Commit Graph

15729 Commits (846fb637af846e0754db9720c864e653621824a9)

Author SHA1 Message Date
svetlana@192500fb6a2e2ef8e78d1a08cca64b1bca9833b9 5e621730bb update 2018-01-30 15:37:58 -04:00
svetlana@192500fb6a2e2ef8e78d1a08cca64b1bca9833b9 7c82d6fd6c %? 2018-01-30 15:37:25 -04:00
svetlana 400f37967c Auto-remove tag pages? 2018-01-28 01:08:19 -04:00
svetlana 6f70580389 2018-01-25 20:34:43 -04:00
svetlana 59b4785155 2018-01-25 20:15:28 -04:00
test419 63ecbc18d6 okay, sorry about that
This reverts commit b7263302c7
2018-01-21 18:05:21 -04:00
test419 b7263302c7 Testing if this is really so easily editable by the public? (my ikiwiki 'instance' is) How is it not constantly being riddled with spam? 2018-01-21 18:03:23 -04:00
svetlana 1653a74475 404, no 'wmd' 2018-01-20 20:23:09 -04:00
anarcat 5f8ce5b1bd move main documentation to converter's README file 2018-01-11 15:16:05 -04:00
anarcat 47329d8aa6 repository was moved 2018-01-11 14:59:13 -04:00
vegardv@75ae889e836bda8ce69bc038d8335c398a2f6f40 cb7aa6cf3d Added a comment: Todo already exists for `basename` 2018-01-10 04:54:28 -04:00
Amitai Schleier 9ddb60e44b co-maintainer opinion 2018-01-08 08:15:53 -05:00
Simon McVittie a147f5349d Don't send relative redirect URLs when behind a reverse proxy 2018-01-08 10:56:12 +00:00
smcv 48fc7db2f7 point to previous TODO entry 2018-01-08 06:33:57 -04:00
smcv 9a15b889c9 this is a web server configuration issue rather than a bug in the ikiwiki code 2018-01-08 06:29:59 -04:00
smcv e5a6689a95 failing test (marked TODO) now present 2018-01-08 06:14:10 -04:00
smcv 6806f3cea1 2018-01-08 06:05:58 -04:00
smcv 92f365f798 test case potentially in progress 2018-01-08 06:05:36 -04:00
smcv 8e280df9de I'm not sure this can be solved without web server configuration 2018-01-08 05:26:50 -04:00
Joey Hess f0121f8c62
Merge branch 'master' of ssh://git.ikiwiki.info 2018-01-07 13:39:55 -04:00
Joey Hess f3b469d43a
bug 2018-01-07 13:39:26 -04:00
smcv 1313c52400 open 2018-01-06 20:39:21 -04:00
Simon McVittie a68b97573b Reinstate links on front page, removed by spam edits 2018-01-06 21:06:30 +00:00
Joey Hess 9dfabb2b35
add news item for ikiwiki 3.20180105 2018-01-05 13:42:52 -04:00
Joey Hess a79ab9ed18
add and use cgiurl_abs_samescheme
* emailauth: Fix cookie problem when user is on https and the cgiurl
   uses http, by making the emailed login link use https.
 * passwordauth: Use https for emailed password reset link when user
   is on https.

Not entirely happy with this approach, but I don't currently see a
better one.

I have not verified that the passwordauth change fixes any problem,
other than the user getting a http link when they were using https.
The emailauth problem is verified fixed by this commit.

