r1559: Closing a SQL injection in register.php with the activationid
[bugdar.git] / docs / changes.txt
1 1.2.0
2 ===============================
3 - Fixed: In userctrl_search.tpl, the floated elements need to be before unfloated ones otherwise Gecko engine offsets it by a line
4 - Fixed: Closed a SQL injection vector in register.php
5
6 1.2.0 Release Candidate 1
7 ===============================
8 - Enhancement: Allow sorting and display of the "assigned to" column on grid display
9 - Fixed: Comments wouldn't be displayed in a right-to-left fashion if the language is RTL (bug://report/80)
10 - Fixed: When submitting the lost password form, error checking was disregarded because we were checking for errors the old way
11 - Change: Force utf8 as the default installation collation for MySQL
12
13 1.2.0 Beta 3
14 ===============================
15 - Fixed: If Gettext isn't installed, a function-not-found error would be thrown
16 - Fixed: On PHP4 systems, a "call to member non-object" error would be thrown because the Authentication class does not have a PHP4 constructor
17 - Fixed: In lost password reset emails, the subject would appear as "Array['trackertitle']" because the variable was not enclosed in curly braces
18 - Fixed: On PHP4 systems, a bug in the BugAPI would prevent any data from being saved because PHP4 doesn't support call_user_func() of parent:: selectors
19 - Change: When clicking the "[Run Search]" link in the "Saved Searches" section of the "Options" tab, force the search to rerun
20 - Fixed: Some email roles would not get notified under certain circumstances because the list of users to notify was reset
21 - Fixed: Errors would occurr on installation due to a problem with not loading all the data at the right time
22 - Enhancement: The installer will now check to ensure that all the proper MySQL permissions are enabled
23 - Fixed: A PHP warning could be generated due to passing an argument by reference (bug://report/78)
24
25 1.2.0 Beta 2
26 ===============================
27 - Fixed: Emails wouldn't be sent out for new comments due to a bug with updating the notices array
28 - Fixed: Searches wouldn't be rerun after 15 minutes because of a typo in the time calculation
29 - Fixed: The installer would show an error if gettext wasn't installed because the emulator wasn't loaded early enough
30 - Fixed: Close a large bug that would cause a PHP error to be thrown regarding string offsets during notification processing
31 - Fixed: Email notifications would be essentially empty in all circumstances
32 - Change: Removed the stylevars system in place of additional CSS classes for formatting of tables and alternate row colors
33 - Fixed: Defining the NO_VERSION_CHECK constant wouldn't work due to a typo in admin/index.php
34 - Fixed: Automations wouldn't properly save custom field changes in the admin section
35 - Fixed: Automations would have no effect on custom fields when running them from the edit screen
36 - Fixed: A SQL error would occur when saving a new usergroup
37 - Fixed: In the product-level permissions screens, not all the products would be listed
38 - Fixed: A minor display issue would occur in a rare instance when showing an error message when trying to add a version without a product
39 - Fixed: If any fields had invalid data in editreport.php no validation errors would be thrown
40 - Fixed: The Logging system would add extra empty logs that would pollute the database; fixed this and then added queries in showhistory.php to clean it up
41 - Fixed: PHP smart tags were used in the installer, which if not enabled on the server would produce strange output (bug://report/67)
42 - Enhancement: Users can now belong to a single primary usergroup and multiple secondary groups, greatly increasing permission flexibility (bug://report/70)
43 - Enahncement: Usergroups can be cloned to allow fast duplication of permissions
44 - Fixed: Even after calling UsergroupAPI::delete(), there would still be usergroup remnants in bugfieldpermission and permission tables
45 - Fixed: The javascript cancel buttons wouldn't work due to a parse error
46 - Fixed: When approving users, the approval email would never be sent and a method not found error would be shown
47
48 1.2.0 Beta 1
49 ===============================
50 - Change: When a user does not have any favorites in his list, show a message instead of an empty screen
51 - Enhancement: Added the ability to show all the users in a paginated list in the admin section (bug://report/55)
52 - Enhancement: Can export search results to an XML file (bug://report/41)
53 - Enhancmenet: Links in comments can be parsed if the option is checked (bug://report/2)
54 - Enhancement: Components can now be displayed on the bug grid (bug://report/43)
55 - Enhancement: Votes can now be displayed and sorted on the bug grid (bug://report/13)
56 - Enhancement: Users can save a search so they can rerun it at any time
57 - Fixed: Component and product changes wouldn't appear correcly on showhistory.php
58 - Enhancement: Versions can be marked "Obsolete" so new bugs cannot be filed against them
59 - Change: When there are no bugs to display on index.php, don't show an empty grid, but rather an error message
60 - Optimize: Reduce a query on bug updates by not querying the automation system if it is not being used
61 - Optimize: Move custom field data into the bug table to reduce the use of JOINs
62 - Optimize: Remove a query on userctrl.php's save options called by build_assignedto() because the API already does this for us
