summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2008-02-10use quotemeta when building the regexpJoey Hess
2008-02-10some updates about the recent holeJoey Hess
2008-02-10add news item for ikiwiki 2.32.3Joey Hess
2008-02-10attributionJoey Hess
2008-02-10Allow the smb: URI scheme.Josh Triplett
2008-02-10Allow the snews: URI scheme.Josh Triplett
2008-02-10Merge branch 'master' of ssh://git.kitenet.net/srv/git/ikiwiki.infoJoey Hess
2008-02-10debian-stable branchJoey Hess
2008-02-10Do not allow the steam: URI scheme.Josh Triplett
2008-02-10Match literal '.' in URI schemas containing '.', rather than matching any ↵Josh Triplett
character
2008-02-10web commit by http://users.itk.ppke.hu/~cstamas/: creating my own pageJoey Hess
2008-02-10updateJoey Hess
2008-02-10* meta: Check that the urls provided for authorurl, permalink, and openidJoey Hess
are safe and can't contain javascript.
2008-02-10export $safe_url_regexpJoey Hess
2008-02-10Also filter the attributes cite, longdesc, and usemap, which can contain URIsJosh Triplett
2008-02-10Move about: fix to version 2.31.3 in the changelogJosh Triplett
2008-02-10add parens around scheme regexpJoey Hess
2008-02-10Do not allow the about: URI schemeJosh Triplett
Some browsers interpret about: URIs like a limited version of data: URIs. In particular, some versions of Internet Explorer interpret arbitrary HTML content in about: URIs.
2008-02-10a few thoughts on data: securityJoey Hess
2008-02-10updateJoey Hess
2008-02-10add news item for ikiwiki 2.31.2Joey Hess
2008-02-10fix data:image handlingJoey Hess
2008-02-10changelog mungingJoey Hess
2008-02-10document security fixJoey Hess
The backported fix for stable is tagged and waiting for the security team to upload.
2008-02-10announcing version 2.31.1Joey Hess
2008-02-10* htmlscrubber security fix: Block javascript in uris.Joey Hess
* Add htmlscrubber test suite.
2008-02-10Merge branch 'master' of ssh://git.kitenet.net/srv/git/ikiwiki.infoJoey Hess
2008-02-10improved sanitiser test suiteJoey Hess
2008-02-10web commit by PatrickWinnertz: add link to my templatesJoey Hess
2008-02-10add some more testsJoey Hess
2008-02-10new test caseJoey Hess
2008-02-10improve wording and fix an example that is intentionall un-prefixedJoey Hess
2008-02-10fix versionsJoey Hess
2008-02-10prefix-directives branch is merged so no need to list anymoreJoey Hess
2008-02-09Merge branch 'master' into prefix-directivesJosh Triplett
Conflicts: debian/changelog templates/change.tmpl
2008-02-09Tighten page name regex to not allow carriage returns or line feedsJosh Triplett
2008-02-10add news item for ikiwiki 2.31Joey Hess
2008-02-10releasing version 2.31Joey Hess
2008-02-09* Page templates can now use CTIME to show when the page was created.Joey Hess
2008-02-09change wordingJoey Hess
2008-02-09reword to put the more important info (page names) nearer the frontJoey Hess
2008-02-09note that's there's a git branch for thisJoey Hess
2008-02-09remove random pageJoey Hess
2008-02-08Add --prefix-directives and --no-prefix-directives options to ikiwikiJosh Triplett
This avoids the need to set prefix_directives with --set.
2008-02-08Mention user wikilists in README.DebianJosh Triplett
2008-02-08Use plural "wikis" for consistencyJosh Triplett
2008-02-08clarify slightlyJoey Hess
2008-02-08replyJoey Hess
2008-02-08Merge branch 'master' of ssh://git.kitenet.net/srv/git/ikiwiki.infoJoey Hess
2008-02-08web commit by lnusselJoey Hess