This commit was sponsored by Michael Magin.
2018-01-05 11:59:35 -04:00
Joey Hess 71064e3af6
how to fix? 2018-01-05 11:17:11 -04:00
Joey Hess 76ff547344
think I cracked it 2018-01-05 11:09:43 -04:00
Joey Hess 2fa7f5f66b
update 2018-01-05 09:58:01 -04:00
Joey Hess 4601dabd42
correction; I did not reproduce this
I was manually reloading /ikiwiki.cgi?do=login, and postsignin is not
set when that's done, which is a bug, but not the bug I was after.
2018-01-04 19:17:45 -04:00
Joey Hess 43a9b6b332
bug report 2018-01-04 19:00:33 -04:00
jon+ikiwiki@663db4cb26e845748f3e7e6d51eeb26c6014f1c3 720f0a77ab Is it still Joey's opinion that ikiwiki.info should remain using the anti-theme? 2017-12-28 18:52:25 -04:00
jamey@90d19ce4e4c32214a97c10f9d98b7c313e236fb4 e31d6b6302 Serialist doesn't use Ikiwiki any more, and also isn't called Serialist any more, whoops 2017-12-10 18:16:43 -04:00
jon+ikiwiki@663db4cb26e845748f3e7e6d51eeb26c6014f1c3 94d358724e 2017-12-08 17:56:58 -04:00
jon+ikiwiki@663db4cb26e845748f3e7e6d51eeb26c6014f1c3 e49149987e possible explanation 2017-12-08 17:56:04 -04:00
STrRedWolf 52b9e9f2d4 Added a comment: Fixed... by upgrading! 2017-12-08 12:06:00 -04:00
STrRedWolf 47c9a8c3e1 Added a comment 2017-12-08 11:11:11 -04:00
jon+ikiwiki@663db4cb26e845748f3e7e6d51eeb26c6014f1c3 b3fdb9374a formatting 2017-12-08 08:01:02 -04:00
jon+ikiwiki@663db4cb26e845748f3e7e6d51eeb26c6014f1c3 d5e3bf092c 2017-12-08 07:59:28 -04:00
jon+ikiwiki@663db4cb26e845748f3e7e6d51eeb26c6014f1c3 e2d7c1e8f4 bug report re http redirect 2017-12-08 07:58:24 -04:00
fixitdad 8d864c2ab6 2017-11-11 20:36:37 -04:00
anarcat ed2c78084c link to the ordering patch 2017-11-06 15:43:27 -04:00
anarcat 8b3c8e327d propose a javascript optimization 2017-11-06 15:36:40 -04:00
https://anarc.at/openid/ fbcf2439eb optimization proposal 2017-11-06 10:36:19 -04:00
111 9d1bfe4087 2017-11-06 00:39:29 -04:00
111 a3921e0aa5 2017-11-06 00:38:14 -04:00
Edward 354e50112b file bug 2017-10-27 04:34:03 -04:00
Edward 0d0df05040 formatting 2017-10-27 04:27:40 -04:00
Edward f16f326ec1 file bug 2017-10-27 04:23:52 -04:00
Edward ebc5016cbb file bug 2017-10-27 04:16:33 -04:00
Amitai Schleier a09e64b0c8 Revert spam edits. 2017-10-26 12:28:20 -04:00
abilash 5d602a8407 2017-10-26 05:22:22 -04:00
abilash 23762c6655 2017-10-26 05:07:58 -04:00
abilash f0f62c96a9 2017-10-26 05:05:44 -04:00
Simon McVittie fddc543fa5 Announce version 3.20171001
Signed-off-by: Simon McVittie <smcv@debian.org>
2017-10-01 17:16:33 +01:00
Simon McVittie 14344f58f0 Update changelog and close bug 2017-09-28 11:30:13 +01:00
