This Day In History For 2026-09-18
2 Years Ago (more context)
|
2024-09-18
| ||
| 19:14 | Revert part of [268bb7394713e22e] so that the Close button on forum posts is not on its own line. Apply the 100% form element width change only to forms on the forumedit page. check-in: a767b75e8f user: stephan tags: trunk | |
| 12:55 | Fix broken link in fossil-v-git. check-in: fd903e92c2 user: drh tags: trunk | |
| 11:53 | Update the built-in SQLite to the latest 3.47.0 alpha, for testing. check-in: 5522ad5fa4 user: drh tags: trunk | |
| 11:42 | Record Olorin's disputes with the fossil-v-git document. Also fix a stale table-of-contents link in that same document. check-in: b08f062316 user: drh tags: trunk | |
3 Years Ago (more context)
|
2023-09-18
| ||
| 22:27 | Whitespace fix in previous check-in: f8bec8f74c user: wyoung tags: trunk | |
| 22:26 | Removal of the Tcl example in §5.5 of the containers doc left hanging references in the Python example in a few places. check-in: 40e537e94d user: wyoung tags: trunk | |
| 22:10 | Added §5.6 to the containers doc, "Email Alerts," explaining how to get email alerts out by use of the included tools/email-sender.tcl script and the "write mail to DB" feature since the default option (sendmail -ti) won't work by default and it wouldn't be appropriate to make it work besides. This then obviated the earlier half-baked advice on injecting a Tcl environment into the container; the essential point is adequately made by the Python example, so there is no point trying to rescue this plan. check-in: 616a37f4f7 user: wyoung tags: trunk | |
| 20:43 | Merge the CSRF-defense enhancements into trunk. check-in: 920ace1739 user: drh tags: trunk | |
| 17:13 | Omit the SameSite=strict specifier for the login cookie, since that prevents users from clicking a hyperlink on an email notification and then going directly to the relevant page and getting logged in. Closed-Leaf check-in: fc5b49e990 user: drh tags: csrf-defense-enhancement | |
| 15:36 | Set the "SameSite=strict" value on cookies (used for authentication) as a further defense-in-depth against CSRF attacks. check-in: bc643c32f8 user: drh tags: csrf-defense-enhancement | |
| 15:24 | Fix forum-post approval buttons so that they send the CSRF token. check-in: bf9974cf8d user: drh tags: csrf-defense-enhancement | |
| 15:10 | More intensive use of the Synchronizer Token Pattern for CSRF defense. check-in: 0a66be2b75 user: drh tags: csrf-defense-enhancement | |
| 14:32 | Strengthen CSRF requirements for the skin editor. check-in: 6912636dc3 user: drh tags: csrf-defense-enhancement | |
| 14:29 | Cleanup forms on the skin editor page. check-in: 5feae3fd75 user: drh tags: csrf-defense-enhancement | |
| 14:13 | Stronger CSRF token based on a SHA1 hash of the login cookie. check-in: ff3746c4c2 user: drh tags: csrf-defense-enhancement | |
| 13:18 | Try to simplify and rationalize the defenses against cross-site request forgery attacks. A hodgepodge of techniques have been used in the past. This changes attempts to make everything work more alike and to centralize CSRF defenses for easier auditing. check-in: 88a402fe2a user: drh tags: csrf-defense-enhancement | |
5 Years Ago (more context)
|
2021-09-18
| ||
| 21:25 | Corrected display of 'hooks' setting in /setup_settings, per [forum:d1ac688c1b|forum post d1ac688c1b]. check-in: 5d9a7442fa user: stephan tags: trunk | |
| 15:15 | Fix the "fossil commit" command so that it does not get confused by files added by merge and then edited but keeping the same file size. See [forum:/forumpost/03f6b307f89c990b|forum thread 03f6b307f89c990b] for discussion and a more detailed description of the problem. check-in: ed5843cf31 user: drh tags: trunk | |
| 03:52 | • Edit [c23aa77411fdb65e|c23aa77411]: Edit check-in comment. artifact: a52627733a user: stephan | |
| 03:40 | Reimplemented /chat settings selection to be more usable, device-portable, and extensible. Re-enabled client-side selection of repo-specific chat nofication sounds. check-in: 9c777150ed user: stephan tags: trunk | |
| 03:26 | /chat: Corrected storage of selected audio URI to account for multiple sounds. Updated change log and chat.md. Closed-Leaf check-in: c23aa77411 user: stephan tags: chat-config-options | |
| 02:36 | /chat: re-enable inclusion of unversioned sound files (mp3, wav, ogg) in the list of chat notification sounds. check-in: 2a59a9a15a user: stephan tags: chat-config-options | |
| 01:37 | Assorted small improvements to the new http-over-ssh.md doc. check-in: d8f470757e user: wyoung tags: trunk | |
| 00:51 | Added the www/server/any/http-over-ssh.md doc, an elaboration of Andy Bradford's OpenSSH ForceCommand based solution for forcing access via ssh:// URLs to go through a wrapper script that rewrites the command, exchanging "test-http" for "http", causing the Fossil RBAC system to come into play in a secure fashion. Linking to it from the top-level "server/" index and from the #webonly section of the caps/ index where it cites this limitation. Reworked the latter section now that we have a documented alternative. check-in: be8ed971f9 user: wyoung tags: trunk | |
15 Years Ago (more context)
|
2011-09-18
| ||
| 19:16 | terribly minor internal cleanups. check-in: 507a458277 user: stephan tags: json | |
| 19:11 | One compile fix and MSVC build fix, from Jeff Slutter. check-in: 5f3a98ae83 user: stephan tags: json | |
| 10:40 | Removed some no-longer valid comments after confirming that JSON mode works without cookies. Dumbed-down the various login errors by default (again). check-in: 52229655df user: stephan tags: json | |
| 10:25 | Added userName to /json/stat output for the nobody user (it was previously not set in that case). Renamed captcha to password in /json/anonymousPassword. Added NYI (not yet implemented) placeholders for several planned request types. check-in: 13cc3b823f user: stephan tags: json | |
| 08:11 | Implemented anonymous user login over JSON. Requires 2 requests (captcha-fetch and then login). check-in: cebf9919f8 user: stephan tags: json | |
| 05:51 | merged trunk [b54b8e751a]. check-in: 76c4ae5e5e user: stephan tags: json | |
| 05:45 | More cleanups to the cson_cgi removal refactoring. Added common "indent" parameter to control indentation of JSON (uses cson_output_opt.indentation semantics). check-in: b3653265d1 user: stephan tags: json | |
| 04:31 | Factored out cson_cgi bits - now using fossil's CGI bits. Removed cson_cgi from cson_amalgamation (cuts its size considerably). Seems to still work, and this removes some discrepancies in how CGI/server modes are handled. check-in: 4cf9681440 user: stephan tags: json | |