Commit Graph

2225 Commits

Author SHA1 Message Date
Frédéric France
86a7a7c8bb use isModEnabled 2022-08-23 20:05:09 +02:00
Frédéric France
582f6b196e use isModEnabled 2022-08-23 20:02:37 +02:00
Frédéric France
4bef0f5745 use isModEnabled 2022-08-23 20:01:34 +02:00
Laurent Destailleur
79974b456f NEW Add the referrer-policy to "same-origin" by default. 2022-08-16 15:49:29 +02:00
Laurent Destailleur
94da628cf4 Clean code for http header + better support for Content-Security-Policy 2022-08-16 15:19:45 +02:00
Laurent Destailleur
43fcb11500 Fix scrutninizer 2022-08-11 01:13:25 +02:00
Laurent Destailleur
c1bea1b1e4 Add the anti-csrf-token into header 2022-08-10 22:24:45 +02:00
lmarcouiller
05ca9da7e1 Fix : php 8.1 warnings 2022-07-29 15:46:13 +02:00
Laurent Destailleur
b6a6dd91d8 # WARNING: head commit changed in the meantime
Merge branch 'develop' of git@github.com:Dolibarr/dolibarr.git into
develop
2022-07-28 18:52:44 +02:00
Laurent Destailleur
3da20beeb5 Fix warning 2022-07-28 18:06:37 +02:00
Laurent Destailleur
5903a9f87f Merge branch 'develop' of git@github.com:Dolibarr/dolibarr.git into
develop
2022-07-26 12:24:24 +02:00
Laurent Destailleur
d307e5b022 Debug v16 2022-07-25 13:12:08 +02:00
Laurent Destailleur
ca323f99ba Merge branch '16.0' of git@github.com:Dolibarr/dolibarr.git into develop 2022-07-22 19:37:55 +02:00
Laurent Destailleur
16c087e04c Clean htmlentities 2022-07-22 19:25:15 +02:00
Laurent Destailleur
fb96145b49 Merge branch '16.0' of git@github.com:Dolibarr/dolibarr.git into develop 2022-07-12 02:05:20 +02:00
Laurent Destailleur
85a0ae1236 Fix token for ping 2022-07-11 19:59:15 +02:00
Laurent Destailleur
15e0b7cbb8 Merge branch '16.0' of git@github.com:Dolibarr/dolibarr.git into develop 2022-07-07 17:17:27 +02:00
Laurent Destailleur
ba82c86bd5 Fix clear of search criteria on clear all button 2022-07-07 17:15:50 +02:00
Laurent Destailleur
0e52c4d0d5
Merge pull request #21401 from cfoellmann/PR/hook-filter-helpurl
NEW hook "changeHelpURL" to modify target of the help button
2022-07-06 14:59:42 +02:00
Laurent Destailleur
6e153b9b75 Debug import FIX #yogosha11618 2022-06-30 22:55:58 +02:00
Laurent Destailleur
046fa77a5a Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/comm/propal/card.php
2022-06-29 16:46:27 +02:00
Laurent Destailleur
cbaa8b4304 FIX False alert of WAF when there is "set" into some URL action=update. 2022-06-29 16:40:19 +02:00
Christian Foellmann
2981b268ae add hook "changeHelpURL" to modify target of the help button 2022-06-28 13:28:31 +02:00
Laurent Destailleur
2033b75c33 Add option MAIN_NO_UPGRADE_REDIRECT_ON_LEVEL_3_CHANGE 2022-06-16 09:17:00 +02:00
Frédéric France
3fdbce7a31 use isModEnabled function 2022-06-11 09:46:28 +02:00
Frédéric FRANCE
38b18a68d7
Merge branch 'develop' into useismodenabled 2022-06-10 10:07:41 +02:00
Frédéric France
e42cf5f3e8 use isModEnabled function 2022-06-09 21:51:48 +02:00
Laurent Destailleur
3bb8e9cdda Debug v16 2022-06-09 12:07:35 +02:00
Laurent Destailleur
87230795cc Fix warning 2022-06-03 14:23:37 +02:00
Laurent Destailleur
1a6903f677 Debug v16 2022-05-23 11:56:39 +02:00
