xisi
bacbb8c36c
after looking into this quite a bit, this is the correct way to do it after all
2014-01-20 04:30:17 -05:00
xisi
13e6c43ba5
add notify_email to accounts table and getUserNotifyEmail() method in user class
2014-01-20 04:30:17 -05:00
xisi
9ecd8d4d3e
added signup_timestamp to accounts table
...
added getSignupTime() method to user class
added 014_accounts_update.sql and updated 000_base_structure.sql
incremented db version
2014-01-20 04:30:17 -05:00
xisi
15eca659b9
fixed a bug in edit account template
...
moved csrf token to above template in smarty assigns
fixed a bug in user class
remove small login/fix header to catch up
2014-01-20 04:30:17 -05:00
xisi
d24f1050ae
fixed test harness
2014-01-20 04:29:45 -05:00
xisi
3625f5acf0
I need to l2markup
2014-01-20 04:29:45 -05:00
xisi
f119ff854a
cmon readme do what I want
2014-01-20 04:29:45 -05:00
xisi
eb788ac621
updated test readme
2014-01-20 04:29:45 -05:00
xisi
bb80fdb337
PHPUnit test harness & sample test
2014-01-20 04:29:45 -05:00
xisi
a36a0c5b79
[UPDATE] CSRF protection + User/IP/Date & time added to login notification
...
* Adds CSRF protection for multiple pages, see bottom
* Adds User/IP/Date & time to successful login notification
* New config option for sitewide CSRF protection
* Fixed a bug in the contact form
* Lots of cleanup related to CSRF stuff
* Increments config version
* CSRF protection: register, contact, account edit, workers, notifications, and invites
2014-01-20 04:29:45 -05:00
xisi
8756036646
cleaned up account edit csrf slightly
...
added csrf protection to workers under sitewide config
added csrf protection to notifications under sitewide config
added csrf protection to invitations under sitewide config
cleaned up login page csrf
cleaned up contactform/contactform page
cleaned up register/register page
moved config->csrf->forms->register to sitewide
added login ip/user/time to notification on login
2014-01-20 04:29:45 -05:00
xisi
e5c9720174
Finished cleanup of account edit page
...
added csrf protection to account edit page under sitewide config
escaped all instances of CTOKEN for csrf in smarty templates
2014-01-20 04:29:13 -05:00
xisi
9ccb5e15bc
refactored old token usage in account edit page
2014-01-20 04:27:58 -05:00
xisi
d83542e03e
Added method to get description image of csrf token with name
...
moved sitewide into options portion of the config option
csrf protection for contact form under sitewide config option
changed register to 1 hour token
2014-01-20 04:27:58 -05:00
xisi
58529547e0
Cleaned up logic of login page csrf protection
...
added csrf protection to register page
2014-01-20 04:27:22 -05:00
xisi
6da5510035
clean up pages that use csrftokens
2014-01-20 04:26:04 -05:00
xisi
42d93f5beb
specific timing for csrf tokens
2014-01-20 04:26:04 -05:00
xisi
a56140ca84
Moved csrftoken stuff into a class
...
added getCurrentIP method to user class
added config option for sitewide csrf protection
2014-01-20 04:26:04 -05:00
xisi
19a0945be2
no config version inc
2014-01-20 04:26:04 -05:00
xisi
6afc876d19
Merge changes from TheSerapher's pull/1404 Added re-Captcha to Login Page
2014-01-20 04:26:04 -05:00
Sebastian Grewe
225b33af1b
Update README.md
...
Highlighting of name
2014-01-20 10:08:54 +01:00
Sebastian Grewe
808f92932d
Update README.md
...
Added MPOS dev channel
Removed pools
2014-01-20 10:08:13 +01:00
Sebastian Grewe
954459b897
Merge branch 'next' of github.com:MPOS/php-mpos into next
2014-01-20 09:58:33 +01:00
Sebastian Grewe
56fbf205b7
[ADDED] Comment for DEBUG levels
2014-01-20 09:58:06 +01:00
Sebastian Grewe
2dab915d6e
Merge pull request #1472 from MPOS/issue-1471
...
