Change logs for ikiwiki source package in Vivid

  • ikiwiki (3.20141016.2) unstable; urgency=high
    
    
      [ Joey Hess ]
      * Fix XSS in openid selector. Thanks, Raghav Bisht. (Closes: #781483)
    
     -- Simon McVittie <email address hidden>  Sun, 29 Mar 2015 22:28:15 +0100
  • ikiwiki (3.20141016.1) unstable; urgency=medium
    
    
      * Backport selected commits for Debian 8:
    
      [ Joey Hess ]
      * Add missing build-depends on libcgi-formbuilder-perl, needed for
        t/relativity.t
      * Set Debian package maintainer to Simon McVittie as I'm retiring from
        Debian.
    
      [ Amitai Schlair ]
      * blogspam: use the 2.0 JSON API (the 1.0 XML-RPC API has been EOL'd).
        Closes: #774441
    
      [ Simon McVittie ]
      * Work around imagemagick Debian bug #771047 by using a non-blank SVG
        for the regression test, to avoid FTBFS in current unstable
    
     -- Simon McVittie <email address hidden>  Wed, 07 Jan 2015 11:08:35 +0000
  • ikiwiki (3.20141016) unstable; urgency=medium
    
    
      [ Joey Hess ]
      * Fix crash that can occur when only_committed_changes is set and a
        file is deleted from the underlay.
    
      [ Simon McVittie ]
      * core: avoid dangerous use of CGI->param in list context, which led
        to a security flaw in Bugzilla; as far as we can tell, ikiwiki
        is not vulnerable to a similar attack, but it's best to be safe
      * core: new reverse_proxy option prevents ikiwiki from trying to detect
        how to make self-referential URLs by using the CGI environment variables,
        for instance when it's deployed behind a HTTP reverse proxy
        (Closes: #745759)
      * core: the default User-Agent is now "ikiwiki/$version" to work around
        ModSecurity rules assuming that only malware uses libwww-perl
      * core: use protocol-relative URLs (e.g. //www.example.com/wiki) so that
        https stays on https and http stays on http, particularly if the
        html5 option is enabled
      * core: avoid mixed content when a https cgiurl links to http static pages
        on the same server (the static pages are assumed to be accessible via
        https too)
      * core: force the correct top URL in w3mmode
      * google plugin: Use search form
      * docwiki: replace Paypal and Flattr buttons with text links
      * comments: don't record the IP address in the wiki if the user is
        logged in via passwordauth or httpauth
      * templates: add ARIA roles to some page elements, if html5 is enabled.
        Thanks, Patrick
      * debian: build-depend on libmagickcore-6.q16-2-extra | libmagickcore-extra
        so we can thumbnail SVGs in the docwiki
      * debian: explicitly depend and build-depend on libcgi-pm-perl
      * debian: drop unused python-support dependency
      * debian: rename debian/link to debian/links so the intended symlinks appear
      * debian: fix some wrong paths in the copyright file
    
     -- Simon McVittie <email address hidden>  Thu, 16 Oct 2014 23:28:26 +0100
  • ikiwiki (3.20140227ubuntu1) utopic; urgency=low
    
      * Merge from Debian unstable.  Remaining changes:
        - Drop wdg-html-validator from Build-Depends field. The xmlns set in the
          generated <html> elements causes /usr/bin/validate to attempt to download
          a file from w3.org. This doesn't work without Internet access.
    
    ikiwiki (3.20140227) unstable; urgency=medium
    
      * Added useragent config setting. Closes: #737121
        Thanks, Tuomas Jormola
      * po: Add html_lang_code and html_lang_dir template variables
        for the language code and direction of text.
        Thanks, Mesar Hameed
      * Allow up to 8 levels of nested directives, rather than previous 3
        in directive infinite loop guard.
      * git diffurl: Do not escape / in paths to changed files, in order to
        interoperate with cgit (gitweb works either way)
        Thanks, intrigeri.
      * git: Explicity push master branch, as will be needed by git 2.0's
        change to push.default=matching by default.
        Thanks, smcv
      * Deal with nasty issue with gettext clobbering $@ while printing
        error message containing it.
        Thanks, smcv
      * Cleanup of the openid login widget, including replacing of hotlinked
        images from openid providers with embedded, freely licensed artwork.
        Thanks, smcv
      * Improve templates testing.
        Thanks, smcv
      * python proxy: Avoid utf-8 related crash.
        Thanks, Antoine Beaupré
      * Special thanks to Simon McVittie for being the patchmeister for this
        release.
    
    ikiwiki (3.20140125) unstable; urgency=medium
    
      * inline: Allow overriding the title of the feed. Closes: #735123
        Thanks, Christophe Rhodes
      * osm: Escape name parameter. Closes: #731797
    
    ikiwiki (3.20140102) unstable; urgency=low
    
      * aggregate: Improve display of post author.
      * poll: Fix behavior of poll buttons when inlined.
      * Fixed unncessary tight loop hash copy in saveindex where a pointer
        can be used instead. Can speed up refreshes by nearly 50% in some
        circumstances.
      * Optimized loadindex by caching the page name in the index.
      * Added only_committed_changes config setting, which speeds up wiki
        refresh by querying git to find the files that were changed, rather
        than looking at the work tree. Not enabled by default as it can
        break some setups where not all files get committed to git.
      * comments: Write pending moderation comments to the transient underlay
        to avoid conflict with only_committed_changes.
      * search: Added google_search option, which makes it search google
        rather than using the internal xapain database.
        (googlesearch plugin is too hard to turn on when xapain databases
        corrupt themselves, which happens all too frequently).
      * osm: Remove invalid use of charset on embedded javascript tags.
        Closes: #731197
      * style.css: Add compatibility definitions for more block-level
        html5 elements. Closes: #731199
      * aggregrate: Fix several bugs in handling of empty and colliding
        titles when generating filenames.
     -- Bhavani Shankar <email address hidden>   Thu, 01 May 2014 22:27:24 +0530