Changesets: LimeSurvey
5.x 21d12cec 2023-06-28 16:43 Committer: GitHub Details Diff |
Fixed issue #18918: [security] ownership permission update (#3250) Fixed issue #18918: [security] ownership permission update |
||
mod - application/controllers/UserManagementController.php | Diff File | ||
5.x 5a5fbd5a 2023-06-28 15:50 Details Diff |
Fixed issue #18923: [security] Admin notification permissions updated | ||
mod - application/controllers/admin/NotificationController.php | Diff File | ||
master 2ac58004 2023-06-28 15:41 Committer: GitHub Details Diff |
Fixed issue #18917: [security] Stored XSS in the user group deletion confirmation popup (#3249) | ||
mod - application/extensions/admin/grid/GridActionsWidget/views/action_dropdown.php | Diff File | ||
mod - application/models/UserGroup.php | Diff File | ||
master 97859da0 2023-06-28 15:22 Details Diff |
Fixed issue #18923: [security] Admin notification permissions updated | ||
mod - application/controllers/admin/NotificationController.php | Diff File | ||
master 83a803a6 2023-06-28 15:12 Details Diff |
Merge remote-tracking branch 'origin/master' into ls6_surveytheme | ||
rm - .github/workflows/build.yml | Diff | ||
mod - application/commands/DemomodeCommand.php | Diff File | ||
mod - application/config/version.php | Diff File | ||
mod - application/controllers/AjaxAlertController.php | Diff File | ||
mod - application/controllers/HomepageSettingsController.php | Diff File | ||
mod - application/controllers/QuestionAdministrationController.php | Diff File | ||
mod - application/controllers/UserGroupController.php | Diff File | ||
mod - application/controllers/UserManagementController.php | Diff File | ||
mod - application/controllers/admin/CheckIntegrity.php | Diff File | ||
mod - application/controllers/admin/DataEntry.php | Diff File | ||
mod - application/controllers/admin/Labels.php | Diff File | ||
mod - application/controllers/admin/SurveysGroupsController.php | Diff File | ||
mod - application/core/LSYii_Application.php | Diff File | ||
mod - application/core/LSYii_Controller.php | Diff File | ||
mod - application/core/LSYii_Validators.php | Diff File | ||
mod - application/core/LsDefaultDataSets.php | Diff File | ||
mod - application/core/plugins/expressionQuestionHelp/expressionQuestionHelp.php | Diff File | ||
mod - application/extensions/admin/grid/CLSGridView.php | Diff File | ||
mod - application/extensions/admin/grid/GridActionsWidget/views/action_dropdown.php | Diff File | ||
add - application/extensions/admin/grid/assets/rowLink.js | Diff File | ||
mod - application/extensions/admin/survey/ListSurveysWidget/views/listSurveys.php | Diff File | ||
mod - application/helpers/SurveyRuntimeHelper.php | Diff File | ||
mod - application/helpers/admin/import_helper.php | Diff File | ||
mod - application/helpers/common_helper.php | Diff File | ||
mod - application/helpers/expressions/em_core_helper.php | Diff File | ||
mod - application/helpers/sanitize_helper.php | Diff File | ||
mod - application/helpers/update/updates/Update_601.php | Diff File | ||
add - application/helpers/update/updates/Update_607.php | Diff File | ||
mod - application/models/QuotaMember.php | Diff File | ||
mod - application/models/SettingsUser.php | Diff File | ||
mod - application/models/Survey.php | Diff File | ||
mod - application/models/SurveysGroups.php | Diff File | ||
mod - application/models/SurveysGroupsettings.php | Diff File | ||
mod - application/models/TemplateConfiguration.php | Diff File | ||
mod - application/models/UpdateForm.php | Diff File | ||
mod - application/models/User.php | Diff File | ||
mod - application/models/UserGroup.php | Diff File | ||
mod - application/models/services/QuickTranslation.php | Diff File | ||
add - application/models/services/UserManager.php | Diff File | ||
mod - application/views/admin/emailtemplates/email_language_template_tab.php | Diff File | ||
mod - application/views/admin/super/footer.php | Diff File | ||
mod - application/views/admin/survey/subview/accordion/_generaloptions_panel.php | Diff File | ||
mod - application/views/admin/update/updater/_error.php | Diff File | ||
mod - application/views/homepageSettings/index.php | Diff File | ||
mod - application/views/homepageSettings/partial/topbarBtns/rightSideButtons.php | Diff File | ||
mod - application/views/questionAdministration/textElements.php | Diff File | ||
