Andrew Dolgov
|
5f66f872b6
|
fix session write handler always assuming that database entry exists and failing silently if it doesn't; remove session cookie-related hacks
|
2018-10-16 14:07:42 +03:00 |
|
Andrew Dolgov
|
d246fb9fe1
|
remove session REMOTE_ADDR checks
|
2018-10-16 12:12:07 +03:00 |
|
Andrew Dolgov
|
f8fc1ac543
|
login: check for stale session in login handler, instead of authenticate_user()
|
2018-10-16 11:39:12 +03:00 |
|
Andrew Dolgov
|
f730d7bb0a
|
another attempt to enforce session ID regeneration on login
|
2018-10-16 09:11:32 +03:00 |
|
Andrew Dolgov
|
9dadbdbb21
|
properly save auth_module after logging in
|
2018-10-16 07:34:22 +03:00 |
|
Andrew Dolgov
|
77aebd7e4a
|
it was probably not the best idea to use session_regenerate_id() right after session_start(), duh
|
2018-10-15 21:47:12 +03:00 |
|
Andrew Dolgov
|
5feed36a3c
|
do not use separate _ssl cookie for secure sessions
|
2018-10-15 15:48:37 +03:00 |
|
Andrew Dolgov
|
65e98f4086
|
force regenerate session id on successful login, remove previous blank SID check
|
2018-10-15 15:47:50 +03:00 |
|
Andrew Dolgov
|
74736fce0f
|
if empty session is autostarted because of a cookie, immediately destroy it
|
2018-10-15 14:53:35 +03:00 |
|
Andrew Dolgov
|
7d53c2b501
|
validate_session: bring back IP session binding (enabled by default) and UA checking
|
2018-10-15 08:26:07 +03:00 |
|
Andrew Dolgov
|
ec5687a62b
|
logout user: commit destroyed session
|
2018-10-14 22:50:45 +03:00 |
|
Andrew Dolgov
|
d2e1e60ecc
|
1. per-feed option STRIP_IMAGES should now also affect other media tags
2. video/audio elements were not replaced with text links properly in
low bandwidth mode
|
2018-09-07 09:55:43 +03:00 |
|
Andrew Dolgov
|
f3068c6397
|
send_local_file: touch() sent files to reset their expiration cooldown
|
2018-08-23 13:43:31 +03:00 |
|
Andrew Dolgov
|
02bb26a93f
|
rewrite_cached_urls: support video posters
|
2018-08-20 14:13:14 +03:00 |
|
Andrew Dolgov
|
a1b8651949
|
Revert "add (hidden) _NGINX_XACCEL_PREFIX which uses nginx X-Accel-Redirect to serve static files faster"
This reverts commit c5c3a0a2a8.
|
2018-08-20 12:48:23 +03:00 |
|
Andrew Dolgov
|
2aef804f4b
|
split transparent rewriting of locally cached media URLs to execute after both sanitize() and HOOK_RENDER_ARTICLE to allow plugins work on original source URLs consistently
|
2018-08-20 12:12:32 +03:00 |
|
Andrew Dolgov
|
c5c3a0a2a8
|
add (hidden) _NGINX_XACCEL_PREFIX which uses nginx X-Accel-Redirect to serve static files faster
|
2018-08-20 09:14:10 +03:00 |
|
Andrew Dolgov
|
88adf3da1b
|
send_local_file: add application/octet-stream hack
cached_url: return original requested filename to save as
|
2018-08-16 12:16:51 +03:00 |
|
Andrew Dolgov
|
c4869cd573
|
if PHP_VERSION check fails, show current version
|
2018-08-13 20:13:08 +03:00 |
|
Andrew Dolgov
|
75e765aa00
|
bump version_static
|
2018-08-13 16:12:03 +03:00 |
|
Andrew Dolgov
|
848c6ac655
|
bump required php version to 5.6
|
2018-08-13 16:04:09 +03:00 |
|
Andrew Dolgov
|
069aea5989
|
remove FEED_CRYPT_KEY and everything related to it
always assume auth_pass_encrypted is false
|
2018-08-13 15:59:24 +03:00 |
|
Andrew Dolgov
|
a2d1fa5b14
|
autoloader: check if class name is namespaced before trying to split it
|
2018-07-18 13:25:18 +03:00 |
|
Andrew Dolgov
|
df47100ad1
|
remove SWF enclosure audio player
|
2018-06-20 18:17:44 +03:00 |
|
Andrew Dolgov
|
a9105e2a61
|
move JShrink Minifier to vendor/
|
2018-06-20 15:04:59 +03:00 |
|
Andrew Dolgov
|
2aaefbfa54
|
update autoloader to consider namespaces for third party libraries: placed and loaded from vendor/namespace/classpath.php
update readability to a newer implementation based on Readability.js (https://github.com/andreskrey/readability.php)
add vendor/Psr/Log interface required for the above
|
2018-06-20 14:58:09 +03:00 |
|
Andrew Dolgov
|
d00d515320
|
feedbrowser: fix incorrect usage of LIMIT in prepared statement
|
2018-06-18 23:50:32 +03:00 |
|
Tobias Bell
|
af3663edec
|
Don't bail out if git gc removed refs
|
2018-06-08 22:07:30 +02:00 |
|
Andrew Dolgov
|
68d9c412ea
|
fetch_file_contents: allow setting http Accept header
|
2018-05-25 14:25:08 +03:00 |
|
Andrew Dolgov
|
f0dbfedc81
|
increase buffersize to 16384 bytes
(also some trailing whitespace got clipped)
|
2018-05-23 10:40:28 +03:00 |
|
Alexander Yaburov
|
74a98a6ff2
|
increased CURLOPT_BUFFERSIZE from 128 to 256
|
2018-05-23 10:02:03 +05:00 |
|
Andrew Dolgov
|
b14f6d58b4
|
implement hard limits on downloaded data size for general fetching and cache plugins: MAX_DOWNLOAD_FILE_SIZE & MAX_CACHE_FILE_SIZE
|
2018-05-20 11:08:33 +03:00 |
|
foobar
|
2008ec4ed7
|
change filter rule regexp type to text
|
2018-04-14 14:11:29 +02:00 |
|
JustAMacUser
|
905ff10dc9
|
Allow abbr tag when sanitizing.
