- Dec 19, 2014
-
-
Boy Baukema authored
-
Boy Baukema authored
Depending on server configuration this may be used in a Denial Of Service attack by tying up all webserver workers with large POST bodies.
-
- Dec 15, 2014
-
-
Jaime Perez authored
-
Jaime Perez authored
-
- Dec 10, 2014
-
-
Thijs Kinkhorst authored
-
- Nov 28, 2014
-
-
Wessel Dankers authored
Fixes a bug in Memcache.php that would cause every fetch to also result in a push if multiple memcache servers were being used. If multiple memcache servers are in use, the code needs to check if they aren't out of sync. If they are, the most recent data needs to be pushed to all mirrors. The original code compared the parsed data structures using ===, but that always fails because that just does a pointer comparison and not a deep comparison. Changed the code to compare the original unparsed values instead. Also added a few debug-level log statements.
-
- Nov 22, 2014
-
-
Jaime Pérez authored
add testing for php 5.6 and hhvm (allow failures)
-
- Nov 21, 2014
-
-
Brook Schofield authored
-
- Nov 12, 2014
-
-
Jaime Perez authored
-
Jaime Perez authored
-
Jaime Perez authored
-
- Nov 11, 2014
-
-
Jaime Perez authored
-
- Nov 10, 2014
-
-
Jaime Perez authored
-
Jaime Perez authored
Avoid the friendly names in attribute definitions to end up in the PHP generated metadata, as it creates trouble for the AttributeLimit filter and others.
-
Andrea Biancini authored
-
- Nov 05, 2014
-
-
Jaime Perez authored
-
Jaime Perez authored
-
Jaime Perez authored
-
Jaime Perez authored
-
Jaime Perez authored
-
Jaime Perez authored
-
- Nov 03, 2014
-
-
Jaime Pérez authored
Sort IdP's in alphabetical order in dropdown.
-
- Oct 31, 2014
-
-
Jaime Pérez authored
Only show languagebar when there's something to choose.
-
- Oct 30, 2014
-
-
Thijs Kinkhorst authored
If you configure language.available to just one language, e.g. "en", you get a language bar with just the unclickable word "English" which is rather unuseful.
-
- Oct 27, 2014
-
-
Jaime Perez authored
-
- Oct 22, 2014
-
-
Daan van Renterghem authored
`preg_match` returns `0` if no matches are found, `FALSE` only on error. This means that with the previous check unmatching certificates would not be identified, only when the preg_match itself would error.
-
- Oct 08, 2014
-
-
Jaime Perez authored
-
Jaime Perez authored
-
Jaime Perez authored
Remove extra URL validation as normalizeURL() will have done that already. Return an empty string if the input URL is empty (disregarding its type). This should make the checkURLAllowed() function transparent and avoid it returning the current URL (normalized) when input is empty. Fixes #99.
-
Jaime Perez authored
Avoid calling SimpleSAML_Utilities::normalizeURL() twice when we are redirecting and need to check if the URL is trusted.
-
- Oct 06, 2014
-
-
Jaime Pérez authored
Add NameIDFormats to output of getMetadata20IdP()
-
Jaime Perez authored
-
Jaime Perez authored
-
Thijs Kinkhorst authored
-
Jaime Perez authored
-
Jaime Perez authored
-
Thijs Kinkhorst authored
Fixes a notice on page load.
-
Jaime Perez authored
-
- Oct 01, 2014
-
-
Jaime Perez authored
-
Jaime Perez authored
-