mod - application/views/responses/browseindex_view.php | Diff File | ||
mod - application/views/survey/questions/answer/arrays/multiflexi/rows/cells/answer_td_checkboxes.twig | Diff File | ||
mod - application/views/surveyAdministration/listSurveys_view.php | Diff File | ||
mod - application/views/userManagement/partial/addedituser.php | Diff File | ||
mod - application/views/userManagement/partial/addrole.php | Diff File | ||
mod - application/views/userManagement/partial/editpermissions.php | Diff File | ||
mod - assets/admin_themes/adminbasics_temporary/000-lime-admin-common.scss | Diff File | ||
mod - assets/packages/adminbasics/build/adminbasics.js | Diff File | ||
mod - assets/packages/adminbasics/build/adminbasics.min.js | Diff File | ||
mod - assets/packages/adminbasics/src/adminbasicsmain.js | Diff File | ||
rm - assets/packages/adminbasics/src/pages/surveyGrid.js | Diff | ||
mod - assets/packages/adminbasics/src/parts/save.js | Diff File | ||
mod - assets/packages/ckeditor/CHANGES.md | Diff File | ||
mod - assets/packages/ckeditor/README.md | Diff File | ||
mod - assets/packages/ckeditor/ckeditor.js | Diff File | ||
mod - assets/packages/ckeditor/lang/af.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ar.js | Diff File | ||
mod - assets/packages/ckeditor/lang/az.js | Diff File | ||
mod - assets/packages/ckeditor/lang/bg.js | Diff File | ||
mod - assets/packages/ckeditor/lang/bn.js | Diff File | ||
mod - assets/packages/ckeditor/lang/bs.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ca.js | Diff File | ||
mod - assets/packages/ckeditor/lang/cs.js | Diff File | ||
mod - assets/packages/ckeditor/lang/cy.js | Diff File | ||
mod - assets/packages/ckeditor/lang/da.js | Diff File | ||
mod - assets/packages/ckeditor/lang/de-ch.js | Diff File | ||
mod - assets/packages/ckeditor/lang/de.js | Diff File | ||
mod - assets/packages/ckeditor/lang/el.js | Diff File | ||
mod - assets/packages/ckeditor/lang/en-au.js | Diff File | ||
mod - assets/packages/ckeditor/lang/en-ca.js | Diff File | ||
mod - assets/packages/ckeditor/lang/en-gb.js | Diff File | ||
mod - assets/packages/ckeditor/lang/en.js | Diff File | ||
mod - assets/packages/ckeditor/lang/eo.js | Diff File | ||
mod - assets/packages/ckeditor/lang/es-mx.js | Diff File | ||
mod - assets/packages/ckeditor/lang/es.js | Diff File | ||
mod - assets/packages/ckeditor/lang/et.js | Diff File | ||
mod - assets/packages/ckeditor/lang/eu.js | Diff File | ||
mod - assets/packages/ckeditor/lang/fa.js | Diff File | ||
mod - assets/packages/ckeditor/lang/fi.js | Diff File | ||
mod - assets/packages/ckeditor/lang/fo.js | Diff File | ||
mod - assets/packages/ckeditor/lang/fr-ca.js | Diff File | ||
mod - assets/packages/ckeditor/lang/fr.js | Diff File | ||
mod - assets/packages/ckeditor/lang/gl.js | Diff File | ||
mod - assets/packages/ckeditor/lang/gu.js | Diff File | ||
mod - assets/packages/ckeditor/lang/he.js | Diff File | ||
mod - assets/packages/ckeditor/lang/hi.js | Diff File | ||
mod - assets/packages/ckeditor/lang/hr.js | Diff File | ||
mod - assets/packages/ckeditor/lang/hu.js | Diff File | ||
mod - assets/packages/ckeditor/lang/id.js | Diff File | ||
mod - assets/packages/ckeditor/lang/is.js | Diff File | ||
mod - assets/packages/ckeditor/lang/it.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ja.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ka.js | Diff File | ||
mod - assets/packages/ckeditor/lang/km.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ko.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ku.js | Diff File | ||
mod - assets/packages/ckeditor/lang/lt.js | Diff File | ||
mod - assets/packages/ckeditor/lang/lv.js | Diff File | ||
mod - assets/packages/ckeditor/lang/mk.js | Diff File | ||
mod - assets/packages/ckeditor/lang/mn.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ms.js | Diff File | ||
mod - assets/packages/ckeditor/lang/nb.js | Diff File | ||
mod - assets/packages/ckeditor/lang/nl.js | Diff File | ||
mod - assets/packages/ckeditor/lang/no.js | Diff File | ||
mod - assets/packages/ckeditor/lang/oc.js | Diff File | ||
mod - assets/packages/ckeditor/lang/pl.js | Diff File | ||
mod - assets/packages/ckeditor/lang/pt-br.js | Diff File | ||
mod - assets/packages/ckeditor/lang/pt.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ro.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ru.js | Diff File | ||
mod - assets/packages/ckeditor/lang/si.js | Diff File | ||
