Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
bd93045088 | ||
|
|
58c24ef2c8 | ||
|
|
ff1b7f4832 | ||
|
|
c12b96a89f | ||
|
|
341a3d1ed6 | ||
|
|
4be1c1ad58 | ||
|
|
eaf0ea0c23 | ||
|
|
d09afa64c8 | ||
|
|
48ee58f6b9 | ||
|
|
3601c13b3b | ||
|
|
88c95e824f | ||
|
|
6ecfcd84b7 |
@@ -35,6 +35,10 @@ class AccountController < ApplicationController
|
|||||||
events = Redmine::Activity::Fetcher.new(User.current, :author => @user).events(nil, nil, :limit => 10)
|
events = Redmine::Activity::Fetcher.new(User.current, :author => @user).events(nil, nil, :limit => 10)
|
||||||
@events_by_day = events.group_by(&:event_date)
|
@events_by_day = events.group_by(&:event_date)
|
||||||
|
|
||||||
|
if @user != User.current && !User.current.admin? && @memberships.empty? && events.empty?
|
||||||
|
render_404 and return
|
||||||
|
end
|
||||||
|
|
||||||
rescue ActiveRecord::RecordNotFound
|
rescue ActiveRecord::RecordNotFound
|
||||||
render_404
|
render_404
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -43,6 +43,10 @@ class IssuesController < ApplicationController
|
|||||||
helper :timelog
|
helper :timelog
|
||||||
include Redmine::Export::PDF
|
include Redmine::Export::PDF
|
||||||
|
|
||||||
|
verify :method => :post,
|
||||||
|
:only => :destroy,
|
||||||
|
:render => { :nothing => true, :status => :method_not_allowed }
|
||||||
|
|
||||||
def index
|
def index
|
||||||
retrieve_query
|
retrieve_query
|
||||||
sort_init 'id', 'desc'
|
sort_init 'id', 'desc'
|
||||||
@@ -147,6 +151,7 @@ class IssuesController < ApplicationController
|
|||||||
attach_files(@issue, params[:attachments])
|
attach_files(@issue, params[:attachments])
|
||||||
flash[:notice] = l(:notice_successful_create)
|
flash[:notice] = l(:notice_successful_create)
|
||||||
Mailer.deliver_issue_add(@issue) if Setting.notified_events.include?('issue_added')
|
Mailer.deliver_issue_add(@issue) if Setting.notified_events.include?('issue_added')
|
||||||
|
call_hook(:controller_issues_new_after_save, { :params => params, :issue => @issue})
|
||||||
redirect_to(params[:continue] ? { :action => 'new', :tracker_id => @issue.tracker } :
|
redirect_to(params[:continue] ? { :action => 'new', :tracker_id => @issue.tracker } :
|
||||||
{ :action => 'show', :id => @issue })
|
{ :action => 'show', :id => @issue })
|
||||||
return
|
return
|
||||||
@@ -194,6 +199,7 @@ class IssuesController < ApplicationController
|
|||||||
flash[:notice] = l(:notice_successful_update)
|
flash[:notice] = l(:notice_successful_update)
|
||||||
Mailer.deliver_issue_edit(journal) if Setting.notified_events.include?('issue_updated')
|
Mailer.deliver_issue_edit(journal) if Setting.notified_events.include?('issue_updated')
|
||||||
end
|
end
|
||||||
|
call_hook(:controller_issues_edit_after_save, { :params => params, :issue => @issue, :time_entry => @time_entry, :journal => journal})
|
||||||
redirect_to(params[:back_to] || {:action => 'show', :id => @issue})
|
redirect_to(params[:back_to] || {:action => 'show', :id => @issue})
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -159,7 +159,7 @@ module ApplicationHelper
|
|||||||
|
|
||||||
# Truncates and returns the string as a single line
|
# Truncates and returns the string as a single line
|
||||||
def truncate_single_line(string, *args)
|
def truncate_single_line(string, *args)
|
||||||
truncate(string, *args).gsub(%r{[\r\n]+}m, ' ')
