Timeline
Not logged in

Many hyperlinks are disabled.
Use anonymous login to enable hyperlinks.

20 check-ins using file src/main.c version 6400d7c08c

2025-04-19
23:32
Fix more issues that were already fixed but overwritten by text editor errors and didn't get committed last time. check-in: bd45dc72dd user: drh tags: th1-taint
23:24
More minor fixes resulting from a code audit. check-in: b1711046d9 user: drh tags: th1-taint
23:02
Fix additional problems on the new TH1 implementation. check-in: 2c2b6c68b2 user: drh tags: th1-taint
22:30
Fix an error that occurs while commiting a new ticket. check-in: 17060ca29a user: drh tags: th1-taint
22:15
fix tainted warning in skin headers check-in: de407148e9 user: jkosche tags: th1-taint
19:18
Update the default ticket configuration to avoid sending out text that seems tainted. There are no actual XSS issues here, but these changes do add an extra margin of safety. check-in: 5d17ced68d user: drh tags: th1-taint
19:08
Mark some TH1 inputs that can be controlled by the user as tainted. check-in: 2742682720 user: drh tags: th1-taint
18:43
The taint markings and detection now appears to be working. check-in: d1bb87bcfd user: drh tags: th1-taint
16:55
Experimental changes to TH1 to try to make it resistant to coding errors that could lead to XSS or SQL injection attacks. check-in: b0b4492480 user: drh tags: th1-taint
2025-04-18
16:12
fix bug in /tktview: use relative instead of absolute link for version check-in: f1db9ead1d user: jkosche tags: trunk
15:32
Use db_get_boolean() instead of db_get_int() for the localauth setting, since localauth is a boolean value. check-in: 00638d9a83 user: drh tags: trunk
14:59
Improved error messages from "fossil push" and similar when the push is disallowed over ssh because "localauth" setting is enabled. check-in: 2765f04694 user: drh tags: trunk
12:28
Resolve accidental fork. check-in: b6e029394d user: florian tags: trunk
12:25
Amend [a11d245478]: Fix positioning of 'show/hide' checkboxes for /ci pages. check-in: 2b59fcd475 user: florian tags: trunk
12:23
Rework the cgi_http_server() routine so that it uses two separate sockets, one each for IPv4 and IPv6. check-in: 945e0ae4eb user: drh tags: trunk
12:18
Modify some links that show/ignore diff whitespace to preserve the diff type. check-in: 1c61fcd9d6 user: florian tags: trunk
07:08
Amend [2b6ad00ea3]: Minor wording improvements to `fossil ssl-config show -v' output. check-in: a9b075af83 user: florian tags: trunk
00:00
Show the FORUMPOST table content associated with a forum thread on the /forumthreadhashlist page (accessible by admins only). check-in: 042a750aa6 user: drh tags: trunk
2025-04-17
23:17
Defend against a possible infinite loop in forumpost_is_closed() that might occur if the forumpost table contains goofy data. check-in: 923aa75345 user: drh tags: trunk
20:04
Add documentation for the FOSSIL_REPOLIST_SHOW environment variable. check-in: fbd77310b6 user: drh tags: trunk