ikiwiki/IkiWiki/Plugin
Simon McVittie 9cada49ed6 Tell `git revert` not to follow renames
Otherwise, we have an authorization bypass vulnerability: rcs_preprevert
looks at what changed in the commit we are reverting, not at what would
result from reverting it now. In particular, if some files were renamed
since the commit we are reverting, a revert of changes that were within
the designated subdirectory and allowed by check_canchange() might now
affect files that are outside the designated subdirectory or disallowed
by check_canchange().

Signed-off-by: Simon McVittie <smcv@debian.org>
2016-12-19 18:21:07 +00:00
..
404.pm
aggregate.pm Silence "used only once: possible typo" warnings for variables that are part of modules' APIs 2016-01-19 11:24:18 +00:00
amazon_s3.pm prune: do not prune beyond an optional base directory, and add a test 2012-04-07 17:52:29 +01:00
anonok.pm
attachment.pm Make the attachment plugin work with CGI.pm 4.x (Closes: #786586; workaround for #786587 in libcgi-pm-perl) 2015-06-07 14:51:13 +01:00
autoindex.pm Silence "used only once: possible typo" warnings for variables that are part of modules' APIs 2016-01-19 11:24:18 +00:00
blogspam.pm Update blogspam to the 2.0 API. 2015-01-02 13:55:10 -05:00
brokenlinks.pm brokenlinks: sort the pages that link to the missing page, for better reproducibility 2015-06-09 22:28:31 +01:00
bzr.pm cloak user PII when making commits etc, and let cloaked PII be used in banned_users 2015-05-14 11:58:21 -04:00
calendar.pm Silence "used only once: possible typo" warnings for variables that are part of modules' APIs 2016-01-19 11:24:18 +00:00
camelcase.pm
color.pm
comments.pm Process .md like .mdwn, but disallow web creation. 2016-03-08 14:31:15 -05:00
conditional.pm In all=no conditionals, depend on the influences, not the test pagespec 2014-03-03 11:30:36 +00:00
creole.pm
cutpaste.pm
cvs.pm Update my surname to its new legal spelling. 2016-09-14 14:28:01 -04:00
darcs.pm cloak user PII when making commits etc, and let cloaked PII be used in banned_users 2015-05-14 11:58:21 -04:00
date.pm
ddate.pm
editdiff.pm
editpage.pm Process .md like .mdwn, but disallow web creation. 2016-03-08 14:31:15 -05:00
edittemplate.pm edittemplate: use unambiguous RFC 3339 datestamps 2014-09-01 09:01:07 +01:00
emailauth.pm emailauth: Added emailauth_sender config. 2015-10-02 11:49:47 -04:00
embed.pm
external.pm
favicon.pm
filecheck.pm filecheck: accept MIME types that don't contain ';' 2014-09-10 09:00:20 +01:00
flattr.pm
format.pm
fortune.pm
getsource.pm
git.pm Tell `git revert` not to follow renames 2016-12-19 18:21:07 +00:00
goodstuff.pm
google.pm
goto.pm Make sure we do not pass multiple CGI parameters in function calls 2014-10-16 22:24:47 +01:00
graphviz.pm graphviz: Handle self-links. 2012-04-18 15:36:27 -04:00
haiku.pm haiku: if deterministic build is requested, return a hard-coded haiku 2015-06-09 22:30:43 +01:00
headinganchors.pm apply Changaco's patch to make headinganchors more like mediawiki's 2011-06-21 15:22:36 -04:00
highlight.pm Silence "used only once: possible typo" warnings for variables that are part of modules' APIs 2016-01-19 11:24:18 +00:00
hnb.pm
html.pm
htmlbalance.pm
htmlscrubber.pm htmlscrubber: Allow the URI schemes of major VCS's. 2013-01-05 17:25:47 -04:00
htmltidy.pm htmltidy: Avoid breaking the sidebar when websetup is running. 2011-02-03 12:49:13 -04:00
httpauth.pm httpauth: When it's the only auth method, avoid a pointless and confusing signin form, and just right to the httpauthurl. 2012-04-04 12:58:36 -04:00
img.pm Detect image type from .JPG just like .jpg (etc.). 2016-05-08 18:31:02 -04:00
inline.pm inline: Prevent creating a file named ".mdwn" when the postform is submitted with an empty title. 2016-09-21 13:51:42 -04:00
link.pm link: Fix renaming wikilinks that contain embedded urls. 2012-04-18 15:15:11 -04:00
linkmap.pm display the pagetitle() in linkmaps 2012-03-15 14:38:42 +01:00
listdirectives.pm
localstyle.pm
lockedit.pm
loginselector.pm loginselector: When only openid and emailauth are enabled, but passwordauth is not, avoid showing a "Other" box which opens an empty form. 2016-03-02 16:35:16 -04:00
map.pm map: postprocess to collapse useless </ul><ul> sequences 2013-02-24 13:10:24 +00:00
