Nathan Patten
e7ec045785
[ADD] Donor
2014-02-22 21:42:45 +11:00
Nathan Patten
a68a5675b1
[ADD] Chat Link To Nav
2014-02-22 21:39:22 +11:00
Nathan Patten
fdd8cb64f9
Create disabled.tpl
2014-02-22 21:36:14 +11:00
Nathan Patten
2aab514624
[ADD] Chat tpl
2014-02-22 21:35:27 +11:00
Sebastian Grewe
8cb42aab2b
Merge pull request #1770 from iAmShorty/realbalance-wrapper
...
[FIX] return balance from main account
2014-02-19 09:34:01 +01:00
iAmShorty
8f4237945b
[UPDATE] make it uppercase
2014-02-17 15:40:26 +01:00
iAmShorty
4532bd6601
[UPDATE] add coinname to qrode
2014-02-17 15:39:10 +01:00
iAmShorty
63ba74fc60
[UPDATE] balance fix for cron and wallet
2014-02-16 17:32:05 +01:00
Sebastian Grewe
85f985060b
Merge pull request #1766 from rog1121/notification-fix
...
Notifications Fix
2014-02-16 14:50:38 +01:00
Sebastian Grewe
e6a396c85b
Merge pull request #1750 from iAmShorty/wallet-info-adminpanel
...
[ENHANCEMENT] Wallet info adminpanel
2014-02-16 08:12:03 +01:00
rog1121
eb382b677c
Notifications Fix
2014-02-15 18:00:36 -07:00
iAmShorty
45d79d0eab
[UPDATE] style change for addresses
2014-02-15 23:17:37 +01:00
iAmShorty
2acf83894d
only show new table if accounts > 1
2014-02-15 13:55:28 +01:00
Sebastian Grewe
bd561ff465
[FIX] Statistics Graphs ACL
...
Fixes #1760
2014-02-15 09:27:38 +01:00
iAmShorty
0ef5fdedef
[UPDATE] small changes
2014-02-14 17:08:22 +01:00
Sebastian Grewe
d7f2e6e5ac
[UPDATE] ACL Management
...
* [ADDED] Smarty acl_check function
* [ADDED] Optional default return value for getValue calls
* [UPDATE] ACL Checks in page controllers
* [UPDATE] Navigation template to use check_acl from Smarty
* [ADDED] New ACL options where needed
* [REMOVED] Disable pages from System Settings Tab
* [ADDED] Above removed pages into ACL Settings Tab
This will make usage of ACLs a bit easier and transparent.
Also fixes #1731 once merged.
2014-02-14 10:56:25 +01:00
Andy Mornes
ac3bea9f1a
[FIX] Correcting user ID for new block emails
...
Also adding the currency to the notifications as well.
2014-02-13 13:26:48 -06:00
iAmShorty
1fd7499856
[UPDATE] style changes
2014-02-13 17:28:47 +01:00
iAmShorty
224af2c9d3
[UPDATE] showing accounts with balance and address
2014-02-13 16:29:33 +01:00
iAmShorty
81b8b976d1
[FEATURE] show addresses from account
2014-02-13 12:29:04 +01:00
iAmShorty
146799d163
[FEATURE] show addresses from account
2014-02-13 12:28:26 +01:00
Andy Mornes
caee4a7c8f
Consolidating the nocache tags
2014-02-12 00:27:21 -06:00
Andy Mornes
91a57903ce
New Block Notification additions
...
Adding the block number, finder, amount, and difficulty to the new block
notification email
2014-02-12 00:18:00 -06:00
Sebastian Grewe
6509cc6039
[ADDE] CSRF validation for Worker Deletion
...
* [ADDED] CSRF token checks to worker page
* [CHANGED] Check for both _GET and _POST ctokens
* [ADDED] CSRF token to each delete call URL
Fixes #1702 once merged
2014-02-07 12:24:48 +01:00
Sebastian Grewe
7cf3fb27fb
[UPDATE] Allow global notification settings
...
Fixes #1232 and allows further expansion in the future.
Addresses #1672 too.
2014-02-06 11:13:22 +01:00
Sebastian Grewe
7673c34d80
Merge branch 'fix-contactform' into next
2014-02-06 10:57:49 +01:00
Sebastian Grewe
5196cc7448
[UPDATE] Highlight next/previous arrows on admin/user
2014-02-06 10:56:19 +01:00
Sebastian Grewe
2f1d68448f
[FIX] CSRF/Re-captcha on Contactform
...
