Commit Graph

1990 Commits

Author SHA1 Message Date
Paula Quispe
5beb7623b3 HOR-4070 2017-11-13 11:19:23 -04:00
Paula Quispe
32bfcd2121 release/3.2.2 2017-11-03 09:53:47 -04:00
Marco Antonio Nina Mena
33a6e236b9 HOR-4017 CLONE 3.2.2 - Unauthenticated download of any file from server with "processes/processes_GetFile" page + Path Traversal
- Add validation path only PATH_DATA_MAILTEMPLATES or PATH_DATA_PUBLIC
2017-10-30 08:31:21 -04:00
Paula Quispe
dc5d17241a HOR-3900 2017-10-24 14:06:54 -04:00
Paula Quispe
81c90278bd release/3.2.2 to develop conflicts 2017-10-23 11:37:41 -04:00
dante
21e1912fd5 moving sanitization to file names of output documents only 2017-10-20 14:38:10 -04:00
Paula Quispe
5327ecdfd5 HOR-3926 2017-10-20 12:00:11 -04:00
davidcallizaya
2a81bba175 HOR-3956
Fix CR
2017-10-20 12:00:11 -04:00
davidcallizaya
7d99f1e69e HOR-3956
+ Enable access to guest user to use the PM_CASES.
+ Add PM_DASHBOARD permission to KPIs.
+ Add internal permission alias:
RBAC->userCanAccess()
     * Verify if the user has a right over the permission. Ex.
     *      $rbac->userCanAccess("PM_CASES");
     *
     * Alias of permissions:
     *      PM_CASES has alias: PM_GUES_CASE
     * This means that a role with PM_GUES_CASE could access like one with PM_CASES
     * unless the permission is required as strict, like this:
     *      $rbac->userCanAccess("PM_CASES/strict");
2017-10-20 12:00:10 -04:00
davidcallizaya
ed32b004f1 HOR-3946
Fix guest username.
2017-10-20 12:00:10 -04:00
Roly Rudy Gutierrez Pinto
69f26c6eee HOR-3926 2017-10-20 12:00:09 -04:00
Roly Rudy Gutierrez Pinto
77b828d67a HOR-3926 2017-10-20 12:00:09 -04:00
Roly Rudy Gutierrez Pinto
fb4a8a4bc3 HOR-3926 2017-10-20 12:00:08 -04:00
Roly Rudy Gutierrez Pinto
465264d57c HOR-3926 2017-10-20 12:00:08 -04:00
davidcallizaya
2509ba1612 HOR-3925
Fix CR observations
2017-10-20 12:00:08 -04:00
davidcallizaya
128e42e71e HOR-3925
Create a user guest by default.
2017-10-20 12:00:08 -04:00
Paula Quispe
dd317925c5 Merged in release/3.2.2 (pull request #6128)
release/3.2.2

Approved-by: Paula Quispe <paula.quispe@processmaker.com>
2017-10-20 12:47:58 +00:00
Marco Antonio Nina Mena
37b2a39c9f Merged in bugfix/HOR-3858 (pull request #6106)
HOR-3858

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
Approved-by: Paula Quispe <paula.quispe@processmaker.com>
2017-10-19 22:01:43 +00:00
Dante Loayza
9cf97125e0 Merged in bugfix/HOR-3845 (pull request #6125)
HOR-3845

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
Approved-by: Paula Quispe <paula.quispe@processmaker.com>
2017-10-19 22:00:42 +00:00
Paula Quispe
28f3e5b97e Merged in bugfix/HOR-3980 (pull request #6121)
HOR-3980