|
truncate(string.to_s, *args).gsub(%r{[\r\n]+}m, ' ')
|
||||||
end
|
end
|
||||||
|
|
||||||
def html_hours(text)
|
def html_hours(text)
|
||||||
|
|||||||
@@ -10,7 +10,7 @@
|
|||||||
<li><%=l(:field_mail)%>: <%= mail_to(h(@user.mail), nil, :encode => 'javascript') %></li>
|
<li><%=l(:field_mail)%>: <%= mail_to(h(@user.mail), nil, :encode => 'javascript') %></li>
|
||||||
<% end %>
|
<% end %>
|
||||||
<% for custom_value in @custom_values %>
|
<% for custom_value in @custom_values %>
|
||||||
<% if !custom_value.value.empty? %>
|
<% if !custom_value.value.blank? %>
|
||||||
<li><%= custom_value.custom_field.name%>: <%=h show_value(custom_value) %></li>
|
<li><%= custom_value.custom_field.name%>: <%=h show_value(custom_value) %></li>
|
||||||
<% end %>
|
<% end %>
|
||||||
<% end %>
|
<% end %>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<% form_remote_tag(:url => {}, :html => { :id => "journal-#{@journal.id}-form" }) do %>
|
<% form_remote_tag(:url => {}, :html => { :id => "journal-#{@journal.id}-form" }) do %>
|
||||||
<%= text_area_tag :notes, h(@journal.notes), :class => 'wiki-edit',
|
<%= text_area_tag :notes, @journal.notes, :class => 'wiki-edit',
|
||||||
:rows => (@journal.notes.blank? ? 10 : [[10, @journal.notes.length / 50].max, 100].min) %>
|
:rows => (@journal.notes.blank? ? 10 : [[10, @journal.notes.length / 50].max, 100].min) %>
|
||||||
<%= call_hook(:view_journals_notes_form_after_notes, { :journal => @journal}) %>
|
<%= call_hook(:view_journals_notes_form_after_notes, { :journal => @journal}) %>
|
||||||
<p><%= submit_tag l(:button_save) %>
|
<p><%= submit_tag l(:button_save) %>
|
||||||
<%= link_to l(:button_cancel), '#', :onclick => "Element.remove('journal-#{@journal.id}-form'); " +
|
<%= link_to l(:button_cancel), '#', :onclick => "Element.remove('journal-#{@journal.id}-form'); " +
|
||||||
|
|||||||
@@ -14,7 +14,7 @@
|
|||||||
<td><%= link_to h(version.name), :controller => 'versions', :action => 'show', :id => version %></td>
|
<td><%= link_to h(version.name), :controller => 'versions', :action => 'show', :id => version %></td>
|
||||||
<td align="center"><%= format_date(version.effective_date) %></td>
|
<td align="center"><%= format_date(version.effective_date) %></td>
|
||||||
<td><%=h version.description %></td>
|
<td><%=h version.description %></td>
|
||||||
<td><%= link_to(version.wiki_page_title, :controller => 'wiki', :page => Wiki.titleize(version.wiki_page_title)) unless version.wiki_page_title.blank? || @project.wiki.nil? %></td>
|
<td><%= link_to(h(version.wiki_page_title), :controller => 'wiki', :page => Wiki.titleize(version.wiki_page_title)) unless version.wiki_page_title.blank? || @project.wiki.nil? %></td>
|
||||||
<td align="center"><%= link_to_if_authorized l(:button_edit), { :controller => 'versions', :action => 'edit', :id => version }, :class => 'icon icon-edit' %></td>
|
<td align="center"><%= link_to_if_authorized l(:button_edit), { :controller => 'versions', :action => 'edit', :id => version }, :class => 'icon icon-edit' %></td>
|
||||||
<td align="center"><%= link_to_if_authorized l(:button_delete), {:controller => 'versions', :action => 'destroy', :id => version}, :confirm => l(:text_are_you_sure), :method => :post, :class => 'icon icon-del' %></td>
|
