The NetBSD Project

CVS log for pkgsrc/www/contao35/distinfo

[BACK] Up to [cvs.NetBSD.org] / pkgsrc / www / contao35

Request diff between arbitrary revisions


Default branch: MAIN


Revision 1.36 / (download) - annotate - [select for diffs], Sun Apr 14 09:23:06 2019 UTC (5 weeks, 5 days ago) by taca
Branch: MAIN
CVS Tags: HEAD
Changes since 1.35: +5 -5 lines
Diff to previous 1.35 (colored)

www/contao35: update to 3.5.40

Version 3.5.40 (2019-04-10)
---------------------------

### Fixed
Fix the save callback in the back end password module (see #429).

Revision 1.34.4.1 / (download) - annotate - [select for diffs], Wed Apr 10 11:45:57 2019 UTC (6 weeks, 2 days ago) by bsiegert
Branch: pkgsrc-2019Q1
Changes since 1.34: +5 -5 lines
Diff to previous 1.34 (colored) next main 1.35 (colored)

Pullup ticket #5940 - requested by taca
www/contao35: security fix

Revisions pulled up:
- www/contao/Makefile.common                                    1.111
- www/contao/files/README                                       deleted
- www/contao/files/contao.conf                                  deleted
- www/contao35/Makefile                                         1.43
- www/contao35/distinfo                                         1.35

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Tue Apr  9 13:07:42 UTC 2019

   Modified Files:
   	pkgsrc/www/contao: Makefile.common
   Removed Files:
   	pkgsrc/www/contao/files: README contao.conf

   Log Message:
   www/contao: clean up

   Remove support files for Contao 4 and later.

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Tue Apr  9 13:09:17 UTC 2019

   Modified Files:
   	pkgsrc/www/contao35: Makefile distinfo

   Log Message:
   www/contao35: update to 3.5.39

   pkgsrc change: use SUBST_VARS.

   Version 3.5.39 (2019-04-09)
   ---------------------------

   ### Fixed
   Invalidate the user sessions if a password changes (see CVE-2019-10641).

Revision 1.35 / (download) - annotate - [select for diffs], Tue Apr 9 13:09:17 2019 UTC (6 weeks, 3 days ago) by taca
Branch: MAIN
Changes since 1.34: +5 -5 lines
Diff to previous 1.34 (colored)

www/contao35: update to 3.5.39

pkgsrc change: use SUBST_VARS.


Version 3.5.39 (2019-04-09)
---------------------------

### Fixed
Invalidate the user sessions if a password changes (see CVE-2019-10641).

Revision 1.34 / (download) - annotate - [select for diffs], Sat Dec 22 11:47:33 2018 UTC (5 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2019Q1-base, pkgsrc-2018Q4-base, pkgsrc-2018Q4
Branch point for: pkgsrc-2019Q1
Changes since 1.33: +5 -5 lines
Diff to previous 1.33 (colored)

www/contao35: update to 3.5.38

Version 3.5.38 (2018-12-21)
---------------------------

### Fixed
Correctly check the permission to move child records as non-admin user.

Revision 1.33 / (download) - annotate - [select for diffs], Sat Dec 15 16:42:19 2018 UTC (5 months, 1 week ago) by taca
Branch: MAIN
Changes since 1.32: +5 -5 lines
Diff to previous 1.32 (colored)

www/contao35: update to 3.5.37

Version 3.5.37 (2018-12-13)
---------------------------

### Fixed
Prevent information disclosure in the back end (see CVE-2018-20028).

Revision 1.31.2.1 / (download) - annotate - [select for diffs], Tue Sep 18 19:12:30 2018 UTC (8 months ago) by bsiegert
Branch: pkgsrc-2018Q2
Changes since 1.31: +5 -5 lines
Diff to previous 1.31 (colored) next main 1.32 (colored)

Pullup ticket #5836 - requested by taca
www/contao35: security fix

Revisions pulled up:
- www/contao35/Makefile                                         1.40
- www/contao35/distinfo                                         1.32

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Tue Sep 18 15:10:58 UTC 2018

   Modified Files:
   	pkgsrc/www/contao35: Makefile distinfo

   Log Message:
   www/contao35: update to 3.5.36

   Version 3.5.36 (2018-09-18)
   ---------------------------

   ### Fixed
   Prevent arbitrary code execution through .phar files (see CVE-2018-17057).

   ### Fixed
   Correctly reset the autologin data upon logout (#8868).

   ### Fixed
   Remove support for deprecated user password hashes (see #8889).

Revision 1.32 / (download) - annotate - [select for diffs], Tue Sep 18 15:10:57 2018 UTC (8 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2018Q3-base, pkgsrc-2018Q3
Changes since 1.31: +5 -5 lines
Diff to previous 1.31 (colored)

www/contao35: update to 3.5.36

Version 3.5.36 (2018-09-18)
---------------------------

### Fixed
Prevent arbitrary code execution through .phar files (see CVE-2018-17057).

### Fixed
Correctly reset the autologin data upon logout (#8868).

### Fixed
Remove support for deprecated user password hashes (see #8889).

Revision 1.30.2.1 / (download) - annotate - [select for diffs], Sun May 6 09:29:50 2018 UTC (12 months, 2 weeks ago) by spz
Branch: pkgsrc-2018Q1
Changes since 1.30: +5 -5 lines
Diff to previous 1.30 (colored) next main 1.31 (colored)

Pullup ticket #5743 - requested by taca
www/contao35: security update

Revisions pulled up:
- www/contao35/Makefile                                         1.39
- www/contao35/distinfo                                         1.31

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Mon Apr 23 14:00:18 UTC 2018

   Modified Files:
   	pkgsrc/www/contao35: Makefile distinfo

   Log Message:
   www/contao35: update to 3.5.35

   Version 3.5.35 (2018-04-18)
   ---------------------------

   ### Fixed
   Fix an XSS vulnerability in the system log (see CVE-2018-10125).

   CVE-2018-10125

   With a manipulated request, an attacker can implant a script which is executed
   when a logged in back end user opens the system log.  The attacker themselves
   does not have to be logged in.