fairusurped@12113b58e7c4c69149ded64c82f268e9fa14ad88 b2b75ca829 2017-09-07 09:55:41 -04:00
azzamsa 0cc2c1f455 2017-09-06 03:13:24 -04:00
azzamsa 8480cdc48c 2017-09-06 03:13:07 -04:00
azzamsa 8b265977bb Added a comment: my issue solved 2017-09-06 03:09:23 -04:00
intrigeri 0208305f5c Report bug + merge request: image resize is not deterministic. 2017-09-01 15:38:30 -04:00
anna19 258feb8bc8 Added a comment: Reposted question on unix.sx 2017-08-28 11:49:19 -04:00
Keeh 056349a7f0 removed 2017-08-21 16:02:23 -04:00
Keeh e13f9dbe87 2017-08-21 10:28:51 -04:00
Keeh f0982b1fd4 2017-08-21 10:20:33 -04:00
tbm@179cf05cd1bd36f352bd555cee25923d4216668f 6d5d1a2179 Clarify how to use sorting 2017-08-19 09:23:20 -04:00
dgsb 11b3fe108d 2017-08-09 02:07:37 -04:00
dgsb aaca2df33c 2017-08-08 16:37:01 -04:00
vpelcak@b216e425210695d731d2673167c7dd45e5e9b1c9 bd7edde9d6 2017-08-07 02:49:07 -04:00
smcv 8496c0c306 Added a comment 2017-07-23 14:02:30 -04:00
smcv e69fe3be51 Added a comment 2017-07-23 13:52:11 -04:00
smcv f3ccc45b89 Added a comment 2017-07-23 13:47:55 -04:00
smcv c68ce1f708 Added a comment 2017-07-23 13:46:37 -04:00
azzamsa ae19c4819c Added a comment: I have the same issue 2017-07-21 04:07:39 -04:00
ankit 2cc645060c Q. How to truncate blog posts? 2017-07-18 09:07:48 -04:00
DavidCary 1958cf8af2 answer question, with reference. 2017-07-05 13:51:19 -04:00
openmedi 37c200f8e0 Added a comment 2017-06-25 12:12:20 -04:00
smcv 0bad6e596b removed 2017-06-23 10:28:02 -04:00
test 3e4f5bb224 2017-06-22 14:01:30 -04:00
Simon McVittie 4fe6dd0551 request more information 2017-06-22 15:37:19 +01:00
Joey Hess 52a9d23e2c
add bug report originally emailed to me by Peter Simons 2017-06-22 09:55:27 -04:00
Simon McVittie fee378f056 Announce 3.20170622 2017-06-22 10:55:32 +01:00
Simon McVittie 453e07fd9f meta: Specifically document [[!meta foo:bar="baz"]] as not working 2017-06-22 09:19:02 +01:00
j@d945f5982c686dda5ab7bc2ef45e09d388233fad 63e6fa68b0 2017-06-20 19:03:02 -04:00
alicef 18c4559f4e 2017-06-12 17:14:22 -04:00
https://tylercipriani.com/ 15278cad15 Ensure repo gets picked up by gitremotes script 2017-06-02 08:55:00 -04:00
https://tylercipriani.com/ e8ca4e5b8c Add jsonfeed patch 2017-06-01 19:26:28 -04:00
https://tylercipriani.com/ 07f0f84a8e Add thcipriani repository 2017-06-01 19:17:04 -04:00
https://tylercipriani.com/ d64ce01e0a Add my user page 2017-06-01 19:15:33 -04:00
smcv af501e9e14 current headinganchors does not damage headings' attributes, although it does not act on those headings 2017-06-01 10:03:51 -04:00
