X-Git-Url: https://git.tokkee.org/?a=blobdiff_plain;f=CHANGES.txt;h=37d98928d8e1526940b7669e3e58aa69017d82c7;hb=82254374e5abbaede04ff126d401f97a16032a25;hp=fadcbbf3fd1025cac24386da2cd222fec1204101;hpb=95ad6a8ef4585ed0d84f1c5201fbe43cd71f5f7b;p=roundup.git diff --git a/CHANGES.txt b/CHANGES.txt index fadcbbf..37d9892 100644 --- a/CHANGES.txt +++ b/CHANGES.txt @@ -1,12 +1,96 @@ This file contains the changes to the Roundup system over time. The entries -are given with the most recent entry first. +are given with the most recent entry first. If no other name is given, +Richard Jones did the change. + +20XX-XX-XX 1.4.17 (rXXXX) + +Features: + +- Add explicit "Search" permissions, see Security Fix below. +- Add "lookup" method to xmlrpc interface (Ralf Schlatterbeck) + +Fixed: + +- Security Fix: Add a check for search-permissions: now we allow + searching for properties only if the property is readable without a + check method or if an explicit search permission (see above unter + "Features) is given for the property. This fixes cases where a user + doesn't have access to a property but can deduce the content by + crafting a clever search, group or sort query. + see doc/upgrading.txt for how to fix your trackers! (Ralf Schlatterbeck). +- Some minor typos fixed in doc/customizing.txt (Thanks Ralf Hemmecke). +- XML-RPC documentation now linked from the docs/index (Bernhard Reiter). +- Fix setting of sys.path when importing schema.py, fixes issue2550675, + thanks to Bryce L Nordgren for reporting. (Ralf Schlatterbeck) +- clear the cache on commit for rdbms backends: Don't carry over cached + values from one transaction to the next (there may be other changes + from other transactions) see new ConcurrentDBTest for a + read-modify-update cycle that fails with the old caching behavior. + (Ralf Schlatterbeck) + +2010-10-08 1.4.16 (r4541) + +Features: + +- allow trackers to override the classes used to render properties in + templating per issue2550659 (thanks Ezio Melotti) +- new mailgw configuration item "subject_updates_title": If set to "no" + a changed subject in a reply to an issue will not update the issue + title with the changed subject. Thanks to Arkadiusz Kita and Peter + Funk for requesting the feature and discussing the implementation. + http://thread.gmane.org/gmane.comp.bug-tracking.roundup.user/10169 +- new rdbms config item sqlite_timeout makes the previously hard-coded + timeout of 30 seconds configurable. This is the time a client waits + for the locked database to become free before giving up. Used only for + SQLite backend. +- new mailgw config item unpack_rfc822 that unpacks message attachments + of type message/rfc822 and attaches the individual parts instead of + attaching the whole message/rfc822 attachment to the roundup issue. + +Fixed: + +- fixed reporting of source missing warnings +- relevant tests made locale independent, issue2550660 (thanks + Benni Bärmann for reporting). +- fix for incorrect except: syntax, issue2550661 (thanks Jakub Wilk) +- No longer use the root logger, use a logger with prefix "roundup", + see http://thread.gmane.org/gmane.comp.bug-tracking.roundup.devel/5356 +- improve handling of '>' when URLs are converted to links, issue2550664 + (thanks Ezio Melotti) +- fixed registration, issue2550665 (thanks Timo Paulssen) +- make sorting of multilinks in the web interface more robust, issue2550663 +- Fix charset of first text-part of outgoing multipart messages, thanks Dirk + Geschke for reporting, see + http://thread.gmane.org/gmane.comp.bug-tracking.roundup.user/10223 +- Fix handling of incoming message/rfc822 attachments. These resulted in + a weird mail usage error because the email module threw a TypeError + which roundup interprets as a Reject exception. Fixes issue2550667. + Added regression tests for message/rfc822 attachments with and without + configured unpacking (mailgw unpack_rfc822, see Features above) + Thanks to Benni Bärmann for reporting. +- Allow search_popup macro to work with all db classes, issue2550567 + (thanks John Kristensen) +- lower memory footprint for (journal-) import + + +2010-07-12 1.4.15 + +Fixed: + +- A bunch of regressions were introduced in the last release making Roundup + no longer work in Python releases prior to 2.6 +- make URL detection a little smarter about brackets per issue2550657 + (thanks Ezio Melotti) + 2010-07-01 1.4.14 Features: + - Preparations for getting 2to3 work, not completed yet. (Richard Jones) Fixed: + - User input not escaped when a bad template name is supplied (thanks Benjamin Pollack) - The email for the first message on an issue was having its In-Reply-To