X-Git-Url: https://vcs.fsf.org/?p=squirrelmail.git;a=blobdiff_plain;f=ChangeLog;h=d30f3f4814f410cbb39041113c19f2c68868e4a4;hp=e40d975b6ff9b0bc1c0b2d874680dc984247e7fd;hb=ee20a285cdd34be33e795db635c4d76846abf82d;hpb=27ff4efb166979a1251e0a8b2faa801e55110ff9 diff --git a/ChangeLog b/ChangeLog index e40d975b..d30f3f48 100644 --- a/ChangeLog +++ b/ChangeLog @@ -63,6 +63,9 @@ Version 1.5.1 -- CVS - Added sort by message size. - Security: Fixed XSS vulnerability in content-type display in the attachment area of read_body.php discovered by Roman Medina. + - Removed src/move_messages.php, move_before_move and move_messages_button_action + hooks. Mailbox listing actions should be handled by src/right_main.php and + functions/mailbox_display.php hooks. - Get alternating row colors of addressbook in sync with mailbox list. - Give proper error when PEAR DB not found. - Remove inappropriate strip_tags() from add-to-addressbook (#968475). @@ -80,8 +83,7 @@ Version 1.5.1 -- CVS - Fix bug when Saving to Draft folder that contains special characters. - Added size limit to signatures saved in file backend. Created error_option_save function, that allows sending error message to options - page. Thanks to Martynas. - Bieliauskas for spotting big signature "option". + page. Thanks to Martynas Bieliauskas for spotting big signature "option". - Make SquirrelSpell work with safe_mode enabled, if using PHP >=4.3.0. Patch by Ray Ferguson. - Make IP-address in Message-ID RFC822 compliant. @@ -362,7 +364,40 @@ Version 1.5.1 -- CVS 508 or WAI fixes. Original idea and patch by dugan passwall.com. - Fixed broken attachments caused by inconsistency of PHP chunk_split(). Thanks to Roalt Zijlstra. - + - Identity code was not checking for domain part in username before setting + email address (Bug #1219184). + - Disallow access to the administrator plugin screens when the plugin is + not enabled in the config. + - Security: fix several cross site scripting (XSS) attacks. Thanks go to + Martijn Brinkers for finding a lot of these. [CAN-2005-1769] + - Update COPYING with new address of the FSF. + - Fixed missing quote character when trying to build cid: urls. + - Added address listing functions and listing controls to address + book LDAP backend. Blocked wildcard searches in file and database + backends when listing is disabled (#529563). + - Some LDAP address book backend configuration options (listing + controls, filtering, scope limit) are moved to 'advanced + configuration' subsection. + - Javascript relied on rg=1 in the login page to force focus to + password box if username was supplied as a url arg (#1222617). + - Fix variable typo in parseFetch which caused IMAP errors on Exchange. + Thanks Christian Froemmel. + - Added Bluesome theme by Saku Lehtiö (#1188209). + - Rewrite of advanced identity handlying to remove stupid extraction + of all post variables. [CAN-2005-2095] + - Added StartTLS support to address book LDAP backend (#1197703). Patch + by John Lane. + - Added subtree/one level search options to address book LDAP backend + (#1212618). + - Added Simple Green 2 and Simple Purple themes by Vicky Pyne (#1217066 + and #1217069). + - sqimap_messages_delete|copy|flag and sqimap_get_small_header() + functions are removed from SquirrelMail IMAP API. Use sqimap_msgs_* + and sqimap_get_small_header_list() functions instead. + - Fix for bad cache on massive expunge/delete/move operations. + - Moved time zone configuration from locale/timezones.cfg to php array. + Adds time zone name localization options and fixes problems on systems + that don't support GNU C time zone mappings (#1177067). Version 1.5.0 - 2 February 2004 -------------------------------