1. 68d7bd6 changed link and image regex to be more precise in matching tags, reducing false positive matches by Derek Jones · 17 years ago
  2. e8e18fe Changed regex for onfoo event handlers to prevent unwanted matching of text such as locatiON, cONtent, etc. by Derek Jones · 17 years ago
  3. 067e5dd whitespace by Derek Jones · 17 years ago
  4. 40f38f1 simplified regex for _remove_invisible_characters() - since we rawurldecode() the string, there's no need to go looking for url encoded characters here by Derek Jones · 17 years ago
  5. cc1be0f Moved the <label> output ability from the language library to a language helper (hotfix for 1.6.3) by Derek Jones · 17 years ago
  6. fd7943a Fixed a double opening &lt;p&gt; tag in the index pages of each system directory. by Derek Allard · 17 years ago
  7. ff845f9 changed your-site.com to example.com doc-wide by Derek Jones · 17 years ago
  8. d6c6998 fixed accidental removal of $converted_string in xss_clean() for image comparison by Derek Jones · 17 years ago
  9. fc18b00 added a bit of leeway for images to avoid the more common false-positives that using xss_clean() on image files might trigger by Derek Jones · 17 years ago
  10. 7aae905 Further improvements to xss_clean() by Derek Jones · 17 years ago
  11. db25721 Added the ability to automatically output language items as form labels in the Language class. by Derek Allard · 17 years ago
  12. d3ee041 Added get_post() to the Input class. Documented get() in the Input class. by Derek Allard · 17 years ago
  13. 9736d3f correcting some docblock comments by Derek Allard · 17 years ago
  14. 27a5aa1 added quoted-printable headers when $this->send_multipart has been manually changed to FALSE by Derek Jones · 17 years ago
  15. 57aea15 Removed an unused Router reference in _display_cache(). by Derek Allard · 17 years ago
  16. 7a3b96e picky picky Jones adjusts some syntax by Derek Jones · 17 years ago
  17. c1acb41 a few tweaks for speed by Derek Allard · 17 years ago
  18. 144cb5b simplified and refactored input filtering and retrieval by Derek Jones · 17 years ago
  19. c04f0fc emendation to on* event handler removal by Derek Jones · 17 years ago
  20. 92bb3e6 decided just to kill all on*= event handlers, rather than trying to keep up with (and require users to do the same) with a blacklist. by Derek Jones · 17 years ago
  21. 9f23e7c moved word compacting to a callback for clarity, added a few js event handlers for removal by Derek Jones · 17 years ago
  22. a459b46 Fixed a bug (#4561) where orhaving() wasn't properly passing values. by Derek Allard · 17 years ago
  23. 908ecc6 more complete protection against malformed link tags to protect against hex entities and href=data:url exploits by Derek Jones · 17 years ago
  24. c6238e9 customizable query string by Derek Allard · 17 years ago
  25. 8ddc0db Added support for query strings to the Pagination class, automatically detected or explicitly declared. by Derek Allard · 17 years ago
  26. bd08d84 improved security in xss_clean(), added <audio> and <video> tags to naughty HTML tags, and the HTML5 event handlers onerror and onended by Derek Jones · 17 years ago
  27. 5453b8e changed foreach() reindexing of segment arrays to array_unshift() - teensy tiny memory and speed improvement. by Derek Jones · 17 years ago
  28. ef40640 fixed regular expression in Image lib, CI bug #4542 by Derek Jones · 17 years ago
  29. 245038d addition xss protection against certain data urls, stripping of anything sent with utf-7 encoding by Derek Jones · 17 years ago
  30. 63fc5fe added ability to use xss_clean() to test images, and improved security for vectors particular to the Opera family of browsers by Derek Jones · 17 years ago
  31. d9d379c Set the mime type check in the Upload class to reference the global mimes variable. by Derek Allard · 17 years ago
  32. 454fa7e force closing tag on eval() for servers not running short_open_tags by Derek Jones · 17 years ago
  33. 000ab69 Hey you! Yeah, you, that other set of hardcoded arrays in xss_clean(). You're coming with me, pal! by Derek Jones · 17 years ago