mod - assets/packages/ckeditor/lang/sk.js | Diff File | ||
mod - assets/packages/ckeditor/lang/sl.js | Diff File | ||
mod - assets/packages/ckeditor/lang/sq.js | Diff File | ||
mod - assets/packages/ckeditor/lang/sr-latn.js | Diff File | ||
mod - assets/packages/ckeditor/lang/sr.js | Diff File | ||
mod - assets/packages/ckeditor/lang/sv.js | Diff File | ||
mod - assets/packages/ckeditor/lang/th.js | Diff File | ||
mod - assets/packages/ckeditor/lang/tr.js | Diff File | ||
mod - assets/packages/ckeditor/lang/tt.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ug.js | Diff File | ||
mod - assets/packages/ckeditor/lang/uk.js | Diff File | ||
mod - assets/packages/ckeditor/lang/vi.js | Diff File | ||
mod - assets/packages/ckeditor/lang/zh-cn.js | Diff File | ||
mod - assets/packages/ckeditor/lang/zh.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/libs/quail/quail.jquery.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/libs/quail/quail.jquery.min.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/AddTableCaption.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/AnchorsMerge.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/AttributeRename.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/AttributeRenameDefault.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/DateUnfold.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/ElementRemove.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/ElementReplace.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/ImgAlt.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/ImgAltNonEmpty.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/LocalizedRepository.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/ParagraphToHeader.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/QuickFix.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/TableHeaders.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/AddTableCaption.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/AnchorsMerge.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/AttributeRename.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/AttributeRenameDefault.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/DateUnfold.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/ElementRemove.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/ElementReplace.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/ImgAlt.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/ImgAltNonEmpty.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/LocalizedRepository.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/ParagraphToHeader.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/QuickFix.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/TableHeaders.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/AddTableCaption.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/AnchorsMerge.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/AttributeRename.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/AttributeRenameDefault.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/DateUnfold.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/ElementRemove.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/ElementReplace.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/ImgAlt.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/ImgAltNonEmpty.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/LocalizedRepository.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/ParagraphToHeader.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/QuickFix.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/TableHeaders.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/AddTableCaption.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/AnchorsMerge.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/AttributeRename.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/AttributeRenameDefault.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/DateUnfold.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/ElementRemove.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/ElementReplace.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/ImgAlt.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/ImgAltNonEmpty.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/LocalizedRepository.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/ParagraphToHeader.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/QuickFix.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/TableHeaders.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/codemirror/dialogs/codemirrorAbout.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/codemirror/js/codemirror.min.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/codemirror/js/codemirror.mode.handlebars.min.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/codemirror/js/codemirror.mode.twig.min.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/codemirror/theme/bespin.css | Diff File | ||
