ikiwiki/IkiWiki/Plugin
Simon McVittie 170cd41489 img: check magic number before giving common formats to ImageMagick
This mitigates CVE-2016-3714 and similar vulnerabilities by
avoiding passing obviously-wrong input to ImageMagick decoders.
2016-05-05 23:43:50 +01:00
..
404.pm
aggregate.pm Silence "used only once: possible typo" warnings for variables that are part of modules' APIs 2016-01-19 11:24:18 +00:00
amazon_s3.pm prune: do not prune beyond an optional base directory, and add a test 2012-04-07 17:52:29 +01:00
anonok.pm
attachment.pm Make the attachment plugin work with CGI.pm 4.x (Closes: #786586; workaround for #786587 in libcgi-pm-perl) 2015-06-07 14:51:13 +01:00
autoindex.pm Silence "used only once: possible typo" warnings for variables that are part of modules' APIs 2016-01-19 11:24:18 +00:00
blogspam.pm Update blogspam to the 2.0 API. 2015-01-02 13:55:10 -05:00
brokenlinks.pm brokenlinks: sort the pages that link to the missing page, for better reproducibility 2015-06-09 22:28:31 +01:00
bzr.pm cloak user PII when making commits etc, and let cloaked PII be used in banned_users 2015-05-14 11:58:21 -04:00
calendar.pm Silence "used only once: possible typo" warnings for variables that are part of modules' APIs 2016-01-19 11:24:18 +00:00
camelcase.pm
color.pm
comments.pm Process .md like .mdwn, but disallow web creation. 2016-03-08 14:31:15 -05:00
conditional.pm In all=no conditionals, depend on the influences, not the test pagespec 2014-03-03 11:30:36 +00:00
creole.pm
cutpaste.pm
cvs.pm cloak user PII when making commits etc, and let cloaked PII be used in banned_users 2015-05-14 11:58:21 -04:00
darcs.pm cloak user PII when making commits etc, and let cloaked PII be used in banned_users 2015-05-14 11:58:21 -04:00
date.pm
ddate.pm
editdiff.pm
editpage.pm Process .md like .mdwn, but disallow web creation. 2016-03-08 14:31:15 -05:00
edittemplate.pm edittemplate: use unambiguous RFC 3339 datestamps 2014-09-01 09:01:07 +01:00
emailauth.pm emailauth: Added emailauth_sender config. 2015-10-02 11:49:47 -04:00
embed.pm
external.pm
favicon.pm
filecheck.pm filecheck: accept MIME types that don't contain ';' 2014-09-10 09:00:20 +01:00
flattr.pm
format.pm
fortune.pm
getsource.pm
git.pm Correctly handle filenames starting with a dash in add/rm/mv. 2016-03-17 11:01:27 -04:00
goodstuff.pm
google.pm
goto.pm Make sure we do not pass multiple CGI parameters in function calls 2014-10-16 22:24:47 +01:00
graphviz.pm graphviz: Handle self-links. 2012-04-18 15:36:27 -04:00
haiku.pm haiku: if deterministic build is requested, return a hard-coded haiku 2015-06-09 22:30:43 +01:00
headinganchors.pm
highlight.pm Silence "used only once: possible typo" warnings for variables that are part of modules' APIs 2016-01-19 11:24:18 +00:00
hnb.pm
html.pm
htmlbalance.pm
htmlscrubber.pm htmlscrubber: Allow the URI schemes of major VCS's. 2013-01-05 17:25:47 -04:00
htmltidy.pm
httpauth.pm httpauth: When it's the only auth method, avoid a pointless and confusing signin form, and just right to the httpauthurl. 2012-04-04 12:58:36 -04:00
img.pm img: check magic number before giving common formats to ImageMagick 2016-05-05 23:43:50 +01:00
inline.pm Compose relative URLs in RSS feeds correctly 2016-01-21 08:40:14 +00:00
link.pm link: Fix renaming wikilinks that contain embedded urls. 2012-04-18 15:15:11 -04:00
linkmap.pm display the pagetitle() in linkmaps 2012-03-15 14:38:42 +01:00
listdirectives.pm
localstyle.pm
lockedit.pm
loginselector.pm loginselector: When only openid and emailauth are enabled, but passwordauth is not, avoid showing a "Other" box which opens an empty form. 2016-03-02 16:35:16 -04:00
map.pm map: postprocess to collapse useless </ul><ul> sequences 2013-02-24 13:10:24 +00:00
mdwn.pm Process .md like .mdwn, but disallow web creation. 2016-03-08 14:31:15 -05:00
mercurial.pm cloak user PII when making commits etc, and let cloaked PII be used in banned_users 2015-05-14 11:58:21 -04:00