  34. e3332b0 increased security and performance of xss_clean(), added _sanitize_naughty_html() callback and removed "never allowed" items to a class property by Derek Jones · 17 years ago
  35. a065bab The Zip class has undergone a substantial re-write for speed and clarity by Derek Allard · 17 years ago
  36. 0b59f27 Some sweeping syntax changes for consistency: by Derek Jones · 17 years ago
  37. 5cf6647 adjusted eval() statement in Loader to accommodate servers with short_open_tag disabled with the new change of removing closing PHP tags from files by Derek Jones · 17 years ago
  38. 0fd8f02 minor source formatting by Derek Allard · 17 years ago
  39. 62bd430 preg_split changed to explode by Derek Allard · 17 years ago
  40. 20d2405 substr checks swapped out with strncmp by Derek Allard · 17 years ago
  41. 751506e fixed a misspelling in the Input library of CDATA by Derek Allard · 17 years ago
  42. 15dcf49 removed an ereg from config by Derek Allard · 17 years ago
  43. 53437de Added protection in xss_clean() for GET variables in URLs by Derek Jones · 17 years ago
  44. c14968d changed $xmlrpcDateTime property to all lowercase 'datetime.iso8601' so it can be recognized as a valid XML-RPC type by Derek Jones · 17 years ago
  45. d56743b fixed a bug that would lead to a PHP notice error of array to string conversion in prep_for_form() by Derek Jones · 17 years ago
  46. 500fa6c changed overlay_watermark() to check for an alpha value before applying the image to help support PNG-24s with alpha transparency by Derek Jones · 17 years ago
  47. a3ffbbb Removed closing PHP tags, replaced with a comment block identifying the end of the file by Derek Jones · 17 years ago
  48. c7deac9 Undoing change committed in r1115 by Derek Jones · 17 years ago
  49. 5583e1a removed closing PHP tag from all framework files by Derek Jones · 17 years ago
  50. af4a8a0 added dot transformation to body of email when sending via SMTP by Derek Jones · 17 years ago
  51. 8e94646 removed extraneous error message from Upload lib on failure of validate_upload_path() by Derek Jones · 17 years ago
  52. 044379d added 'object' key to the XML-RPCS config allowing the passing of a class object for method calls that aren't part of the CI super object by Derek Jones · 17 years ago
  53. 40306b5 Fixed a bug where $data was not being converted to an array properly in set_rules() by Derek Jones · 17 years ago
  54. 4dc0618 Fixed bug with recursive deletes in delete_dir() by Derek Jones · 17 years ago
  55. 62a9020 removed SCRIPT_NAME from path provided by ORIG_PATH_INFO to remove the path and script name from the URI data by Derek Jones · 17 years ago
  56. be8ec80 Fixed a bug in the table library that could cause identically constructed rows to be dropped (#3459). by Derek Allard · 17 years ago
  57. ff390bd DB Forge is now assigned to any models that exist after loading (#3457). by Derek Allard · 17 years ago
  58. 3be20e2 tweak to the new fopen mode constant names by Derek Jones · 17 years ago
  59. 14031d1 implemented fopen mode constants by Derek Jones · 17 years ago
  60. 7327499 Added get_dir_file_info(), get_file_info(), and get_mime_by_extension() to the File Helper. by Derek Allard · 17 years ago
  61. c39d202 The Zip class now exits within download(). by Derek Allard · 17 years ago
  62. b94b89c Added a valid_emails rule to the Validation class. by Derek Allard · 17 years ago
  63. f9d5348 Unit Testing results are now colour coded, and a change was made to the default template of results. by Derek Allard · 17 years ago
  64. 7c53be4 Added the ability to set CRLF settings via config in the Email class. by Derek Allard · 17 years ago
  65. 27b5005 added check to make sure the URI path is not constructed entirely of slashes in URI::_fetch_uri_string() by Derek Jones · 17 years ago
  66. 3ad8efe added constants.php file and implemented constants for file system modes by Derek Jones · 17 years ago
  67. 72c82c1 include() vs include_once() allows for multiple views with the same name by Derek Allard · 17 years ago
  68. d888c35 changed include into include_once by Derek Allard · 17 years ago
  69. 9c4280b added hashing to prevent client side data tampering to sessions by Derek Allard · 17 years ago