   The problem affects Contao 3.0.0 to 3.5.34, 4.0.0 to 4.4.17 and 4.5.0 to
   4.5.7. We highly recommend you to update.


   To generate a diff of this commit:
   cvs rdiff -u -r1.38 -r1.39 pkgsrc/www/contao35/Makefile
   cvs rdiff -u -r1.30 -r1.31 pkgsrc/www/contao35/distinfo

Revision 1.31 / (download) - annotate - [select for diffs], Mon Apr 23 14:00:17 2018 UTC (13 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2018Q2-base
Branch point for: pkgsrc-2018Q2
Changes since 1.30: +5 -5 lines
Diff to previous 1.30 (colored)

www/contao35: update to 3.5.35

Version 3.5.35 (2018-04-18)
---------------------------

### Fixed
Fix an XSS vulnerability in the system log (see CVE-2018-10125).

CVE-2018-10125

With a manipulated request, an attacker can implant a script which is executed
when a logged in back end user opens the system log.  The attacker themselves
does not have to be logged in.

The problem affects Contao 3.0.0 to 3.5.34, 4.0.0 to 4.4.17 and 4.5.0 to
4.5.7. We highly recommend you to update.

Revision 1.30 / (download) - annotate - [select for diffs], Tue Mar 6 16:25:38 2018 UTC (14 months, 2 weeks ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2018Q1-base
Branch point for: pkgsrc-2018Q1
Changes since 1.29: +5 -5 lines
Diff to previous 1.29 (colored)

www/contao35: update to 3.5.34

Version 3.5.34 (2018-03-06)
---------------------------

### Fixed
Check the registry for table prefixed queries (see contao/core-bundle#1161).

### Fixed
Improve the folder hashing performance (see #8856).

### Fixed
Reset the autologin hash if the username or password changes (see #8843).

### Fixed
Correctly encode the sitemap URLs (see #8849).

Revision 1.29 / (download) - annotate - [select for diffs], Mon Jan 22 16:11:29 2018 UTC (16 months ago) by taca
Branch: MAIN
Changes since 1.28: +5 -5 lines
Diff to previous 1.28 (colored)

www/contao35: update to 3.5.33

Contao 3.5.33 is available			2018/01/22 10:08 by Leo Feyer

Contao version 3.5.33 is available.  The bugfix release restores the PHP 5.4
compatibility and fixes problems with MariaDB 10.2.4+ and MySQL 8.

PHP 5.4

Even if Contao 3.5 still supports PHP 5.4, we strongly advise against using
outdated PHP versions.  Contao 3.5 is compatible with the latest PHP versions,
therefore if the installed extensions allow it you should run it with PHP
7 or at least PHP 5.6.

Identifier Quoting

We have revised identifier quoting, which we had added to Contao 4.4.10, and
ported it to Contao 3, so Contao 3.5 should be compatible with MariaDB 10.2.4+
and MySQL 8 now.

Revision 1.27.2.1 / (download) - annotate - [select for diffs], Fri Jan 19 22:11:35 2018 UTC (16 months ago) by spz
Branch: pkgsrc-2017Q4
Changes since 1.27: +5 -5 lines
Diff to previous 1.27 (colored) next main 1.28 (colored)

Pullup ticket #5686 - requested by taca
www/contao35: security update

Revisions pulled up:
- www/contao35/Makefile                                         1.36
- www/contao35/PLIST                                            1.18
- www/contao35/distinfo                                         1.28

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Thu Jan 18 16:13:31 UTC 2018

   Modified Files:
   	pkgsrc/www/contao35: Makefile PLIST distinfo

   Log Message:
   www/contao35: update to 3.5.32

   Contao 3.5.32 is available		2018/01/18 09:48 by Leo Feyer

   Contao version 3.5.32 is available. The bugfix release fixes an XSS
   vulnerability in the newsletter extension (CVE-2018-5478).

   CVE-2018-5478

   The vulnerability is in the "unsubscribe" module of the newsletter extension
   and can easily be exploited by anyone in the front end. We therefore strongly
   recommend you to update.

   The problem affects Contao 2.0.0 to 3.5.31 and the Contao newsletter bundle
   4.0.0 to 4.0.3.

   If you are not using the newsletter extension or the "unsubscribe" module,
   your installation is not affected by the vulnerability.


   To generate a diff of this commit:
   cvs rdiff -u -r1.35 -r1.36 pkgsrc/www/contao35/Makefile
   cvs rdiff -u -r1.17 -r1.18 pkgsrc/www/contao35/PLIST
   cvs rdiff -u -r1.27 -r1.28 pkgsrc/www/contao35/distinfo

Revision 1.28 / (download) - annotate - [select for diffs], Thu Jan 18 16:13:31 2018 UTC (16 months ago) by taca
Branch: MAIN
Changes since 1.27: +5 -5 lines
Diff to previous 1.27 (colored)

www/contao35: update to 3.5.32

Contao 3.5.32 is available		2018/01/18 09:48 by Leo Feyer

Contao version 3.5.32 is available. The bugfix release fixes an XSS
vulnerability in the newsletter extension (CVE-2018-5478).

CVE-2018-5478

The vulnerability is in the "unsubscribe" module of the newsletter extension
and can easily be exploited by anyone in the front end. We therefore strongly
recommend you to update.

The problem affects Contao 2.0.0 to 3.5.31 and the Contao newsletter bundle
4.0.0 to 4.0.3.

If you are not using the newsletter extension or the "unsubscribe" module,
your installation is not affected by the vulnerability.

