xisi
9f6cf99aa3
small fixes
2014-01-28 08:08:53 -05:00
xisi
f56c18276a
small fixes
2014-01-28 07:26:33 -05:00
xisi
6398e5dfec
merged session manager/memcache limiter
...
cleanup for PR
2014-01-28 07:26:33 -05:00
Joey
63c3b96a29
now enforce client & server validity on login with strict on
...
fixed csrf token check for a few pages where it mightve been broken
session manager now can be bound to base user class and used, like in login
logout now pushes you to login regardless, no longer has param to push to custom url
fixed validate client, hijacking sessions no longer works
2014-01-28 07:26:32 -05:00
Joey
795e019d0d
cleaned up config options a bit
2014-01-28 07:26:32 -05:00
Joey
493c43e0ed
updated check in autoloader so default needs to be changed if SECHASH_CHECK is enabled
2014-01-28 07:26:32 -05:00
Joey
d5f1c97f82
fixed check against define like it used to even if SECHASH_CHECK is disabled
...
fixed ajax calls in memcache limiter to use REQUEST page/action rather than QUERY_STRING
2014-01-28 07:26:32 -05:00
xisi
b728b680ca
blah blah
2014-01-28 07:26:08 -05:00
xisi
9dcb855b34
strict class, trying to figure out why edit account doesnt work
2014-01-28 06:18:57 -05:00
xisi
f21f05e874
pushing to start core rebuild
2014-01-28 06:18:57 -05:00
xisi
7393f21d01
just pushing so I can rebase zzz
2014-01-28 06:18:57 -05:00
Sebastian Grewe
56f995c86f
Merge pull request #1617 from HerrKauwer/pwcheck
...
Cleaned up pwcheck.js
2014-01-28 00:28:32 -08:00
Sebastian Grewe
5f65904431
[FIX] HTTPS detecion on Template
2014-01-28 09:25:50 +01:00
Sebastian Grewe
967c1cc48f
[FIX] Proper HTTPS detection
...
Fixes #1618 once merged
2014-01-28 09:25:20 +01:00
Sebastian Grewe
b783237c2e
Merge pull request #1457 from MPOS/issue-1332
...
Issue 1332
2014-01-28 00:18:56 -08:00
Sebastian Grewe
f83c88aae6
Merge pull request #1603 from MPOS/double-payouts
...
Double payouts
2014-01-27 22:25:44 -08:00
HerrKauwer
095ee2e40a
Cleaned up pwcheck.js
2014-01-27 23:56:39 +01:00
Sebastian Grewe
ecfa741223
[FIX] Do not assign smarty vars if caching hits
2014-01-27 13:43:33 +01:00
Sebastian Grewe
b5cb8171ba
Merge branch 'master-read-only-check' into next
2014-01-27 13:26:14 +01:00
Sebastian Grewe
f183b586a8
[ADDED] Check if master is read-only
...
Just to ensure we can run at all.
2014-01-27 12:58:41 +01:00
Sebastian Grewe
fab3c44e90
[ADDED] THash/second modifier
2014-01-27 12:45:46 +01:00
Sebastian Grewe
1cd9352952
[FIX] Transaction ID and RPC Transaction ID
2014-01-27 10:31:18 +01:00
Sebastian Grewe
d4557982ba
[FIX] API call for transactions
...
Fixes #1602 once merged.
2014-01-27 09:13:09 +01:00
Sebastian Grewe
b87691371f
[SECURITY] Path disclosure and redirects
...
* [SECURITY] Do not disclose paths with wrong query arguments in API
* [SECURITY] Removed $to redirect after login
Fixes #1596 once merged.
2014-01-26 17:41:27 +01:00
Sebastian Grewe
7c8d7701f2
[FIX] Lock state 2 for admin locks
2014-01-26 11:17:33 +01:00
Sebastian Grewe
702ed49704
[ADDED] Account lock status
...
* Lock 1: user confirmation/unlock pending, count shares
* Lock 2: Admin disabled, ignore shares
This further addresses #1332 and should allow proper dropping of shares
for banned accounts.
2014-01-26 11:17:33 +01:00
Sebastian Grewe
e4627fc51d
[IMPROVED] Ignore locked account shares
...