Fixes #1666
2014-02-06 10:19:58 +01:00
Sebastian Grewe
bc0d340bf3
Merge pull request #1642 from MPOS/payout-overhaul
...
[IMPROVED] Payout logics
2014-02-04 21:59:22 -08:00
Sebastian Grewe
c00b6d6757
[IMPROVED] Payout logics
...
* [ADDED] More methods to our transaction class
* `createDebitAPRecord` and `createDebitMPRecord`, will handle the
* entire debit process
* Adds Debit transaction
* Adds TXFee transaction
* mark transactions as archived
* validate user is fully paid out
* send notification to user
* `getMPQueue` was added to unify the process of getting payout queues
* [MOVED] Only one mail template for both payout methods
* [ADDED] Some minor calls to user class
* [ADDED] Full address validation to bitcoin class
* [SQL] New SQL upgrade and Version Increment
* Adding UNIQUE index to coin_address in accounts table
* preperation for `sendmany` implementation
2014-02-03 08:16:58 +01:00
HerrKauwer
70e8b27085
Used zxcvbn for password strength determination
2014-02-02 15:04:55 +01:00
Sebastian Grewe
319d9439a4
Merge pull request #1621 from xisi/sessions-mclimiter-fixes
...
[UPDATE] Security updates and fixes
2014-01-31 05:55:09 -08:00
Yefta Sutanto
0bd1606207
Update sidebar_prop.tpl
...
Fixing "Your Invalid" percentage calculation
2014-01-30 00:17:20 +07:00
Yefta Sutanto
0a9398b99e
Update sidebar_pps.tpl
2014-01-30 00:16:45 +07:00
Yefta Sutanto
016da6cd61
Update sidebar_pplns.tpl
...
Fixing "Your Invalid" percentage calculation
2014-01-30 00:12:34 +07:00
xisi
ae47437ab7
fixed worker delete csrf thing I stubbed earlier
...
took to field out of the rest of the login forms
2014-01-29 09:41:50 -05:00
Zen00
0e8949c71d
Linked Site-Title
...
Seems that there was plans to make the site title a link, but the .tpl
was never updated.
2014-01-28 08:16:31 -07:00
xisi
6398e5dfec
merged session manager/memcache limiter
...
cleanup for PR
2014-01-28 07:26:33 -05:00
xisi
b728b680ca
blah blah
2014-01-28 07:26:08 -05:00
Sebastian Grewe
5f65904431
[FIX] HTTPS detecion on Template
2014-01-28 09:25:50 +01:00
Sebastian Grewe
768d193793
Merge pull request #1576 from xisi/csrf-backend-only
...
[FIXES] More CSRF improvements
2014-01-25 06:59:08 -08:00
xisi
8fbda49fd1
Don't even need the suppression
2014-01-24 16:33:55 -05:00
xisi
a043e5ed19
Fixes #1561 , which happened to me even with the API key in the correct format
2014-01-24 16:32:00 -05:00
xisi
3006cb544f
Reworked csrf tokens, now enabled globally
...
The way this now works is, if csrf is enabled:
* Any new or existing template can have csrf protection by adding the hidden input ctoken that's in this batch to its form, removes any logic in templates
* Page controllers that already exist have been updated, new ones only require checking if csrf is enabled and valid
2014-01-24 13:00:24 -05:00
Sebastian Grewe
70a09811ec
[FIX] PHP Notice on Mobile Template
2014-01-24 11:29:19 +01:00
Sebastian Grewe
a1a3d7e873
[IMPROVED] Added donation minimum and rounding
...
* [ADDED] Config option `$config['donate_threshold']['min'] = 1;`
* [VERSION] Incremented config file version to `0.0.6`
* [CHANGED] Round donations to at least two digits
* [CHANGED] Honor minimum set pool donation percentage
* [UPDATED] Account edit template
Fixes #1475 once merged
2014-01-24 10:06:13 +01:00
xisi
1fd0adf038
Removed unused config setting
2014-01-23 11:01:30 -05:00
Sebastian Grewe
4b04df5d8a
[FIX] Allow TAB to focus on email login
2014-01-23 10:11:37 +01:00
Sebastian Grewe
0d10079a2a
[FIX] remove mail debug output
2014-01-22 12:48:03 +01:00
Sebastian Grewe
3b13ea4990
[FIX] Properly show login details on mail notif.
...
Fixes #1530 once merged
2014-01-22 11:14:50 +01:00
nrpatten
151decb2b6
[FIX] Align Checkbox
...
"Edit template" checkbox align closer to "Active"
2014-01-22 00:39:42 +11:00
nrpatten
fc7a939b1e
[FIX] Update github footer link
...
