<feed xmlns='http://www.w3.org/2005/Atom'>
<title>markzz/aurweb.git/web/lib/aurjson.class.php, branch v4.2.0</title>
<subtitle>aurweb working repository</subtitle>
<id>https://git.markzz.net/markzz/aurweb.git/atom/web/lib/aurjson.class.php?h=v4.2.0</id>
<link rel='self' href='https://git.markzz.net/markzz/aurweb.git/atom/web/lib/aurjson.class.php?h=v4.2.0'/>
<link rel='alternate' type='text/html' href='https://git.markzz.net/markzz/aurweb.git/'/>
<updated>2016-02-09T20:54:39Z</updated>
<entry>
<title>aurjson: Add package base keywords</title>
<updated>2016-02-09T20:54:39Z</updated>
<author>
<name>Lukas Fleischer</name>
<email>lfleischer@archlinux.org</email>
</author>
<published>2016-02-09T20:49:57Z</published>
<link rel='alternate' type='text/html' href='https://git.markzz.net/markzz/aurweb.git/commit/?id=9d7d1be731eea243587a046774a650576521bcbb'/>
<id>urn:sha1:9d7d1be731eea243587a046774a650576521bcbb</id>
<content type='text'>
Expose package base keywords through the RPC interface (version 5).

Signed-off-by: Lukas Fleischer &lt;lfleischer@archlinux.org&gt;
</content>
</entry>
<entry>
<title>aurjson: Do not search by ID when argument is numeric</title>
<updated>2015-12-13T09:22:59Z</updated>
<author>
<name>Lukas Fleischer</name>
<email>lfleischer@archlinux.org</email>
</author>
<published>2015-12-12T16:35:29Z</published>
<link rel='alternate' type='text/html' href='https://git.markzz.net/markzz/aurweb.git/commit/?id=1f179c9fbc5fc4bb7d94e53a52f519110d0b660e'/>
<id>urn:sha1:1f179c9fbc5fc4bb7d94e53a52f519110d0b660e</id>
<content type='text'>
When performing info or multiinfo queries, one can currently either pass
package names or package IDs as parameters. As a consequence, it is
impossible to search for packages with a numeric package name because
numeric arguments are always treated as IDs. Since package IDs are not
public anymore these days, simply remove the possibility to search by ID
in revision 5 of the RPC interface.

Fixes FS#47324.

Suggested-by: Dave Reisner &lt;dreisner@archlinux.org&gt;
Signed-off-by: Lukas Fleischer &lt;lfleischer@archlinux.org&gt;
</content>
</entry>
<entry>
<title>aurjson: Allow underscores in JSONP callback names</title>
<updated>2015-10-24T16:03:19Z</updated>
<author>
<name>Lukas Fleischer</name>
<email>lfleischer@archlinux.org</email>
</author>
<published>2015-10-24T16:03:19Z</published>
<link rel='alternate' type='text/html' href='https://git.markzz.net/markzz/aurweb.git/commit/?id=a2cbc7f646a54cc2c19adc5f76a2ba1003e25c3c'/>
<id>urn:sha1:a2cbc7f646a54cc2c19adc5f76a2ba1003e25c3c</id>
<content type='text'>
Signed-off-by: Lukas Fleischer &lt;lfleischer@archlinux.org&gt;
</content>
</entry>
<entry>
<title>aurjson: Rename the search_by parameter to "by"</title>
<updated>2015-10-09T15:35:51Z</updated>
<author>
<name>Lukas Fleischer</name>
<email>lfleischer@archlinux.org</email>
</author>
<published>2015-10-09T15:35:29Z</published>
<link rel='alternate' type='text/html' href='https://git.markzz.net/markzz/aurweb.git/commit/?id=1f6237ffa73f1cc931ec7cb2abbdd6ff54e1581a'/>
<id>urn:sha1:1f6237ffa73f1cc931ec7cb2abbdd6ff54e1581a</id>
<content type='text'>
This parameter is only supported by the search command. We do not need
to repeat ourselves.