63 - Optimize: Setting system cleanup that improves speed by reducing queries and not using eval()
64 - Enhancement: Search results can be mass-updated to change bug fields
65 - Change: Search system no longer stores the actual query of the search, but rather the paramters
66 - Enhancement: Added a lost password reset system
67 - Fixed: Cached usernames would be cleared by the UserAPI if the display name wasn't set in the values array
68 - Enhancement: Extracted email text to the template system to make it easier to modify them
69 - Enhancement: Improved the admin security system by creating a session system that is much harder to bypass
70 - Change: Cleaned and refactored up the MessageReporter class
71 - Optimize: Template are now cached in the database to greatly improve speed; this does not effect editing templates at all
72 - Enhancement: An Authentication API was created in order to allow custom applications or databases to be used when authenticating at either login or with cookies
73
74 1.1.5
75 ===============================
76 - Fixed a potential SQL error on search.php because no results were found (bug://report/62)
77 - Fixed a SQL error on admin/user.php when adding a new user from the admin section (bug://report/63)
78 - When adding a new user from the admin section, email options were not saved properly
79 - Added an option to only perform header redirects instead of intermediate-stage redirects (bug://report/65)
80 - Fixed a foreach() error after adding a new user in the admin section without email options [admin/user.php#102]
81 - Fixed a minor typo on the guest welcome banner (bug://report/66)
82
83 1.1.4
84 ===============================
85 - Time zones with half-hours are not saved because the field only allows INTs (but://report/38)
86 - Fixed a SQL error received upon deleting a resolution (but://report/40)
87 - When searching and selecting multiple items for a field, only the first one is used in the search (but://report/39)
88 - Need to cast the unserialized data to an array to remove an implode() warning [admin/field.php#235]
89 - When $bugsys->options['pagelinks'] is set to 0, it now actually does its advertised behavior (but://report/45)
90 - Foreign langauge users cannot use the product/component editing system beacause localized strings are used to create the do actions instead of english variable ones (but://report/42)
91 - Fixed a SQL error that would occur when editing a report with no emails linked to it (but://report/46)
92 - Added the ability to delete attachments from the database (but://report/47)
93 - Fixed a scrollpane bug related to new reply <textarea>s in IE (but://report/48)
94 - In the "My Controls" tab, change the name of the email and password fields to prevent autocomplete from working on them
95 - Include the Gettext mimic functions into the installer so people without the PHP extension can install Bugdar (but://report/51)
96 - Fixed a SQL error that would occur when editing or deleting comments (but://report/52)
97 - Allow administrators to set the default time zone which guests view all times and dates in (but://report/53)
98 - The "[Edit]" and "[Delete]" options for attachments were off by one line (but://report/56)
99 - Fixed a spelling error in search.php when there is no search criteria
100 - Adding a quick search feature to the header bar (but://report/57)
101 - Fixed an occurence in header.tpl where the $stylevar align wasn't used, but a hard-coded one was
102 - Only allow JPG, JPEG, PNG, and GIF attachments to be displayed inline because all other types could lead to an XSS attack
103 - Added maxlength attributes to all <input type="text"/> fields so the database doesn't truncate (but://report/58)
104 - Fixed display issues in Firefox for RTL languages in the bug report screen and attachment display (but://report/59)
105 - Localized the version checking information strings in admin/index.php
106 - Localized the word "Home" in the admin/index.php <title>
107 - Fixed a bug in admin/user.php where email options would be changed for the admin making the changes to another user's account instead of that user
108 - Emails weren't being sent under certain conditions for new comments
109
110 1.1.3
111 ===============================
112 - If a user leaves a comment and does not have bug change access, data loss occurs
113 - Fixed IE's redirection issue when using Message_Reporter->redirect() (but://report/32)
114 - On the admin login page, prevent the number "15" from appearing as text and marked another string for translation that was missed
115 - Error messages are no longer hidden in IE6 (but://report/30)
116
117 1.1.2
118 ===============================
119 - Fixed a SQL injection on login.php (but://report/36)
120 - Fixed potential SQL injections on search.php
121 - Fixed potential SQL injections on install/install.php
122
123 1.1.1
124 ===============================
125 - Registration email functions do not work because they are not ISSO2/Mail compatible [register.php]
126 - Removed TABLE_PREFIX-related SQL errors in syndicate.php
127 - Use the correct language variable key for exporting the XML encoding in syndicate.php
128 - API-level errors are not caught in the registration process before insertion because of user_cumulative [register.php]
129 - Remove warnings on explain.php?do=products (but://report/29)
130 - Removed SQL errors when deleting a product or version due to bad column names (but://report/28) [admin/product.php]