Revision 1.24.4.1 / (download) - annotate - [select for diffs], Sat Nov 25 08:49:25 2017 UTC (17 months, 4 weeks ago) by bsiegert
Branch: pkgsrc-2017Q3
Changes since 1.24: +5 -5 lines
Diff to previous 1.24 (colored) next main 1.25 (colored)

Pullup ticket #5647 - requested by taca
www/contao35: security fix

Revisions pulled up:
- www/contao35/Makefile                                         1.33-1.35
- www/contao35/PLIST                                            1.16-1.17
- www/contao35/distinfo                                         1.25-1.27

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Thu Sep 28 12:46:25 UTC 2017

   Modified Files:
   	pkgsrc/www/contao35: Makefile PLIST distinfo

   Log Message:
   www/contao35: update to 3.5.29

   Version 3.5.29 (2017-09-27)
   ---------------------------

   ### Fixed
   Correctly handle unencoded data images in the Combiner (see #8788).

   ### Fixed
   Correctly show multi-day events if the shortened view is disabled (see #8782).

   ### Fixed
   Do not add a suffix when copying if the "doNotCopy" flag is set (see #8610).

   ### Fixed
   Use the module type as group header if sorted by type (see #8402).

   ### Fixed
   Always show the "show from" and "show until" fields (see #8766).

   ### Fixed
   Encode the username when opening the front end preview as a member (see #8762).

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Sat Oct  7 13:01:17 UTC 2017

   Modified Files:
   	pkgsrc/www/contao35: Makefile distinfo

   Log Message:
   www/contao35: Update to 3.5.30.

   Version 3.5.30 (2017-10-06)
   ---------------------------

   ### Fixed
   Filter multi-day events outside the scope in the event list (see #8792).

   ### Fixed
   Correctly show multi-day events if the shortened view is disabled (see #8782).

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Wed Nov 15 14:07:53 UTC 2017

   Modified Files:
   	pkgsrc/www/contao35: Makefile PLIST distinfo

   Log Message:
   Update contaoet to 3.5.31.

   Version 3.5.31 (2017-11-15)
   ---------------------------

   ### Fixed
   Prevent SQL injections in the back end search panel (see CVE-2017-16558).

Revision 1.27 / (download) - annotate - [select for diffs], Wed Nov 15 14:07:53 2017 UTC (18 months, 1 week ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2017Q4-base
Branch point for: pkgsrc-2017Q4
Changes since 1.26: +5 -5 lines
Diff to previous 1.26 (colored)

Update contaoet to 3.5.31.

Version 3.5.31 (2017-11-15)
---------------------------

### Fixed
Prevent SQL injections in the back end search panel (see CVE-2017-16558).

Revision 1.26 / (download) - annotate - [select for diffs], Sat Oct 7 13:01:17 2017 UTC (19 months, 2 weeks ago) by taca
Branch: MAIN
Changes since 1.25: +5 -5 lines
Diff to previous 1.25 (colored)

www/contao35: Update to 3.5.30.

Version 3.5.30 (2017-10-06)
---------------------------

### Fixed
Filter multi-day events outside the scope in the event list (see #8792).

### Fixed
Correctly show multi-day events if the shortened view is disabled (see #8782).

Revision 1.25 / (download) - annotate - [select for diffs], Thu Sep 28 12:46:24 2017 UTC (19 months, 3 weeks ago) by taca
Branch: MAIN
Changes since 1.24: +5 -5 lines
Diff to previous 1.24 (colored)

www/contao35: update to 3.5.29

Version 3.5.29 (2017-09-27)
---------------------------

### Fixed
Correctly handle unencoded data images in the Combiner (see #8788).

### Fixed
Correctly show multi-day events if the shortened view is disabled (see #8782).

### Fixed
Do not add a suffix when copying if the "doNotCopy" flag is set (see #8610).

### Fixed
Use the module type as group header if sorted by type (see #8402).

### Fixed
Always show the "show from" and "show until" fields (see #8766).

### Fixed
Encode the username when opening the front end preview as a member (see #8762).

Revision 1.23.2.1 / (download) - annotate - [select for diffs], Sun Jul 16 08:16:42 2017 UTC (22 months, 1 week ago) by bsiegert
Branch: pkgsrc-2017Q2
Changes since 1.23: +5 -5 lines
Diff to previous 1.23 (colored) next main 1.24 (colored)

Pullup ticket #5513 - requested by taca
www/contao35: security fix

Revisions pulled up:
- www/contao35/Makefile                                         1.31
- www/contao35/distinfo                                         1.24

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Wed Jul 12 14:42:55 UTC 2017

   Modified Files:
   	pkgsrc/www/contao35: Makefile distinfo

   Log Message:
   Update contao35 to 3.5.28.

   Version 3.5.28 (2017-07-12)
   ---------------------------

   ### Fixed
   Prevent arbitrary PHP file inclusions in the back end (see CVE-2017-10993).

   ### Fixed
   Improve the accessibility of the CAPTCHA widget (see #8709).

   ### Fixed
   Fixed the iOS scrolling bug in the simple modal script (see #8708).

   ### Fixed
   Correctly cache the unique keys in the SQL cache (see #8712).

Revision 1.24 / (download) - annotate - [select for diffs], Wed Jul 12 14:42:55 2017 UTC (22 months, 1 week ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2017Q3-base, pkgsrc-
Branch point for: pkgsrc-2017Q3
Changes since 1.23: +5 -5 lines
Diff to previous 1.23 (colored)

Update contao35 to 3.5.28.

Version 3.5.28 (2017-07-12)
---------------------------

### Fixed
Prevent arbitrary PHP file inclusions in the back end (see CVE-2017-10993).

### Fixed
Improve the accessibility of the CAPTCHA widget (see #8709).

### Fixed
Fixed the iOS scrolling bug in the simple modal script (see #8708).

### Fixed
Correctly cache the unique keys in the SQL cache (see #8712).

Revision 1.23 / (download) - annotate - [select for diffs], Tue Apr 25 15:50:41 2017 UTC (2 years ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2017Q2-base
Branch point for: pkgsrc-2017Q2
Changes since 1.22: +5 -5 lines
Diff to previous 1.22 (colored)

Update contao35 to 3.5.27.