mod - assets/packages/ckeditor/plugins/div/dialogs/div.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/html5video/dialogs/html5video.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/icons.png | Diff File | ||
mod - assets/packages/ckeditor/plugins/icons_hidpi.png | Diff File | ||
mod - assets/packages/ckeditor/plugins/iframe/dialogs/iframe.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/markdown/js/codemirror-gfm-min.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/markdown/js/marked.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/markdown/js/to-markdown.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/scayt/dialogs/options.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/videodetector/dialogs/videoDialog.js | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/editor.css | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/editor_gecko.css | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/editor_ie.css | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/editor_ie7.css | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/editor_ie8.css | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/editor_iequirks.css | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/icons.png | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/icons_hidpi.png | Diff File | ||
mod - assets/packages/emailtemplates/emailtemplates.js | Diff File | ||
mod - assets/packages/questions/5pointchoice/scripts/slider-rating.js | Diff File | ||
add - assets/scripts/admin/dataentry.js | Diff File | ||
mod - assets/scripts/admin/homepagesettings.js | Diff File | ||
mod - assets/scripts/admin/tokens.js | Diff File | ||
mod - docs/release_notes.txt | Diff File | ||
mod - locale/_template/limesurvey.pot | Diff File | ||
mod - locale/ca/ca.mo | Diff File | ||
mod - locale/cs-informal/cs-informal.mo | Diff File | ||
mod - locale/cs/cs.mo | Diff File | ||
mod - locale/de-informal/de-informal.mo | Diff File | ||
mod - locale/de/de.mo | Diff File | ||
mod - locale/fi/fi.mo | Diff File | ||
mod - locale/hu/hu.mo | Diff File | ||
mod - locale/it-informal/it-informal.mo | Diff File | ||
mod - locale/it/it.mo | Diff File | ||
mod - locale/nb/nb.mo | Diff File | ||
mod - locale/pl-informal/pl-informal.mo | Diff File | ||
mod - locale/pl/pl.mo | Diff File | ||
mod - locale/pt-BR/pt-BR.mo | Diff File | ||
mod - locale/sk/sk.mo | Diff File | ||
mod - locale/sv/sv.mo | Diff File | ||
mod - tests/LimeSurveyWebDriver.php | Diff File | ||
add - tests/data/surveys/limesurvey_survey_MandatorySoftMultiPage.lss | Diff File | ||
mod - tests/functional/frontend/MandatorySoftTest.php | Diff File | ||
add - tests/unit/helpers/CheckDateWrapTest.php | Diff File | ||
add - tests/unit/helpers/remotecontrol/ExportResponsesStataXmlTest.php | Diff File | ||
add - tests/unit/models/SurveySearchTest.php | Diff File | ||
mod - themes/admin/Sea_Green/css/sea_green-rtl.css | Diff File | ||
mod - themes/admin/Sea_Green/css/sea_green-rtl.min.css | Diff File | ||
mod - themes/admin/Sea_Green/css/sea_green.css | Diff File | ||
mod - themes/admin/Sea_Green/css/sea_green.min.css | Diff File | ||
5.x 094dad2a 2023-06-28 13:51 Committer: GitHub Details Diff |
Fixed issue #18913: [security] incorrect permissions for useraction (#3255) | ||
mod - application/controllers/UserManagementController.php | Diff File | ||
5.x 094dad2a 2023-06-28 13:51 Committer: GitHub Details Diff |
Fixed issue #18913: [security] incorrect permissions for useraction (#3255) | ||
mod - application/controllers/UserManagementController.php | Diff File | ||
master 4824bc93 2023-06-28 13:25 Committer: GitHub Details Diff |
Fixed issue #18913: [security] incorrect permissions for useraction (#3253) | ||
mod - application/controllers/AjaxAlertController.php | Diff File | ||