  70. 6ef8b69 added filename prepping in the Upload library to prevent files with multiple extensions to potentially be parsed as a script by Apache by Derek Jones · 17 years ago
  71. 4acd41a restore a comment by Derek Allard · 17 years ago
  72. 8a16077 added improved check for controller method access so that CI does not attempt to load private or protected controller methods by Derek Jones · 17 years ago
  73. 964366d changed conditional for empty cells to not match on variables that would be loosely cast as an empty string by Derek Jones · 17 years ago
  74. 80ddb6b Moved the safe mode and auth checks for the Email library into the constructor by Derek Allard · 17 years ago
  75. b069789 removed the array_diff comparison in _reindex_segments(). That conditional and use of those functions is probably slower than looping through both arrays, even if someone went crazy with dozens of URI segments. by Derek Jones · 17 years ago
  76. 881a79e Fixed bug (#3445) where the routed segment array when the default controller is used was not being re-indexed to begin with 1 by Derek Jones · 17 years ago
  77. eb002ff adding is_numeric back into validation library by Derek Allard · 17 years ago
  78. b35c3f5 changed order of SQL keywords in the $highlight array so OR would not be highlighted before ORDER BY by Derek Jones · 17 years ago
  79. 0ea06fd * Fixed a bug (#3396) where certain POST variables would cause a PHP warning. by Derek Jones · 17 years ago
  80. ab32a42 changed URL decoding implementation of xss_clean() to use rawurldecode() to discontinue misconversion of characters to bad entities, and to continue avoidance of unwanted removal of + signs by Derek Jones · 17 years ago
  81. 72d6133 Fixed bug #1813 - added check for $CI->db isset() and is_object() before returning false in Loader::database() by Derek Jones · 17 years ago
  82. 63df95e removed last_visit from the Session class by Derek Jones · 17 years ago
  83. c38c703 bugfix (#1842) - added 'index' to routed segment array when only the controller was specified in the URI. by Derek Jones · 17 years ago
  84. d45379e Fixed a bug (#3269) where the rsegment array would not be set properly when there is no URI request. by Derek Jones · 17 years ago
  85. f37fa6e Fixed a bug (#2679) where the "previous" pagination link would get drawn on the first page. by Derek Allard · 17 years ago
  86. 240292e fixed bug (#3284) where the $rsegment array would not be set properly if the requested URI contained more segments than the routed URI. by Derek Jones · 17 years ago
  87. 2712610 fixed bug (#3321) where the uri_string was not being set properly when retrieved from $_GET (segment based GET, not ?c=controller) by Derek Jones · 17 years ago
  88. 15a3477 fixed a syntax bug in strip_imge_tags by Derek Allard · 17 years ago
  89. 44dbc78 Fixed a bug (#3024) in which master_dim wasn't getting reset by clear() in the Image library. by Derek Allard · 17 years ago
  90. 26fba46 fixed bug (#3331) with image destination path in image_process_ntpbm() by Derek Jones · 17 years ago
  91. c9c6faa added verbose comment regarding the $v2_override change by Derek Jones · 17 years ago
  92. 1d3137b fixed a dynamic_output error, and a gdversion bug. by Derek Allard · 17 years ago
  93. 878cd70 Fixed a bug (#2858) which referenced a wrong variable in the Image class. by Derek Allard · 17 years ago
  94. 9ece743 fixed an error message, and added one if the path is invalid. by Derek Allard · 17 years ago
  95. 31438fe Removed an unused parameter from Profiler (#3332). by Derek Allard · 17 years ago
  96. 269b942 added ability to "extend" helpers by Derek Jones · 17 years ago
  97. a25530f added is_really_writable() to Common.php, replaced is_writable() throughout application with is_really_writable() by Derek Jones · 17 years ago
  98. 15130ca * Added valid_base64() to the Validation class by Derek Jones · 17 years ago
  99. 1353ffb Fixed a bug (#3330) in the FTP class where a comparison wasn't getting made. by Derek Allard · 17 years ago
  100. a665743 Added a stripslashes() into the Upload Library. by Derek Allard · 17 years ago