smcv d20dd0c97e 2017-06-01 09:59:36 -04:00
smcv 2f765597de resolved 2017-06-01 09:48:10 -04:00
anarcat bbf2d13ae3 response 2017-06-01 09:14:23 -04:00
anarcat 1bb8301ad6 response 2017-06-01 09:02:26 -04:00
https://me.yahoo.com/a/GwQv.Tw.p_ux8p4eLf9CkcwYsQ--#2fdeb 5c57e46dd5 2017-05-26 22:25:07 -04:00
smcv 25ba5d260c Added a comment: Please do not patch out the symlink check 2017-05-26 02:20:23 -04:00
mail@b2ae8518bb6eba14728f86acae7830e4c2d9943d 4bb6132283 Added a comment: git-annex support 2017-05-25 10:43:20 -04:00
openmedi 11b9eb0c19 2017-05-25 07:30:47 -04:00
smcv b29efcb4c6 Added a comment: I suggest asking macOS/brew people 2017-05-22 07:02:44 -04:00
qazwsx 88ca349cd1 2017-05-21 19:23:36 -04:00
qazwsx aeb9317387 2017-05-21 19:22:54 -04:00
openmedi dbb06580d5 Added a comment 2017-05-19 11:32:18 -04:00
smcv 8503f8ddaa Suggested syntax does work, and has a test 2017-05-19 09:57:28 -04:00
smcv 778d9e50d4 Document the special case for [[!meta name=foo content=bar]] 2017-05-19 09:50:52 -04:00
smcv 1e4e51754e it is (meant to be) possible, just not with that syntax 2017-05-19 09:43:08 -04:00
fmarier 219134beff 2017-05-18 13:33:44 -04:00
bma@d2ddf927e0bde7166ad151d794bee58589bedb40 da0900649c long out of date 2017-05-16 08:59:37 -04:00
Simon McVittie 01f2a84360 color: Use markup for the preserved CSS, not character data
This still smuggles it past the sanitize step, but avoids having
other plugins that want to capture text content without markup
(notably toc) see the CSS as if it was text content.
2017-05-16 12:08:55 +01:00
smcv 6ab4dee728 we should prefer existing IDs and only act as a fallback 2017-05-16 05:38:02 -04:00
smcv 81221cb030 cross-reference i18nheadinganchors 2017-05-16 05:26:25 -04:00
smcv ab793c1db0 correct ID syntax 2017-05-16 05:17:57 -04:00
smcv 5150874861 browsers and specifications support more Unicode than we give them credit for 2017-05-16 05:17:00 -04:00
smcv cad72ecfad close 2017-05-16 04:27:56 -04:00
Simon McVittie 787fb8b058 Prune dead links 2017-05-16 08:55:24 +01:00
Simon McVittie 9858519cc5 Reinstate a git repo that has come back 2017-05-16 08:55:24 +01:00
smcv 55ae3c7368 Added a comment 2017-05-16 03:29:33 -04:00
Simon McVittie 4fd5f7d910 Clarify documentation 2017-05-16 08:28:04 +01:00
Simon McVittie c72dc5ddb7 mdwn: Don't enable alphabetically labelled ordered lists by default
This avoids misinterpreting initials ("C. S. Lewis was an author"),
the abbreviation for Monsieur ("M. Descartes was a philosopher") and
German page numbering ("S. 42") as ordered lists if they happen to
begin a line.