Version 3.5.27 (2017-04-25)
---------------------------

### Fixed
Revert the Punycode library changes (see #8693).

Revision 1.22 / (download) - annotate - [select for diffs], Sun Apr 23 14:56:37 2017 UTC (2 years, 1 month ago) by taca
Branch: MAIN
Changes since 1.21: +5 -5 lines
Diff to previous 1.21 (colored)

Update contao35 to 3.5.26.

Version 3.5.26 (2017-04-20)
---------------------------

### Fixed
Prevent endless loops in the book navigation module (see #8665).

### Fixed
Limit the maximum size of dimensionless SVGs in the back end (see #8684).

### Fixed
Correctly handle custom namespaces when combining DCA files (see #8682).

### Fixed
Also check the X-Forwarded-Proto header when determining HTTPS (see #8691).

### Fixed
Correctly support 64 character template names everywhere (see #6819).

### Updated
Updated the Punycode library to version 2 (see #8693).

### Fixed
Correctly use the en dash in the calendar modules (see #8690).

### Fixed
Remove the UTF-8 BOM when combining files (see #8689).

### Fixed
Do not add the CORS headers in the install tool (see #8681).

### Fixed
Correctly move folders with an "@" in their name (see #8674).

### Fixed
Correctly redirect to the last page visited upon login (see #8632).

### Fixed
Back port the e-mail extraction improvements (see #8679).

Revision 1.21 / (download) - annotate - [select for diffs], Mon Mar 20 16:48:20 2017 UTC (2 years, 2 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2017Q1-base, pkgsrc-2017Q1
Changes since 1.20: +5 -5 lines
Diff to previous 1.20 (colored)

Update contao35 to 3.5.25.

Version 3.5.25 (2017-03-20)
---------------------------

### Fixed
Only show error messages to authenticated users in the install tool (see #8666).

### Fixed
Always show the modal windows in full height (see #8631).

### Fixed
Support cross domain requests when rebuilding the search index (see #8597).

### Fixed
Correctly store numbers with leading zero in the Config class (see #4035).

### Fixed
Delete an old search entry if the new URL is more canonical (see #8647).

### Fixed
Also make Folder::$dirname an absolute path again (see #8325).

### Fixed
Support using namespaces and use statements in DCA/config files (see #8635).

Revision 1.20 / (download) - annotate - [select for diffs], Thu Jan 19 14:58:05 2017 UTC (2 years, 4 months ago) by taca
Branch: MAIN
Changes since 1.19: +5 -5 lines
Diff to previous 1.19 (colored)

Update contao35 to 3.5.24.

Version 3.5.24 (2017-01-19)
---------------------------

### Fixed
Correctly handle SVGZ files in the file manager (also fixes #8624).

### Fixed
Revert the download element changes (see #8620).

Revision 1.19 / (download) - annotate - [select for diffs], Tue Jan 17 16:23:08 2017 UTC (2 years, 4 months ago) by taca
Branch: MAIN
Changes since 1.18: +5 -5 lines
Diff to previous 1.18 (colored)

Update contao35 to 3.5.23.

Version 3.5.23 (2017-01-17)
---------------------------

### Fixed
Handle non-numeric values when calculating the image margin (see #8617).

### Fixed
Correctly generate the download elements in the back end (see #8620).


Version 3.5.22 (2017-01-16)
---------------------------

### Fixed
Prevent an endless redirect loop if the page alias is "/" (see #8560).

### Fixed
Correctly parse German dates with two digit years in MooTools (see #8593).

### Fixed
Correctly add new resources to the user/group permissions (see #8583).

### Fixed
Trigger the auto-submit function in the date picker (see #8603).

### Fixed
Call the load callback when loading page/file picker nodes (see #7702).

Revision 1.17.2.1 / (download) - annotate - [select for diffs], Sun Jan 8 19:37:43 2017 UTC (2 years, 4 months ago) by bsiegert
Branch: pkgsrc-2016Q4
Changes since 1.17: +5 -5 lines
Diff to previous 1.17 (colored) next main 1.18 (colored)

Pullup ticket #5180 - requested by taca
www/contao35: security fix

Revisions pulled up:
- www/contao35/Makefile                                         1.22
- www/contao35/distinfo                                         1.18

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Fri Dec 30 04:46:20 UTC 2016

   Modified Files:
   	pkgsrc/www/contao35: Makefile distinfo

   Log Message:
   Update contao35 to 3.5.21.

   Version 3.5.21 (2016-12-29)
   ---------------------------

   ### Updated
   Update SwiftMailer to version 5.4.5 (fixes CVE-2016-10074).

Revision 1.18 / (download) - annotate - [select for diffs], Fri Dec 30 04:46:19 2016 UTC (2 years, 4 months ago) by taca
Branch: MAIN
Changes since 1.17: +5 -5 lines
Diff to previous 1.17 (colored)

Update contao35 to 3.5.21.

Version 3.5.21 (2016-12-29)
---------------------------

### Updated
Update SwiftMailer to version 5.4.5 (fixes CVE-2016-10074).

Revision 1.17 / (download) - annotate - [select for diffs], Tue Dec 20 21:08:29 2016 UTC (2 years, 5 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2016Q4-base
Branch point for: pkgsrc-2016Q4
Changes since 1.16: +5 -5 lines
Diff to previous 1.16 (colored)

Update contao35 to 3.5.20 which includes potential XSS security problem.

Version 3.5.20 (2016-12-19)
---------------------------

### Fixed
Correctly show running repeated events in the event list (see #8588).

### Fixed
Improve the PHP 7.1 compatibility.

### Fixed
Keep the root nodes order in the page selector (see #8577).

### Fixed
Do not output invalid option values in widget error messages (see #8594).
Thanks to Pascal Gerundt for finding and reporting the issue.

