Release 2.6.1-1

SVN revision: 1622
This commit is contained in:
Stefan Ritt 2006-01-19 09:10:02 +00:00
parent 6a823fb603
commit a5220a2c49
14 changed files with 202 additions and 118 deletions

View File

@ -1,3 +1,35 @@
Version 2.6.1, released Jan 19th, 2005
======================================
- Major security fix
- Prohibit '..' in URLs
- Use absolute links only for email notification
- Added string substitution for email heading
- Improved error display in sendmail()
- Fixed quick filters with MOptions
- Highlight search results in http link correctly
- Removed (int)'s for 64-bit compatibility
- Removed "nowrap" from MOptions and ROptions attributes in edit form
- Fixed problem with attachments containing "HTTP" in their name
- Fixed bug with ### presets
- Added SVN revision to server version in HTTP header
- Fixed problem with empty bottom and top text
- Fixed bug with sorting attributes
- Show SVN revision on bottom of page
- Fixed wrong </td></tr> when showing attachments in list mode
- Fixed problem with page navigation after "find" command
- Implemented "Fonts = " option
- Fixed HelpELCode page permission with guest menus
- Highlight previous entry in full list mode
- "List" link goes to corresponding listing page
- Fixed problem with missing non-required attribute
- Strip attachments on "duplicate"
- Don't evaluate preset attributes on "duplicate"
- Implemented $shell substitution
- Fixed double entries when using inline images
- Added warning it email notification buffer size exceeded
- Increased mail notification buffer for long attachments
- Fixed bug in self registering
Version 2.6.0, released Dec 14th, 2005 Version 2.6.0, released Dec 14th, 2005
====================================== ======================================

View File

@ -25,7 +25,7 @@
&nbsp;[<a class="nav" href="#links">Links</a>]&nbsp; *&nbsp;</div> &nbsp;[<a class="nav" href="#links">Links</a>]&nbsp; *&nbsp;</div>
<P class="Sub">Home of the <i>Electronic Logbook</i> package by <a href="mailto:Stefan.Ritt&#64;psi.ch"> <P class="Sub">Home of the <i>Electronic Logbook</i> package by <a href="mailto:Stefan.Ritt&#64;psi.ch">
Stefan Ritt</a></P> Stefan Ritt</a></P>
<div class="version">Current version is : 2.6.0</div> <div class="version">Current version is : 2.6.1</div>
<hr> <hr>
<a name="whatis"> <a name="whatis">
<div class="section">&nbsp; What is ELOG ? &nbsp;</div> <div class="section">&nbsp; What is ELOG ? &nbsp;</div>

View File

@ -401,3 +401,7 @@ Enter URL of hyperlink =
astonished = astonished =
Error in regular expression "%s" = Error in regular expression "%s" =
File not found at URL "%s" = File not found at URL "%s" =
Entry size too large for email notification =
Please specify a valid email address =
Cannot send email notification to "%s" =
Error: Command "<b>%s</b>" is not allowed for user "<b>%s</b>" =

View File

@ -403,3 +403,7 @@ Enter URL of hyperlink =
astonished = astonished =
Error in regular expression "%s" = Error in regular expression "%s" =
File not found at URL "%s" = File not found at URL "%s" =
Entry size too large for email notification =
Please specify a valid email address =
Cannot send email notification to "%s" =
Error: Command "<b>%s</b>" is not allowed for user "<b>%s</b>" =

View File

@ -401,3 +401,7 @@ Enter URL of hyperlink =
astonished = astonished =
Error in regular expression "%s" = Error in regular expression "%s" =
File not found at URL "%s" = File not found at URL "%s" =
Entry size too large for email notification =
Please specify a valid email address =
Cannot send email notification to "%s" =
Error: Command "<b>%s</b>" is not allowed for user "<b>%s</b>" =

View File

@ -397,3 +397,14 @@ Enter URL of hyperlink = Geef URL van de hyperlink
astonished = verbaast astonished = verbaast
Error in regular expression "%s" = Fout in reguliere expressie "%s" Error in regular expression "%s" = Fout in reguliere expressie "%s"
File not found at URL "%s" = Kan bestand niet gevonden bij URL "%s" File not found at URL "%s" = Kan bestand niet gevonden bij URL "%s"
#
#---- please translate following items and then remove this comment ----#
#
Entry size too large for email notification =
Please specify a valid email address =
Cannot send email notification to "%s" =
Enable email notifications =
text =
From =
Error: Command "<b>%s</b>" is not allowed for user "<b>%s</b>" =

