437 Commits

Author SHA1 Message Date
Pablo Zmdl
6a6d331509 Ensure correct permissions and absence of ACLs in files for release
Some combinations of sed executed on virtiofs-mounted file systems produce
files with wrong permissions (0600) and ACLs set, which we want to avoid. This
change makes sure of that.

Signed-off-by: Pablo Zmdl <pablo@nextcloud.com>
2026-02-13 21:14:37 +01:00
Aleksander Machniak
c1acfe677a Installer: Fix broken link to download the created configuration file (#10092) 2026-02-12 14:38:59 +01:00
Aleksander Machniak
8dac75abbd Fix CSS injection vulnerability reported by CERT Polska 2026-02-08 09:24:29 +01:00
Aleksander Machniak
26d7677471 Fix remote image blocking bypass via SVG content reported by nullcathedral 2026-02-08 09:21:34 +01:00
Aleksander Machniak
609124d94f OAuth: Add oauth_auth_type option 2026-01-25 13:03:05 +01:00
Aleksander Machniak
75dbc2fe11 OAuth: Fix bug where it was impossible to login again after logout (#10073) 2026-01-25 12:26:43 +01:00
Aleksander Machniak
343c6a0c2d Update changelog
[skip ci]
2026-01-25 10:16:14 +01:00
Aleksander Machniak
719b8be259 Fix handling of string-list format values for date tests in Out of Office (#10075) 2026-01-25 09:42:52 +01:00
Aleksander Machniak
cb7f2d0066 Fix a UI issue on using browser Back button after allowing remote resources (#10062) 2026-01-04 13:34:43 +01:00
Aleksander Machniak
42794a40aa Support request_url config option for resolving relative URLs (#9868) 2026-01-01 15:14:18 +01:00
Aleksander Machniak
7a3843f9b7 Support X-Forwarded-Host/X-Forwarded-Port in self URLs generation (#9952) 2026-01-01 12:57:02 +01:00
Aleksander Machniak
2e43fe13de Update changelog
[skip ci]
2025-12-28 19:49:57 +01:00
James Renken
fd395ddf0d Support $HasAttachment/$HasNoAttachment keywords for "With attachment" search filter (#10056)
Also make content-types consistent between app.js:add_message_row() & rcmail_action_mail_index()

Fixes #10053
2025-12-28 19:49:04 +01:00
Aleksander Machniak
98c811dc90 CS fixes, cleanup 2025-12-27 11:21:30 +01:00
Aleksander Machniak
366ad7a174 Fix syntax error in DDL scripts for Postgres (#10052) 2025-12-14 12:30:50 +01:00
Aleksander Machniak
7c3267b9b0 Fix Information Disclosure vulnerability in the HTML style sanitizer
reported by somerandomdev
2025-12-14 09:02:25 +01:00
Aleksander Machniak
5162a0d9d7 Fix Cross-Site-Scripting vulnerability via SVG's animate tag
reported by Valentin T., CrowdStrike.
2025-12-14 09:01:26 +01:00
Pablo Zmdl
1421d0d96f Changelog item for rel=noopener (a361fa79f1) 2025-12-10 16:34:41 +01:00
Pablo Zmdl
202daa6f97 Replace changed by expires_at in session handling
This prepares using extended session lifetimes configurable per session
2025-12-04 14:47:16 +01:00
Aleksander Machniak
ea110e9b4b Bump managesieve version, update changelog 2025-11-29 18:29:36 +01:00
Aleksander Machniak
305ff6a791 Update changelog
[skip ci]
2025-11-29 18:22:20 +01:00
Aleksander Machniak
161fdf05d0 Update changelog
[skip ci]
2025-11-23 14:56:52 +01:00
Aleksander Machniak
7ca48152d4 Fix skin_logo with a relative URL (#10030) 2025-11-22 14:54:03 +01:00
Pablo Zmdl
e34a813355 New plugin "markdown_editor": compose in markdown, send as HTML
This adds a markdown editor that sends HTML to the server.