This only affects the default Discount implementation: Text::Markdown
and Text::MultiMarkdown do not have this feature anyway. A new
mdwn_alpha_list option can be used to restore the old interpretation.
2017-05-16 08:09:15 +01:00
qazwsx 94316fca54 Added a comment 2017-05-15 02:19:37 -04:00
Simon McVittie 4db4e589e4 mdwn: Enable footnotes by default when using Discount
A new mdwn_footnotes option can be used to disable footnotes in
MultiMarkdown and Discount.
2017-05-14 18:16:53 +01:00
Simon McVittie 81c3258269 mdwn: Don't mangle <style> into <elyts> under some circumstances
We can ask libdiscount not to elide <style> blocks, which means we
don't have to work around them.
2017-05-14 17:45:55 +01:00
Simon McVittie 31c89db246 httpauth: If REMOTE_USER is empty, behave as though it was unset
A frequently cut-and-pasted HTTP basic authentication configuration
for nginx sets it to the empty string when not authenticated, which
is not useful.
2017-05-14 15:37:45 +01:00
Simon McVittie 59daf36cb2 httpauth: Recommend if_not_empty parameter for REMOTE_USER
This is untested, but should hopefully avoid the failure mode
described in [[bugs/Anon_edit_caused_lock_out_on_entire_site_]].
2017-05-14 15:36:26 +01:00
smcv 365a930c2c complete last paragraph 2017-05-14 08:31:49 -04:00
smcv f6fc4543fb I have a theory 2017-05-14 08:20:49 -04:00
smcv 1f2f8d5f77 Added a comment 2017-05-14 08:01:09 -04:00
smcv 75f905a18a 2017-05-14 07:53:24 -04:00
smcv 65fe86e6f3 recommend discount over multimarkdown 2017-05-14 07:51:56 -04:00
smcv b14e3456dd multimarkdown: it's a trap! 2017-05-14 07:47:42 -04:00
smcv 50fb6f8b95 Added a comment: Use an underlay instead 2017-05-14 07:37:14 -04:00
smcv b047fc3757 removed 2017-05-14 07:28:50 -04:00
smcv f56e365dd0 Added a comment: You can do almost this with an underlay 2017-05-14 07:27:54 -04:00
smcv 02b4fb50c9 Added a comment 2017-05-14 07:00:48 -04:00
smcv 74d99b0063 Added a comment: you can't use and/or/! inside the page() parameter, move them outside 2017-05-14 06:49:54 -04:00
smcv d49aefdb19 fix syntax 2017-05-14 06:41:21 -04:00
Joe Rayhawk b919f1c3d4
Piny: mothballing 2017-05-13 09:23:56 -07:00
STrRedWolf de347f9f6c 2017-05-10 20:52:32 -04:00
qazwsx 69a0f01355 2017-05-09 13:45:51 -04:00
DataComputist 708023250a Added a comment 2017-05-08 17:16:18 -04:00
DataComputist 587d5dc874 2017-05-08 14:04:22 -04:00
desci cd651030ea Updating links 2017-05-01 15:18:15 -04:00
desci 187c5a259c Updating links 2017-05-01 15:14:33 -04:00
openmedi d00ddc9aea Added a comment 2017-04-18 09:13:42 -04:00
openmedi d16946c950 2017-04-18 08:19:44 -04:00
STrRedWolf 3f709fab6c Initial commit. 2017-04-16 17:38:24 -04:00
STrRedWolf 42bfe31b8a 2017-04-16 16:53:43 -04:00
STrRedWolf d090696696 First time theme help needed. 2017-04-16 16:53:21 -04:00
anarcat defdf8544f add list of pending patches 2017-04-13 09:27:10 -04:00
anarcat 76001618c2 mark this as a real plugin: forgot the plugin template! 2017-04-13 09:23:21 -04:00
anarcat 2c0f52cd48 mark this as ready for merging 2017-04-13 09:22:28 -04:00
anarcat 1d96095af7 clarify that "patch" on contrib plugins means the author wants to merge 2017-04-13 09:21:09 -04:00
anarcat ad6d2e7de0 this is a patch - i'd like this in core, or at least a discussion on how to merge it with the main plugin 2017-04-13 09:19:23 -04:00
anarcat 6a1efc5c6a add a patch to make this happen 2017-04-12 16:15:23 -04:00
anarcat 7d72549ef8 rename plugins/contrib/i18nheadinganchor.mdwn to plugins/contrib/i18nheadinganchors.mdwn 2017-04-12 16:14:30 -04:00