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
Approved-by: Paula Quispe <paula.quispe@processmaker.com>
2017-10-19 19:20:04 +00:00
dante
305585b874 change to static self reference form to call methods 2017-10-19 10:59:28 -04:00
dante
31b12efbb5 HOR-3845 2017-10-19 10:53:56 -04:00
Paula Quispe
adc0c23acf HOR-3980 2017-10-18 16:02:20 -04:00
Paula Quispe
8b2e2147d9 HOR-3834 2017-10-13 15:58:40 -04:00
Marco Antonio Nina Mena
99700467b8 HOR-3858 Unauthenticated download of any file from server with "processes/processes_GetFile" page + Path Traversal
- Add validation path only PATH_DATA_MAILTEMPLATES or PATH_DATA_PUBLIC
- exists process uid
2017-10-10 16:18:22 -04:00
Roly Rudy Gutierrez Pinto
8ac8e50691 HOR-3851 2017-10-10 12:33:25 -04:00
Roly Rudy Gutierrez Pinto
216e2dca28 HOR-3851 2017-10-06 17:21:21 -04:00
Roly
ac313f342c Merged in bugfix/HOR-3221 (pull request #6052)
HOR-3221

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
2017-09-25 20:36:16 +00:00
Roly
01d98368da Merged in bugfix/HOR-3182 (pull request #6067)
HOR-3182

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
2017-09-20 18:27:22 +00:00
Paula Quispe
63268cb835 Merged in bugfix/HOR-3508 (pull request #6068)
HOR-3508

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
2017-09-20 16:25:35 +00:00
Paula Quispe
37cc674010 HOR-3508 2017-09-19 13:26:57 -04:00
Julio Cesar Laura Avendaño
3605a634e7 Merged in release/3.2.2 (pull request #6069)
Updating branch release/3.2.3 with the last changes made on branch release/3.2.2 (second PR)

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
2017-09-19 16:09:20 +00:00
Roly Rudy Gutierrez Pinto
59fc56265a HOR-3221 improvement 2017-09-19 11:19:45 -04:00
Roly Rudy Gutierrez Pinto
381985824c HOR-3182 2017-09-18 16:17:39 -04:00
Paula Quispe
39c01c23de Merged in bugfix/HOR-3850 (pull request #6049)
HOR-3850

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
2017-09-15 14:18:25 +00:00
Julio Cesar Laura Avendaño
9dec186a1a Merged in release/3.2.2 (pull request #6059)
Updating branch release/3.2.3 with the last changes made on branch release/3.2.2

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
2017-09-14 19:48:06 +00:00
Paula Quispe
7705525261 Merged in bugfix/HOR-3866 (pull request #6047)
HOR-3866

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
2017-09-14 18:56:05 +00:00
Julio Cesar Laura Avendaño
ebb6c276df HOR-3861 2017-09-12 15:16:07 -04:00
Paula Quispe
2bbad9904b HOR-3850 2017-09-12 14:42:10 -04:00
Paula Quispe
32927ea06b HOR-3866 2017-09-12 12:13:05 -04:00
Fabio Guachalla
22e026bb46 FBI-841:incorrect window size on insert/editTable 2017-09-11 16:21:04 -04:00
hjonathan
ec971836e8 HOR-3821
update
2017-09-01 15:04:34 -04:00
David Callizaya
7984499571 HOR-3769
Compatibility fixes for PowerUp plugin.
2017-08-25 15:44:53 -04:00
David Callizaya
30cf5568fc Merged in bugfix/HOR-3768 (pull request #5997)
HOR-3768

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
2017-08-22 19:15:50 +00:00
David Callizaya
480488ad49 HOR-3768
Fix compatibility errors with PHP 5.6
2017-08-22 14:37:54 -04:00
David Callizaya
bfe2b7ec38 HOR-3700
Fix Tree ambiguos class. Resolved renaming Tree to PmTree
2017-08-21 10:39:10 -04:00
Marco A. Nina Mena
18e14b3ba8 Fix name class dashboards 2017-08-17 18:24:05 -04:00
David Callizaya
1b8d210282 HOR-3700
Implement factory for adapters used for dashlets and ldap.
2017-08-17 17:19:43 -04:00
Roly Rudy Gutierrez Pinto
8c195a1b4b HOR-3700-RG 2017-08-16 16:15:08 -04:00
dante
3db607af2d LoadAllModelClasses in correction 2017-08-15 16:29:20 -04:00