Re: [aur-dev] [PATCH] Geshi AUR implementation

2010-10-02 Thread Manuel Tortosa
On Saturday 02 October 2010 01:06:41 Loui Chang wrote: On Thu 30 Sep 2010 20:13 +0200, Lukas Fleischer wrote: On Wed, Sep 29, 2010 at 03:35:24PM +0200, Manuel Tortosa wrote: This introduces a remote file inclusion vulnerability allowing an attacker to read arbitrary files since

Re: [aur-dev] [PATCH] Cross-Site Scripting vulnerability

2010-10-02 Thread Loui Chang
On Sat 02 Oct 2010 16:56 +, Viktor Leonhardt wrote: Hello, While working on a better E-mail validation, i found some cross-site vulnerabilities in the lib/accfuncs.inc. Here is the Patch, witch is fixing this problem. I hope, that i found all relevant parts, because I'm not so familiar

Re: [aur-dev] [PATCH] Add timestamp when a package is flagged out-of-date (FS#20848).

2010-10-02 Thread Loui Chang
On Fri 01 Oct 2010 21:41 -0500, Dan McGee wrote: On Fri, Oct 1, 2010 at 9:39 PM, Loui Chang louipc@gmail.com wrote: On Thu 30 Sep 2010 18:19 +0200, Lukas Fleischer wrote: I was thinking - could we just change things so that OutOfDateTS is the sole indicator of whether a package has been

Re: [aur-dev] [PATCH] Make external links in comments clickable (FS#20137).

2010-10-02 Thread Loui Chang
On Fri 01 Oct 2010 01:05 +0200, Lukas Fleischer wrote: On Thu, Sep 30, 2010 at 08:56:56PM +0200, PyroPeter wrote: You can also link to a homepage using valid URL's. The additional feature may be nice, but makes the code more complex. It also trains users to omit the http://; and produces