|
2018-02-27 16:06:10 +00:00 |
|
Andrew Dolgov
|
e7c9bc60ec
|
fix previous wrt if-modified-since being added to context options headers
|
2018-02-25 14:22:46 +03:00 |
|
Metallizzer
|
dd597297cb
|
Обновить 'include/functions.php'
The "Connection: close" header is added to the context_options
|
2018-02-25 10:03:09 +00:00 |
|
Andrew Dolgov
|
3d7db21602
|
Merge branch 'master' of git.fakecake.org:tt-rss
|
2018-02-12 09:37:31 +03:00 |
|
Andrew Dolgov
|
8babb8e75a
|
sanitize: disallow width and height attributes for images
|
2018-02-11 16:47:19 +03:00 |
|
fox
|
1aeb282be1
|
Merge branch 'save-effective-url' of JustAMacUser/tt-rss into master
|
2018-02-11 08:57:12 +00:00 |
|
JustAMacUser
|
7ae05ed790
|
Have fetch_file_contents() save the effective URL.
|
2018-02-11 07:56:28 +00:00 |
|
Andrew Dolgov
|
2eaf2a1f36
|
tag_is_valid: simplify code
|
2018-02-11 10:26:33 +03:00 |
|
Andrew Dolgov
|
7f4a404566
|
include: convert some spaces to tabs
|
2018-01-30 10:44:31 +03:00 |
|
martin scharm
|
32dc9ec854
|
undocumenting the proxy settings [see #36]
in response to https://git.tt-rss.org/git/tt-rss/pulls/36#issuecomment-119
|
2018-01-18 08:48:53 +01:00 |
|
martin scharm
|
213c01d459
|
some proxies require request_fulluri set to true [see #36]
at least polipo won't work for plain HTTP URLs (HTTPS strangely also works without `request_fulluri`..?)
see https://git.tt-rss.org/git/tt-rss/pulls/36
|
2018-01-17 12:28:47 +01:00 |
|
martin scharm
|
ea55f2e11c
|
Add proper support for proxies
There are situations where you want tt-rss to use a proxy (e.g.
because of network restrictions, or privacy concerns).
tt-rss already comes with an undocumented `_CURL_HTTP_PROXY`
variable (see eg https://binfalse.de/2015/05/06/ttrss-with-proxy/),
however that won't have an effect when, for example, php-curl is
not installed, see
https://git.tt-rss.org/git/tt-rss/src/c30f5e18119d1935e8fe6d422053b127e8f4f1b3/include/functions.php#L377
In this case it would use the `file_get_contents` with a stream
context without a proxy definition:
https://git.tt-rss.org/git/tt-rss/src/c30f5e18119d1935e8fe6d422053b127e8f4f1b3/include/functions.php#L487
Here I propose to properly support proxies, and I introduced a
`PROXY` variable, that is respected in both scenarios, with and
without curl installed.
|
2018-01-14 00:30:22 +01:00 |
|
Andrew Dolgov
|
9274109c19
|
search_to_sql: quote fallback search language
|
2017-12-30 16:27:05 +03:00 |
|
JustAMacUser
|
56c2216295
|
Add missing quotes to array_map.
|
2017-12-30 01:00:56 -05:00 |
|
Andrew Dolgov
|
bed2d6e054
|
force-cast some variables used in queries to integer
do not display SQL query in headlines debug mode
|
2017-12-17 16:24:13 +03:00 |
|
Andrew Dolgov
|
7651b6e2cd
|
sanitize: disable referrer via referrerpolicy for img elements
|
2017-12-13 20:07:10 +03:00 |
|
Andrew Dolgov
|
4d10b4abca
|
merge login form css into default.css
update more hardcoded colors to use @color-accent
update @color-accent
|
2017-12-10 22:51:39 +03:00 |
|