Fix message 2020-01-16 01:40:14 +01:00