[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2021-04-09 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Jonathan Druart changed: What|Removed |Added Blocks||28024 Referenced Bugs: h

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2020-04-20 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Martin Renvoize changed: What|Removed |Added See Also||https://bugs.koha-community

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2013-04-20 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Chris Cormack changed: What|Removed |Added Status|Pushed to Master|Pushed to Stable --- Comment

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-07-05 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #29 from Katrin Fischer --- I have forwarded this to a coworker and hoping to find out what we have to do soon. Whatever we do, we should not forget about the lists as they are also sent out using a similar technique. --

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-07-04 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #28 from Paul Poulain --- (In reply to comment #27) > (In reply to comment #26) > > OK, patch pushed and discussion started on mailing lists > Paul: I do not see the followup appearing in master ? Sorry, it was commited on

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-07-04 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #27 from M. de Rooy --- (In reply to comment #26) > OK, patch pushed and discussion started on mailing lists Paul: I do not see the followup appearing in master ? -- You are receiving this mail because: You are watching a

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-07-03 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Paul Poulain changed: What|Removed |Added Status|Passed QA |Pushed to Master --- Comment #

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-07-02 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 M. de Rooy changed: What|Removed |Added Status|Signed Off |Passed QA --- Comment #25 from M

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-07-02 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #24 from M. de Rooy --- Setting this to Signed off to get Paul's attention :-) -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing li

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-07-02 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 M. de Rooy changed: What|Removed |Added Status|Needs Signoff |Signed Off -- You are receiving

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-07-02 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 M. de Rooy changed: What|Removed |Added Status|ASSIGNED|Needs Signoff -- You are receiv

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-07-02 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 M. de Rooy changed: What|Removed |Added Status|Pushed to Master|ASSIGNED -- You are receiving t

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-07-02 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #23 from M. de Rooy --- Created attachment 10595 --> http://bugs.koha-community.org/bugzilla3/attachment.cgi?id=10595&action=edit Followup for privacy issue Paul: Katrin raised the question on privacy issue on x-orig-ip.

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-07-02 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #22 from Paul Poulain --- (In reply to comment #21) > (In reply to comment #20) > > Ok, rereading through the bug report there is a bit that worries me: > > - add field X-Orig-IP with IP of sender > > > > IP addresses in w

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-07-02 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #21 from M. de Rooy --- (In reply to comment #20) > Ok, rereading through the bug report there is a bit that worries me: > - add field X-Orig-IP with IP of sender > > IP addresses in web server logs have been issue of data

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-07-02 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #20 from Katrin Fischer --- Ok, rereading through the bug report there is a bit that worries me: - add field X-Orig-IP with IP of sender IP addresses in web server logs have been issue of data privacy here - I wonder if it

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-30 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #19 from Katrin Fischer --- Hi Chris, but this is already the case in 3.6? -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list K

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-29 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Chris Cormack changed: What|Removed |Added Version|rel_3_8 |rel_3_10 --- Comment #18 from

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-29 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Paul Poulain changed: What|Removed |Added Status|Passed QA |Pushed to Master

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-28 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #16 from M. de Rooy --- (In reply to comment #3) > Does opac/opac-sendshelf.pl should be have a separated bug report ? > As there have same features (send email to someone), corrections (or > enhancements) should be consist

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-28 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 M. de Rooy changed: What|Removed |Added Status|Signed Off |Passed QA --- Comment #15 from M

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-28 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 M. de Rooy changed: What|Removed |Added Status|Needs Signoff |Signed Off QA Contact|ko

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-28 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 M. de Rooy changed: What|Removed |Added Attachment #10547|0 |1 is obsolete|

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-28 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Frère Sébastien Marie changed: What|Removed |Added Attachment #10027|0 |1 is obsolete|

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-28 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #12 from Frère Sébastien Marie --- (En réponse au commentaire 11) > (En réponse au commentaire 10) > > One question remains: It works for me. But if you change the From address to > > the patron's address, could we have Rel

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-28 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #11 from Frère Sébastien Marie --- (En réponse au commentaire 10) > One question remains: It works for me. But if you change the From address to > the patron's address, could we have Relay Access Denied errors or similar? A

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-28 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #10 from M. de Rooy --- OK. The patch came from Frere Sebastien Marie. And current master does not allow anynomous users here (anymore). One question remains: It works for me. But if you change the From address to the patr

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-28 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 M. de Rooy changed: What|Removed |Added See Also||http://bugs.koha-community.

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-28 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #9 from M. de Rooy --- (In reply to comment #8) > Perhaps it changed again? :( I tested on 3.6.3. No, it is not possible. Somehow I cannot reproduce anymore what I did before.. -- You are receiving this mail because: You

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-28 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #8 from Katrin Fischer --- Perhaps it changed again? :( I tested on 3.6.3. -- You are receiving this mail because: You are the QA Contact for the bug. You are watching all bug changes.

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-28 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #7 from M. de Rooy --- (In reply to comment #6) > Hi Marcel, not sure that was Kyle - there is bug 4274 for the problem. It > used to be possible for not logged in users to mail the cart (I know it was > in 3.2.x). Then it

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-28 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Katrin Fischer changed: What|Removed |Added CC||katrin.fisc...@bsz-bw.de ---

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-28 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 M. de Rooy changed: What|Removed |Added CC||m.de.r...@rijksmuseum.nl --- Com

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-09 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Kyle M Hall changed: What|Removed |Added Status|Patch doesn't apply |Needs Signoff C

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-06-09 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Kyle M Hall changed: What|Removed |Added Attachment #6576|0 |1 is obsolete|

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-02-12 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Jared Camins-Esakov changed: What|Removed |Added Status|Needs Signoff |Patch doesn't apply --

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2012-02-12 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Jared Camins-Esakov changed: What|Removed |Added Status|NEW |Needs Signoff

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2011-12-05 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #3 from Frère Sébastien Marie 2011-12-05 09:25:37 UTC --- Does opac/opac-sendshelf.pl should be have a separated bug report ? As there have same features (send email to someone), corrections (or enhancements) should be co

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2011-12-05 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 --- Comment #2 from Frère Sébastien Marie 2011-12-05 09:21:46 UTC --- Created attachment 6576 --> http://bugs.koha-community.org/bugzilla3/attachment.cgi?id=6576 Bug 3280 Restrict Send-basket feature Here a proposal (should be disc

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2011-12-04 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Frère Sébastien Marie changed: What|Removed |Added CC||semarie-k...@latrappe.

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2011-12-04 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Ian Walls changed: What|Removed |Added CC||ian.walls@bywatersolutions.

[Koha-bugs] [Bug 3280] opac/opac-sendbasket.pl security leaky

2011-05-17 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=3280 Owen Leonard changed: What|Removed |Added Platform|Other |All QAContact|