It uses codemirror and some custom code to show a syntax highlighted
textarea and some buttons to help editing
(including a preview).

Drafts get marked via an internal email header that causes the markdown
editor to automatically start if a message composition is
continued that was started using the markdown editor.
2025-10-27 15:34:19 +01:00
Aleksander Machniak
b81d9981d7 Fix jqueryui plugin's minicolors.css issue with custom skins (#9967) 2025-10-11 17:19:25 +02:00
Aleksander Machniak
3a75f8962d Update changelog
[skip ci]
2025-10-11 17:15:49 +02:00
Aleksander Machniak
dec1d668ed Password: Removed the (insecure) virtualmin driver (#8007) 2025-10-08 13:42:47 +02:00
Aleksander Machniak
82da927e1c Update changelog
[skip ci]
2025-10-08 13:38:59 +02:00
Aleksander Machniak
1b48ed62c2 Update changelog
[skip ci]
2025-10-07 15:39:41 +02:00
Aleksander Machniak
fc6a28a1da Update changelog
[skip ci]
2025-10-05 18:50:58 +02:00
Pablo Zmdl
38e29a772a Version 1.7-beta2 2025-10-01 16:40:55 +02:00
Pablo Zmdl
d39acfb74b Update Changelog 2025-10-01 10:56:22 +02:00
Aleksander Machniak
2c3b46c1f2 Fix regression in handling of non-unicode characters in a plain text message (#9953) 2025-08-13 19:41:18 +02:00
Aleksander Machniak
eff91a93ca Update changelog
[skip ci]
2025-08-10 10:51:47 +02:00
Aleksander Machniak
a0d0f5e72e Fix parsing of inline styles that aren't well-formatted (#9948) 2025-08-03 11:28:53 +02:00
Aleksander Machniak
70e4e86148 Support IPv6 in database DSN (#9937) 2025-07-25 18:55:21 +02:00
Pablo Zmdl
8f7cc42fd6 Mark release 1.7-beta in the changelog (#9931)
[skip ci]
2025-07-15 17:45:58 +02:00
Aleksander Machniak
7be1c23b7a Update changelog
[skip ci]
2025-06-23 08:49:57 +02:00
Aleksander Machniak
d12aa395b8 Update changelog
[skip ci]
2025-06-19 17:04:29 +02:00
Aleksander Machniak
6390ad1466 Fix bug where an mbox export file could include inconsistent message delimiters (#9879) 2025-06-15 10:50:08 +02:00
Aleksander Machniak
8b8c7f27ca Update changelog
[skip ci]
2025-06-15 09:09:39 +02:00
Aleksander Machniak
7841cdb983 Update changelog
[skip ci]
2025-06-15 08:04:35 +02:00
Aleksander Machniak
536971901b Update changelog
[skip ci]
2025-06-15 07:56:17 +02:00
Aleksander Machniak
48381d7f5f Fix "Assign to group" action state after creation of a first group (#9889) 2025-06-12 15:30:11 +02:00
Aleksander Machniak
6a0cec468e Update changelog
[skip ci]
2025-06-01 10:45:59 +02:00
Aleksander Machniak
b5f92b3125 Update changelog
[skip ci]
2025-06-01 09:20:38 +02:00
Aleksander Machniak
0f2c627e04 Fix bug where attachments with content type of application/vnd.ms-tnef were not parsed (#7119) 2025-05-29 18:05:53 +02:00
Aleksander Machniak
6a067d223b Fix cursor position on "below the quote" reply in HTML mode (#8700) 2025-05-25 15:29:17 +02:00
Aleksander Machniak
c396e79aae - Fix connecting to LDAP using ldapi:// URI (#8990) 2025-05-25 09:40:50 +02:00
Aleksander Machniak
699ab5a767 Fix Delete and Empty buttons state while creating a folder (#9047) 2025-04-27 11:13:24 +02:00