View File

@ -397,3 +397,11 @@ Enter name of hyperlink = Nom du lien
Enter URL of hyperlink = URL du lien Enter URL of hyperlink = URL du lien
Error in regular expression "%s" = Erreur dans l'expression régulière "%s" Error in regular expression "%s" = Erreur dans l'expression régulière "%s"
File not found at URL "%s" = Fichier non trouvé à l'URL "%s" File not found at URL "%s" = Fichier non trouvé à l'URL "%s"
#
#---- please translate following items and then remove this comment ----#
#
Entry size too large for email notification =
Please specify a valid email address =
Cannot send email notification to "%s" =
Error: Command "<b>%s</b>" is not allowed for user "<b>%s</b>" =

View File

@ -396,4 +396,7 @@ Enter URL of hyperlink = URL von Hyperlink eingeben
astonished = erstaunt astonished = erstaunt
Error in regular expression "%s" = Fehler in regulärem Ausdruck "%s" Error in regular expression "%s" = Fehler in regulärem Ausdruck "%s"
File not found at URL "%s" = Datei bei URL "%s" nicht gefunden File not found at URL "%s" = Datei bei URL "%s" nicht gefunden
Entry size too large for email notification = Eintrag zu groß für Email-Benachrichtigung
Please specify a valid email address = Bitte eine gültige Email-Adresse eingeben
Cannot send email notification to "%s" = Kann Email-Benachrichtigung nicht an "%s" senden
Error: Command "<b>%s</b>" is not allowed for user "<b>%s</b>" = Fehler: Kommando "<b>%s</b>" ist nicht erlaubt für Benutzer "<b>%s</b>"

View File

@ -399,3 +399,7 @@ Enter URL of hyperlink =
astonished = astonished =
Error in regular expression "%s" = Error in regular expression "%s" =
File not found at URL "%s" = File not found at URL "%s" =
Entry size too large for email notification =
Please specify a valid email address =
Cannot send email notification to "%s" =
Error: Command "<b>%s</b>" is not allowed for user "<b>%s</b>" =

View File

@ -399,3 +399,7 @@ Enter URL of hyperlink =
astonished = astonished =
Error in regular expression "%s" = Error in regular expression "%s" =
File not found at URL "%s" = File not found at URL "%s" =
Entry size too large for email notification =
Please specify a valid email address =
Cannot send email notification to "%s" =
Error: Command "<b>%s</b>" is not allowed for user "<b>%s</b>" =

View File

@ -401,3 +401,7 @@ Cannot retrieve file from URL "%s" = No puedo obtener el archivo desde la URL "%
astonished = astonished =
Error in regular expression "%s" = Error in regular expression "%s" =
File not found at URL "%s" = File not found at URL "%s" =
Entry size too large for email notification =
Please specify a valid email address =
Cannot send email notification to "%s" =
Error: Command "<b>%s</b>" is not allowed for user "<b>%s</b>" =

View File

@ -401,3 +401,7 @@ Enter URL of hyperlink =
astonished = astonished =
Error in regular expression "%s" = Error in regular expression "%s" =
File not found at URL "%s" = File not found at URL "%s" =
Entry size too large for email notification =
Please specify a valid email address =
Cannot send email notification to "%s" =
Error: Command "<b>%s</b>" is not allowed for user "<b>%s</b>" =

View File

@ -401,3 +401,7 @@ Enter URL of hyperlink =
astonished = astonished =
Error in regular expression "%s" = Error in regular expression "%s" =
File not found at URL "%s" = File not found at URL "%s" =
Entry size too large for email notification =
Please specify a valid email address =
Cannot send email notification to "%s" =
Error: Command "<b>%s</b>" is not allowed for user "<b>%s</b>" =