Issue 1471
2014-01-20 00:42:35 -08:00
Sebastian Grewe
3359ada950
Merge pull request #1477 from MPOS/issue-1476
...
[FIX] E-Mail login location
2014-01-20 00:16:55 -08:00
Sebastian Grewe
24e24576af
[FIX] E-Mail login location
2014-01-20 09:16:38 +01:00
Sebastian Grewe
81bf2f784a
Merge pull request #1473 from rog1121/patch-3
...
Prevent username entries
2014-01-19 12:30:18 -08:00
rog1121
77a0287c7f
Update default.tpl
2014-01-19 12:37:54 -07:00
Sebastian Grewe
5b7cf6ab93
[FIX] SQL again, sigh
2014-01-19 17:28:34 +01:00
Sebastian Grewe
8a983835c6
[FIX] Whoopsie SQL
2014-01-19 17:25:55 +01:00
Sebastian Grewe
fbea334121
[REMOVED] Unused stats update
2014-01-19 17:22:40 +01:00
Sebastian Grewe
d4db477c2d
[FIX] Also honor diff for share difficulties if unset
2014-01-19 17:22:00 +01:00
Sebastian Grewe
b905089a01
[FIX] Removed debug output
2014-01-19 17:18:09 +01:00
Sebastian Grewe
0fb543c3ed
[FIX] Honor target_bits for hashrate
2014-01-19 17:17:24 +01:00
Sebastian Grewe
cf49db4535
[IMPROVED] Cronbased global Hash-/Sharerate cache
...
* [ADDED] New statistic method to fetch all user mining stats
* [ADDED] New global cache to getUserHash/Sharerate calls
* [ADDED] New memcache key for new global cache
Addresses #1471 and may fix it already if no other changes are required.
2014-01-19 17:05:27 +01:00
Sebastian Grewe
10e3fcab7e
Merge pull request #1468 from Neozonz/issue-1467
...
MySQL Optimization: always use order by when using limits
2014-01-19 06:39:13 -08:00
Neozonz
44e0fa6745
Reverted
2014-01-19 09:35:39 -05:00
Sebastian Grewe
97ac3c29e5
Merge pull request #1469 from Metice/patch-1
...
Update login template
2014-01-19 06:19:25 -08:00
Metice
e665552c05
Update default.tpl
...
Remove username of placeholder
2014-01-19 15:01:11 +01:00
Neozonz
73e3bb2284
Removed ORDER BY for single queries
2014-01-19 06:05:55 -05:00
Neozonz
773286bd06
ORDER BY for Updates/Deletes
2014-01-19 06:00:29 -05:00
Neozonz
38f5daba6b
Search blocks by desc and order by for deletes
2014-01-19 06:00:14 -05:00
Neozonz
47eb9f7fa0
Allow getWorkerHashRate to set invervals
2014-01-19 05:56:31 -05:00
Sebastian Grewe
1bf9c1027a
Merge pull request #1458 from TheSerapher/drop-small-login
...
[SECURITY] Dropped small login form
2014-01-17 06:45:55 -08:00
Sebastian Grewe
48a344ed25
[SECURITY] Dropped small login form
...
Since we are adding more security realted features, we drop the small
login in the header. It will need more workarounds than we'd like and is
already dropped when re-Captcha is enabled.
Security > Convenience :D
2014-01-17 15:43:58 +01:00
Sebastian Grewe
ba67814d6c
Update README.md
...
Check only next branch for status picture.
2014-01-17 14:26:22 +01:00
Sebastian Grewe
b1f8d14c18
Update README.md
2014-01-17 14:23:31 +01:00
Sebastian Grewe
832d43bd6b
Update README.md
...
Testing Codeship builds Image.
2014-01-17 14:13:45 +01:00
Joey
0309886645
What a stupid thing of me to miss
...
UNIX_TIMESTAMP() for time comparison, oops
2014-01-17 03:53:09 -05:00