- 06 Nov, 2018 1 commit
-
-
Thomas Löffler authored
-
- 19 Jul, 2018 1 commit
-
-
Thomas Löffler authored
* Casts uploadComment to string before writing in DB
-
- 12 Jul, 2018 1 commit
-
-
Thomas Löffler authored
-
- 09 Mar, 2018 2 commits
-
-
Andreas Fernandez authored
-
Thomas Löffler authored
-
- 08 Mar, 2018 2 commits
-
-
Thomas Löffler authored
-
Thomas Löffler authored
-
- 12 Dec, 2017 1 commit
-
-
Thomas Löffler authored
-
- 09 Nov, 2017 2 commits
-
-
Thomas Löffler authored
-
Thomas Löffler authored
-
- 08 Nov, 2017 1 commit
-
-
Thomas Löffler authored
-
- 15 Oct, 2017 1 commit
-
-
Stefan Froemken authored
-
- 15 Sep, 2017 1 commit
-
-
Stefan Froemken authored
-
- 14 Sep, 2017 2 commits
-
-
Stefan Froemken authored
-
Markus Sommer authored
-
- 13 Sep, 2017 1 commit
-
-
Thomas Löffler authored
-
- 06 Sep, 2017 3 commits
-
-
Thomas Löffler authored
-
Helmut Hummel authored
Since we call the SOAP endpoint for certain actions of an authenticated user on extensions.typo3.org (like registering ext keys) and we do not know the password at this point any more, we now include the session id in the SOAP request, so that TYPO3 will login this user before the SOAP endpoint is triggered. In the endpoint, we can then just check if a user is already logged in and whether the username given matches the username of the logged in user.
-
Thomas Löffler authored
-
- 05 Sep, 2017 2 commits
-
-
Thomas Löffler authored
-
Thomas Löffler authored
-
- 01 Sep, 2017 1 commit
-
-
Helmut Hummel authored
By having an inverted condition, attackers could upload arbitrary extensions by only knowing the username and the extension key. When knowing a username of a TER admin, it was also possible to perform TER admin commands (like deleting extensions) via SOAP
-
- 11 Aug, 2017 3 commits
-
-
Thomas Löffler authored
-
Thomas Löffler authored
-
Thomas Löffler authored
-
- 10 Aug, 2017 1 commit
-
-
Thomas Löffler authored
-
- 28 Jul, 2017 1 commit
-
-
Thomas Löffler authored
-
- 19 Jul, 2017 1 commit
-
-
Jens Jacobsen authored
-
- 02 Mar, 2017 1 commit
-
-
Sascha Marcel Schmidt authored
-
- 27 Feb, 2017 1 commit
-
-
Sascha Marcel Schmidt authored
-