<td align="center"><%= link_to_if_authorized l(:button_delete), {:controller => 'versions', :action => 'destroy', :id => version}, :confirm => l(:text_are_you_sure), :method => :post, :class => 'icon icon-del' %></td>
|
||||||
</tr>
|
</tr>
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
<li><%=l(:field_parent)%>: <%= link_to h(@project.parent.name), :controller => 'projects', :action => 'show', :id => @project.parent %></li>
|
<li><%=l(:field_parent)%>: <%= link_to h(@project.parent.name), :controller => 'projects', :action => 'show', :id => @project.parent %></li>
|
||||||
<% end %>
|
<% end %>
|
||||||
<% @project.custom_values.each do |custom_value| %>
|
<% @project.custom_values.each do |custom_value| %>
|
||||||
<% if !custom_value.value.empty? %>
|
<% if !custom_value.value.blank? %>
|
||||||
<li><%= custom_value.custom_field.name%>: <%=h show_value(custom_value) %></li>
|
<li><%= custom_value.custom_field.name%>: <%=h show_value(custom_value) %></li>
|
||||||
<% end %>
|
<% end %>
|
||||||
<% end %>
|
<% end %>
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
<h2><%=l(:label_role)%>: <%= @role.name %></h2>
|
<h2><%=l(:label_role)%>: <%=h @role.name %></h2>
|
||||||
|
|
||||||
<% labelled_tabular_form_for :role, @role, :url => { :action => 'edit' }, :html => {:id => 'role_form'} do |f| %>
|
<% labelled_tabular_form_for :role, @role, :url => { :action => 'edit' }, :html => {:id => 'role_form'} do |f| %>
|
||||||
<%= render :partial => 'form', :locals => { :f => f } %>
|
<%= render :partial => 'form', :locals => { :f => f } %>
|
||||||
|
|||||||
@@ -4,6 +4,18 @@ Redmine - project management software
|
|||||||
Copyright (C) 2006-2009 Jean-Philippe Lang
|
Copyright (C) 2006-2009 Jean-Philippe Lang
|
||||||
http://www.redmine.org/
|
http://www.redmine.org/
|
||||||
|
|
||||||
|
== 2009-11-04 v0.8.6
|
||||||
|
|
||||||
|
* Change links to closed issues to be a grey color
|
||||||
|
* Change subversion adapter to not cache authentication and run non interactively
|
||||||
|
* Fixed: Custom Values with a nil value cause HTTP error 500
|
||||||
|
* Fixed: Failure to convert HTML entities when editing an Issue reply
|
||||||
|
* Fixed: Error trying to show repository when there are no comments in a changeset
|
||||||
|
* Fixed: account/show/:user_id should not be accessible for other users not in your projects
|
||||||
|
* Fixed: XSS vulnerabilities
|
||||||
|
* Fixed: IssuesController#destroy should accept POST only
|
||||||
|
* Fixed: Inline images in wiki headings
|
||||||
|
|
||||||
|
|
||||||
== 2009-09-13 v0.8.5
|
== 2009-09-13 v0.8.5
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -907,7 +907,7 @@ class RedCloth3 < String
|
|||||||
end
|
end
|
||||||
|
|
||||||
IMAGE_RE = /
|
IMAGE_RE = /
|
||||||
(<p>|\s|^) # start of line?
|
(>|\s|^) # start of line?
|
||||||
\! # opening
|
\! # opening
|
||||||
(\<|\=|\>)? # optional alignment atts
|
(\<|\=|\>)? # optional alignment atts
|
||||||
(#{C}) # optional style,class atts
|
(#{C}) # optional style,class atts
|
||||||
|
|||||||
@@ -224,6 +224,7 @@ module Redmine
|
|||||||
str = ''
|
str = ''
|
||||||
str << " --username #{shell_quote(@login)}" unless @login.blank?
|
str << " --username #{shell_quote(@login)}" unless @login.blank?
|
||||||
str << " --password #{shell_quote(@password)}" unless @login.blank? || @password.blank?
|
str << " --password #{shell_quote(@password)}" unless @login.blank? || @password.blank?
