X-Git-Url: https://vcs.fsf.org/?a=blobdiff_plain;f=ChangeLog;h=b62b16edf1e9dbf52ea2268e01d7b77054f9975b;hb=fba9992167e8f8ebe8fba0006b193090e1c07937;hp=9ac593a549f39dc15bfae65c5cf9f0e386c5d61f;hpb=61e49023896ede28dcaa1d4f64992bf38ecce40b;p=squirrelmail.git diff --git a/ChangeLog b/ChangeLog index 9ac593a5..b62b16ed 100644 --- a/ChangeLog +++ b/ChangeLog @@ -4,6 +4,16 @@ Version 1.5.2 - CVS ------------------- + - The search expression in the LDAP backend of the Addressbook is now + configurable, which can allow the result set to be expanded. + - Preliminary support for NAMESPACE in Squirrelmail IMAP Backend: NAMESPACE + is parsed and stored in session upon login. + - Now uses the $Forwarded IMAP keyword for forwarded messages, when it is + enabled or when arbitrary keywords ("PERMANENT FLAGS \*") are permitted. + RFC 4550, paragraph 2.8. + - Added support for authorization identifier in IMAP backend, for SASL + authentication mechanisms PLAIN and DIGEST-MD5. This can be set upon login + by use of an external plugin. - Fix warning about array required in array_keys for display options when no fontset is defined. - Added "bad plugin" blacklist in configtest.php. @@ -107,6 +117,57 @@ Version 1.5.2 - CVS - Removed conf.pl dependency on Perl IO::Socket module. Automatic detection of supported authentication mechanisms is disabled, if IO::Socket is not available. + - Removed HTTP Status header from signout page (#1424748). + - config_default.php is loaded before site configuration file. + config_local.php overrides are removed from config.php and loaded by + main initiation script. + - Fixed resuming of compose when session expired while writing, and make + sure the code only sets those variables that are needed in compose and + are not already set. Thanks James Bercegay from GulfTech for pointing + this out. + - Subfolders of system folders are not tagged as special in folder + management page in order to allow rename and delete operations with + subfolders (#1460011). + - Trash subfolders are allowed in courier. INBOX.Trash is not treated + as special on Courier, unless some SquirrelMail configuration option + marks this folder as special (#1354393). Configtest utility should + display warning, if Courier IMAP XMAGICTRASH extension is detected. + - Show purge link for Trash folder without any messages, if folder has + subfolders (#1413569). + - Custom SMTP AUTH configuration variables are moved from config_local.php + to main configuration file. + - Fixed subscription of new 'noselect' folders (#1315912). + - Moving the development documentation to the documentation module. + - Drop obsolete script plugins/make_archive.pl. + - Fix misspelled constant PREG_SPLIT_NI_EMPTY in sqimap_get_message + (#1543573). + - Provide View Unsafe Images link on viewing a text/html attachment. + - Added APOP, TLS and STLS support to mail_fetch plugin (#575299). + - Added Courier IMAP OUTBOX check to configtest utility. + - Moved login_form hook to its own table row on login page. + - Added check_plugin_version() function. + - If mailbox name starts with slash or contains ../, error message is + generated. Safety check for insecure default UW IMAP setup (#1557078). + - Ignore message copy errors when messages are deleted. Allows to delete + messages when quota is exceeded. (#614887) (#646386) (#1446026) + - Fixed unintended literal fetching (#1562271). + - Checked if configuration file is readable in configuration utility + (#1568355). + - Added PHP pspell extension support to squirrelspell plugin. + - Add CEST and MEST (non-standard) timezone codes for +0200. + - Add support for SpamAssassin's X-Spam-Status header (#1589520). + - Added plugin on/off switch, which completely disables all plugins + (optionally for one named user, otherwise for all users). + - Security: close cross site scripting vulnerability in draft, compose + and mailto functionality [CVE-2006-6142]. + - Security: work around an issue in Internet Explorer that would guess + the mime type of a file based on contents, not Content-Type header. + - Security: Multiple IE cross site scripting issues related to the + generous parsing of the words 'expression' and 'url' by IE. + - Security: Removing @import when sanitizing html mail. + - Redesigned plugin hook system. do_hook_function() has been removed + and do_hook() now emulates do_hook_function()'s return value and + also has its plugin arguments passed by value, etc. Version 1.5.1 (branched on 2006-02-12) --------------------------------------