1. dd7f4a9 re-included URL encoded characters within _remove_invisible_characters() which were mistakenly pulled out in a previous commit, not released by Derek Jones · 17 years ago
  2. 68d7bd6 changed link and image regex to be more precise in matching tags, reducing false positive matches by Derek Jones · 17 years ago
  3. e8e18fe Changed regex for onfoo event handlers to prevent unwanted matching of text such as locatiON, cONtent, etc. by Derek Jones · 17 years ago
  4. 067e5dd whitespace by Derek Jones · 17 years ago
  5. 40f38f1 simplified regex for _remove_invisible_characters() - since we rawurldecode() the string, there's no need to go looking for url encoded characters here by Derek Jones · 17 years ago
  6. e37fa05 fixed some whitespace in the number helper and improved on the calculation method by Derek Jones · 17 years ago
  7. cc1be0f Moved the <label> output ability from the language library to a language helper (hotfix for 1.6.3) by Derek Jones · 17 years ago
  8. fd7943a Fixed a double opening &lt;p&gt; tag in the index pages of each system directory. by Derek Allard · 17 years ago
  9. a145e92 bump CI_VERSION to 1.6.3 by Derek Allard · 17 years ago
  10. ff845f9 changed your-site.com to example.com doc-wide by Derek Jones · 17 years ago
  11. 85f66ea Number helper uses lang files by Derek Allard · 17 years ago
  12. d6c6998 fixed accidental removal of $converted_string in xss_clean() for image comparison by Derek Jones · 17 years ago
  13. fc18b00 added a bit of leeway for images to avoid the more common false-positives that using xss_clean() on image files might trigger by Derek Jones · 17 years ago
  14. 7aae905 Further improvements to xss_clean() by Derek Jones · 17 years ago
  15. db25721 Added the ability to automatically output language items as form labels in the Language class. by Derek Allard · 17 years ago
  16. d3ee041 Added get_post() to the Input class. Documented get() in the Input class. by Derek Allard · 17 years ago
  17. 0f10919 by Derek Allard · 17 years ago
  18. a935c3f added a Number helper by Derek Jones · 17 years ago
  19. 3640a0b removed maxlength and size as automatically added attributes in form helper by Derek Allard · 17 years ago
  20. 9736d3f correcting some docblock comments by Derek Allard · 17 years ago
  21. 61860c9 Added a language key for valid_emails in validation_lang.php. by Derek Allard · 17 years ago
  22. 27a5aa1 added quoted-printable headers when $this->send_multipart has been manually changed to FALSE by Derek Jones · 17 years ago
  23. 57aea15 Removed an unused Router reference in _display_cache(). by Derek Allard · 17 years ago
  24. 96537fd goofed. Fixed up. by Derek Allard · 17 years ago
  25. f7623aa default to post method by Derek Allard · 17 years ago
  26. 1e6ab99 Form helper refactored to allow form_open() and form_fieldset() to accept arrays or strings as arguments. by Derek Allard · 17 years ago
  27. 7a3b96e picky picky Jones adjusts some syntax by Derek Jones · 17 years ago
  28. c1acb41 a few tweaks for speed by Derek Allard · 17 years ago
  29. 144cb5b simplified and refactored input filtering and retrieval by Derek Jones · 17 years ago
  30. c04f0fc emendation to on* event handler removal by Derek Jones · 17 years ago
  31. 7e98a27 whitespace, whitespace, schmeitespace by Derek Jones · 17 years ago
  32. c06f58e compacting some whitespace by Derek Jones · 17 years ago
  33. d8364c4 bit of a code cleanup by Derek Allard · 17 years ago
  34. 694096e change AR behaviour so that blank values result in empty quotes by Derek Allard · 17 years ago
  35. 92bb3e6 decided just to kill all on*= event handlers, rather than trying to keep up with (and require users to do the same) with a blacklist. by Derek Jones · 17 years ago
  36. 9f23e7c moved word compacting to a callback for clarity, added a few js event handlers for removal by Derek Jones · 17 years ago