Signed-off-by: Lukas Fleischer &lt;lfleischer@archlinux.org&gt;
</content>
</entry>
<entry>
<title>aurjson: Merge info and multiinfo commands</title>
<updated>2015-10-04T09:40:38Z</updated>
<author>
<name>Lukas Fleischer</name>
<email>lfleischer@archlinux.org</email>
</author>
<published>2015-10-04T07:57:35Z</published>
<link rel='alternate' type='text/html' href='https://git.markzz.net/markzz/aurweb.git/commit/?id=3c06716c729580f28c20d7b7522a3382ed857322'/>
<id>urn:sha1:3c06716c729580f28c20d7b7522a3382ed857322</id>
<content type='text'>
Signed-off-by: Lukas Fleischer &lt;lfleischer@archlinux.org&gt;
</content>
</entry>
<entry>
<title>aurjson: Add "maintainer" search type</title>
<updated>2015-10-04T09:40:37Z</updated>
<author>
<name>Lukas Fleischer</name>
<email>lfleischer@archlinux.org</email>
</author>
<published>2015-10-04T07:50:05Z</published>
<link rel='alternate' type='text/html' href='https://git.markzz.net/markzz/aurweb.git/commit/?id=261c7f74dd17ad277fc9e1a1478983749578f133'/>
<id>urn:sha1:261c7f74dd17ad277fc9e1a1478983749578f133</id>
<content type='text'>
Deprecate the msearch command and add a new search type to the search
command.

Signed-off-by: Lukas Fleischer &lt;lfleischer@archlinux.org&gt;
</content>
</entry>
<entry>
<title>Fix parameter processing in parse_multiinfo_args()</title>
<updated>2015-10-03T09:07:39Z</updated>
<author>
<name>Lukas Fleischer</name>
<email>lfleischer@archlinux.org</email>
</author>
<published>2015-10-03T09:07:39Z</published>
<link rel='alternate' type='text/html' href='https://git.markzz.net/markzz/aurweb.git/commit/?id=f5b4f7e996a095dbc04305cb32a89c700f585acd'/>
<id>urn:sha1:f5b4f7e996a095dbc04305cb32a89c700f585acd</id>
<content type='text'>
Fixes a regression introduced in 94aeead (aurjson: Pass http_data array
to all functions, 2015-06-28).

Signed-off-by: Lukas Fleischer &lt;lfleischer@archlinux.org&gt;
</content>
</entry>
<entry>
<title>aurjson.class.php: Sync error message with front-end</title>
<updated>2015-09-26T05:43:10Z</updated>
<author>
<name>Lukas Fleischer</name>
<email>lfleischer@archlinux.org</email>
</author>
<published>2015-09-26T05:42:05Z</published>
<link rel='alternate' type='text/html' href='https://git.markzz.net/markzz/aurweb.git/commit/?id=c67e5a1cdf970062c75ad11f019340d318193cbb'/>
<id>urn:sha1:c67e5a1cdf970062c75ad11f019340d318193cbb</id>
<content type='text'>
Instead of introducing a new message "You do not have the right to edit
this comment." for the RPC interface, use "You are not allowed to edit
this comment." which we already show in the front-end.

Reported-by: Christoph Seitz &lt;seitz.christoph@gmail.com&gt;
Signed-off-by: Lukas Fleischer &lt;lfleischer@archlinux.org&gt;
</content>
</entry>
<entry>
<title>aurjson.class.php: Fix "Undefined index" notices</title>
<updated>2015-09-25T06:35:43Z</updated>
<author>
<name>Lukas Fleischer</name>
<email>lfleischer@archlinux.org</email>
</author>
<published>2015-09-24T16:27:21Z</published>
<link rel='alternate' type='text/html' href='https://git.markzz.net/markzz/aurweb.git/commit/?id=2f8e0dfa3ac67a4225b27135977a48b124717762'/>
<id>urn:sha1:2f8e0dfa3ac67a4225b27135977a48b124717762</id>
<content type='text'>
Signed-off-by: Lukas Fleischer &lt;lfleischer@archlinux.org&gt;
</content>
</entry>
<entry>
<title>Mitigate JSONP callback vulnerabilities</title>
<updated>2015-09-12T08:20:03Z</updated>
<author>
<name>Lukas Fleischer</name>
<email>lfleischer@archlinux.org</email>
</author>
<published>2015-09-12T08:04:43Z</published>
<link rel='alternate' type='text/html' href='https://git.markzz.net/markzz/aurweb.git/commit/?id=209b0b6edad0c18a2ea14eac83c6c4787264aa63'/>
<id>urn:sha1:209b0b6edad0c18a2ea14eac83c6c4787264aa63</id>
<content type='text'>
The callback parameter of the RPC interface currently allows for
specifying a prefix of arbitrary length of the returned result. This can
be exploited by certain attacks.

As a countermeasure, this patch restricts the allowed character set for
the callback name to letters, digits, underscores, parenthesis and dots.
It also limits the length of the name to 128 characters. Furthermore,
the reflected callback name is now always prepended with "/**/", which
is a common workaround to protect against attacks such as Rosetta Flash.

Fixes FS#46259.

Signed-off-by: Lukas Fleischer &lt;lfleischer@archlinux.org&gt;
</content>
</entry>
</feed>