View File

@ -10,7 +10,7 @@
\********************************************************************/ \********************************************************************/
/* Version of ELOG */ /* Version of ELOG */
#define VERSION "2.6.0" #define VERSION "2.6.1"
char svn_revision[] = "$Id$"; char svn_revision[] = "$Id$";
/* ELOG identification */ /* ELOG identification */
@ -895,8 +895,7 @@ int subst_shell(char *cmd, char *result, int size)
#ifdef OS_WINNT #ifdef OS_WINNT
HANDLE hChildStdinRd, hChildStdinWr, hChildStdinWrDup, HANDLE hChildStdinRd, hChildStdinWr, hChildStdinWrDup,
hChildStdoutRd, hChildStdoutWr, hChildStdoutRd, hChildStdoutWr, hChildStderrRd, hChildStderrWr, hSaveStdin, hSaveStdout, hSaveStderr;
hChildStderrRd, hChildStderrWr, hSaveStdin, hSaveStdout, hSaveStderr;
SECURITY_ATTRIBUTES saAttr; SECURITY_ATTRIBUTES saAttr;
PROCESS_INFORMATION piProcInfo; PROCESS_INFORMATION piProcInfo;
@ -5245,8 +5244,7 @@ void rsputs2(LOGBOOK * lbs, int absolute_link, const char *str)
compose_base_url(lbs, base_url, sizeof(base_url)); compose_base_url(lbs, base_url, sizeof(base_url));
else else
base_url[0] = 0; base_url[0] = 0;
sprintf(return_buffer + j, "<a href=\"%s%s\">elog:%s</a>", base_url, sprintf(return_buffer + j, "<a href=\"%s%s\">elog:%s</a>", base_url, link, link_text);
link, link_text);
} }
} else if (strcmp(key_list[l], "mailto:") == 0) { } else if (strcmp(key_list[l], "mailto:") == 0) {
@ -6073,8 +6071,7 @@ void set_location(LOGBOOK * lbs, char *rel_path)
rsputs(rel_path); rsputs(rel_path);
} else { } else {
if (getcfg(lbs->name, "redirection", str, sizeof(str)) && if (getcfg(lbs->name, "redirection", str, sizeof(str)) && atoi(str) == 1) {
atoi(str) == 1) {
/* use relative redirection */ /* use relative redirection */
if (lbs) if (lbs)
@ -10882,7 +10879,9 @@ int save_user_config(LOGBOOK * lbs, char *user, BOOL new_user, BOOL activate)
sprintf(url + strlen(url), "?cmd=Login&unm=%s", getparam("new_user_name")); sprintf(url + strlen(url), "?cmd=Login&unm=%s", getparam("new_user_name"));
sprintf(mail_text + strlen(mail_text), "%s %s\r\n", loc("You can access it at"), url); sprintf(mail_text + strlen(mail_text), "%s %s\r\n", loc("You can access it at"), url);
if (sendmail(lbs, smtp_host, mail_from, getparam("new_user_email"), mail_text, error, sizeof(error)) == -1) { if (sendmail
(lbs, smtp_host, mail_from, getparam("new_user_email"), mail_text, error,
sizeof(error)) == -1) {
sprintf(str, loc("Cannot send email notification to \"%s\""), getparam("new_user_email")); sprintf(str, loc("Cannot send email notification to \"%s\""), getparam("new_user_email"));
strlcat(str, " : ", sizeof(str)); strlcat(str, " : ", sizeof(str));
strlcat(str, error, sizeof(str)); strlcat(str, error, sizeof(str));
@ -10953,10 +10952,12 @@ int save_user_config(LOGBOOK * lbs, char *user, BOOL new_user, BOOL activate)
enc_pwd[0] = 0; enc_pwd[0] = 0;
url_encode(enc_pwd, sizeof(enc_pwd)); url_encode(enc_pwd, sizeof(enc_pwd));
if (isparam("new_user_name")) if (isparam("new_user_name"))
sprintf(mail_text + strlen(mail_text), "?cmd=Activate&new_user_name=%s&new_full_name=%s", sprintf(mail_text + strlen(mail_text),
getparam("new_user_name"), str); "?cmd=Activate&new_user_name=%s&new_full_name=%s", getparam("new_user_name"),
str);
if (isparam("new_user_email")) if (isparam("new_user_email"))
sprintf(mail_text + strlen(mail_text), "&new_user_email=%s", getparam("new_user_email")); sprintf(mail_text + strlen(mail_text), "&new_user_email=%s",