Laurent Destailleur
775a8c5334 Look and feel v16 2022-05-12 20:18:58 +02:00
Laurent Destailleur
f52a7a26f6 Debug v16 - Fix for postgresql - Fix for sql loading per module - php8 2022-05-08 15:18:34 +02:00
Laurent Destailleur
3256ac2f2a css 2022-05-07 19:47:51 +02:00
Laurent Destailleur
7c058c9ae6 NEW Add param to keep the robot=index meta tag on public pages 2022-05-01 11:48:11 +02:00
Laurent Destailleur
477d681c49 Fix warnings 2022-04-30 17:47:45 +02:00
Laurent Destailleur
a3812e0f73
Merge pull request #20665 from aspangaro/16a19
Fix proper links for the Quick add feature
2022-04-29 19:35:06 +02:00
Laurent Destailleur
40d0c3b996 Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/compta/tva/card.php
	htdocs/langs/en_US/admin.lang
2022-04-28 19:23:13 +02:00
Laurent Destailleur
ad7fcd264b FIX Tabulation must be allowed for HTML content 2022-04-19 23:39:09 +02:00
Alexandre SPANGARO
9a59362da2 Fix proper links for the Quick add feature 2022-04-18 07:18:02 +02:00
Laurent Destailleur
140f983ca7 Fix look and feel v16 for the Quick add feature. 2022-04-15 18:04:58 +02:00
Laurent Destailleur
252888fc11
Merge pull request #20483 from hregis/fix_avoid_cookie_warning_missing_samesite
FIX avoid warning for missing cookie samesite params (and more secure)
2022-04-14 22:48:44 +02:00
Laurent Destailleur
75d3b3527c
Update main.inc.php 2022-04-14 22:45:56 +02:00
Laurent Destailleur
06f112d3ce
Update main.inc.php 2022-04-14 22:43:43 +02:00
Laurent Destailleur
40720fad25 Fix php8 compatibility 2022-04-11 02:01:32 +02:00
Laurent Destailleur
994b500a68 PHP 8.0 compatibility 2022-04-08 00:14:29 +02:00
Laurent Destailleur
b8d19c9311 Debug v16 2022-04-07 15:59:50 +02:00
Laurent Destailleur
637f73a833
Merge pull request #17966 from cfoellmann/quickadd
quickadd menu like bookmarks
2022-04-07 15:41:57 +02:00
Laurent Destailleur
45fca25408 NEW Upgrade chartjs library to 3.7.1 2022-04-03 11:52:25 +02:00
Laurent Destailleur
7e34ce7245 Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/main.inc.php
2022-04-02 15:39:15 +02:00
Laurent Destailleur
d4accb97c5 FIX #yogosha9754 2022-04-02 15:26:40 +02:00
Laurent Destailleur
9c00115abe FIX #yogosha9754 2022-04-02 14:32:53 +02:00
Laurent Destailleur
889c35e8df NEW Default value for MAIN_SECURITY_CSRF_WITH_TOKEN is now 2 2022-03-30 12:02:20 +02:00
Laurent Destailleur
63d9f69732 Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/compta/facture/card.php
2022-03-29 15:55:47 +02:00
Regis Houssin
29a4e7c725 FIX check if https or not 2022-03-29 12:03:18 +02:00
Regis Houssin
b7d6436e33 FIX add doc 2022-03-29 11:10:41 +02:00
Regis Houssin
ca7ecfbb57 FIX avoid warning for missing cookie samesite params (and more secure) 2022-03-29 11:06:18 +02:00
Laurent Destailleur
301805f383 More log 2022-03-29 10:28:44 +02:00
Laurent Destailleur
50847efdf8 Add the country into the popup with info on company. 2022-03-26 11:44:36 +01:00
Laurent Destailleur
396b532400 Can cumulate error message on different authentication modes 2022-03-26 09:40:22 +01:00
Laurent Destailleur
ac22b1ce81 # WARNING: head commit changed in the meantime