mod - application/controllers/UserManagementController.php | Diff File | ||
master 4824bc93 2023-06-28 13:25 Committer: GitHub Details Diff |
Fixed issue #18913: [security] incorrect permissions for useraction (#3253) | ||
mod - application/controllers/AjaxAlertController.php | Diff File | ||
mod - application/controllers/UserManagementController.php | Diff File | ||
master 7f8efd36 2023-06-28 10:48 Committer: GitHub Details Diff |
Fixed issue CR-1206: Token field in responses table not actionable (#3230) | ||
mod - assets/scripts/admin/tokens.js | Diff File | ||
master 7f8efd36 2023-06-28 10:48 Committer: GitHub Details Diff |
Fixed issue CR-1206: Token field in responses table not actionable (#3230) | ||
mod - assets/scripts/admin/tokens.js | Diff File | ||
master 0dd395a8 2023-06-28 10:47 Committer: GitHub Details Diff |
Fixed issue CR-1205: Request-URI Too Large on Responses page (#3235) | ||
mod - application/extensions/admin/grid/CLSGridView.php | Diff File | ||
5.x e1aeb0c0 2023-06-27 20:06 Committer: GitHub Details Diff |
Fixed issue 18915: [security] Non-superadmin Admin user is able to edit groups not owned (#3258) | ||
mod - application/controllers/UserGroupController.php | Diff File | ||
mod - application/models/UserGroup.php | Diff File | ||
master d2ab1fe5 2023-06-27 19:58 Committer: GitHub Details Diff |
Fixed issue 18915: [security] Non-superadmin Admin user is able to edit groups not owned (#3248) | ||
mod - application/controllers/UserGroupController.php | Diff File | ||
mod - application/models/UserGroup.php | Diff File | ||
master 4a3db1e1 2023-06-26 18:44 Details Diff |
Dev: added description for new rowLink function | ||
mod - application/extensions/admin/grid/CLSGridView.php | Diff File | ||
master a2eece78 2023-06-26 15:47 Gabriel Jenik Committer: GitHub Details Diff |
Fixed issue #18356: [security] User with only user update allowed can set/remove any role to any user (#2625) * Fix part of #18355: make sure a user can only assign permissions to it's own child users --------- Co-authored-by: encuestabizdevgit <devgit@encuesta.biz> Co-authored-by: lapiudevgit <devgit@lapiu.biz> |
||
mod - application/controllers/UserManagementController.php | Diff File | ||
mod - application/models/User.php | Diff File | ||
add - application/models/services/UserManager.php | Diff File | ||
mod - application/views/userManagement/partial/addrole.php | Diff File | ||
mod - application/views/userManagement/partial/editpermissions.php | Diff File | ||
master 23372d2d 2023-06-26 15:41 Details Diff |
Merge branch 'master' into develop | ||
mod - application/commands/DemomodeCommand.php | Diff File | ||
mod - application/config/version.php | Diff File | ||
mod - application/controllers/HomepageSettingsController.php | Diff File | ||
mod - application/controllers/admin/SurveysGroupsController.php | Diff File | ||
mod - application/core/LSYii_Application.php | Diff File | ||
mod - application/core/LSYii_Controller.php | Diff File | ||
mod - application/core/LSYii_Validators.php | Diff File | ||
mod - application/core/plugins/expressionQuestionHelp/expressionQuestionHelp.php | Diff File | ||
mod - application/extensions/admin/grid/CLSGridView.php | Diff File | ||
mod - application/extensions/admin/grid/GridActionsWidget/views/action_dropdown.php | Diff File | ||
add - application/extensions/admin/grid/assets/rowLink.js | Diff File | ||
mod - application/extensions/admin/survey/ListSurveysWidget/views/listSurveys.php | Diff File | ||
mod - application/helpers/SurveyRuntimeHelper.php | Diff File | ||
mod - application/helpers/admin/import_helper.php | Diff File | ||
mod - application/models/QuotaMember.php | Diff File | ||
mod - application/models/Survey.php | Diff File | ||
mod - application/models/SurveysGroups.php | Diff File | ||
mod - application/models/SurveysGroupsettings.php | Diff File | ||
mod - application/models/TemplateConfiguration.php | Diff File | ||
mod - application/models/User.php | Diff File | ||
mod - application/views/admin/super/footer.php | Diff File | ||
mod - application/views/admin/survey/subview/accordion/_generaloptions_panel.php | Diff File | ||
mod - application/views/admin/update/updater/_error.php | Diff File | ||
mod - application/views/homepageSettings/index.php | Diff File | ||
mod - application/views/homepageSettings/partial/topbarBtns/rightSideButtons.php | Diff File | ||
mod - application/views/questionAdministration/textElements.php | Diff File | ||