* Updated getRoundShares to honor locked accounts
* Updated getSharesForAccounts and getArchiveShares
This will fix #1332 and ignore locked user accounts in share
calculations for payouts.
2014-01-26 11:17:33 +01:00
Sebastian Grewe
816fb783ce
Merge pull request #1589 from joebauers/next
...
Update user.class.php
2014-01-25 23:50:25 -08:00
joebauers
48ce68e612
Update user.class.php
...
No need to show world if valid account.
2014-01-26 02:44:30 -05:00
Sebastian Grewe
a343ac4047
Merge pull request #1568 from MPOS/payout-fail-bail
...
[FIX] Bail payouts on failed sendtoaddress calls
2014-01-25 08:38:56 -08:00
Sebastian Grewe
768d193793
Merge pull request #1576 from xisi/csrf-backend-only
...
[FIXES] More CSRF improvements
2014-01-25 06:59:08 -08:00
Sebastian Grewe
9e6a2a3bea
[FIX] Do not treat disabled notification as error
...
Fixes #1582 once merged.
2014-01-25 13:10:38 +01:00
xisi
8fbda49fd1
Don't even need the suppression
2014-01-24 16:33:55 -05:00
xisi
a043e5ed19
Fixes #1561 , which happened to me even with the API key in the correct format
2014-01-24 16:32:00 -05:00
xisi
c81aec4c64
fixed bug in registration form
2014-01-24 15:38:56 -05:00
xisi
0f88f70fcf
fixes bug in registration form, thanks @Zen00
2014-01-24 15:34:01 -05:00
xisi
4e18ff318b
cleaned up tabbing and sessions in index
2014-01-24 15:07:00 -05:00
xisi
c192cbb0bd
Token failure condition fix
2014-01-24 14:46:50 -05:00
xisi
3006cb544f
Reworked csrf tokens, now enabled globally
...
The way this now works is, if csrf is enabled:
* Any new or existing template can have csrf protection by adding the hidden input ctoken that's in this batch to its form, removes any logic in templates
* Page controllers that already exist have been updated, new ones only require checking if csrf is enabled and valid
2014-01-24 13:00:24 -05:00
Sebastian Grewe
a586cc36ab
[FIX] Honor cache flag for getUserSharerate
2014-01-24 12:32:21 +01:00
Sebastian Grewe
2891a07637
[FIX] Bail payouts on failed sendtoaddress calls
...
* [WORKAROUND] Helps for coins that run a bad RPC implementation
* Addresses #1406 and wil at least stop double payouts
2014-01-24 12:15:23 +01:00
Sebastian Grewe
70a09811ec
[FIX] PHP Notice on Mobile Template
2014-01-24 11:29:19 +01:00
Sebastian Grewe
481c8dd980
[FIX] Round donations on donor page
2014-01-24 10:52:13 +01:00
Sebastian Grewe
a1a3d7e873
[IMPROVED] Added donation minimum and rounding
...
* [ADDED] Config option `$config['donate_threshold']['min'] = 1;`
* [VERSION] Incremented config file version to `0.0.6`
* [CHANGED] Round donations to at least two digits
* [CHANGED] Honor minimum set pool donation percentage
* [UPDATED] Account edit template
Fixes #1475 once merged
2014-01-24 10:06:13 +01:00
Sebastian Grewe
659c203c06
Merge pull request #1551 from xisi/csrf-improvements
...
[FIXES] CSRF tokens & login cleanup
2014-01-23 23:27:31 -08:00
Sebastian Grewe
90d0ff1081
Merge pull request #1546 from ahmedbodi/patch-1
...
Get Cronjob Status API
2014-01-23 23:13:42 -08:00
Sebastian Grewe
f75200ce1e
Merge pull request #1560 from raistlinthewiz/next
...
Added reward_type and reward info to api/getpoolinfo
2014-01-23 23:09:06 -08:00
Neozonz
2d607cca97
[FIX/ENHANCE] Session management
...
@herrkauwer appreciate the code review and help
@xisi initial code pr
@add1ct3dd reporting the issue
2014-01-23 16:52:29 -08:00
Hüseyin Uslu
b518ce0799
Tiny update.
2014-01-24 00:38:28 +02:00
Hüseyin Uslu
0639af54b3
Added reward_type and reward info to api/getpoolinfo
2014-01-24 00:37:50 +02:00