Merge branch 'develop' of git@github.com:Dolibarr/dolibarr.git into
develop
2022-03-16 21:31:08 +01:00
Laurent Destailleur
abe542f49e Fix removed the cache.manifest file (useless and pb with some browsers) 2022-03-16 19:45:39 +01:00
Laurent Destailleur
c2fb5d577c Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/install/mysql/migration/14.0.0-15.0.0.sql
	htdocs/langs/en_US/banks.lang
	htdocs/projet/list.php
2022-02-28 20:12:28 +01:00
Laurent Destailleur
8866d447c7 Fix error message 2022-02-28 16:01:07 +01:00
Laurent Destailleur
f0c5fe31f8 FIX #yogosha9083 2022-02-24 17:49:52 +01:00
Laurent Destailleur
77e2969411 Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop 2022-02-22 22:27:32 +01:00
Laurent Destailleur
e0c24e5d29 Enhance WAF 2022-02-22 22:19:32 +01:00
Laurent Destailleur
00e6d2786d Do not use dol_hash anymore for the name of cookies. 2022-02-21 12:21:43 +01:00
Laurent Destailleur
9e6f782907 Clean code 2022-02-21 11:26:10 +01:00
Laurent Destailleur
678c3bdb76 Fix switch to login page 2022-02-20 18:07:10 +01:00
Laurent Destailleur
3b6f7bff66 Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop 2022-02-18 16:32:51 +01:00
Laurent Destailleur
cd9c1acafe Fix missing token 2022-02-18 16:09:23 +01:00
Laurent Destailleur
4a343247b0 Return a 404 http code when CSRF protection fails 2022-02-16 14:34:32 +01:00
Laurent Destailleur
05bd37a921 Fix menu "New" when using paranoiac MAIN_SECURITY_CSRF_WITH_TOKEN = 3 2022-02-14 12:29:00 +01:00
Laurent Destailleur
56f5b471bc Fix menu "New" when using paranoiac MAIN_SECURITY_CSRF_WITH_TOKEN = 3 2022-02-11 15:30:45 +01:00
Laurent Destailleur
47800aebfa Fix phpunit and mode save after opening a ref 2022-02-09 15:21:25 +01:00
Laurent Destailleur
9b1f04209d NEW Change in theme colors does not need to use the refresh button 2022-02-06 22:11:44 +01:00
Laurent Destailleur
91be7b279e Merge branch '15.0' of git@github.com:Dolibarr/dolibarr.git into develop 2022-01-30 17:28:23 +01:00
Laurent Destailleur
723b9d101a FIX #yogosha8604 2022-01-30 17:24:10 +01:00
Laurent Destailleur
728df13238 Optimize files loaded on login and passwordforgotten page 2022-01-29 16:22:55 +01:00
Laurent Destailleur
289ce87f6d Fix fatal error 2022-01-28 19:06:41 +01:00
Sylvain Legrand
b65f849c5d New - Improve the reading of profIDs 2022-01-28 11:22:12 +01:00
stickler-ci
0bb697c3ae Fixing style errors. 2022-01-20 06:47:57 +00:00
alsoft10
e212395f00 PR REQUEST #19679 2022-01-20 12:12:59 +05:30
Laurent Destailleur
60b90056c4 Fix #yogosha8450 2022-01-19 15:20:10 +01:00
Laurent Destailleur
499dd859ee
Merge pull request #19853 from atm-maxime/new_hook_main_area
New hook printMainArea
2022-01-19 01:57:39 +01:00
Laurent Destailleur
200f796232 Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into 15.0 2022-01-18 16:08:54 +01:00
Laurent Destailleur
01aa2deae6 Fix bad include 2022-01-18 15:27:43 +01:00
Laurent Destailleur
22ab3c03a1 Fix another way to write the preg_replace_callback 2022-01-17 09:12:09 +01:00
Laurent Destailleur
cfc39ebf0a Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into 15.0 2022-01-17 08:59:34 +01:00
Maxime Kohlhaas