131 - Added a way to view and approve "Pending" and "Awaiting" users
132 - Prevent a weird bug with notifications where multiple emails would be sent out to the wrong people
133 - Numerous improvements for RTL languages (but://report/34)
134
135 1.1.0
136 ===============================
137 - When gettext is not installed, a "method call on unobject" error is thrown
138 - Renamed "automatic action" to "automation"
139 - If no user comment is entered but there's an automation comment, then the automation comment is no longer disregarded
140 - Get rid of a foreach() warning if there are no products [admin/product.php#317]
141 - If no custom fields were setup, an empty query error would be thrown [newreport.php#130]
142 - If no custom fields were present, adding an automation would fail [admin/automation.php#74]
143 - Remove a warning when saving a usergroup and there are no custom fields present [admin/usergroup.php#221]
144 - Update cached usernames when the display name changes
145
146 1.1.0 Release Candidate 1
147 ===============================
148 - Fixed many problems with install/install.php
149 - Changed array casting instances to is_array() checks, which are better
150 - Made some of the email notifications better-worded
151 - Fix the correct stylevar for language codes
152 - Fixed another can_perform() product-based permissions check [search.php]
153 - More changes to syndicate.php to increase performance
154 - Add checks to newreport.php and search.php to see if there are products or versions, if there aren't, then throw a message about needing them to be setup
155 - Process custom field data on newreport.php
156 - Add regex matching check to process_custom_fields()
157 - Missed some string conversions to gettext
158 - If cookies do not authenticate right, unset them [includes/init.php]
159
160 1.1.0 Beta 2
161 ===============================
162 - Array casting to remove foreach() warnings [editreport.php#132]
163 - Update last post information after deleting a comment (but://report/25)
164 - Improved Atom feed by using a <table> and properly specifying type information
165 - Changed the access key for "Save Report and Add Another" button to E
166 - Removed potential warnings when there are no products [includes/functions.php#417] (but://report/26)
167 - Removed potential warnings if there is no page navigator [class_pagination.php#243] (but://report/26)
168 - Created a Language API
169 - Fix a call to a non-object error [editcomment.php#116]
170 - Switch to gettext language system instead of the XML-strings format
171 - Fixing warnings related to Printer->page_confirm() throughout the entire admin section
172 - After you delete a resolution, severity, priority, or status, set all bugs with the deleted field item back to the value set as default
173 - Fixed a bug where there could be two <select> menus in userctrl.php because we double-wrapped a <select> [userctrl.tpl]
174 - Cast to array to remove foreach() warnings [userctrl.php#160]
175 - Fixed a bug that would cause searching to result in a SQL error
176 - Added better checking of hidden bugs for the favorites list
177 - Better permissions checking in vote.php, viewattachment.php, attachment.php, showhistory.php, and favorite.php
178 - Fixed numerous permission checks in showreport.php
179 - Added a permission to allow viewing of one's hidden reported bugs ("canviewownhidden")
180 - Added an is_array() check to prevent foreach() warnings [admin/user.php#135]
181
182 1.1.0 Beta 1
183 ===============================
184 - User help cache was not rebuilt for descriptions in custom fields (but://report/7)
185 - Custom fields did not appear on newreport.php (but://report/8)
186 - If the first SQL query fails (datastore fetch), show a link to the installer (but://report/20)
187 - Removed potential divide by 0 warnings in showreport.php under PHP5
188 - No longer highlight the <title> and <input> tags when viewing a bug report (but://report/21)
189 - Removed potential implode() warnings in showreport.php under PHP5
190 - When logging out, you will be redirected to the page you were previously viewing
191 - Rewrote the logging mechanism
192 - Usernames are now cached in the database for bug reports to remove the need to do complex joins at runtime
193 - Added notification system (but://report/11)
194 - When searching, you can now select multiple values for <select> menus (but://report/3)
195 - Add a notice for guests explaining that registration is a good thing (but://report/19)
196 - Create a separate screen that lists a user's favourites (but://report/12)
197 - Atom syndication of the bugs list (but://report/18)
198 - Removed the useless "dependency" table
199 - Added the following APIs:
200 - Attachment
201 - Automatic action
202 - Bug
203 - Comment
204 - Custom field
205 - Priority
206 - Resolution
207 - Severity
208 - User
209 - Usergroup
210 - User help
211 - Added support for DST observation (but://report/22)
212 - Data (bugs and comments) can now be removed (but://report/16)
213 - Specific statuses can be hidden by the administrator and users individually (but://report/9)
214 - Column sorting of bug lists (but://report/14)
215 - Added a version checker in the admin section
216 - Removed the plus sign in "class1 + class2" for HTML CSS class attributes
217
218 1.0.1
219 ===============================
220 - Fixed a SQL error in voting for those with a table prefix (but://report/6)
221 - Users with register_globals ON can now install software
222 - Users with register_globals ON can now log in
223