### Fixed
Correctly parse english dates in MooTools (see #8573).

Revision 1.16 / (download) - annotate - [select for diffs], Wed Nov 16 16:29:34 2016 UTC (2 years, 6 months ago) by taca
Branch: MAIN
Changes since 1.15: +5 -5 lines
Diff to previous 1.15 (colored)

Update contao35 to 3.5.19.

Version 3.5.19 (2016-11-16)
---------------------------

### Fixed
Only evaluate `hasDetails()` and `hasText()` upon the first call.

### Fixed
Cache the `PageModel::findPublishedFallbackByHostname()` results (see #8544).

### Fixed
Correctly redirect to the website root page (see #8552).

### Fixed
Continue rebuilding the search index if there are errors (see #8541).

Revision 1.15 / (download) - annotate - [select for diffs], Tue Oct 25 16:27:05 2016 UTC (2 years, 6 months ago) by taca
Branch: MAIN
Changes since 1.14: +5 -5 lines
Diff to previous 1.14 (colored)

Update contao35 to 3.5.18.

It also welcome back to Danish and Slovenian.

Version 3.5.18 (2016-10-25)
---------------------------

### Fixed
Correctly "toggle select" nodes that are loaded via Ajax (see #8535).

### Fixed
Show running events in the event list again (see #8497).

### Fixed
Correctly calculate the maximum length of tl_files.name (see #8536).

### Fixed
Correctly add the headline if a content element is versionized (see #8502).

### Fixed
Optimize the DCA sorting filter for date fields (see #8485).

### Fixed
Do not show version entries of deleted files (see #8480).

### Fixed
Redirect the empty URL depending on language and alias name (see #8498).

### Fixed
Apply `specialchars()` to widget attributes (see #8505).

### Updated
Updated the Ace code editor to version 1.1.9.

### Fixed
Handle special characters in passwords when creating an admin user (see #8512).

### Fixed
Queue the requests when rebuilding the search index (see #8449).

Revision 1.14 / (download) - annotate - [select for diffs], Sat Sep 24 13:23:23 2016 UTC (2 years, 7 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2016Q3-base, pkgsrc-2016Q3
Changes since 1.13: +5 -5 lines
Diff to previous 1.13 (colored)

Update contao35 to 3.5.17.  This is a leaf package.

Version 3.5.17 (2016-09-20)
---------------------------

### Fixed
Handle special character passwords in the "close account" module (see #8455).

### Fixed
Handle broken SVG files in the Image and File class (see #8470).

### Fixed
Reduce the maximum field length by the file extension length (see #8472).

### Fixed
Fall back to the field name if there is no label (see #8461).

### Fixed
Do not assume NULL by default for binary fields (see #8477).

### Fixed
Correctly render the diff view if not the latest version is active (see #8481).

### Fixed
Update the list of countries and languages (see #8453).

### Fixed
Correctly set up the MooTools CDN URL (see #8458).

### Fixed
Also check the URL length when determining the search URL (see #8460).

### Fixed
Only regenerate the session ID upon login.

Revision 1.13 / (download) - annotate - [select for diffs], Thu Sep 8 03:26:48 2016 UTC (2 years, 8 months ago) by taca
Branch: MAIN
Changes since 1.12: +5 -5 lines
Diff to previous 1.12 (colored)

Update contao35 to 3.5.16.

Version 3.5.16 (2016-09-05)
---------------------------

### Fixed
Check if a reader page is protected when generating a sitemap (see #8416).

### Fixed
Support all characters but =!<> and whitespace in simple tokens (see #8436).

### Fixed
Check the user's permission when generating links in the picker (see #8407).

### Fixed
Handle forward pages without target in the navigation modules (see #8377).

### Fixed
Stop the event recurrence if the upper boundary is reached (see #8445).

### Fixed
Show upcoming events if the first occurrence is in the past (see #8447).

### Updated
Update MooTools to version 1.5.2.

### Fixed
Provide the same template variables for downloads and enclosures (see #8392).

### Fixed
Handle %n when parsing date formats (see #8411).

### Fixed
Fix the module wizard's accessibility (see #8391).

### Fixed
Correctly initialize TinyMCE in sub-palettes in Firefox (see #3673).

### Fixed
Validate form field names more accurately (see #8403).

### Fixed
Correctly show the ctime, mtime and atime of a folder (see #8408).

### Fixed
Correctly index changed pages (see #8439).

### Fixed
Always store the UUID of an uploaded file (see #8421).

Revision 1.11.2.1 / (download) - annotate - [select for diffs], Thu Jul 28 16:11:34 2016 UTC (2 years, 9 months ago) by spz
Branch: pkgsrc-2016Q2
Changes since 1.11: +5 -5 lines
Diff to previous 1.11 (colored) next main 1.12 (colored)

Pullup ticket #5061 - requested by taca
www/contao35: security update

Revisions pulled up:
- www/contao35/Makefile                                         1.15
- www/contao35/PLIST                                            1.9
- www/contao35/distinfo                                         1.12

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Sun Jul 17 13:58:00 UTC 2016

   Modified Files:
   	pkgsrc/www/contao35: Makefile PLIST distinfo

   Log Message:
   Update contao35 to 3.5.15, including fix for CVE-2016-4567.

   Version 3.5.15 (2016-07-15)
   ---------------------------

   ### Fixed
   Strip soft hyphens when indexing a page (see #8389).

   ### Fixed
   Update mediaelement.js to version 2.21.2 (fixes CVE-2016-4567).


   To generate a diff of this commit:
   cvs rdiff -u -r1.14 -r1.15 pkgsrc/www/contao35/Makefile
   cvs rdiff -u -r1.8 -r1.9 pkgsrc/www/contao35/PLIST
   cvs rdiff -u -r1.11 -r1.12 pkgsrc/www/contao35/distinfo

Revision 1.12 / (download) - annotate - [select for diffs], Sun Jul 17 13:58:00 2016 UTC (2 years, 10 months ago) by taca
Branch: MAIN
Changes since 1.11: +5 -5 lines
Diff to previous 1.11 (colored)

Update contao35 to 3.5.15, including fix for CVE-2016-4567.

