Commit Graph

875 Commits

Author SHA1 Message Date
Laurent Destailleur
bae75281e3 QUAL: Code fix using rector 2023-10-11 19:44:06 +02:00
Laurent Destailleur
3e0e64ac41 Clean code 2023-10-11 00:21:25 +02:00
Jon Bendtsen
154ce1329f adding mariadb and mariadb-dump to the list of restricted os commands 2023-09-13 22:58:36 +02:00
Laurent Destailleur
b265dd0548 NEW extrafields password accepts 'dolcrypt' algorithm (reversible algo) 2023-09-10 19:29:49 +02:00
Laurent Destailleur
bfde27ea36 Merge branch '18.0' of git@github.com:Dolibarr/dolibarr.git into develop 2023-08-13 16:33:23 +02:00
Laurent Destailleur
fa18f958d7 Debug v18 2023-08-12 13:08:36 +02:00
Laurent Destailleur
7ce9bf6b23 Clean code 2023-08-05 15:44:28 +02:00
Laurent Destailleur
761565cabb Merge branch '18.0' of git@github.com:Dolibarr/dolibarr.git into develop 2023-07-25 23:47:28 +02:00
Laurent Destailleur
2bc6cd20dd Debug v18 2023-07-25 13:15:52 +02:00
Laurent Destailleur
01eca1eb47 Debug v18 2023-07-25 12:56:11 +02:00
Laurent Destailleur
7ccd50d2b8 Fix class not initialized 2023-07-25 12:38:27 +02:00
Laurent Destailleur
9c62e76c46 NEW Disable not used PHP streams 2023-07-25 12:30:09 +02:00
Laurent Destailleur
b08d24348c Add 2 more dangerous function to disable 2023-07-25 12:00:50 +02:00
UT from dolibit
9bdee115d9
Update os.php (#25447) 2023-07-24 19:21:54 +02:00
Laurent Destailleur
4ba8324a3f Doc 2023-07-19 04:22:02 +02:00
Frédéric France
44d3270a48 use user hasRight 2023-06-12 20:43:28 +02:00
Frédéric FRANCE
d55ae5dbd2 use isModEnabled 2023-06-09 13:53:58 +02:00
Laurent Destailleur
51708f4d70 Ad option MAIN_ALLOW_SVG_FILES_AS_EXTERNAL_LINKS in security page 2023-06-03 11:31:24 +02:00
Laurent Destailleur
57a9ef35ae NEW Implement MAIN_ACTIVATE_FILECACHE on bithday widget 2023-05-05 13:21:54 +02:00
Laurent Destailleur
155c52bc30 Fix #yogosha16184 2023-04-24 13:52:31 +02:00
Frédéric FRANCE
199650f498 fix typo 2023-04-20 22:51:33 +02:00
Laurent Destailleur
869a73befc Add option MAIN_DISALLOW_EXT_URL_INTO_DESCRIPTIONS into security page 2023-04-06 13:39:04 +02:00
Laurent Destailleur
46055fd195 Hide session ID 2023-03-28 23:53:16 +02:00
Laurent Destailleur
3821f5c27c Update security page 2023-03-21 01:50:14 +01:00
Laurent Destailleur
72750c3b8d Add notice in security to show if installmodules.lock exists. 2023-03-21 01:43:09 +01:00
Laurent Destailleur
6b01edbf01 Hide PHP_AUTH_PW into debugbar 2023-03-19 11:06:48 +01:00
Laurent Destailleur
b2afcad3f5 Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop 2023-03-16 09:43:30 +01:00
Laurent Destailleur
e922f5052b Fix tooltip on table on list of pages 2023-03-15 15:17:34 +01:00
Laurent Destailleur
29417861db Fix bad var shown 2023-03-12 11:54:46 +01:00
Laurent Destailleur
54d1250887 Merge + Clean duplicate trigger code. We must use the context. 2023-03-02 02:19:24 +01:00
Laurent Destailleur
14a59483f5 Debug v17 2023-03-01 23:50:02 +01:00
Laurent Destailleur
6fc473bd71 Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop 2023-02-28 19:16:29 +01:00
Laurent Destailleur
afae14d914 Fix CSP Policy 2023-02-28 11:35:40 +01:00
