Lauri Ojansivu
|
cbb1cd78de
|
Security Fix 1: There was not enough permission checks. Moved migrations to Admin Panel/Settings/Cron.
Thanks to [Joshua Rogers](https://joshua.hu) of [Aisle Research](https://aisle.com) and xet7.
|
5 days ago |
GitHub Copilot
|
2e564bd076
|
Fix attachment download error with non-ASCII filenames
Fixes #6055.
Signed-off-by: Buo-ren Lin (OSSII) <buoren.lin@ossii.com.tw>
|
2 weeks ago |
Lauri Ojansivu
|
1d16955b6d
|
Security Fix 9: Attachment upload not scoped to card/board relationship.
Thanks to Joshua Rogers of joshua.hu, Twitter MegaManSec !
|
2 weeks ago |
Lauri Ojansivu
|
6dfa3beb2b
|
Security Fix 8: Attachments publication leaks metadata without auth.
Thanks to Joshua Rogers of joshua.hu, Twitter MegaManSec !
|
2 weeks ago |
Lauri Ojansivu
|
181f837d8c
|
Security Fix 5: Read-only roles can still update cards.
Thanks to Joshua Rogers of joshua.hu, Twitter MegaManSec !
|
2 weeks ago |
Lauri Ojansivu
|
a039bb1066
|
Per-User and Board-level data save fixes. Part 3.
Thanks to xet7 !
|
3 weeks ago |
Lauri Ojansivu
|
58e970d685
|
Per-User and Board-level data save fixes. Part 2.
Thanks to xet7 !
|
3 weeks ago |
Lauri Ojansivu
|
414b8dbf41
|
Per-User and Board-level data save fixes. Per-User is collapse, width, height. Per-Board is Swimlanes, Lists, Cards etc.
Thanks to xet7 !
Fixes #5997
|
3 weeks ago |
Lauri Ojansivu
|
1b6e8797ec
|
Feature: Grey Icons. This makes WeKan very slow. Not recommended.
Thanks to xet7 !
|
2 months ago |
Lauri Ojansivu
|
e4638d5fbc
|
Fixed sidebar migrations to be per-board, not global. Clarified translations.
Thanks to xet7 !
|
2 months ago |
Lauri Ojansivu
|
ba49d4d140
|
Remove old translations and code not in use anymore.
Thanks to xet7 !
|
2 months ago |
Lauri Ojansivu
|
7713e613b4
|
Fix 8.16 Lists with no items are deleted every time when board is opened. Moved migrations to right sidebar.
Thanks to xet7 !
Fixes #5994
|
2 months ago |
Lauri Ojansivu
|
1b25d1d572
|
Moved migrations from opening board to right sidebar / Migrations.
Thanks to xet7 !
|
2 months ago |
Lauri Ojansivu
|
ccd9034339
|
Fix SECURITY ISSUE 5: Attachment API uses bearer value as userId and DoS (Low).
Thanks to Siam Thanat Hack (STH) and xet7 !
|
2 months ago |
Lauri Ojansivu
|
0a1a075f31
|
Fix SECURITY ISSUE 4: Members can forge others’ votes (Low). Bonus: Similar fixes to planning poker too done by xet7.
Thanks to Siam Thanat Hack (STH) and xet7 !
|
2 months ago |
Lauri Ojansivu
|
ea310d7508
|
Fix SECURITY ISSUE 3: Unauthenticated (or any) user can update board sort.
Thanks to Siam Thanat Hack (STH) !
|
2 months ago |
Lauri Ojansivu
|
f26d582018
|
Fix SECURITY ISSUE 2: Access to boards of any Orgs/Teams, and avatar permissions.
Thanks to Siam Thanat Hack (STH) !
|
2 months ago |
Lauri Ojansivu
|
e9a727301d
|
Fix SECURITY ISSUE 1: File Attachments enables stored XSS (High).
Thanks to Siam Thanat Hack (STH) !
|
2 months ago |
Lauri Ojansivu
|
30620d0ca4
|
Some migrations and mobile fixes.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
ae11e80bde
|
Fix Regression - unable to view cards by due date v8.11.
Thanks to xet7 !