|
||||||
|
str << " --no-auth-cache --non-interactive"
|
||||||
str
|
str
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ module Redmine
|
|||||||
module VERSION #:nodoc:
|
module VERSION #:nodoc:
|
||||||
MAJOR = 0
|
MAJOR = 0
|
||||||
MINOR = 8
|
MINOR = 8
|
||||||
TINY = 4
|
TINY = 6
|
||||||
|
|
||||||
# Branch values:
|
# Branch values:
|
||||||
# * official release: nil
|
# * official release: nil
|
||||||
|
|||||||
@@ -76,7 +76,7 @@ a, a:link, a:visited{ color: #2A5685; text-decoration: none; }
|
|||||||
a:hover, a:active{ color: #c61a1a; text-decoration: underline;}
|
a:hover, a:active{ color: #c61a1a; text-decoration: underline;}
|
||||||
a img{ border: 0; }
|
a img{ border: 0; }
|
||||||
|
|
||||||
a.issue.closed, a.issue.closed:link, a.issue.closed:visited { text-decoration: line-through; }
|
a.issue.closed, a.issue.closed:link, a.issue.closed:visited { color: #999; text-decoration: line-through; }
|
||||||
|
|
||||||
/***** Tables *****/
|
/***** Tables *****/
|
||||||
table.list { border: 1px solid #e4e4e4; border-collapse: collapse; width: 100%; margin-bottom: 4px; }
|
table.list { border: 1px solid #e4e4e4; border-collapse: collapse; width: 100%; margin-bottom: 4px; }
|
||||||
|
|||||||
Vendored
+48
@@ -96,5 +96,53 @@ users_006:
|
|||||||
mail_notification: false
|
mail_notification: false
|
||||||
login: ''
|
login: ''
|
||||||
type: AnonymousUser
|
type: AnonymousUser
|
||||||
|
users_007:
|
||||||
|
id: 7
|
||||||
|
created_on: 2006-07-19 19:33:19 +02:00
|
||||||
|
status: 1
|
||||||
|
last_login_on:
|
||||||
|
language: ''
|
||||||
|
hashed_password: 1
|
||||||
|
updated_on: 2006-07-19 19:33:19 +02:00
|
||||||
|
admin: false
|
||||||
|
mail: someone@foo.bar
|
||||||
|
lastname: One
|
||||||
|
firstname: Some
|
||||||
|
auth_source_id:
|
||||||
|
mail_notification: false
|
||||||
|
login: someone
|
||||||
|
type: User
|
||||||
|
users_008:
|
||||||
|
id: 8
|
||||||
|
created_on: 2006-07-19 19:33:19 +02:00
|
||||||
|
status: 1
|
||||||
|
last_login_on:
|
||||||
|
language: 'it'
|
||||||
|
hashed_password: 1
|
||||||
|
updated_on: 2006-07-19 19:33:19 +02:00
|
||||||
|
admin: false
|
||||||
|
mail: miscuser8@foo.bar
|
||||||
|
lastname: Misc
|
||||||
|
firstname: User
|
||||||
|
auth_source_id:
|
||||||
|
mail_notification: false
|
||||||
|
login: miscuser8
|
||||||
|
type: User
|
||||||
|
users_009:
|
||||||
|
id: 9
|
||||||
|
created_on: 2006-07-19 19:33:19 +02:00
|
||||||
|
status: 1
|
||||||
|
last_login_on:
|
||||||
|
language: 'it'
|
||||||
|
hashed_password: 1
|
||||||
|
updated_on: 2006-07-19 19:33:19 +02:00
|
||||||
|
admin: false
|
||||||
|
mail: miscuser9@foo.bar
|
||||||
|
lastname: Misc
|
||||||
|
firstname: User
|
||||||
|
auth_source_id:
|
||||||
|
mail_notification: false
|
||||||
|
login: miscuser9
|
||||||
|
type: User
|
||||||
|
|
||||||
|
|
||||||
@@ -37,13 +37,30 @@ class AccountControllerTest < Test::Unit::TestCase
|
|||||||
assert_template 'show'
|
assert_template 'show'
|
||||||
assert_not_nil assigns(:user)
|
assert_not_nil assigns(:user)
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def test_show_should_not_fail_when_custom_values_are_nil
|
||||||
|
user = User.find(2)
|
||||||
|
|
||||||
|
# Create a custom field to illustrate the issue
|
||||||
|
custom_field = CustomField.create!(:name => 'Testing', :field_format => 'text')
|
||||||
|
custom_value = user.custom_values.build(:custom_field => custom_field).save!
