Froxlor/lib
Michael Kaufmann 1b44ee2e06
Merge pull request from GHSA-x525-54hf-xr53
* do not log unvalidated user-input to mysql-log (if enabled)

Signed-off-by: Michael Kaufmann <d00p@froxlor.org>

* clean log-text to only allow a subset of special characters

Signed-off-by: Michael Kaufmann <d00p@froxlor.org>

* clean log-text when selecting from database to avoid possible previously added malicious entries

Signed-off-by: Michael Kaufmann <d00p@froxlor.org>

---------

Signed-off-by: Michael Kaufmann <d00p@froxlor.org>
2024-05-03 07:54:13 +02:00
..
configfiles added configuration adjustment for prodtpd if renew-hook for lets encrypt is used; updater-compatibility if gui_access field is not present yet (froxlor <2.2); removed depercated gentoo config templates 2024-01-14 09:40:33 +01:00
formfields correctly save pass_authorizationheader flag for php-configs if FCGID is used; correctly add 'FcgidPassHeader' for froxlor-vhost itself if set 2024-03-11 08:00:26 +01:00
Froxlor Merge pull request from GHSA-x525-54hf-xr53 2024-05-03 07:54:13 +02:00
navigation little work on installation; replace hardcoded strings with variables/constants; update dependencies 2023-11-30 11:41:20 +01:00
tablelisting add gui_access flag to admins and customers to allow/disallow login to the webui; fixes #1219 2024-01-07 10:23:02 +01:00
ajax.php adjust Request-class methods to be more flexible 2022-12-30 21:43:27 +01:00
config.example.inc.php implementation start of rspam/antispam feature 2024-01-05 15:37:04 +01:00
functions.php include custom.css from config.json if preset correctly 2023-12-21 10:59:15 +01:00
index.html add empty index.html file to all folders to avoid accidental folder-content disclosure if 'Options Indexes' is set for a (parent)folder containing froxlor in webserver-config 2022-03-24 14:35:30 +01:00
init.php Fix "expires" option cannot have a year greater than 9999 (#1246) 2024-03-23 15:14:11 +01:00
tables.inc.php remove wip backup-feature for later releases, see branch backup-feature 2023-09-17 13:19:00 +02:00