dolibarr-git
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Dolibarr-git] [Dolibarr/dolibarr] 24128a: TODO security broken with Mul


From: Laurent Destailleur
Subject: [Dolibarr-git] [Dolibarr/dolibarr] 24128a: TODO security broken with Multicompany
Date: Sat, 26 Jan 2019 05:28:15 -0800

  Branch: refs/heads/develop
  Home:   https://github.com/Dolibarr/dolibarr
  Commit: 24128ac28d782f8522ec4c72988f54dc45eea998
      
https://github.com/Dolibarr/dolibarr/commit/24128ac28d782f8522ec4c72988f54dc45eea998
  Author: Regis Houssin <address@hidden>
  Date:   2019-01-16 (Wed, 16 Jan 2019)

  Changed paths:
    M htdocs/user/card.php

  Log Message:
  -----------
  TODO security broken with Multicompany


  Commit: 45a7e0356236705c516e8098112cca0c7a2566ca
      
https://github.com/Dolibarr/dolibarr/commit/45a7e0356236705c516e8098112cca0c7a2566ca
  Author: Regis Houssin <address@hidden>
  Date:   2019-01-16 (Wed, 16 Jan 2019)

  Changed paths:
    M htdocs/core/lib/security.lib.php
    M htdocs/user/card.php

  Log Message:
  -----------
  FIX a user can always read its own card


  Commit: c4b9bdd569ccb6eaaf564c2c978e12985f5ac48c
      
https://github.com/Dolibarr/dolibarr/commit/c4b9bdd569ccb6eaaf564c2c978e12985f5ac48c
  Author: Regis Houssin <address@hidden>
  Date:   2019-01-16 (Wed, 16 Jan 2019)

  Changed paths:
    M htdocs/core/lib/security.lib.php

  Log Message:
  -----------
  FIX remove var_dump


  Commit: ffeeb782b0b655d79766c460cafe7c11366ab0e0
      
https://github.com/Dolibarr/dolibarr/commit/ffeeb782b0b655d79766c460cafe7c11366ab0e0
  Author: Regis Houssin <address@hidden>
  Date:   2019-01-16 (Wed, 16 Jan 2019)

  Changed paths:
    M htdocs/user/agenda_extsites.php
    M htdocs/user/clicktodial.php
    M htdocs/user/document.php
    M htdocs/user/info.php
    M htdocs/user/ldap.php
    M htdocs/user/note.php
    M htdocs/user/param_ihm.php
    M htdocs/user/perms.php

  Log Message:
  -----------
  FIX check is moved to restrictedArea() function


  Commit: f7703235c7a85f32a80f74739af94def9462ad3a
      
https://github.com/Dolibarr/dolibarr/commit/f7703235c7a85f32a80f74739af94def9462ad3a
  Author: Regis Houssin <address@hidden>
  Date:   2019-01-16 (Wed, 16 Jan 2019)

  Changed paths:
    M htdocs/user/perms.php

  Log Message:
  -----------
  FIX broken feature (better check)


  Commit: 6e7562b6a64a67285da9ba626192ed6d658357a3
      
https://github.com/Dolibarr/dolibarr/commit/6e7562b6a64a67285da9ba626192ed6d658357a3
  Author: Regis Houssin <address@hidden>
  Date:   2019-01-18 (Fri, 18 Jan 2019)

  Changed paths:
    M htdocs/adherents/class/adherent.class.php
    M htdocs/adherents/subscription.php
    M htdocs/cashdesk/class/Facturation.class.php
    M htdocs/cashdesk/index.php
    M htdocs/cashdesk/tpl/liste_articles.tpl.php
    M htdocs/compta/facture/card.php
    M htdocs/compta/facture/class/paymentterm.class.php

  Log Message:
  -----------
  Merge branch '8.0' of https://github.com/Dolibarr/dolibarr.git into 8.0_bug


  Commit: fcb97a58dac2eb0de4f43b1d37ca1f23bcd98c1d
      
https://github.com/Dolibarr/dolibarr/commit/fcb97a58dac2eb0de4f43b1d37ca1f23bcd98c1d
  Author: Regis Houssin <address@hidden>
  Date:   2019-01-19 (Sat, 19 Jan 2019)

  Changed paths:
    M htdocs/core/class/stats.class.php

  Log Message:
  -----------
  Merge branch '8.0' of https://github.com/Dolibarr/dolibarr.git into 8.0_bug


  Commit: d5b66eeffb285d6470d3a393df6fff529242c0df
      
https://github.com/Dolibarr/dolibarr/commit/d5b66eeffb285d6470d3a393df6fff529242c0df
  Author: Regis Houssin <address@hidden>
  Date:   2019-01-19 (Sat, 19 Jan 2019)

  Changed paths:
    M htdocs/core/lib/security.lib.php

  Log Message:
  -----------
  FIX $user is already in parameters


  Commit: fd192f10c457f6ce9bc407ad1a695ebf47686f10
      
https://github.com/Dolibarr/dolibarr/commit/fd192f10c457f6ce9bc407ad1a695ebf47686f10
  Author: Laurent Destailleur <address@hidden>
  Date:   2019-01-26 (Sat, 26 Jan 2019)

  Changed paths:
    M htdocs/core/lib/security.lib.php
    M htdocs/user/agenda_extsites.php
    M htdocs/user/card.php
    M htdocs/user/clicktodial.php
    M htdocs/user/document.php
    M htdocs/user/info.php
    M htdocs/user/ldap.php
    M htdocs/user/note.php
    M htdocs/user/param_ihm.php
    M htdocs/user/perms.php

  Log Message:
  -----------
  Merge pull request #10341 from hregis/8.0_bug

FIX security broken with Multicompany


Compare: 
https://github.com/Dolibarr/dolibarr/compare/b4400b95db11...fd192f10c457
      **NOTE:** GitHub Services has been marked for deprecation: 
https://developer.github.com/changes/2018-04-25-github-services-deprecation/

      We will provide an alternative path for the email notifications by 
January 31st, 2019.

reply via email to

[Prev in Thread] Current Thread [Next in Thread]