mdwn.pm Process .md like .mdwn, but disallow web creation. 2016-03-08 14:31:15 -05:00
mercurial.pm cloak user PII when making commits etc, and let cloaked PII be used in banned_users 2015-05-14 11:58:21 -04:00
meta.pm Fix [[!meta name=foo]] by closing the open quote. 2015-08-22 22:34:53 -04:00
mirrorlist.pm Always produce HTML5 doctype and new attributes, but not new elements 2014-10-16 11:04:53 +01:00
moderatedcomments.pm
monotone.pm cloak user PII when making commits etc, and let cloaked PII be used in banned_users 2015-05-14 11:58:21 -04:00
more.pm
norcs.pm
notifyemail.pm notifyemail: Fix bug that caused duplicate emails to be sent when site was rebuilt. 2013-05-18 16:26:48 -04:00
opendiscussion.pm opendiscussion: don't allow editing discussionpage if discussion is disabled 2013-01-02 18:05:33 +00:00
openid.pm Do not directly enable emailauth by default, only indirectly via openid 2015-05-27 08:52:01 +01:00
orphans.pm
osm.pm osm: Escape name parameter. Closes: #731797 2014-01-15 15:53:51 -04:00
otl.pm
pagecount.pm
pagestats.pm pagestats: rename disp to show, and document it 2014-09-14 15:57:09 +01:00
pagetemplate.pm
parentlinks.pm
passwordauth.pm passwordauth: Don't allow registering accounts that look like openids. 2015-05-14 10:57:56 -04:00
pingee.pm
pinger.pm Bug#737121: ikiwiki: [PATCH] Implement configuration option to set the user agent string for outbound HTTP requests 2014-02-01 16:53:33 -04:00
po.pm po: If msgmerge falls over on a problem po file, print a warning message, but don't let this problem crash ikiwiki entirely. 2014-12-30 15:51:50 -04:00
poll.pm Make sure we do not pass multiple CGI parameters in function calls 2014-10-16 22:24:47 +01:00
polygen.pm polygen: if deterministic build is requested, use a well-known random seed 2015-06-09 22:30:44 +01:00
postsparkline.pm
prettydate.pm revert change to prettydate 2012-02-02 22:27:55 -04:00
progress.pm
rawhtml.pm
recentchanges.pm Do not pass ignored sid parameter to checksessionexpiry 2014-10-12 18:03:57 +01:00
recentchangesdiff.pm include manually the toggle js code 2012-07-19 10:32:02 -04:00
relativedate.pm
remove.pm Silence "used only once: possible typo" warnings for variables that are part of modules' APIs 2016-01-19 11:24:18 +00:00
rename.pm Process .md like .mdwn, but disallow web creation. 2016-03-08 14:31:15 -05:00
repolist.pm
rsync.pm Added a "changes" hook. Renamed the "change" hook to "rendered", but 2012-03-28 18:43:07 -04:00
search.pm Fix typo. 2016-02-20 22:00:54 -05:00
shortcut.pm shortcut: Support Wikipedia's form of url-encoding for unicode characters 2012-03-03 11:27:59 -04:00
sidebar.pm
signinedit.pm
skeleton.pm.example remove misc section 2012-03-28 20:36:25 -04:00
smiley.pm
sortnaturally.pm Add path and path_natural sort orders 2011-12-06 14:26:27 -04:00
sparkline.pm
svn.pm cloak user PII when making commits etc, and let cloaked PII be used in banned_users 2015-05-14 11:58:21 -04:00
table.pm
tag.pm Silence "used only once: possible typo" warnings for variables that are part of modules' APIs 2016-01-19 11:24:18 +00:00
template.pm protect $@ whenever a block using $@ is non-trivial 2014-02-21 17:06:36 +00:00
templatebody.pm Add templatebody plugin and directive, and enable it by default 2014-03-05 10:42:19 +00:00
testpagespec.pm
teximg.pm Squelch regex deprecation warnings from Perl 5.22. 2015-06-14 21:35:51 -04:00
textile.pm
theme.pm theme: Now <TMPL_IF THEME_$NAME> can be used in all templates when a theme is enabled. 2013-05-16 22:20:56 -04:00
tla.pm cloak user PII when making commits etc, and let cloaked PII be used in banned_users 2015-05-14 11:58:21 -04:00
toc.pm
toggle.pm
trail.pm trail: don't generate a costly dependency when forcing sort order 2014-07-11 22:08:08 +01:00
transient.pm prune: do not prune beyond an optional base directory, and add a test 2012-04-07 17:52:29 +01:00
txt.pm
typography.pm
underlay.pm Add missing plugin section, and deal with missing sections with a warning. 2013-03-04 13:03:34 -04:00
userlist.pm encode html 2011-06-09 10:46:09 -04:00
version.pm
websetup.pm Standardize on --long-option instead of -long-option 2015-03-01 16:15:01 +00:00
wikitext.pm
wmd.pm