Remove https://github.com/TheSerapher/php-mpos
Add https://github.com/MPOS/php-mpos
2014-01-21 23:42:58 +11:00
Sebastian Grewe
bf484c4be2
Merge pull request #1510 from xisi/security-pagecontrollerfix
...
Fix issue #1508
2014-01-21 03:20:38 -08:00
nrpatten
6b938a66d2
[FIX] Unknown Pool Footer
...
Remove <p>{$GLOBAL.website.name|default:"Unknown Pool"}</p>
Add <p>{$WEBSITENAME}</p>
2014-01-21 20:50:29 +11:00
nrpatten
dfd4d57361
[FIX] Unknown Pool
...
Remove <p>{$GLOBAL.website.name|default:"Unknown Pool"}</p>
Add <p>{$WEBSITENAME}</p>
2014-01-21 20:49:42 +11:00
nrpatten
35d6317ec2
[FIX] Unknown Pool Footer
...
Remove <p>{$GLOBAL.website.name|default:"Unknown Pool"}</p>
Add <p>{$WEBSITENAME}</p>
2014-01-21 20:48:48 +11:00
nrpatten
1c07abb2c0
[FIX] Unknown Pool Footer
...
Remove <p>{$GLOBAL.website.name|default:"Unknown Pool"}</p>
Add <p>{$WEBSITENAME}</p>
2014-01-21 20:47:37 +11:00
xisi
ac91d70c5f
This should fix issue #1508
2014-01-21 04:04:53 -05:00
Sebastian Grewe
2d760c2934
Merge pull request #1504 from daygle/patch-6
...
Update default.tpl
2014-01-21 01:00:00 -08:00
Sebastian Grewe
9520795e07
Merge pull request #1506 from nrpatten/next
...
[FIX] input[type=email] in the wrong order and Overlap and Reposition TABS
2014-01-21 00:07:58 -08:00
Sebastian Grewe
0edd964930
Merge pull request #1507 from xisi/security-js-pwstrength
...
Simple javascript password strength/match
2014-01-21 00:04:18 -08:00
nrpatten
0cfc92bd2b
[FIX] Overlap and Reposition TABS
...
[FIX] "E-mail address for system error" Overlap and realign class="tabs" to fieldset
2014-01-21 17:12:06 +11:00
xisi
a20c2324e2
Added pw strength/match to change password form
2014-01-21 00:02:57 -05:00
xisi
b0053b65e1
Added basic javascript password strength/match testing
...
Added pw strength/match to registration form
2014-01-20 23:57:07 -05:00
Glen
3a43ed4e42
Update default.tpl
...
Getting started page modification suggestions for all users.
1. Add BFGMiner details.
2. Remove bullet points for steps.
3. Add additional line for BFGMiner command line.
2014-01-21 14:38:10 +11:00
rog1121
0a6ab8748b
Mail Titles
2014-01-20 09:33:21 -07:00
Sebastian Grewe
eb6692b31c
Merge pull request #1481 from raistlinthewiz/next
...
tx fee's shouldn't be %
2014-01-20 07:46:45 -08:00
Hüseyin Uslu
51d0879f8d
Wording fix for index.php?page=account&action=edit - tx fee's shouldn't be %
2014-01-20 17:44:45 +02:00
xisi
ffda9dbae1
rebase + fix bug in overview tpl that could throw a notice
2014-01-20 04:53:00 -05:00
xisi
fd49e0eb78
disabled is actually correct to use in cash out form, we want the css props
...
slightly optimization
2014-01-20 04:41:13 -05:00
xisi
a987878c8e
removed extraneous disabling of a field in edit account page, thanks @rog1121
2014-01-20 04:41:13 -05:00
xisi
b0413226b4
removed extraneous disabling of a field in edit account page, thanks @rog1121
2014-01-20 04:41:13 -05:00
xisi
76a67cb71a
Changed the config options for CSRF/disabling forms
...
