Mercurial > p > roundup > code
view doc/.cvsignore @ 4088:34434785f308
Plug a number of security holes:
- EditCSV and ExportCSV altered to include permission checks
- HTTP POST required on actions which alter data
- HTML file uploads served as application/octet-stream
- New item action reject creation of new users
- Item retirement was not being controlled
Additionally include documentation of the changes and modify affected tests.
| author | Richard Jones <richard@users.sourceforge.net> |
|---|---|
| date | Thu, 12 Mar 2009 02:25:03 +0000 |
| parents | fb25f2567a91 |
| children |
line wrap: on
line source
announcement.html customizing.html developers.html implementation.html index.html installation.html user_guide.html FAQ.html security.html features.html upgrading.html glossary.html design.html admin_guide.html overview.html mysql.html postgresql.html tracker_templates.html whatsnew-0.7.html whatsnew-0.8.html *.ht