|
||||||
|
|
||||||
|
get :show, :id => 2
|
||||||
|
assert_response :success
|
||||||
|
end
|
||||||
|
|
||||||
|
|
||||||
def test_show_inactive
|
def test_show_inactive
|
||||||
get :show, :id => 5
|
get :show, :id => 5
|
||||||
assert_response 404
|
assert_response 404
|
||||||
assert_nil assigns(:user)
|
assert_nil assigns(:user)
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def test_show_should_not_reveal_users_with_no_visible_activity_or_project
|
||||||
|
get :show, :id => 9
|
||||||
|
assert_response 404
|
||||||
|
end
|
||||||
|
|
||||||
def test_login_should_redirect_to_back_url_param
|
def test_login_should_redirect_to_back_url_param
|
||||||
# request.uri is "test.host" in test environment
|
# request.uri is "test.host" in test environment
|
||||||
post :login, :username => 'jsmith', :password => 'jsmith', :back_url => 'http%3A%2F%2Ftest.host%2Fissues%2Fshow%2F1'
|
post :login, :username => 'jsmith', :password => 'jsmith', :back_url => 'http%3A%2F%2Ftest.host%2Fissues%2Fshow%2F1'
|
||||||
|
|||||||
@@ -68,6 +68,16 @@ class ProjectsControllerTest < Test::Unit::TestCase
|
|||||||
assert_equal Project.find_by_identifier('ecookbook'), assigns(:project)
|
assert_equal Project.find_by_identifier('ecookbook'), assigns(:project)
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def test_show_should_not_fail_when_custom_values_are_nil
|
||||||
|
project = Project.find_by_identifier('ecookbook')
|
||||||
|
project.custom_values.first.update_attribute(:value, nil)
|
||||||
|
get :show, :id => 'ecookbook'
|
||||||
|
assert_response :success
|
||||||
|
assert_template 'show'
|
||||||
|
assert_not_nil assigns(:project)
|
||||||
|
assert_equal Project.find_by_identifier('ecookbook'), assigns(:project)
|
||||||
|
end
|
||||||
|
|
||||||
def test_private_subprojects_hidden
|
def test_private_subprojects_hidden
|
||||||
get :show, :id => 'ecookbook'
|
get :show, :id => 'ecookbook'
|
||||||
assert_response :success
|
assert_response :success
|
||||||
|
|||||||
@@ -79,6 +79,19 @@ class ApplicationHelperTest < HelperTestCase
|
|||||||
to_test.each { |text, result| assert_equal "<p>#{result}</p>", textilizable(text) }
|
to_test.each { |text, result| assert_equal "<p>#{result}</p>", textilizable(text) }
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def test_inline_images_inside_tags
|
||||||
|
raw = <<-RAW
|
||||||
|
h1. !foo.png! Heading
|
||||||
|
|
||||||
|
Centered image:
|
||||||
|
|
||||||
|
p=. !bar.gif!
|
||||||
|
RAW
|
||||||
|
|
||||||
|
assert textilizable(raw).include?('<img src="foo.png" alt="" />')
|
||||||
|
assert textilizable(raw).include?('<img src="bar.gif" alt="" />')
|
||||||
|
end
|
||||||
|
|
||||||
def test_acronyms
|
def test_acronyms
|
||||||
to_test = {
|
to_test = {
|
||||||
'this is an acronym: GPL(General Public License)' => 'this is an acronym: <acronym title="General Public License">GPL</acronym>',
|
'this is an acronym: GPL(General Public License)' => 'this is an acronym: <acronym title="General Public License">GPL</acronym>',
|
||||||
|
|||||||
Reference in New Issue
Block a user