anarcat 42b8a58565 add i18nheadinganchors plugin 2017-04-12 16:14:13 -04:00
anarcat a0a57fa8cc move my repo to gitlab 2017-04-12 16:13:47 -04:00
anarcat f65eae2126 respond to an old question 2017-04-12 15:40:09 -04:00
Joey Hess 6cdba67dac
todo 2017-04-04 12:51:40 -04:00
desci 207666e903 Fixing format 2017-03-29 15:37:02 -04:00
desci 886610d85b As requested 2017-03-29 15:36:28 -04:00
desci 5c9d9b3213 Answering questions and updating links 2017-03-29 15:35:54 -04:00
tuxillo eba821b5f8 2017-03-19 20:33:38 -04:00
tuxillo 8d4342183b 2017-03-19 20:32:47 -04:00
martymcfly@55267c498da1bbb4b9fe2a8baadc45dc1bd8f57a f6f482af42 MyUserPage 2017-03-09 10:01:37 -04:00
martymcfly@55267c498da1bbb4b9fe2a8baadc45dc1bd8f57a 3e1d1ec36a Added a comment: PS 2017-03-09 10:00:23 -04:00
martymcfly@55267c498da1bbb4b9fe2a8baadc45dc1bd8f57a 17988f95b1 Ikiwiki error with Asciidoc 2017-03-09 09:59:06 -04:00
Joey Hess a3a6ec02e7
cleanup 2017-03-07 11:53:39 -04:00
kw_ikiwiki1@64633d204c198f52735247ca119bddbcbfaafdef 48a959eebb 2017-03-07 10:04:42 -04:00
kw_ikiwiki1@64633d204c198f52735247ca119bddbcbfaafdef 888b4603e1 test test blah blah 2017-03-07 09:59:48 -04:00
jmtd@d79be1606aba831a3b476d5fff7d99f4b321eab2 6b75169007 speed up commenting by optionally providing a comment form in static pages 2017-03-03 10:52:14 -04:00
jmtd@d79be1606aba831a3b476d5fff7d99f4b321eab2 5fc2e8b55b Added a comment 2017-03-03 10:48:03 -04:00
jmtd@d79be1606aba831a3b476d5fff7d99f4b321eab2 135a302acc Added a comment 2017-03-03 10:29:13 -04:00
Joey Hess 90f4fd6635
my github mirror of ikiwiki has been deleted due to their horrible anti-free-software TOS 2017-03-01 13:34:42 -04:00
svetlana@192500fb6a2e2ef8e78d1a08cca64b1bca9833b9 31e095be9b Added a comment 2017-02-21 18:02:45 -04:00
svetlana@192500fb6a2e2ef8e78d1a08cca64b1bca9833b9 a7cf415822 +aka use page/index.mdwn source files 2017-02-21 17:51:59 -04:00
smcv 5bc7a30f64 Added a comment 2017-02-21 14:21:19 -04:00
smcv c24f538c6d Added a comment 2017-02-21 14:17:35 -04:00
svetlana@192500fb6a2e2ef8e78d1a08cca64b1bca9833b9 4e77978328 Added a comment 2017-02-20 23:56:19 -04:00
svetlana@192500fb6a2e2ef8e78d1a08cca64b1bca9833b9 4a2c4842bf Added a comment 2017-02-20 23:47:35 -04:00
svetlana@192500fb6a2e2ef8e78d1a08cca64b1bca9833b9 dc232c0006 Added a comment 2017-02-20 19:42:13 -04:00
openmedi 7618dafe0c Added a comment 2017-02-20 11:43:13 -04:00
svetlana@192500fb6a2e2ef8e78d1a08cca64b1bca9833b9 f3a9bed1c5 Added a comment 2017-02-19 17:59:26 -04:00
svetlana@192500fb6a2e2ef8e78d1a08cca64b1bca9833b9 8c4408900c removed 2017-02-19 17:52:54 -04:00
svetlana@192500fb6a2e2ef8e78d1a08cca64b1bca9833b9 3b19cc0ddd Added a comment 2017-02-19 17:48:23 -04:00
Louis 37056e736a Merge branch 'master' of git://ikiwiki.branchable.com 2017-02-18 22:56:06 +01:00
Louis ff784524b4 Update my (spalax) information 2017-02-18 21:11:47 +01:00
Louis e66912e677 Apology about the poor choice for the name of the sidebar2 plugin 2017-02-18 21:08:48 +01:00
Louis d9f6141cd7 New plugin: verboserpc 2017-02-18 21:08:48 +01:00
Louis 7bb8226987 New plugin: pageversion 2017-02-18 21:08:48 +01:00
Louis d2c4047282 New plugin: redirect 2017-02-18 20:43:52 +01:00
krqt.kndy@eb44788e4eb202f3e68eeb8ba175d3897c3979a9 b92b8caf11 2017-02-17 17:15:00 -04:00
vegardv@75ae889e836bda8ce69bc038d8335c398a2f6f40 c0fcd409fa Added a comment 2017-02-10 04:33:42 -04:00
