Project

General

Profile

Activity

From 2014-04-29 to 2014-05-01

2014-05-01

16:15 Patch #16685: Introduce the request_store gem to hold User.current and prevent data leakage in error messages
Thanks, it was just my personal opinion; it may be safer than adding a new gem which might itself contain some securi... Etienne Massip
15:40 Patch #16685: Introduce the request_store gem to hold User.current and prevent data leakage in error messages
OK. I have reverted 2.4-stable and 2.5-stable revisions. Toshi MARUYAMA
15:27 Patch #16685: Introduce the request_store gem to hold User.current and prevent data leakage in error messages
Sure but this is not a security fix, only a potential fix (which from my very personal pov may be a bit of overkill s... Etienne Massip
15:22 Patch #16685: Introduce the request_store gem to hold User.current and prevent data leakage in error messages
We usually upgrade Rails version for security fix in minor release.
And r13110 does not change application behaviors.
Toshi MARUYAMA
15:13 Patch #16685: Introduce the request_store gem to hold User.current and prevent data leakage in error messages
I meant request store, not mocha. This should be handled by RoR, not by a specific dependency. Etienne Massip
15:07 Patch #16685: Introduce the request_store gem to hold User.current and prevent data leakage in error messages
Etienne Massip wrote:
> Is it really useful to add a new runtime dependency?
mocha is in "test" group.
> Wouldn'...
Toshi MARUYAMA
14:52 Patch #16685: Introduce the request_store gem to hold User.current and prevent data leakage in error messages
Is it really useful to add a new runtime dependency? Wouldn't a complete test be enough instead? And if jot, could th... Etienne Massip
13:39 Patch #16685: Introduce the request_store gem to hold User.current and prevent data leakage in error messages
On Ubuntu 12.04.4 LTS,
ruby 1.9.3p545 (2014-02-24 revision 45159) [x86_64-linux]...
Toshi MARUYAMA
10:35 Patch #16685: Introduce the request_store gem to hold User.current and prevent data leakage in error messages
Test fails on drone.io.
https://drone.io/github.com/marutosi/redmine/211
https://drone.io/github.com/marutosi/red...
Toshi MARUYAMA
15:39 Revision 13121 (svn): 2.4-stable: revert r13114 (#16685)
Toshi MARUYAMA
15:37 Revision 13120 (svn): 2.5-stable: revert r13111 and r13113 (#16685)
Toshi MARUYAMA
15:08 Defect #16778 (Closed): Issue in description field
Please use forums for this kind of questions. Field name is ??description?? in ??issues?? Table; type is varchar(max)... Etienne Massip
14:28 Revision 13119 (svn): Merged r13117 from trunk to 2.4-stable (#16685)
Gemfile: upgrade mocha version. Toshi MARUYAMA
14:27 Revision 13118 (svn): Merged r13117 from trunk to 2.5-stable (#16685)
Gemfile: upgrade mocha version. Toshi MARUYAMA
13:44 Revision 13117 (svn): Gemfile: upgrade mocha version (#16685)
Toshi MARUYAMA
11:14 Feature #2870: Recursive download from the repository
+1
I would really like to see this feature or a plugin which emulates this feature for 2.x
Jack Michaels
11:00 Feature #5816: New issue initial status should be settable in workflow
+1 Enmos Proje
10:31 Feature #16729: properties of issue dynamically available in wiki
Jean-Baptiste Barth (http://www.redmine.org/users/1188) has created a plugin which implements this feature. It would ... Johan Lichtjager
03:59 Revision 13116 (svn): use rvm 2.0 and 2.1 instead of 2.0.0 and 2.1.0 at .travis.yml
See:
https://github.com/travis-ci/travis-ci/issues/2220
Toshi MARUYAMA
03:59 Revision 13115 (svn): add patch for regression of Hash#reject in Ruby 2.1.1 (#16194)
Toshi MARUYAMA
03:55 Revision 13114 (svn): Merged r13110 and r13112 from trunk to 2.4-stable (#16685)
introduce request_store to ensure that the current user doesn't leak across request boundaries.
Contributed by Holge...
Toshi MARUYAMA
03:52 Revision 13113 (svn): Merged r13112 from trunk to 2.5-stable (#16685)
Gemfile: use double quote for request_store Toshi MARUYAMA
03:50 Revision 13112 (svn): Gemfile: use double quote for request_store (#16685)
Toshi MARUYAMA
03:45 Revision 13111 (svn): Merged r13110 from trunk to 2.5-stable (#16685)
introduce request_store to ensure that the current user doesn't leak across request boundaries.
Contributed by Holge...
Toshi MARUYAMA
02:44 Revision 13110 (svn): introduce request_store to ensure that the current user doesn't leak across request boundaries (#16685)
Contributed by Holger Just. Toshi MARUYAMA

2014-04-30

15:51 Defect #16784 (Closed): Notifications not sent when receiving emails with rake task and async deliveries
Hi all,
I just installed redmine 2.5.0 and my all team is glad to use it.
I tried to allow issue creation by emai...
JEREMY LEGRAND
11:54 Defect #16489 (Needs feedback): Autologin Cookie doesn't differentiate between different Redmine systems within the same browser
Ebrahim Mohammadi wrote:
> Aren't you using the same secret token for both of your Redmine instances?
And you can...
Toshi MARUYAMA
11:40 Defect #16780 (Closed): Unable to import tasks: undefined local variable or method `issue' for #
Please contact plugin author. Toshi MARUYAMA
10:34 Defect #16780 (Closed): Unable to import tasks: undefined local variable or method `issue' for #
I'm new to Redmine.
when i'm using red mine loader plugin to import project XML file .
I got these error .
Unable...
Muditha Jayawardana
11:31 Defect #16661: Different users sharing same role have rights in projects in which user is not a member
Martin Denizet wrote:
> As discussed is "this forum thread":http://www.redmine.org/boards/2/topics/42021, the curren...
Lajish Lakshmanan
10:38 Patch #16781: Crash in markdown formatter causes ruby process to end
the patch... Jens Krämer
10:37 Patch #16781 (Closed): Crash in markdown formatter causes ruby process to end
We observed this behavior at "Planio":https://plan.io when invalid markdown syntax was input by the user, which cause... Jens Krämer

2014-04-29

17:49 Feature #16549: Set multiple values in emails for list custom fields
There still were 2 small issues with the last proposed patch. This one should be good. (unfortunately I can't delete ... Felix Schäfer
17:39 Feature #16779 (New): Make all kind of URL a html link
It would be very usefull if all sort of URI would parsed as html link.
Like:
ftp://example.com
ssh://example.com
...
S M
15:35 Defect #16778 (Closed): Issue in description field
The Issue description field have reached a limit of available size/characters and adding further ones are discarded (... Sunith kumar
13:44 Feature #16712: Create an up-to-date documentation for Redmine on Heroku
Thanks, could you please create an howto in wiki?
Etienne Massip
12:44 Feature #11724: Prevent users from seeing other users based on their project membership
Thanks Rafał for this new fix, it works like a charm on 2.5.1 ! Anonymous
09:16 Feature #16483 (Closed): stable redmine subversion tag
We have.
source:tags
Toshi MARUYAMA
04:29 Feature #16769 (Closed): auto-close resolved issues
Toshi MARUYAMA
04:27 Feature #16769: auto-close resolved issues
Duplicate with #11313. Toshi MARUYAMA
 

Also available in: Atom