8eeb0caa78 New hook printMainArea 2022-01-16 21:10:02 +01:00
Laurent Destailleur
8e4c7efed5 Fix do not include file if url not correctly detected 2022-01-15 20:53:16 +01:00
Laurent Destailleur
5881e36ba6 Code comment 2022-01-14 10:15:46 +01:00
Laurent Destailleur
7e11677117 Fix: Add token to the url logout 2021-12-31 14:33:12 +01:00
Laurent Destailleur
dd94745e33 Fix css for rtl languages 2021-12-22 20:57:14 +01:00
stickler-ci
0f177274e0 Fixing style errors. 2021-12-20 10:20:14 +01:00
Christian Foellmann
9329e54fc3 fix hook 'menuDropdownQuickaddItems' 2021-12-20 10:20:14 +01:00
Christian Foellmann
03d4317302 add hook 'menuDropdownQuickaddItems' to manipulate dropdown menu 2021-12-20 10:20:14 +01:00
Laurent Destailleur
f6c1ad6094 css 2021-12-12 21:20:12 +01:00
Laurent Destailleur
9fbe0dee9b Fix trans 2021-12-10 12:36:51 +01:00
Laurent Destailleur
8de8dacaa3 Fix php warning 2021-12-08 15:07:55 +01:00
Laurent Destailleur
20f4b5389b Fix the experimental feature to manage session in database 2021-12-07 17:39:46 +01:00
Laurent Destailleur
441af6b6fb Fix add rel="noopener noreferrer" 2021-11-22 02:35:55 +01:00
Laurent Destailleur
715a65eab2 Clean code for md theme 2021-11-12 13:33:59 +01:00
Laurent Destailleur
897b00faf0 Clean code 2021-11-05 14:23:19 +01:00
Frédéric FRANCE
1683f46d9b
backport fix 2021-10-25 21:21:48 +02:00
Laurent Destailleur
f5562177e7 Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop 2021-10-25 13:06:33 +02:00
Laurent Destailleur
664fd13428 Clean CSS 2021-10-25 13:04:52 +02:00
Laurent Destailleur
940c69b46d Clean code 2021-10-25 12:09:17 +02:00
Laurent Destailleur
4ab759b067 Fix check/uncheck of ping 2021-10-24 14:23:35 +02:00
Laurent Destailleur
ad3297b0ef Use of MAIN_FIRST_PING_OK_ID = 'disabled' works when forcing reinstall. 2021-10-24 14:01:38 +02:00
Scrutinizer Auto-Fixer
f7a41f1848 Scrutinizer Auto-Fixes
This commit consists of patches automatically generated for this project on https://scrutinizer-ci.com
2021-10-23 20:22:10 +00:00
John BOTELLA
4831128836 Fix dom declaration 2021-10-23 15:01:28 +02:00
Laurent Destailleur
7bb840fb04 Add a line to know instance uses not stable level of features 2021-10-16 16:58:55 +02:00
Laurent Destailleur
1b504b3e2c Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop 2021-10-08 12:15:18 +02:00
Laurent Destailleur
2f61c4e93b Add onbeforecopy and onbeforecut into the WAF 2021-10-08 12:14:42 +02:00
Christian Foellmann
caf26d95d6 add hook beforeBodyClose 2021-10-05 10:41:11 +02:00
Laurent Destailleur
3102d0725c Fix test on action param 2021-10-02 13:04:57 +02:00
Laurent Destailleur
d064ab2b17 Add more action to GET action to check 2021-10-02 12:58:15 +02:00
Laurent Destailleur
c664b78800 MAIN_SECURITY_CSRF_WITH_TOKEN now has 3 levels (1, 2, 3) 2021-10-01 12:37:32 +02:00
Laurent Destailleur
c244d7375c MAIN_SECURITY_CSRF_WITH_TOKEN now has 3 levels (1, 2, 3) 2021-10-01 12:30:24 +02:00
Laurent Destailleur
d4cc60640b Clean code 2021-09-27 15:41:58 +02:00
Laurent Destailleur
621296d84f Fix implement CSRF protection by session (with option per call) 2021-09-26 20:56:40 +02:00
Laurent Destailleur
1ade905daa