svetlana@192500fb6a2e2ef8e78d1a08cca64b1bca9833b9 e748e0016d Added a comment 2017-02-09 17:48:06 -04:00
smcv 8502eb47fa Added a comment 2017-02-09 08:13:03 -04:00
svetlana@192500fb6a2e2ef8e78d1a08cca64b1bca9833b9 3d177313d6 2017-02-09 07:22:48 -04:00
svetlana 40d3bdac4c +update broken uris 2017-02-07 20:36:02 -04:00
svetlana 139197d823 2017-02-07 19:15:02 -04:00
svetlana 4f9a8d10de Confuses a map 2017-02-07 19:11:17 -04:00
svetlana 7b664f4151 2017-02-06 01:39:02 -04:00
svetlana 7c0292edc5 removed 2017-02-05 22:37:01 -04:00
svetlana@192500fb6a2e2ef8e78d1a08cca64b1bca9833b9 4c96c9decd 2017-02-05 15:31:24 -04:00
smcv 7744b4d849 change `pwd` to $HOME so assumptions are met even if you cd elsewhere 2017-02-03 16:48:48 -04:00
me@4eb1b66f86170ba2ff0690b93ad01f46bfc8eac4 c72fbbe21d No longer using ikiwiki 2017-02-03 12:54:47 -04:00
smcv 47b12458ae 2017-01-26 07:38:48 -04:00
svetlana 2265aef4e6 Does not show up in the setup 2017-01-24 00:59:27 -04:00
svetlana 9581c039e8 * [[guppy|http://guppy.branchable.com]] an internationalized modular Python IRC bot 2017-01-18 19:27:48 -04:00
smcv 1c8c0ccf59 Added a comment 2017-01-18 17:46:14 -04:00
smcv 0acf3b6d0c Added a comment: Do that through your web server, not ikiwiki 2017-01-18 17:45:30 -04:00
openmedi 6d0f460b12 2017-01-17 08:44:20 -04:00
Simon McVittie 12b4618228 Note another Debian 8 backport 2017-01-12 00:31:10 +00:00
Simon McVittie 666d87a50c Fix typo 2017-01-11 19:02:10 +00:00
Simon McVittie 8b54ba7ad1 Release 3.20170111 2017-01-11 18:18:38 +00:00
Simon McVittie 4d0e525e6a Document the security fix soon to be released in 3.20170111 2017-01-11 18:16:42 +00:00
Simon McVittie c7a4d57772 3.20170110 2017-01-10 13:22:13 +00:00
Simon McVittie 7586f5165e news: Use Debian security tracker instead of MITRE for CVE references
The Debian security tracker gets timely updates, whereas the official
CVE pages hosted by MITRE tend to show up as "RESERVED" for several
weeks or months after assignment.
2017-01-09 14:11:18 +00:00
Simon McVittie 9e03c00202 shortcuts: Use security-tracker.debian.org for [[!debcve]]
security.debian.org currently rejects HTTPS connections.
2017-01-09 14:09:35 +00:00
https://anarc.at/openid/ f2b65d0370 add debian security tracker 2016-12-30 16:48:40 -04:00
Simon McVittie a60f837695 Merge remote-tracking branch 'origin/master' 2016-12-29 21:34:10 +00:00
Simon McVittie e0341d0e88 3.20161229.1 2016-12-29 20:47:17 +00:00
smcv 7562350a3a add anchors for use in advisory to oss-security 2016-12-29 16:24:48 -04:00
Simon McVittie 04e322fd6b Clarify which versions of ikiwiki fixed CVE-2016-9645, -9646 2016-12-29 20:08:49 +00:00
Simon McVittie 287bb19883 3.20161229 2016-12-29 17:37:51 +00:00
Simon McVittie cf0166347c Add CVE references for CVE-2016-9646, CVE-2016-9645
Thanks to the Debian security team for allocating these.
2016-12-29 17:36:11 +00:00
Simon McVittie 078d4208ca Prune git remotes that are unreachable or unresponsive 2016-12-29 17:30:56 +00:00
Simon McVittie a8a7462382 Try revert operations (on a branch) before approving them
Otherwise, we have a time-of-check/time-of-use vulnerability:
rcs_preprevert previously looked at what changed in the commit we are
reverting, not at what would result from reverting it now. In
particular, if some files were renamed since the commit we are
reverting, a revert of changes that were within the designated
subdirectory and allowed by check_canchange() might now affect
files that are outside the designated subdirectory or disallowed
by check_canchange().

