Sun, 04 Sep 2011 02:32:49 -0400 | Dan Fuhry | SECURITY: Various security enhancements to password resets. They are now rate-limited by username and IP, and it is possible to disable username autofill for guests. | changeset | files |
Fri, 22 Jul 2011 23:14:06 -0400 | Dan Fuhry | Fixed CLI installer failing to set the DB version | changeset | files |
Tue, 12 Jul 2011 22:49:40 -0400 | Dan Fuhry | Release: 1.1.8pl1 | changeset | files |
Tue, 12 Jul 2011 22:34:02 -0400 | Dan Fuhry | Release prep 1.1.8pl1 | changeset | files |
Tue, 12 Jul 2011 22:21:08 -0400 | Dan Fuhry | SECURITY: CSRF protection in Private Messaging, which is a really broken feature and should get the TinyMCE treatment. *sigh* Reported by Secunia. | changeset | files |
Tue, 12 Jul 2011 22:15:18 -0400 | Dan Fuhry | SECURITY: Fixed XSS in post-login page redirection. Reported by Secunia. | changeset | files |