Merge pull request #18772 from javieralapps4up/14.0
Update main.inc.php
2021-09-21 19:10:39 +02:00
javieralapps4up
278ae34b5f
Update main.inc.php 2021-09-21 00:53:10 +02:00
stickler-ci
a8a8fd7cff Fixing style errors. 2021-09-20 22:50:48 +00:00
javieralapps4up
08504c4e16
Update main.inc.php 2021-09-21 00:45:06 +02:00
Laurent Destailleur
deb1965cd5 Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/comm/action/card.php
	htdocs/compta/paiement/list.php
	htdocs/core/class/commonobject.class.php
	htdocs/mrp/mo_list.php
	htdocs/projet/tasks/task.php
	htdocs/public/payment/newpayment.php
2021-09-20 17:15:12 +02:00
javieralapps4up
0453a27bda
Update main.inc.php 2021-09-20 12:24:44 +02:00
stickler-ci
1ea2182bf7 Fixing style errors. 2021-09-19 20:32:07 +00:00
javieralapps4up
77e493755f
Fix: #18760 bad rights admin if advanced perms
Insufficient rights to view a group's card for admin users if advanced permissions are used
2021-09-19 22:26:49 +02:00
Laurent Destailleur
1d597e8a72 Fix add unset* action as sensible GET actions 2021-09-19 18:03:38 +02:00
Laurent Destailleur
bf9f007c98 Fix MAIN_SECURITY_CSRF_WITH_TOKEN = 2 2021-09-19 14:57:14 +02:00
Laurent Destailleur
4d563651fa Add a mode MAIN_SECURITY_CSRF_WITH_TOKEN = 2 2021-09-19 14:49:11 +02:00
Laurent Destailleur
5c8fb38426 Fix add del* action into list of sensitive actions 2021-09-19 14:41:46 +02:00
Laurent Destailleur
e92a24d5f1 Fix test 2021-09-19 13:49:21 +02:00
Laurent Destailleur
4253b564ba Fix add reopen as sensitive actions 2021-09-18 22:55:23 +02:00
Laurent Destailleur
89e8f24e15 Fix CSRF protection for all massactions 2021-09-18 22:38:25 +02:00
Laurent Destailleur
c3e88579ab Fix add remove_* action as sensitive action 2021-09-18 22:24:51 +02:00
Laurent Destailleur
d760686239 Fix case of newtoken() 2021-09-18 22:24:00 +02:00
Laurent Destailleur
0749d01c5a Fix add action delete* as sensitive action 2021-09-18 22:04:41 +02:00
Laurent Destailleur
8bdc53f469 Fix Add action classify as sensitive actions 2021-09-18 20:49:24 +02:00
Laurent Destailleur
6390f2de6f Fix add all confirm_* action as sensitive actions 2021-09-18 19:47:51 +02:00
Laurent Destailleur
7dfedd242a Fix add confirm_deleteline as sensitive action 2021-09-18 19:43:38 +02:00
Laurent Destailleur
62b721a904 Add deletecontact as sentitive action
Replace dol_buildpath with DOL_URL_ROOT
2021-09-18 19:34:46 +02:00
Laurent Destailleur
858a5ab188 Add confirm_validate and confirm_close as sensitive actions 2021-09-18 18:36:45 +02:00
Laurent Destailleur
fa28621709 Merge branch '14.0' of git@github.com:Dolibarr/dolibarr.git into develop
Conflicts:
	htdocs/reception/list.php
2021-09-09 16:11:29 +02:00
Laurent Destailleur
5d5b7c3af4 Merge branch '13.0' of git@github.com:Dolibarr/dolibarr.git into 14.0
Conflicts:
	htdocs/comm/action/peruser.php
	htdocs/main.inc.php
2021-09-09 15:15:26 +02:00
Laurent Destailleur
70f22f2648 # WARNING: head commit changed in the meantime
Merge
2021-09-09 15:12:02 +02:00
Frédéric FRANCE
456f25d57e
fix #17634 2021-09-04 11:30:03 +02:00
Laurent Destailleur
e4cbc2140e Fix doc and token renewal with NOSESSION 2021-08-24 21:48:38 +02:00