meta.pm Fix [[!meta name=foo]] by closing the open quote. 2015-08-22 22:34:53 -04:00
mirrorlist.pm Always produce HTML5 doctype and new attributes, but not new elements 2014-10-16 11:04:53 +01:00
moderatedcomments.pm
monotone.pm cloak user PII when making commits etc, and let cloaked PII be used in banned_users 2015-05-14 11:58:21 -04:00
more.pm
norcs.pm
notifyemail.pm notifyemail: Fix bug that caused duplicate emails to be sent when site was rebuilt. 2013-05-18 16:26:48 -04:00
opendiscussion.pm opendiscussion: don't allow editing discussionpage if discussion is disabled 2013-01-02 18:05:33 +00:00
openid.pm Do not directly enable emailauth by default, only indirectly via openid 2015-05-27 08:52:01 +01:00
orphans.pm
osm.pm osm: Escape name parameter. Closes: #731797 2014-01-15 15:53:51 -04:00
otl.pm
pagecount.pm
pagestats.pm pagestats: rename disp to show, and document it 2014-09-14 15:57:09 +01:00
pagetemplate.pm
parentlinks.pm
passwordauth.pm passwordauth: Don't allow registering accounts that look like openids. 2015-05-14 10:57:56 -04:00
pingee.pm
pinger.pm Bug#737121: ikiwiki: [PATCH] Implement configuration option to set the user agent string for outbound HTTP requests 2014-02-01 16:53:33 -04:00
po.pm po: If msgmerge falls over on a problem po file, print a warning message, but don't let this problem crash ikiwiki entirely. 2014-12-30 15:51:50 -04:00
poll.pm Make sure we do not pass multiple CGI parameters in function calls 2014-10-16 22:24:47 +01:00
polygen.pm polygen: if deterministic build is requested, use a well-known random seed 2015-06-09 22:30:44 +01:00
postsparkline.pm
prettydate.pm revert change to prettydate 2012-02-02 22:27:55 -04:00
progress.pm
rawhtml.pm
recentchanges.pm Do not pass ignored sid parameter to checksessionexpiry 2014-10-12 18:03:57 +01:00
recentchangesdiff.pm include manually the toggle js code 2012-07-19 10:32:02 -04:00
relativedate.pm
remove.pm Silence "used only once: possible typo" warnings for variables that are part of modules' APIs 2016-01-19 11:24:18 +00:00
rename.pm Process .md like .mdwn, but disallow web creation. 2016-03-08 14:31:15 -05:00
repolist.pm
rsync.pm Added a "changes" hook. Renamed the "change" hook to "rendered", but 2012-03-28 18:43:07 -04:00
search.pm Fix typo. 2016-02-20 22:00:54 -05:00
shortcut.pm shortcut: Support Wikipedia's form of url-encoding for unicode characters 2012-03-03 11:27:59 -04:00
sidebar.pm
signinedit.pm
skeleton.pm.example remove misc section 2012-03-28 20:36:25 -04:00
smiley.pm
sortnaturally.pm Add path and path_natural sort orders 2011-12-06 14:26:27 -04:00
sparkline.pm
svn.pm cloak user PII when making commits etc, and let cloaked PII be used in banned_users 2015-05-14 11:58:21 -04:00
table.pm
tag.pm Silence "used only once: possible typo" warnings for variables that are part of modules' APIs 2016-01-19 11:24:18 +00:00
template.pm protect $@ whenever a block using $@ is non-trivial 2014-02-21 17:06:36 +00:00
templatebody.pm Add templatebody plugin and directive, and enable it by default 2014-03-05 10:42:19 +00:00
testpagespec.pm
teximg.pm Squelch regex deprecation warnings from Perl 5.22. 2015-06-14 21:35:51 -04:00
textile.pm
theme.pm theme: Now <TMPL_IF THEME_$NAME> can be used in all templates when a theme is enabled. 2013-05-16 22:20:56 -04:00
tla.pm cloak user PII when making commits etc, and let cloaked PII be used in banned_users 2015-05-14 11:58:21 -04:00
toc.pm
toggle.pm
trail.pm trail: don't generate a costly dependency when forcing sort order 2014-07-11 22:08:08 +01:00
transient.pm prune: do not prune beyond an optional base directory, and add a test 2012-04-07 17:52:29 +01:00
txt.pm
typography.pm
underlay.pm Add missing plugin section, and deal with missing sections with a warning. 2013-03-04 13:03:34 -04:00
userlist.pm
version.pm
websetup.pm Standardize on --long-option instead of -long-option 2015-03-01 16:15:01 +00:00
wikitext.pm
wmd.pm