* Now an array to disable with granularity
* Fixed all CSRF tokens back to 1 min
* Added CSRF protection for unlock account
* Unified error message for all csrf tokens
* Fixed a few issues with last commit
2014-01-20 04:41:13 -05:00
xisi
bd2999526e
fixed mobile templates, have not tested as they use same methods as main template
...
fixed change pw templates; added csrf token
added csrf protection for password reset
fixed reset and change pass templates; were missing csrf token (form only tpl)
2014-01-20 04:40:38 -05:00
xisi
15eca659b9
fixed a bug in edit account template
...
moved csrf token to above template in smarty assigns
fixed a bug in user class
remove small login/fix header to catch up
2014-01-20 04:30:17 -05:00
xisi
8756036646
cleaned up account edit csrf slightly
...
added csrf protection to workers under sitewide config
added csrf protection to notifications under sitewide config
added csrf protection to invitations under sitewide config
cleaned up login page csrf
cleaned up contactform/contactform page
cleaned up register/register page
moved config->csrf->forms->register to sitewide
added login ip/user/time to notification on login
2014-01-20 04:29:45 -05:00
xisi
e5c9720174
Finished cleanup of account edit page
...
added csrf protection to account edit page under sitewide config
escaped all instances of CTOKEN for csrf in smarty templates
2014-01-20 04:29:13 -05:00
xisi
d83542e03e
Added method to get description image of csrf token with name
...
moved sitewide into options portion of the config option
csrf protection for contact form under sitewide config option
changed register to 1 hour token
2014-01-20 04:27:58 -05:00
xisi
58529547e0
Cleaned up logic of login page csrf protection
...
added csrf protection to register page
2014-01-20 04:27:22 -05:00
xisi
6afc876d19
Merge changes from TheSerapher's pull/1404 Added re-Captcha to Login Page
2014-01-20 04:26:04 -05:00
rog1121
77a0287c7f
Update default.tpl
2014-01-19 12:37:54 -07:00
Metice
e665552c05
Update default.tpl
...
Remove username of placeholder
2014-01-19 15:01:11 +01:00
Sebastian Grewe
48a344ed25
[SECURITY] Dropped small login form
...
Since we are adding more security realted features, we drop the small
login in the header. It will need more workarounds than we'd like and is
already dropped when re-Captcha is enabled.
Security > Convenience :D
2014-01-17 15:43:58 +01:00
Jesse Collier
bc833eb40b
[IMPROVED] Adds Email label and removes maxlength
...
When logging in from mobile, there currently is not an indicater to
use email or username. This labels it correctly.
Removed maxlength to allow for lengthier email addresses.
2014-01-16 14:42:05 +01:00
Sebastian Grewe
2829f6a746
[IMPROVED] Dropped username from login
2014-01-16 14:40:51 +01:00
Sebastian Grewe
63f062af9d
[UPDATE] CSRF to Mobile template
2014-01-16 14:33:04 +01:00
Sebastian Grewe
bef4298e1f
[ADDED] Default re-Captcha HTML to mobile
2014-01-16 14:14:29 +01:00
Sebastian Grewe
d5bff56f6f
[ADDED] re-Captha admin options
2014-01-16 14:14:29 +01:00
Sebastian Grewe
b9d36bcfc9
[IMPROVED] Added re-Captcha to Login Page
...
* Enable re-captcha to use it
* Disables the mini-login box in header
* Requires re-Captcha to be setup in Admin Panel
Fixes #1400 once merged.
2014-01-16 14:13:50 +01:00
xisi
b613182dfb
what fix, nothing to see here
2014-01-16 05:55:57 -05:00
xisi
2d0938b35b
[ADDED] Simple CSRF protection tokens
...
* Adds config options for disabling, timeout lead time, and forms
* Adds another salt in config that's used in the token
* Adds protection for login form by default
2014-01-16 05:55:57 -05:00
xisi
bae30b2e4f
fixed success_login tpl verbiage
2014-01-16 05:55:57 -05:00
xisi
9d14902bb5
fix nocache in account/edit template
2014-01-16 05:55:57 -05:00
xisi
dc984aca63
fixed gitignore for eclipse, added templates/compile/mpos folder and a blank file to fix issues with setup guide/chowning compile dir
2014-01-16 05:53:36 -05:00
xisi
f3a6d65eab
send notifications on successful login when active
2014-01-16 05:53:36 -05:00
xisi
741b6464ef
success_login tpl for new notification
2014-01-16 05:53:36 -05:00
xisi
ed8349ef50
works as far as I can tell
2014-01-16 05:53:36 -05:00
xisi
d9d678be61
retooled most of the email confirmation setup
2014-01-16 05:53:36 -05:00
xisi
69eec05cb7
simplified notifications with index, updated the settings method, and fixed up template, sql fixes
2014-01-16 05:42:43 -05:00
xisi
ef904858ae
[Addition] E-mail confirmations for user actions
...
* If enabled, sends e-mail to confirm user withdraws, edits and pw changes
* Adds 4 config options, enabled + individual settings
* Adds 3 new token_types
2014-01-16 05:42:43 -05:00