Fixes #5964
|
3 months ago |
Lauri Ojansivu
|
58df525b49
|
Fix duplicated lists and do not show debug messages when env DEBUG is not true. Part 3.
Thanks to xet7 !
Fixes #5952
|
3 months ago |
Lauri Ojansivu
|
b7ca2310b2
|
Fix duplicated lists.
Thanks to xet7 !
Fixes #5952
|
3 months ago |
Lauri Ojansivu
|
b6e7b258e0
|
Fix duplicated lists.
Thanks to xet7 !
Fixes #5952
|
3 months ago |
Lauri Ojansivu
|
347fa9e5cd
|
Fix Regression - due date taking a while to load all cards v8.06.
Thanks to xet7 !
Fixes #5955
|
3 months ago |
Lauri Ojansivu
|
4987a95d8e
|
Prevent opened board re-migrating and reloading every 5 seconds.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
9536e60bd1
|
Fix opening board migration of Shared Lists to Per-Swimlane lists to use ReactiveCache correctly without errors.
Thanks to xet7 !
Fixes #5960
|
3 months ago |
Lauri Ojansivu
|
80777b4663
|
When opening board, add missing lists.
Thanks to xet7 !
Fixes #5926
|
3 months ago |
Lauri Ojansivu
|
0acbf30b03
|
Fix migrations.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
eb6b42c4c9
|
Fix syntax error at migrations.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
1e6252de7f
|
When opening board, migrate from Shared Lists to Per-Swimlane Lists.
Thanks to xet7 !
Fixes #5952
|
3 months ago |
Lauri Ojansivu
|
951d2e4937
|
Legacy Lists button at one board view to restore missing lists/cards.
Thanks to xet7 !
Fixes #5952
|
3 months ago |
Lauri Ojansivu
|
66b444e2b0
|
Fix unable to see My Due Cards.
Thanks to xet7 !
Fixes #5948
|
3 months ago |
Lauri Ojansivu
|
cb6afe67a7
|
Replaced moment.js with Javascript date.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
79b94824ef
|
Changed wekan-boostrap-datepicker to HTML datepicker.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
2543df9425
|
Show original positions of swimlanes, lists and cards.
Thanks to xet7 !
Fixes #5939
|
3 months ago |
Lauri Ojansivu
|
0a34ee1b64
|
Removed not needed console log message.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
63c314ca18
|
Fixed migrations.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
bd8c565415
|
Fixes to make board showing correctly.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
317138ab72
|
If there is no cron jobs running, run migrations for boards that have not been opened yet.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
da68b01502
|
Added Cron Manager to Admin Panel for long running jobs, like running migrations when opening board, copying or moving boards swimlanes lists cards etc.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
2b5c56484a
|
Run database migrations when opening board. Not when updating WeKan.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
fc32a89292
|
Fixed per-card and per-board settings of showing checkist at minicard.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
ae1f80a52c
|
Added attachments API and admin panel attachment management for file storage backends settings. Fixed drag drop upload attachments from file manager to minicard or opened card.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
d59683eff1
|
Fixed attachments migrations at Admin Panel to not use too much CPU while migrating attachments.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
74ccfea570
|
Add support for MongoDB 3-8, detecting which one is in use.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
3ccdc2e307
|
Made possible to start WeKan immediately without running any database migrations.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
1a7bd65e59
|
Fixed showing translations always, regardsless of is ROOT_URL set correctly or not.
Thanks to xet7 !
|
3 months ago |
Lauri Ojansivu
|
f6591d7820
|
Security Fix usd-2022-0041: CWE-284 Improper Access Control.
Thanks to Christian Pöschl of usd AG and xet7 !
|
3 months ago |
Lauri Ojansivu
|
ee79cab7b2
|
Security Fix JVN#86586539: Stored XSS.
Thanks to Ryoya Koyama of Mitsui Bussan Secure Directions, Inc and xet7.
|
3 months ago |
Lauri Ojansivu
|
e1fa607f87
|
Security Fix JVN#74210258: Stored XSS.
Thanks to Ryoya Koyama of Mitsui Bussan Secure Directions, Inc and xet7 !
|
3 months ago |