  37. bd44009 made MySQL/MySQLi forge use explicitly named KEYs, added ability to specify multi-column non-primary keys in table creation by Derek Jones · 17 years ago
  38. 9e11220 added error suppression to fopen() in write_file() by Derek Jones · 17 years ago
  39. a459b46 Fixed a bug (#4561) where orhaving() wasn't properly passing values. by Derek Allard · 17 years ago
  40. 908ecc6 more complete protection against malformed link tags to protect against hex entities and href=data:url exploits by Derek Jones · 17 years ago
  41. c6238e9 customizable query string by Derek Allard · 17 years ago
  42. 8ddc0db Added support for query strings to the Pagination class, automatically detected or explicitly declared. by Derek Allard · 17 years ago
  43. bd08d84 improved security in xss_clean(), added <audio> and <video> tags to naughty HTML tags, and the HTML5 event handlers onerror and onended by Derek Jones · 17 years ago
  44. 513ce07 Moved the _has_operators() function into DB_driver from DB_active_rec. by Derek Allard · 17 years ago
  45. 23df94d reduced $mobiles to single array by Derek Jones · 17 years ago
  46. ac27fbe Considerably expanded list of mobile user-agents in config/user_agents.php. by Derek Allard · 17 years ago
  47. 5453b8e changed foreach() reindexing of segment arrays to array_unshift() - teensy tiny memory and speed improvement. by Derek Jones · 17 years ago
  48. ef40640 fixed regular expression in Image lib, CI bug #4542 by Derek Jones · 17 years ago
  49. 245038d addition xss protection against certain data urls, stripping of anything sent with utf-7 encoding by Derek Jones · 17 years ago
  50. 63fc5fe added ability to use xss_clean() to test images, and improved security for vectors particular to the Opera family of browsers by Derek Jones · 17 years ago
  51. d9d379c Set the mime type check in the Upload class to reference the global mimes variable. by Derek Allard · 17 years ago
  52. b846d38 Added missing semicolon in upload_lang.php by Derek Jones · 17 years ago
  53. cafd63e set $DB->char_set and $DB->dbcollat defaults to utf8 and utf8_general_ci respectively by Derek Jones · 17 years ago
  54. 97bc010 fixed bug #3419 where the 'database' setting for DSN connections was using the host portion of the URL instead of the path. by Derek Jones · 17 years ago
  55. 454fa7e force closing tag on eval() for servers not running short_open_tags by Derek Jones · 17 years ago
  56. f38fe09 hotfix for a bug in database error display introduced by 1.6.2 fix for bugs #4451, #4299, and #4339 by Derek Jones · 17 years ago
  57. 000ab69 Hey you! Yeah, you, that other set of hardcoded arrays in xss_clean(). You're coming with me, pal! by Derek Jones · 17 years ago
  58. e3332b0 increased security and performance of xss_clean(), added _sanitize_naughty_html() callback and removed "never allowed" items to a class property by Derek Jones · 17 years ago
  59. a065bab The Zip class has undergone a substantial re-write for speed and clarity by Derek Allard · 17 years ago
  60. 687cdca removed some stray testing code by Derek Allard · 17 years ago
  61. 1b7ef4f reverted OR back to || for js_calendar_pi.php javascript by Derek Jones · 17 years ago
  62. 0b59f27 Some sweeping syntax changes for consistency: by Derek Jones · 17 years ago
  63. 5cf6647 adjusted eval() statement in Loader to accommodate servers with short_open_tag disabled with the new change of removing closing PHP tags from files by Derek Jones · 17 years ago
  64. 0fd8f02 minor source formatting by Derek Allard · 17 years ago
  65. 62bd430 preg_split changed to explode by Derek Allard · 17 years ago
  66. 20d2405 substr checks swapped out with strncmp by Derek Allard · 17 years ago
  67. 751506e fixed a misspelling in the Input library of CDATA by Derek Allard · 17 years ago
  68. 15dcf49 removed an ereg from config by Derek Allard · 17 years ago
  69. 5fe155e Escape behaviour in where() clauses has changed; values in those with the "FALSE" argument are no longer escaped (ie: quoted). by Derek Allard · 17 years ago