getparam("new_user_email"));
for (i = 0; lb_list[i].name[0]; i++) { for (i = 0; lb_list[i].name[0]; i++) {
sprintf(str, "sub_lb%d", i); sprintf(str, "sub_lb%d", i);
@ -10973,7 +10974,8 @@ int save_user_config(LOGBOOK * lbs, char *user, BOOL new_user, BOOL activate)
} }
if (sendmail(lbs, smtp_host, mail_from, email_addr, mail_text, error, sizeof(error)) == -1) { if (sendmail(lbs, smtp_host, mail_from, email_addr, mail_text, error, sizeof(error)) == -1) {
sprintf(str, loc("Cannot send email notification to \"%s\""), getparam("new_user_email")); sprintf(str, loc("Cannot send email notification to \"%s\""),
getparam("new_user_email"));
strlcat(str, " : ", sizeof(str)); strlcat(str, " : ", sizeof(str));
strlcat(str, error, sizeof(str)); strlcat(str, error, sizeof(str));
show_error(str); show_error(str);
@ -11321,7 +11323,8 @@ void show_forgot_pwd_page(LOGBOOK * lbs)
mail_text, sizeof(mail_text), 1, 0, NULL); mail_text, sizeof(mail_text), 1, 0, NULL);
strlcat(mail_text, "\r\n", sizeof(mail_text)); strlcat(mail_text, "\r\n", sizeof(mail_text));
sprintf(mail_text+strlen(mail_text), loc("A new password has been created for you on host %s"), host_name); sprintf(mail_text + strlen(mail_text), loc("A new password has been created for you on host %s"),
host_name);
strlcat(mail_text, ".\r\n", sizeof(mail_text)); strlcat(mail_text, ".\r\n", sizeof(mail_text));
strlcat(mail_text, strlcat(mail_text,
loc loc
@ -11619,8 +11622,7 @@ void show_elog_delete(LOGBOOK * lbs, int message_id)
if (!reply) { if (!reply) {
el_retrieve(lbs, isparam(str) ? atoi(getparam(str)) : 0, el_retrieve(lbs, isparam(str) ? atoi(getparam(str)) : 0,
NULL, attr_list, NULL, 0, NULL, NULL, NULL, attr_list, NULL, 0, NULL, NULL, in_reply_to, reply_to, NULL, NULL, NULL);
in_reply_to, reply_to, NULL, NULL, NULL);
if (reply_to[0]) if (reply_to[0])
reply = TRUE; reply = TRUE;
} }
@ -14894,8 +14896,7 @@ void display_line(LOGBOOK * lbs, int message_id, int number, char *mode,
void display_reply(LOGBOOK * lbs, int message_id, int printable, void display_reply(LOGBOOK * lbs, int message_id, int printable,
int expand, int n_line, int n_attr_disp, int expand, int n_line, int n_attr_disp,
char disp_attr[MAX_N_ATTR + 4][NAME_LENGTH], BOOL show_text, char disp_attr[MAX_N_ATTR + 4][NAME_LENGTH], BOOL show_text,
int level, int highlight, regex_t * re_buf, int highlight_mid, int level, int highlight, regex_t * re_buf, int highlight_mid, int absolute_link)
int absolute_link)
{ {
char *date, *text, *in_reply_to, *reply_to, *encoding, *locked_by, *attachment, *attrib, *p; char *date, *text, *in_reply_to, *reply_to, *encoding, *locked_by, *attachment, *attrib, *p;
int status, size; int status, size;
@ -14933,15 +14934,13 @@ void display_reply(LOGBOOK * lbs, int message_id, int printable,
display_line(lbs, message_id, 0, "threaded", expand, level, printable, display_line(lbs, message_id, 0, "threaded", expand, level, printable,
n_line, FALSE, date, in_reply_to, reply_to, n_attr_disp, n_line, FALSE, date, in_reply_to, reply_to, n_attr_disp,
disp_attr, NULL, (void *) attrib, lbs->n_attr, text, show_text, disp_attr, NULL, (void *) attrib, lbs->n_attr, text, show_text,
NULL, encoding, 0, NULL, locked_by, highlight, &re_buf[0], NULL, encoding, 0, NULL, locked_by, highlight, &re_buf[0], highlight_mid, absolute_link);
highlight_mid, absolute_link);
if (reply_to[0]) { if (reply_to[0]) {
p = reply_to; p = reply_to;