It is not sufficient to disable rename detection, since git older
than 2.8.0rc0 (in particular the version in Debian stable) silently
accepts and ignores the relevant options.

OVE-20161226-0002
2016-12-28 21:32:12 +00:00
Simon McVittie c1120bbbe8 Force CGI::FormBuilder->field to scalar context where necessary
CGI::FormBuilder->field has behaviour similar to the CGI.pm misfeature
we avoided in f4ec7b0. Force it into scalar context where it is used
in an argument list.

This prevents two (relatively minor) commit metadata forgery
vulnerabilities:

* In the comments plugin, an attacker who was able to post a comment
  could give it a user-specified author and author-URL even if the wiki
  configuration did not allow for that, by crafting multiple values
  to other fields.
* In the editpage plugin, an attacker who was able to edit a page
  could potentially forge commit authorship by crafting multiple values
  for the rcsinfo field.

The remaining plugins changed in this commit appear to have been
protected by use of explicit scalar prototypes for the called functions,
but have been changed anyway to make them more obviously correct.
In particular, checkpassword() in passwordauth has a known prototype,
so an attacker cannot trick it into treating multiple values of the
name field as being the username, password and field to check for.

OVE-20161226-0001
2016-12-28 21:32:12 +00:00
spalax a9b876e1fa Added a comment 2016-12-26 18:03:28 -04:00
smcv 836f165939 Added a comment 2016-12-26 15:26:25 -04:00
spalax 1a73c8d528 Question about default timezone ":/etc/localtime" 2016-12-25 17:05:08 -04:00
Simon McVittie 28409cd358 Add CVE references for CVE-2016-10026 2016-12-21 13:03:36 +00:00
intrigeri bec3047aff Replied. 2016-12-20 10:26:22 +00:00
Simon McVittie fd6b947889 Announce 3.20161219 2016-12-19 21:20:41 +00:00
smcv 7e78712782 mention security contacts here too 2016-12-19 16:33:48 -04:00
Amitai Schleier 952404edaa Opt in to whatever spam this may bring. 2016-12-19 20:23:43 +01:00
Simon McVittie cde2cc1862 Restrict CSS matches on .header to not affect <tr>
Pandoc generates <tr class="header"> to hold <th> elements, and
we don't want to make those be display: block.

Signed-off-by: Simon McVittie <smcv@debian.org>
2016-12-19 18:21:07 +00:00
Simon McVittie 2a9e9f13f6 List security contacts
We still don't have a security@ alias; listing personal emails is
unfortunately the next-best thing.
2016-12-19 18:21:07 +00:00
Simon McVittie 9cada49ed6 Tell `git revert` not to follow renames
Otherwise, we have an authorization bypass vulnerability: rcs_preprevert
looks at what changed in the commit we are reverting, not at what would
result from reverting it now. In particular, if some files were renamed
since the commit we are reverting, a revert of changes that were within
the designated subdirectory and allowed by check_canchange() might now
affect files that are outside the designated subdirectory or disallowed
by check_canchange().

Signed-off-by: Simon McVittie <smcv@debian.org>
2016-12-19 18:21:07 +00:00
smcv 7244b712c1 Added a comment: no, not supported 2016-12-19 13:23:06 -04:00
smcv 32493312c8 rename bugs/img_tag_should_support_relative_size.mdwn to todo/img_tag_should_support_relative_size.mdwn 2016-12-19 12:46:46 -04:00
smcv 8395e43099 Not possible as stated, but could be adapted into a valid feature request 2016-12-19 12:46:22 -04:00
smcv 7d35dc88f3 2016-12-19 09:55:58 -04:00
Simon McVittie bc89021523 cgitemplate: remove dead code
blipvert points out in [[bugs/use of $topurl in cgitemplate]] that this
variable has not been used since commit a052771
"Now that we're always using HTML5, <base href> can be relative".

Signed-off-by: Simon McVittie <smcv@debian.org>
2016-12-19 12:00:34 +00:00
intrigeri 706bf876ea Report authorization bypass via RCS revert. 2016-12-17 11:11:44 +00:00
blipvert@b874dc05477cdc0dc8c9c8d9bbe2e39240253a85 bd46db3fb9 2016-12-14 19:07:00 -04:00
blipvert@b874dc05477cdc0dc8c9c8d9bbe2e39240253a85 85c1fa60b8 2016-12-14 19:06:05 -04:00
blipvert@b874dc05477cdc0dc8c9c8d9bbe2e39240253a85 bd6a4567fd 2016-12-14 19:04:05 -04:00
jeff+ikiwiki@b5854f0ab9935492e3dfefa98419b6530c92b049 9b0e02394b 2016-11-26 23:44:42 -04:00
intrigeri 2e865043d6 pagestats determinism: report bug + patch. 2016-11-20 07:00:20 +00:00
svetlana@192500fb6a2e2ef8e78d1a08cca64b1bca9833b9 021ae7050a svetlana.nfshost 2016-11-17 07:42:50 -04:00
Juego 3a36009158 Added custom solution 2016-11-16 18:17:48 -04:00
Juego 99e0945732 rename forum/FastCGI_problem_on_Arch.mdwn to forum/__91__Solved__93__FastCGI_problem_on_Arch.mdwn 2016-11-16 18:15:14 -04:00