  70. 244b4c7 by Rick Ellis · 17 years ago
  71. 53437de Added protection in xss_clean() for GET variables in URLs by Derek Jones · 17 years ago
  72. a632589 Fixed a bug in AR compiling, where select statements with arguments got incorrectly escaped (#3478). by Derek Allard · 17 years ago
  73. c14968d changed $xmlrpcDateTime property to all lowercase 'datetime.iso8601' so it can be recognized as a valid XML-RPC type by Derek Jones · 17 years ago
  74. d56743b fixed a bug that would lead to a PHP notice error of array to string conversion in prep_for_form() by Derek Jones · 17 years ago
  75. d36ade0 passed db object by reference to DB Cache class, and changed the cache class to use that db object instead of $CI->db, to support returned db objects and multiple db connections by Derek Jones · 17 years ago
  76. 500fa6c changed overlay_watermark() to check for an alpha value before applying the image to help support PNG-24s with alpha transparency by Derek Jones · 17 years ago
  77. 7f88aa5 changed class instantiations to reference global $LANG and fetch existing Exceptions class, and added language variable for database error heading by Derek Jones · 17 years ago
  78. a3ffbbb Removed closing PHP tags, replaced with a comment block identifying the end of the file by Derek Jones · 17 years ago
  79. c7deac9 Undoing change committed in r1115 by Derek Jones · 17 years ago
  80. 5583e1a removed closing PHP tag from all framework files by Derek Jones · 17 years ago
  81. af4a8a0 added dot transformation to body of email when sending via SMTP by Derek Jones · 17 years ago
  82. 8e94646 removed extraneous error message from Upload lib on failure of validate_upload_path() by Derek Jones · 17 years ago
  83. 044379d added 'object' key to the XML-RPCS config allowing the passing of a class object for method calls that aren't part of the CI super object by Derek Jones · 17 years ago
  84. 0f13a13 added SET to the list of write type queries by Derek Jones · 17 years ago
  85. 94a2182 added symbolic_permissions() and octal_permissions() to the File helper by Derek Jones · 17 years ago
  86. 40306b5 Fixed a bug where $data was not being converted to an array properly in set_rules() by Derek Jones · 17 years ago
  87. 4dc0618 Fixed bug with recursive deletes in delete_dir() by Derek Jones · 17 years ago
  88. d007243 flipped the $not flag for or_where_not_in() by Derek Jones · 17 years ago
  89. b514b02 added code comment for 'directory_trigger' config value which is not yet implemented by Derek Jones · 17 years ago
  90. 0509775 Added checks for objects in DB driver instead of just resources to accommodate MySQLi, and fixed check in mysqli_result.php checking for a resource. by Derek Jones · 17 years ago
  91. cd6f9cd removed default title= attribute from anchor() in URL Helper by Derek Jones · 17 years ago
  92. 62a9020 removed SCRIPT_NAME from path provided by ORIG_PATH_INFO to remove the path and script name from the URI data by Derek Jones · 17 years ago
  93. d196d4e fixed a typo with a variable in the compatibility helper by Derek Jones · 17 years ago
  94. f9f9f66 updated CI_VERSION to 1.6.2 by Derek Allard · 17 years ago
  95. 00618de Added a Compatibility Helper by Derek Jones · 17 years ago
  96. fd93d22 Flipped user guide page titles for easier recognition in tabs: by Derek Jones · 17 years ago
  97. 2798b50 fixed a bug where the dir resource was not closed in the directory helper, and made it more efficient by Derek Jones · 17 years ago
  98. de7320b Changed the radio() and checkbox() functions to default to not checked by default. by Derek Allard · 17 years ago
  99. be8ec80 Fixed a bug in the table library that could cause identically constructed rows to be dropped (#3459). by Derek Allard · 17 years ago
  100. ff390bd DB Forge is now assigned to any models that exist after loading (#3457). by Derek Allard · 17 years ago