do { do {
display_reply(lbs, atoi(p), printable, expand, n_line, n_attr_disp, display_reply(lbs, atoi(p), printable, expand, n_line, n_attr_disp,
disp_attr, show_text, level + 1, highlight, &re_buf[0], disp_attr, show_text, level + 1, highlight, &re_buf[0], highlight_mid, absolute_link);
highlight_mid, absolute_link);
while (*p && isdigit(*p)) while (*p && isdigit(*p))
p++; p++;
@ -15552,7 +15551,8 @@ void show_page_filters(LOGBOOK * lbs, int n_msg, int page_n, BOOL mode_commands,
else { else {
rsprintf("<input type=text onChange=\"document.form1.submit()\""); rsprintf("<input type=text onChange=\"document.form1.submit()\"");
rsprintf(" name=\"%s\" value=\"%s\">\n", list[index], isparam(list[index]) ? getparam(list[index]) : ""); rsprintf(" name=\"%s\" value=\"%s\">\n", list[index],
isparam(list[index]) ? getparam(list[index]) : "");
} }
} else { } else {
rsprintf("<select name=\"%s\" onChange=\"document.form1.submit()\">\n", list[index]); rsprintf("<select name=\"%s\" onChange=\"document.form1.submit()\">\n", list[index]);
@ -16711,8 +16711,7 @@ void show_elog_list(LOGBOOK * lbs, int past_n, int last_n, int page_n, BOOL defa
if (msg_list[j].lbs == msg_list[index].lbs && msg_list[j].index == i) if (msg_list[j].lbs == msg_list[index].lbs && msg_list[j].index == i)
break; break;
if (page_mid && if (page_mid && msg_list[index].lbs->el_index[msg_list[index].index].message_id == page_mid)
msg_list[index].lbs->el_index[msg_list[index].index].message_id == page_mid)
page_mid_head = message_id; page_mid_head = message_id;
if (j < index) { if (j < index) {
@ -19500,7 +19499,8 @@ void show_elog_entry(LOGBOOK * lbs, char *dec_path, char *command)
/* check for locked attributes */ /* check for locked attributes */
for (i = 0; i < lbs->n_attr; i++) { for (i = 0; i < lbs->n_attr; i++) {
sprintf(lattr, "l%s", attr_list[i]); sprintf(lattr, "l%s", attr_list[i]);
if (isparam(lattr) == '1' && !(isparam(attr_list[i]) && strieq(getparam(attr_list[i]), attrib[i]))) if (isparam(lattr) == '1'
&& !(isparam(attr_list[i]) && strieq(getparam(attr_list[i]), attrib[i])))
break; break;
} }
if (i < lbs->n_attr) if (i < lbs->n_attr)
@ -21147,8 +21147,7 @@ void show_logbook_node(LBLIST plb, LBLIST pparent, int level, int btop)
rsprintf(plb->name); rsprintf(plb->name);
else { else {
if (getcfg_topgroup()) if (getcfg_topgroup())
rsprintf("<a href=\"%s/?gexp=%s\">+ %s</a> ", getcfg_topgroup(), plb->name, rsprintf("<a href=\"%s/?gexp=%s\">+ %s</a> ", getcfg_topgroup(), plb->name, plb->name);
plb->name);
else else
rsprintf("<a href=\".?gexp=%s\">+ %s</a> ", plb->name, plb->name); rsprintf("<a href=\".?gexp=%s\">+ %s</a> ", plb->name, plb->name);
} }
@ -21735,8 +21734,7 @@ void interprete(char *lbook, char *path)
int status, i, j, n, index, lb_index, message_id; int status, i, j, n, index, lb_index, message_id;
char exp[80], list[1000], section[256], str[NAME_LENGTH], str2[NAME_LENGTH], char exp[80], list[1000], section[256], str[NAME_LENGTH], str2[NAME_LENGTH],
enc_pwd[80], file_name[256], command[80], ref[256], enc_path[256], dec_path[256], enc_pwd[80], file_name[256], command[80], ref[256], enc_path[256], dec_path[256],
logbook[256], logbook_enc[256], *experiment, group[256], css[256], *pfile, logbook[256], logbook_enc[256], *experiment, group[256], css[256], *pfile, attachment[MAX_PATH_LENGTH];
attachment[MAX_PATH_LENGTH];
BOOL global; BOOL global;
LOGBOOK *lbs; LOGBOOK *lbs;
FILE *f; FILE *f;