Laurent Destailleur
3354a27a6f css 2023-02-25 01:21:12 +01:00
Laurent Destailleur
5aaca18567 css 2023-02-25 00:48:50 +01:00
Laurent Destailleur
44da230012 Clean code 2023-02-21 12:57:36 +01:00
Laurent Destailleur
870ac42082 Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop 2023-02-20 16:20:49 +01:00
Laurent Destailleur
a4c2c671be Fix option example 2023-02-20 15:29:17 +01:00
Laurent Destailleur
0300ccebfd Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop 2023-02-18 21:09:58 +01:00
Laurent Destailleur
a81510ccd6 Better exemple for RCP security string 2023-02-18 14:15:39 +01:00
Laurent Destailleur
2168578f2e Fix inline css 2023-02-18 14:00:25 +01:00
Laurent Destailleur
183ae35ab7 Fix #huntr10e423cd-7051-43fd-b736-4e18650d0172 2023-02-13 12:57:35 +01:00
Laurent Destailleur
53be37148b NEW Support option MAIN_SECURITY_MAXFILESIZE_DOWNLOADED #yogosha10660 2023-02-04 11:32:38 +01:00
Laurent Destailleur
35bc94095a Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop 2023-01-19 13:50:59 +01:00
Laurent Destailleur
58645a1d4a Debug v17 2023-01-19 00:19:57 +01:00
Laurent Destailleur
377ba47763 Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop 2022-12-30 19:53:25 +01:00
Laurent Destailleur
8dc89e9a9a Fix warning 2022-12-30 19:51:07 +01:00
Laurent Destailleur
ea42fc7605 Clean code, fix warnings 2022-12-30 18:43:43 +01:00
Laurent Destailleur
dbc5f5742f Clean code 2022-12-28 12:05:30 +01:00
Laurent Destailleur
3d390d4aeb
Merge pull request #23313 from randallmoraes/patch-4
Update perf.php
2022-12-26 23:53:55 +01:00
Laurent Destailleur
8f02fb2ab8 Merge branch '17.0' of git@github.com:Dolibarr/dolibarr.git into develop 2022-12-22 20:34:22 +01:00
Randall Mora
4110669098
Update perf.php
Check validate when BROTLI_COMPRESS  is enable
2022-12-22 10:30:58 -06:00
Laurent Destailleur
d183760841 Clean code 2022-12-22 13:21:46 +01:00
Frédéric FRANCE
b1b46556be fix stickler 2022-12-21 09:17:07 +01:00
Frédéric FRANCE
6c24230d9e
fix typo 2022-12-20 18:34:50 +01:00
Frédéric FRANCE
172aa02eff fix typo in url 2022-12-20 18:30:53 +01:00
Frédéric FRANCE
5a5794b64a fix warnings 2022-12-20 18:22:10 +01:00
Laurent Destailleur
981e165c3e Reduce default value from 1000 to 200 for
MAIN_SECURITY_MAX_POST_ON_PUBLIC_PAGES_BY_IP_ADDRESS
2022-11-29 10:24:21 +01:00
Laurent Destailleur
427a785fb3 Update help on security 2022-11-22 21:27:30 +01:00
Laurent Destailleur
767f5db7dc Typo 2022-11-20 22:42:35 +01:00
Laurent Destailleur
3041edc013 Debug 2022-11-20 21:59:35 +01:00
Laurent Destailleur
e5a4824ed2 Enhance default WEBSITE_MAIN_SECURITY_FORCECSP 2022-11-20 16:12:18 +01:00
Laurent Destailleur
c5459a47eb Enhance default WEBSITE_MAIN_SECURITY_FORCECSP 2022-11-20 16:08:32 +01:00
Laurent Destailleur
9b9ed31997 Sec: Hide sensitive data in phpinfo 2022-11-15 09:36:35 +01:00
Laurent Destailleur
d8c74eff5f css 2022-10-28 12:39:37 +02:00
Laurent Destailleur
6645693b45 Remove useless html colspan 2022-10-28 12:34:49 +02:00
Laurent Destailleur
ce494354e2 NEW Finish removal of code using adodbtime 2022-10-22 01:54:50 +02:00
Laurent Destailleur
938bc27917 Update sample for fail2ban 2022-10-18 12:59:15 +02:00