mod - application/views/responses/browseindex_view.php | Diff File | ||
mod - application/views/surveyAdministration/listSurveys_view.php | Diff File | ||
mod - application/views/userManagement/partial/addedituser.php | Diff File | ||
mod - assets/packages/adminbasics/build/adminbasics.js | Diff File | ||
mod - assets/packages/adminbasics/build/adminbasics.min.js | Diff File | ||
mod - assets/packages/adminbasics/src/adminbasicsmain.js | Diff File | ||
rm - assets/packages/adminbasics/src/pages/surveyGrid.js | Diff | ||
mod - assets/packages/ckeditor/CHANGES.md | Diff File | ||
mod - assets/packages/ckeditor/README.md | Diff File | ||
mod - assets/packages/ckeditor/ckeditor.js | Diff File | ||
mod - assets/packages/ckeditor/lang/af.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ar.js | Diff File | ||
mod - assets/packages/ckeditor/lang/az.js | Diff File | ||
mod - assets/packages/ckeditor/lang/bg.js | Diff File | ||
mod - assets/packages/ckeditor/lang/bn.js | Diff File | ||
mod - assets/packages/ckeditor/lang/bs.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ca.js | Diff File | ||
mod - assets/packages/ckeditor/lang/cs.js | Diff File | ||
mod - assets/packages/ckeditor/lang/cy.js | Diff File | ||
mod - assets/packages/ckeditor/lang/da.js | Diff File | ||
mod - assets/packages/ckeditor/lang/de-ch.js | Diff File | ||
mod - assets/packages/ckeditor/lang/de.js | Diff File | ||
mod - assets/packages/ckeditor/lang/el.js | Diff File | ||
mod - assets/packages/ckeditor/lang/en-au.js | Diff File | ||
mod - assets/packages/ckeditor/lang/en-ca.js | Diff File | ||
mod - assets/packages/ckeditor/lang/en-gb.js | Diff File | ||
mod - assets/packages/ckeditor/lang/en.js | Diff File | ||
mod - assets/packages/ckeditor/lang/eo.js | Diff File | ||
mod - assets/packages/ckeditor/lang/es-mx.js | Diff File | ||
mod - assets/packages/ckeditor/lang/es.js | Diff File | ||
mod - assets/packages/ckeditor/lang/et.js | Diff File | ||
mod - assets/packages/ckeditor/lang/eu.js | Diff File | ||
mod - assets/packages/ckeditor/lang/fa.js | Diff File | ||
mod - assets/packages/ckeditor/lang/fi.js | Diff File | ||
mod - assets/packages/ckeditor/lang/fo.js | Diff File | ||
mod - assets/packages/ckeditor/lang/fr-ca.js | Diff File | ||
mod - assets/packages/ckeditor/lang/fr.js | Diff File | ||
mod - assets/packages/ckeditor/lang/gl.js | Diff File | ||
mod - assets/packages/ckeditor/lang/gu.js | Diff File | ||
mod - assets/packages/ckeditor/lang/he.js | Diff File | ||
mod - assets/packages/ckeditor/lang/hi.js | Diff File | ||
mod - assets/packages/ckeditor/lang/hr.js | Diff File | ||
mod - assets/packages/ckeditor/lang/hu.js | Diff File | ||
mod - assets/packages/ckeditor/lang/id.js | Diff File | ||
mod - assets/packages/ckeditor/lang/is.js | Diff File | ||
mod - assets/packages/ckeditor/lang/it.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ja.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ka.js | Diff File | ||
mod - assets/packages/ckeditor/lang/km.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ko.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ku.js | Diff File | ||
mod - assets/packages/ckeditor/lang/lt.js | Diff File | ||
mod - assets/packages/ckeditor/lang/lv.js | Diff File | ||
mod - assets/packages/ckeditor/lang/mk.js | Diff File | ||
mod - assets/packages/ckeditor/lang/mn.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ms.js | Diff File | ||
mod - assets/packages/ckeditor/lang/nb.js | Diff File | ||
mod - assets/packages/ckeditor/lang/nl.js | Diff File | ||
mod - assets/packages/ckeditor/lang/no.js | Diff File | ||
mod - assets/packages/ckeditor/lang/oc.js | Diff File | ||
mod - assets/packages/ckeditor/lang/pl.js | Diff File | ||
mod - assets/packages/ckeditor/lang/pt-br.js | Diff File | ||
mod - assets/packages/ckeditor/lang/pt.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ro.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ru.js | Diff File | ||
mod - assets/packages/ckeditor/lang/si.js | Diff File | ||
mod - assets/packages/ckeditor/lang/sk.js | Diff File | ||
mod - assets/packages/ckeditor/lang/sl.js | Diff File | ||
mod - assets/packages/ckeditor/lang/sq.js | Diff File | ||
mod - assets/packages/ckeditor/lang/sr-latn.js | Diff File | ||
mod - assets/packages/ckeditor/lang/sr.js | Diff File | ||
mod - assets/packages/ckeditor/lang/sv.js | Diff File | ||
