X-Git-Url: https://vcs.fsf.org/?p=squirrelmail.git;a=blobdiff_plain;f=ChangeLog;h=88fc5b09255b4f71e56f479daf014ad9c09ffa3b;hp=b62b16edf1e9dbf52ea2268e01d7b77054f9975b;hb=93917f92375f25b02bbba71f70ee99b7e81eceb0;hpb=031a141e84a4d11a247b23a6fde38551f7d41253 diff --git a/ChangeLog b/ChangeLog index b62b16ed..88fc5b09 100644 --- a/ChangeLog +++ b/ChangeLog @@ -2,8 +2,10 @@ *** SquirrelMail Devel Series 1.5 *** ************************************* -Version 1.5.2 - CVS +Version 1.5.2 - SVN ------------------- + - Fix broken set_url_var function in functions/html.php (#1729814). + - Fix incorrect detection of auth mechanisms in conf.pl (#1727033). - The search expression in the LDAP backend of the Addressbook is now configurable, which can allow the result set to be expanded. - Preliminary support for NAMESPACE in Squirrelmail IMAP Backend: NAMESPACE @@ -168,6 +170,51 @@ Version 1.5.2 - CVS - Redesigned plugin hook system. do_hook_function() has been removed and do_hook() now emulates do_hook_function()'s return value and also has its plugin arguments passed by value, etc. + - Drop obsolete ORDB RBL from filters plugin (#1629398). + - Add warning about magic_quotes_* in configtest. + - Unify accepted versions for imap_server_type and set_defaults (#1629722). + - Improve attachment temp file creation. + - Add ability for listcommands plugin to show post and reply links for + user-configured non-RFC 2369-compliant lists; admin must enable by + configuring plugin. Thanks to Peter Steiner. + - Fixed HttpOnly cookies again. + - Update for switch from CVS to Subversion. + - Default provider URI link fixed (was broken when on plugin options pages, etc) + - Fix URL to send read receipts from read_body (#1637572). + - Add option to ask users for personal information on first login. + - Drop redundant call to session_register, which could trigger a segfault + in PHP 4.4.5 (#1664155). + - If a date-header cannot be parsed, display the unparsed version as a + better-than-nothing alternative. + - Fix Priority and Receipt compose options being reset after return from + HTML addressbook, and allow returning from an empty address book (#1673056). + - Do not special case the 'None' folder. + - Fixes for filters issues (#1634735). + - session_id reporting session id when no active session (#1685031). + - Added sq_change_text_domain() for plugins to use when switching text + domains. If plugins use this function, it fixes #1434043. + - Add dynamic textarea sizing slider control to compose screen (default_advanced + skin) + - Security: fixes for the HTML filter to counter further XSS exploits: + HTML attachments containing 'data:' URLs, Internet Explorer-specifc + charset conversion exploits, and request forgery through included + images. Thanks to Mikhail Markin, Tomas Kuliavas and Michael Jordon + for reporting these issues. [CVE-2007-1262, CVE-2007-2589] + - Fix busy loop and notice when two literals in IMAP fetch (#1739433). + - Resolved issue with compose session not being updated after send/save. + - Added ability to detect HTTP_X_FORWARDED_PROTO in get_location(), + thanks to Daniel Watts. + - Fix test for signout.php in the logged in check in init.php so it + cannot be circumvented by manipulating the URL. External plugins might + rely on init.php guaranteeing that the user is logged in. + - Sort readdir() output in conf.pl (#1755886). + - Made the webmail_top hook work again for plugins that want to change + the URI of the "right" frame; plugins have to change the value of the + global variable $right_frame_url + - No longer store all message composition sessions in the PHP session, + since it was not made use of and in rare cases, made sessions too big + - Composition restoration functionality now correctly restores attachments + - Added smtp_auth hook Version 1.5.1 (branched on 2006-02-12) --------------------------------------