Version 3.5.15 (2016-07-15)
---------------------------

### Fixed
Strip soft hyphens when indexing a page (see #8389).

### Fixed
Update mediaelement.js to version 2.21.2 (fixes CVE-2016-4567).

Revision 1.11 / (download) - annotate - [select for diffs], Thu Jun 16 17:21:35 2016 UTC (2 years, 11 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2016Q2-base
Branch point for: pkgsrc-2016Q2
Changes since 1.10: +5 -5 lines
Diff to previous 1.10 (colored)

Update contao35 to 3.5.14.

Version 3.5.14 (2016-06-16)
---------------------------

### Fixed
Validate the settings when loading a recurring event (see #8286).

### Fixed
Also check for the back end cookie when loading from cache (see #8249).

### Fixed
Unset "mode" and "pid" upon save and edit (see #8292).

### Fixed
Always use the relative path in DC_Folder (see #8370).

Revision 1.10 / (download) - annotate - [select for diffs], Thu Jun 16 15:47:19 2016 UTC (2 years, 11 months ago) by taca
Branch: MAIN
Changes since 1.9: +5 -5 lines
Diff to previous 1.9 (colored)

Update contao35 to 3.5.13.

Version 3.5.13 (2016-06-15)
---------------------------

### Fixed
Use the correct empty value when resetting copied fields (see #8365).

### Fixed
Remove the "required" attribute if a subpalette is closed (see #8192).

### Fixed
Correctly generate the feed links in a multi-domain setup (see #8329).

### Fixed
Correctly calculate the maximum file size for DropZone (see #8098).

### Fixed
Do not adjust the start date of a multi-day event (see #8194).

### Fixed
Versionize and show password changes (see #8301).

### Fixed
Make File::$dirname an absolute path again (see #8325).

### Fixed
Store the full URLs in the search index (see contao/core-bundle#491).

### Fixed
Standardize the group names in the checkbox widget (see #8002).

### Fixed
Prevent models from being registered twice (see #8224).

### Fixed
Prevent horizontal scrolling in the ACE editor (see #8328).

### Fixed
Correctly render the breadcrumb links in the template editor (see #8341).

### Fixed
Remove the role attributes from the navigation templates (see #8343).

### Fixed
Do not add `role="tablist"` to the accordion container (see #8344).

Revision 1.9 / (download) - annotate - [select for diffs], Sat Apr 23 12:40:42 2016 UTC (3 years, 1 month ago) by taca
Branch: MAIN
Changes since 1.8: +5 -5 lines
Diff to previous 1.8 (colored)

Update contao35 to 3.5.12.

Version 3.5.12 (2016-04-22)
---------------------------

### Fixed
Correctly handle files with uppercase file extensions (see #8317).


Version 3.5.11 (2016-04-21)
---------------------------

### Fixed
Correctly pass the channel ID to the newsletter list template (see #8311).

### Fixed
Do not encode the database password (see #8314).

### Fixed
Fixed adding new folders in the file manager (see #8315).


Version 3.5.10 (2016-04-20)
---------------------------

### Fixed
Always trigger the "isVisibleElement" hook (see #8312).

### Fixed
Do not change all sessions when switching users (see #8158).

### Fixed
Do not allow to close fieldsets with empty required fields (see #8300).

### Fixed
Make the path related properties of the File class binary-safe (see #8295).

### Fixed
Always allow to navigate to the current month in the calendar (see #8283).

### Fixed
Correctly validate and decode IDNA e-mail addresses (see #8306).

### Fixed
Do not add the debug bar resources if `hideDebugBar` is enabled (see #8307).

### Fixed
Skip forward pages entirely in the book navigation module (see #5074).

### Fixed
Do not add the X-Priority header in the Email class (see #8298).

### Fixed
Fix an error message in the newsletter subscription module (see #7887).

### Fixed
Determine the search index checksum in a more reliable way (see #7652).

Revision 1.8 / (download) - annotate - [select for diffs], Tue Mar 22 16:57:55 2016 UTC (3 years, 2 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2016Q1-base, pkgsrc-2016Q1
Changes since 1.7: +5 -5 lines
Diff to previous 1.7 (colored)

Update contao35 to 3.5.9, a leaf package.

Version 3.5.9 (2016-03-21)
--------------------------

### Fixed
Prevent the autofocus attribute from being added multiple times (see #8281).

### Fixed
Respect the SSL settings of the root page when generating sitemaps (see #8270).

### Fixed
Read from the temporary file if it has not been closed yet (see #8269).

### Fixed
Always use HTTPS if the target server supports SSL connections (see #8183).

### Fixed
Adjust the meta wizard field length to the column length (see #8277).

### Fixed
Correctly handle custom mime icon paths (see #8275).

### Fixed
Only log errors that have been configured to get logged (see #8267).

### Fixed
Show the 404 error page if an unpublished article is requested (see #8264).

### Fixed
Correctly count the URLs when rebuilding the search index (see #8262).

### Fixed
Ensure that every image has a width and height attribute (see #8162).

### Fixed
Set the correct mime type when embedding SVG images (see #8245).

### Fixed
Handle the "float_left" and "float_right" classes in the back end (see #8239).

### Fixed
Consider the fallback language if a page alias is ambiguous (see #8142).

### Fixed
Fix the error 403/404 redirect (see contao/website#74).

Revision 1.7 / (download) - annotate - [select for diffs], Sat Mar 5 06:16:44 2016 UTC (3 years, 2 months ago) by taca
Branch: MAIN
Changes since 1.6: +5 -5 lines
Diff to previous 1.6 (colored)

Update contao35 to 3.5.8.

