| changeset | d0460348bf9a |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | John Rouillard <rouilj@ieee.org> |
| description | fix: issue2550924. clean up schema for devel/responsive templates. both templates have the same schema. Changes patches class to patch in devel schema. Change bug.issue.html to account for patches -> patch rename. Sort property list for a permission. Add patch class for responsive template. From both remove incorrect comment. |
| files |
| changeset | 984bc9f94ec6 |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | John Rouillard <rouilj@ieee.org> |
| description | chore: format schema.pys in templates so ruff is ok. Also makes comparing them easier. |
| files |
| changeset | 670ab365e76f |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | John Rouillard <rouilj@ieee.org> |
| description | Finish adding anyonymous Register role in devel/responsive templates I missed adding the Register permission definition from the 1.4.11 upgrade directions. |
| files |
| changeset | c087ad45bf4d |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | John Rouillard <rouilj@ieee.org> |
| description | update Anonymous Create user to Register user permissions the devel and responsive tracker templates still had the old Create user permissions for the anonymous user. Replace with the Regiter permission that has been the standard since 1.4.11 maybe. Also update references to Create permission in comment for the Email Access permission for anon user. |
| files |
| changeset | 94a7669677ae |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | John Rouillard <rouilj@ieee.org> |
| description | add permissions to control user of rest and xmlrpc API interfaces. issue2551058: Add new permissions: 'Rest Access' and 'Xmlrpc Access' to allow per-user access control to rest and xmlrpc interfaces using roles. Updated all schemas to add these new perms to all authenticated roles. Error conditions in handle_xmlrpc were not working right in manual testing. I tried to make it a little better, but I don't actually understand how the fault xmlrpc object is supposed to be used. So I may have messed something up. I'll try to ping the people who wrote the xmlrpc code to have them review. |
| files |
| changeset | 602d544e3a93 |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | John Rouillard <rouilj@ieee.org> |
| description | fixing some mismatched patches/patch references that I borked in a prior checkin. Patch support was not and still is not working. But at least this tracker runs without errors with demo.py -t devel, just missing features. |
| files |
| changeset | ce5512002629 |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | John Rouillard <rouilj@ieee.org> |
| description | merge from upstream |
| files |
| changeset | 85eee1f236b2 |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | John Rouillard <rouilj@ieee.org> |
| description | I had an incorrect fix for issue2550601. Changed schema to define class patches not patch. Changed commented out patches section in bug.item.html to use patches-1 an not patch-1 as a result of schema changes. The show open Milestones link had a leak of the @group value. If you clicked on show open tasks or show open bugs they group by priority. The url being formed for show open milestones was inheriting the @group if you were on an index page for bugs or milestones. Explicit set the @group to status (which a milestone does have) prevents the @group=priority from being applied to a milestone index page which results in a red error banner stating priority is an invalid param for milestones. ./demo.py -t devel now runs without obvious breakage. |
| files |
| changeset | cf112b90fa8d |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | John Rouillard <rouilj@ieee.org> |
| description | issue2550855: added search perms for anonymous to the user class. This lets the "show unassigned" search work for anonymous. Patch by Stuart McGraw. Added warning to upgrading.txt and a comment block before the schema change in every template tracker except minimal (doesn't have the search). |
| files |
| changeset | 29bd12331b86 |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | John Rouillard <rouilj@ieee.org> |
| description | issue2550601: add multilink to patches to the bug issue. The doc string above the definition already included the code. |
| files |
| changeset | a403c29ffaf9 |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | Ralf Schlatterbeck <rsc@runtux.com> |
| description | Security fix default user permissions Default user permissions should not include all user attributes. We now limit this to the username, realname and some further attributes depending on the schema. Note that we no longer include the email addresses, depending on your installation you may want to further restrict this or add some attributes like ``address`` and ``alternate_addresses``. |
| files |
| changeset | d3f8d0be588c |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | rouilj |
| description | Issue2550783 - change spelling of organization to organisation so that the user's organisation can be edited by the user. |
| files |
| changeset | 89dd446af2a8 |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | Stefan Seefeld <stefan@seefeld.name> |
| description | Don't allow users to create tasks and milestones. |
| files |
| changeset | cc402f5ad93e |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | Stefan Seefeld <stefan@seefeld.name> |
| description | Anonymous can only see bugs, but neither tasks nor milestones. |
| files |
| changeset | 261c9f913ff7 |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | Ralf Schlatterbeck <schlatterbeck@users.sourceforge.net> |
| description | - Add explicit "Search" permissions, see Security Fix below. - Security Fix: Add a check for search-permissions: now we allow searching for properties only if the property is readable without a check method or if an explicit search permission (see above unter "Features) is given for the property. This fixes cases where a user doesn't have access to a property but can deduce the content by crafting a clever search, group or sort query. see doc/upgrading.txt for how to fix your trackers! |
| files |
| changeset | b419f29b1e2f |
|---|---|
| branch | |
| bookmark | |
| tag | |
| user | Stefan Seefeld <stefan@seefeld.name> |
| description | Add new tracker template. |
| files |
| changeset | e8fb186265b7 |
|---|---|
| branch | gsoc-2009 |
| bookmark | |
| tag | |
| user | Pygi <pygi@users.sourceforge.net> |
| description | Added some hg patch apply things |
| files |
| changeset | 8838ff0165fa |
|---|---|
| branch | gsoc-2009 |
| bookmark | |
| tag | |
| user | Pygi <pygi@users.sourceforge.net> |
| description | Revision should be a string |
| files |
| changeset | 2b554b262d29 |
|---|---|
| branch | gsoc-2009 |
| bookmark | |
| tag | |
| user | Pygi <pygi@users.sourceforge.net> |
| description | Changed schema to be vcs agnostic |
| files |
| changeset | c2e920eaee0a |
|---|---|
| branch | gsoc-2009 |
| bookmark | |
| tag | |
| user | Pygi <pygi@users.sourceforge.net> |
| description | Implemented schema changes for svn-roundup support |
| files |
| changeset | 115e9883311e |
|---|---|
| branch | gsoc-2009 |
| bookmark | |
| tag | |
| user | Stefan Seefeld <stefan@seefeld.name> |
| description | Add new tracker template sandbox. |
| files |