mod - assets/packages/ckeditor/lang/th.js | Diff File | ||
mod - assets/packages/ckeditor/lang/tr.js | Diff File | ||
mod - assets/packages/ckeditor/lang/tt.js | Diff File | ||
mod - assets/packages/ckeditor/lang/ug.js | Diff File | ||
mod - assets/packages/ckeditor/lang/uk.js | Diff File | ||
mod - assets/packages/ckeditor/lang/vi.js | Diff File | ||
mod - assets/packages/ckeditor/lang/zh-cn.js | Diff File | ||
mod - assets/packages/ckeditor/lang/zh.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/libs/quail/quail.jquery.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/libs/quail/quail.jquery.min.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/AddTableCaption.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/AnchorsMerge.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/AttributeRename.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/AttributeRenameDefault.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/DateUnfold.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/ElementRemove.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/ElementReplace.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/ImgAlt.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/ImgAltNonEmpty.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/LocalizedRepository.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/ParagraphToHeader.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/QuickFix.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/de/TableHeaders.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/AddTableCaption.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/AnchorsMerge.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/AttributeRename.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/AttributeRenameDefault.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/DateUnfold.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/ElementRemove.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/ElementReplace.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/ImgAlt.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/ImgAltNonEmpty.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/LocalizedRepository.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/ParagraphToHeader.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/QuickFix.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/en/TableHeaders.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/AddTableCaption.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/AnchorsMerge.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/AttributeRename.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/AttributeRenameDefault.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/DateUnfold.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/ElementRemove.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/ElementReplace.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/ImgAlt.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/ImgAltNonEmpty.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/LocalizedRepository.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/ParagraphToHeader.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/QuickFix.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/nl/TableHeaders.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/AddTableCaption.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/AnchorsMerge.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/AttributeRename.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/AttributeRenameDefault.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/DateUnfold.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/ElementRemove.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/ElementReplace.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/ImgAlt.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/ImgAltNonEmpty.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/LocalizedRepository.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/ParagraphToHeader.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/QuickFix.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/a11ychecker/quickfix/pt-br/TableHeaders.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/codemirror/dialogs/codemirrorAbout.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/codemirror/js/codemirror.min.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/codemirror/js/codemirror.mode.handlebars.min.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/codemirror/js/codemirror.mode.twig.min.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/codemirror/theme/bespin.css | Diff File | ||