Version 3.5.8 (2016-03-01)
--------------------------

### Fixed
Re-add the `$blnFixDomain` argument to keep backwards compatibility.


Version 3.5.7 (2016-02-29)
--------------------------

### Fixed
Always fix the domain and language when generating URLs (see #8238).

### Fixed
Fix two issues with the flexible back end theme (see #8227).

### New
Added new versioning hooks (see #8168).

 * "oncreate_version_callback" (supersedes "onversion_callback")
 * "onrestore_version_callback" (supersedes "onrestore_callback")

### Fixed
Correctly toggle custom page type icons (see #8236).

### Fixed
Fix the domain in all article, news, event and FAQ insert tags (see #8204).

### Fixed
Update mediaelement.js to version 2.19.0.1 (see #8217).

### Fixed
Correctly render the links in the monthly/yearly event list menu (see #8140).

### Fixed
Skip the registration related fields if a user is duplicated (see #8185).

### Fixed
Correctly show the form field type help text (see #8200).

### Fixed
Correctly create the initial version of a record (see #8141).

### Fixed
Correctly show the "expand preview" buttons (see #8146).

### Fixed
Correctly check that a password does not match the username (see #8209).

### Fixed
Check if a directory exists before executing `mkdir()` (see #8150).

### Fixed
Do not link to the maintenance module if the user cannot access it (see #8151).

### Fixed
Show the "new folder" button in the template manager (see #8138).

Revision 1.6 / (download) - annotate - [select for diffs], Sat Nov 28 05:45:42 2015 UTC (3 years, 5 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2015Q4-base, pkgsrc-2015Q4
Changes since 1.5: +5 -5 lines
Diff to previous 1.5 (colored)

Update contao35 to 3.5.6.

Version 3.5.6 (2015-11-27)
--------------------------

### Fixed
Correctly determin the protocol delimiter in `Idna::encodeUrl()`.

### Fixed
Handle relative URLs when following redirects in the Request class (see #7799).

### Fixed
Correctly handle empty UUIDs when comparing versions (see #7971).

### Fixed
Remove the "required" attribute when setting up TinyMCE (see #8131).


Version 3.5.5 (2015-11-25)
--------------------------

### Fixed
Fix the domain when forwarding in the page controllers (see #8123).

### Fixed
Use the feed URL instead of the base URL for enclosures (see #8116).

### Fixed
Fix the `<time>` tags and standardize the event templates (see #8012).

### Fixed
Handle empty `href` attributes in the book navigation (see #8104).

### Fixed
Do not store e-mail addresses in the newsletter (un)subscription log.

### Fixed
Correctly encrypt fields upon registration (see #8110).

### Fixed
Correctly render required single checkboxes in the back end (see #7731).

### Fixed
Correctly store multi select menus if no value is selected (see #7760).

### Fixed
Prevent recursion when rendering 403/404 pages (see #8060).

### Fixed
Map the `FileTree` widget to `FormFileUpload` in the front end (see #8091).

### Fixed
Preserve the user input when loading image meta data (see #8108).

### Fixed
Show the "toggle all" buttons in "edit multiple" mode (see #5622).

### Fixed
Disable the gallery pagination if the images are sorted randomly (see #8033).

### Fixed
Set the correct empty value when copying elements (see #8064).

### Fixed
Correctly hide forward pages with no public subpages (see #8054).

### Fixed
Correctly render the page picker if the value starts with `#` (see #8055).

### Fixed
Correctly render the "group" option in the radio button and checkbox widgets.

### Fixed
Correctly set the ID when toggling fields via Ajax (see #8043).

### Fixed
Support call, sms and app hyperlinks when converting relative URLs (see #8102).

### Fixed
Correctly check if a folder is protected when loading subfolders.

### Fixed
Correctly check the synchronization status when copying or moving files.

### Fixed
Adjust the code to be compatible with PHP7 (see #8018).

### Fixed
Correctly show the UUID in the back end file manager popup (see #8058).

Revision 1.5 / (download) - annotate - [select for diffs], Wed Nov 4 02:46:51 2015 UTC (3 years, 6 months ago) by agc
Branch: MAIN
Changes since 1.4: +2 -1 lines
Diff to previous 1.4 (colored)

Add SHA512 digests for distfiles for www category

Problems found locating distfiles:
	Package haskell-cgi: missing distfile haskell-cgi-20001206.tar.gz
	Package nginx: missing distfile array-var-nginx-module-0.04.tar.gz
	Package nginx: missing distfile encrypted-session-nginx-module-0.04.tar.gz
	Package nginx: missing distfile headers-more-nginx-module-0.261.tar.gz
	Package nginx: missing distfile nginx_http_push_module-0.692.tar.gz
	Package nginx: missing distfile set-misc-nginx-module-0.29.tar.gz
	Package nginx-devel: missing distfile echo-nginx-module-0.58.tar.gz
	Package nginx-devel: missing distfile form-input-nginx-module-0.11.tar.gz
	Package nginx-devel: missing distfile lua-nginx-module-0.9.16.tar.gz
	Package nginx-devel: missing distfile nginx_http_push_module-0.692.tar.gz
	Package nginx-devel: missing distfile set-misc-nginx-module-0.29.tar.gz
	Package php-owncloud: missing distfile owncloud-8.2.0.tar.bz2

Otherwise, existing SHA1 digests verified and found to be the same on
the machine holding the existing distfiles (morden).  All existing
SHA1 digests retained for now as an audit trail.

Revision 1.4 / (download) - annotate - [select for diffs], Mon Oct 12 05:47:19 2015 UTC (3 years, 7 months ago) by taca
Branch: MAIN
Changes since 1.3: +4 -4 lines
Diff to previous 1.3 (colored)

Update contao35 to 3.5.4.