Laurent Destailleur
3d9cb3e411 Fix missing test on zip php module 2022-09-28 19:59:51 +02:00
Laurent Destailleur
6df6400792 New Add copy/paste button after LDAP password field in LDAP setup 2022-09-27 14:32:50 +02:00
lmarcouiller
b0d2aa6d9b Fix : php 8.1 warnings 2022-09-23 16:05:11 +02:00
Laurent Destailleur
4b2c4d2df3 Merge branch '16.0' of git@github.com:Dolibarr/dolibarr.git into develop 2022-09-15 18:13:27 +02:00
Laurent Destailleur
08be53494f trans 2022-09-15 17:43:34 +02:00
Laurent Destailleur
4a17fae9af Add info on mitigation 2022-09-11 20:48:23 +02:00
Laurent Destailleur
3ac9304055 css 2022-09-11 15:17:10 +02:00
Laurent Destailleur
60c39933d4 Clean code 2022-09-11 13:26:24 +02:00
Laurent Destailleur
a0dda0ed77 NEW Add more advices into the Setup security page 2022-09-11 12:35:40 +02:00
Laurent Destailleur
2293d82607 NEW Add picto property on sub-module for paswword generation 2022-09-11 12:18:43 +02:00
Frédéric France
8d33953142 add comment 2022-09-07 20:08:59 +02:00
Philippe GRAND
2900c7aaf7 FIX php8 compatibility 2022-08-28 13:38:02 +02:00
Philippe GRAND
41ed2967c5 FIX php8 compatibility 2022-08-28 13:36:26 +02:00
Laurent Destailleur
3b195fa1fb Can add Permissions-Policy on web sites 2022-08-16 16:58:28 +02:00
Laurent Destailleur
5ef941311a NEW can set header "Strict-Transport-Security" in web sites 2022-08-16 16:06:09 +02:00
Laurent Destailleur
f404eddad0 Fix recommended value 2022-08-16 15:23:53 +02:00
Laurent Destailleur
94da628cf4 Clean code for http header + better support for Content-Security-Policy 2022-08-16 15:19:45 +02:00
Laurent Destailleur
60117bbaee Debug v16 2022-07-24 19:45:37 +02:00
Laurent Destailleur
97acf949fc Clean message on email limit 2022-07-13 13:39:16 +02:00
Laurent Destailleur
5de434eb37 css 2022-07-10 19:14:33 +02:00
Laurent Destailleur
7262a097e3 Better error message 2022-06-26 20:27:51 +02:00
Laurent Destailleur
00649e791c Fix #yogosha11452 2022-06-25 02:18:16 +02:00
Laurent Destailleur
4de50da0dd Repare code to forbidden var_dump() into code 2022-05-17 14:55:38 +02:00
Laurent Destailleur
e9d7e216e2 Debug v16 2022-05-09 12:13:31 +02:00
Laurent Destailleur
40d0c3b996 Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/compta/tva/card.php
	htdocs/langs/en_US/admin.lang
2022-04-28 19:23:13 +02:00
Laurent Destailleur
aa86b2c71f Fix root passfield not editable on install
Fix user photo when gravatar not reachable
2022-04-19 22:26:27 +02:00
Laurent Destailleur
524b001f3b Add $dolibarr_main_restrict_os_commands in security center. 2022-04-06 21:14:35 +02:00
Laurent Destailleur
9bda7ba8c7 Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/core/class/doleditor.class.php
2022-03-03 00:16:55 +01:00
Laurent Destailleur
8051128665 Split section experimental and stable 2022-03-02 11:37:19 +01:00
Laurent Destailleur
12b2a10865 Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop 2022-03-01 18:15:13 +01:00
Laurent Destailleur
237b6fc922 Fix value recommended 2022-03-01 17:07:28 +01:00
Laurent Destailleur
8c61a29051 Show value of short_open_tags 2022-02-25 01:30:34 +01:00