mod - assets/packages/ckeditor/plugins/div/dialogs/div.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/html5video/dialogs/html5video.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/icons.png | Diff File | ||
mod - assets/packages/ckeditor/plugins/icons_hidpi.png | Diff File | ||
mod - assets/packages/ckeditor/plugins/iframe/dialogs/iframe.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/markdown/js/codemirror-gfm-min.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/markdown/js/marked.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/markdown/js/to-markdown.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/scayt/dialogs/options.js | Diff File | ||
mod - assets/packages/ckeditor/plugins/videodetector/dialogs/videoDialog.js | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/editor.css | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/editor_gecko.css | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/editor_ie.css | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/editor_ie7.css | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/editor_ie8.css | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/editor_iequirks.css | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/icons.png | Diff File | ||
mod - assets/packages/ckeditor/skins/bootstrapck/icons_hidpi.png | Diff File | ||
mod - assets/scripts/admin/homepagesettings.js | Diff File | ||
mod - docs/release_notes.txt | Diff File | ||
mod - locale/_template/limesurvey.pot | Diff File | ||
mod - locale/ca/ca.mo | Diff File | ||
mod - locale/de-informal/de-informal.mo | Diff File | ||
mod - locale/de/de.mo | Diff File | ||
mod - locale/fi/fi.mo | Diff File | ||
mod - locale/it-informal/it-informal.mo | Diff File | ||
mod - locale/it/it.mo | Diff File | ||
mod - locale/pl-informal/pl-informal.mo | Diff File | ||
mod - locale/pl/pl.mo | Diff File | ||
mod - locale/sv/sv.mo | Diff File | ||
3.x-LTS 439459fc 2023-06-26 14:06 Details Diff |
Release 3.28.63+230628 | ||
mod - application/config/version.php | Diff File | ||
mod - docs/release_notes.txt | Diff File | ||
5.x 2f45ce23 2023-06-26 14:03 Details Diff |
Release 5.6.28+230627 | ||
mod - application/config/version.php | Diff File | ||
mod - docs/release_notes.txt | Diff File | ||
master 5ff86506 2023-06-26 14:01 Details Diff |
Release 6.1.5+230626 | ||
mod - application/config/version.php | Diff File | ||
mod - docs/release_notes.txt | Diff File | ||
5.x 24a192ea 2023-06-26 14:00 LimeSurvey Translations Bot Details Diff |
Updated translation: Catalan by qualitatuvic Updated translation: Polish by elissa Updated translation: Swedish by maxzomborszki Updated translation: Polish (Informal) by elissa |
||
mod - locale/ca/ca.mo | Diff File | ||
mod - locale/pl-informal/pl-informal.mo | Diff File | ||
mod - locale/pl/pl.mo | Diff File | ||
mod - locale/sv/sv.mo | Diff File | ||
master 1e689d34 2023-06-26 13:59 LimeSurvey Translations Bot Details Diff |
Updated translation: Catalan by qualitatuvic Updated translation: Polish by elissa Updated translation: Swedish by maxzomborszki Updated translation: Polish (Informal) by elissa |
||
mod - locale/_template/limesurvey.pot | Diff File | ||
mod - locale/ca/ca.mo | Diff File | ||
mod - locale/pl-informal/pl-informal.mo | Diff File | ||
mod - locale/pl/pl.mo | Diff File | ||
mod - locale/sv/sv.mo | Diff File | ||
master 6e5a5767 2023-06-23 17:13 Committer: GitHub Details Diff |
Fixed issue #18883: [security] Stored XSS vulnerability in user profile (#3247) | ||
mod - application/extensions/admin/grid/GridActionsWidget/views/action_dropdown.php | Diff File | ||
mod - application/models/TemplateConfiguration.php | Diff File | ||
mod - application/models/User.php | Diff File | ||
master 46e2bb68 2023-06-23 16:47 Details Diff |
Fixed issue #18912: [security] Able to change username that is by default unchangeable | ||
mod - application/models/User.php | Diff File | ||
mod - application/views/userManagement/partial/addedituser.php | Diff File | ||
master a36f8e1f 2023-06-23 15:42 Details Diff |
Fixed issue: Disable system information in demo mode | ||
mod - application/views/admin/super/footer.php | Diff File |