Version 3.5.4 (2015-10-09)
--------------------------

### Fixed
Do not add the back end language in the meta wizard (see #8056).

### Fixed
Do not add excluded files to the DBAFS if they are edited in the file manager.

### Fixed
Add the `|flatten` insert tag flag to handle arrays (see #8021).

### Fixed
Check for excluded folders in the back end file popup (see #8003).

### Fixed
Fixed a wrong option name when initializing sortables (see #8053).

### Fixed
Translate UUIDs to paths in the parent view header fields.

### Fixed
Trigger the options_callback for the parent view header fields (see #8031).

### Fixed
Correctly create the initial version of a member without username (see #8037).

### Fixed
Improve the performance of the debug bar (see #7839).

### Fixed
Correctly output the event details in the `event_list` template (see #8041).

### Fixed
Only modify empty `href` attributes in the `nav_` template (see #8006, #8038).

### Fixed
Correctly show the group headlines in the repository DB updater (see #8020).

### Fixed
Improve the e-mail regex to also match the new TLDs (see #7984).

### Fixed
Ensure that the database port is not empty (see #7950).

### Fixed
Remove the left-over usages of `$this->v2warning` (see #8027).

### Fixed
Support the `hasDetails` variable in the event reader (see #8011).

Revision 1.3 / (download) - annotate - [select for diffs], Sun Sep 13 02:22:47 2015 UTC (3 years, 8 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2015Q3-base, pkgsrc-2015Q3
Changes since 1.2: +4 -4 lines
Diff to previous 1.2 (colored)

Update contao35 to 3.5.3.  Latvian language was added, too.

Version 3.5.3 (2015-09-10)
--------------------------

### Fixed
Correctly handle dimensionless SVG images (see #7882).

### Fixed
Correctly fill in the image meta data in news, events and FAQs (see #7907).

### Fixed
Enable the `strictMath` option of the LESS parser (see #7985).

### Fixed
Consider the pagination menu when inserting at the top (see #7895).

### Fixed
Use en-dashes in event intervals (see #7978).

### Fixed
Store the correct edit URL in the back end personal data module (see #7987).

### Fixed
Adjust the breadcrumb trail when creating new folders (see #7980).

### Fixed
Use `$this->hasText` in news and event templates (see #7993).

### Fixed
Convert the HTML content to XHTML when generating Atom feeds (see #7996).

### Fixed
Correctly link the items in the files breadcrumb menu (see #7965).

### Fixed
Handle explicit collations matching the default collation (see #7979).

### Fixed
Fix the duplicate content check in the front end controller (see #7661).

### Fixed
Correctly parse dates in MooTools (see #7983).

### Fixed
Register the related models in the registry (see contao/core-bundle#333).

### Fixed
Correctly escape in the `findMultipleFilesByFolder()` method (see #7966).

### Fixed
Override the tabindex handling of the accordion to ensure that the togglers are
always focusable via keyboard (see #7963).

### Fixed
Correctly generate the news and event menu URLs (see #7953).

### Fixed
Check the script when storing the front end referer (see #7908).

### Fixed
Fix the back end pagination menu (see #7956).

### Fixed
Handle option callbacks in the back end help (see #7951).

### Fixed
Fixed the external links in the text field help wizard (see #7954) and the
keyboard shortcuts link on the back end start page (see #7935).

### Fixed
Fixed the CSS group field explanations (see #7949).

### Fixed
Use ./ instead of an empty href (see #7967).

### Fixed
Correctly detect Microsoft Edge (see #7970).

### Fixed
Respect the "order" parameter in the `findMultipleByIds()` method (see #7940).

### Fixed
Always trigger the "parseDate" hook (see #4260).

### Fixed
Allow to instantiate the `InsertTags` class (see #7946).

### Fixed
Do not parse the image `src` attribute to determine the state of an element,
because the image path might have been replaced with a `data:` string (e.g. by
the Apache module "mod_pagespeed").

Revision 1.2 / (download) - annotate - [select for diffs], Sun Jul 26 17:18:35 2015 UTC (3 years, 9 months ago) by taca
Branch: MAIN
Changes since 1.1: +4 -4 lines
Diff to previous 1.1 (colored)

Update contao35 to 3.5.2.

* Add Serbian language files.

Version 3.5.2 (2015-07-24)
--------------------------

### Fixed
Revert some of the PhpStorm code inspector changes (see #7937).


Version 3.5.1 (2015-07-24)
--------------------------

### Fixed
Add a `StringUtil` class to restore PHP 7 compatibility (see contao/core-bundle#309).

### Fixed
Fix the `Validator::isEmail()` method (see contao/core-bundle#313).

### Fixed
Strip tags before auto-generating aliases (see #7857).

### Fixed
Correctly encode the URLs in the popup file manager (see #7929).

### Fixed
Check for the comments module when compiling the news meta fields (see #7901).

### Fixed
Also sort the newsletter channels alphabetically in the front end (see #7864).

### Fixed
Disable responsive images in the back end preview (see #7875).

### Fixed
Overwrite the request string when generating news/event feeds (see #7756).

### Fixed
Store the static URLs with the cached file (see #7914).

### Fixed
Correctly check the subfolders in the `hasAccess()` method (see #7920).

### Fixed
Updated the countries list (see #7918).

### Fixed
Respect the `notSortable` flag in the parent (see #7902).

### Fixed
Round the maximum upload size to an integer value (see #7880).

### Fixed
Make the markup minification less aggressive (see #7734).

### Fixed
Filter the indices in `Database::getFieldNames()` (see #7869).

### Fixed
Back-ported two fixes from the upstream versions.

Revision 1.1 / (download) - annotate - [select for diffs], Sat Jun 6 03:41:24 2015 UTC (3 years, 11 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2015Q2-base, pkgsrc-2015Q2

Add Contao 3.5.0 package.

Contao is an Open Source PHP Content Management System for people who want a
professional website that is easy to maintain. Visit the https://contao.org
for more information.

This is new Long Term Support release which replase existing Contao 3.2
and the last stable release from Contao 3.x series.

Please refer system/docs/CHANGELOG.md in detail.

This form allows you to request diff's between any two revisions of a file. You may select a symbolic revision name using the selection box or you may type in a numeric name using the type-in text box.




CVSweb <webmaster@jp.NetBSD.org>