The branch, STABLE has been updated via 0881b0a7c2d5b2ab4b0ded1c0f68ef2687e775f0 (commit) via b5686c68ab98b2916f187daff90f8b8f392ce394 (commit) via dd81a0fce80b7766e7305c16c7b2cf32207d80fd (commit) via f00c57bdf3669d7471b30e6750f6762d2e01947b (commit) via 4e5c583dcfdd6307f1093f80a9e1d1ff0480cc7d (commit) via c547703b1089bff62b238a908d8559ca3ad845f1 (commit) via b659fbeb128b3235738d6fd787cab096ddc3a591 (commit) via 0f5f2d960184db7333ecf7d52da406cae306412b (commit) via 39edf6e1fbe4a39f6fec0919d60eca5dfc2708ff (commit) via 3d8fddceb0f084d4b77c58c48a98e002db6baa6a (commit) via 2b0d12b2deb1b6b5c4073ecaa7971cb0bbb83389 (commit) via ec848d825ffe896b96b6c3e4b8c7d4c12aadd310 (commit) via 09b30b8b6e462aafc24cc32a78491cd9513305c6 (commit) via 08ee54d4a43b1bd6eff1e6695ff8553e6f26b37a (commit) via 3534dda30a587eafe3bf5016f2fb302dbc224c2e (commit) via 06bfdd7ca6d76335f45d53134770979d7d25d739 (commit) via 9a268729f0cb0aeb2d124b58ca22ef8e7bd7baf6 (commit) via 201ad07ea8883fc8c3a18227a656ea56fe7b18fc (commit) via 5f9c187010dcf2b51bf3dee516789b6fae9f2363 (commit) via 54398f8a124702e30820bc4636040dda1db6b71b (commit) via bea5556023b4561c23e82f5005059c5fb7b1cde8 (commit) via 36c0339eb00394d4c51ccbf82a20feae7b70fb18 (commit) via 58b48a3d4555d0469ee6fed361a9cf8820fb8c9d (commit) via 9eba5726bd809ab874fc29360ac6ff351d86335b (commit) via 3ec3c7ee1766331a25899483ff78ff468516fc2e (commit) via 40d7c3b8baa84c474af5f710e60351b05330f3c6 (commit) via b185ca88f7c8241804cff13a2b315fc3d1222a38 (commit) via 2cc22c8aba33ad12b3d98905d6dfc29f7c878837 (commit) via 70083ad58346ff7190bcd8e56b63ab92f6abfa40 (commit) via 65d962d39703b412dc482be47e092f97933eb8e0 (commit) via 6d0f28b425dc9f975543301c4b194dd6fbdd494d (commit) via ed88c4a7b68c8efd764a364d1a9579aa762ebdaa (commit) via 58d25ddcb8a036743e32879c9320dcd802626082 (commit) via a546479680cd1da8af6812ed0eef83b390bab07f (commit) via 95927229deb417c2df4fad3baccaf9de575c70b5 (commit) via 90a232d8fb9b6e321481cac4c3db21767a3f1189 (commit) via 39cb4d4798f495db25bf65dda95fc8c4e9893367 (commit) via 2ec0de3a9f8d77c750f02c27ba8d83b407a87ea5 (commit) via c4ecddb5a2df58f26675f0162d8f2335b71bfbd5 (commit) via 041cd7e7d2dfa95dd055da6fd2eb5308902fda95 (commit) via 58d86350c439c2ea06d58ba37f723e6e8a8f1abf (commit) via 5217946601b64ee6e92f97443cf4e515c03c0c27 (commit) via 4d1540cc1c8136040968bcfb3a4629aad2551b3a (commit) via 614639a5c5d94b9c693f7ec6e32c1a6e71a7e203 (commit) via 9129444381fef0d9b57466219f21deae8fc95582 (commit) via 31df8ebb5dd444fc40d566407d9b2a00eee8d1b9 (commit) via edf46c8022020099ac953b2e16f36f4f99687d87 (commit) via 43c7f939c31e9304cacbbc456d999d9d6afc8682 (commit) via 5e28dbea224d21b2c03cd325ef67f36b42d2b58d (commit) via f09d19cfa3bd2f31185848adfdeb808576396851 (commit) via e8ee4eb11b784b56d51bf4d37dd4811e8d213569 (commit) via 9e224184d786068317b801291c8f960109f0bdc5 (commit) via c2dd99965dea7756e9de5a58100c1c701ef83de3 (commit) via 341dc1296f8e3fe6b80a9b5f5e752cfd868bdb10 (commit) via 3336bf363625d3512da5f32d5d9f276a64dae02b (commit) via 7ecb1abaa49142a7e0b3f6d6e37cb4855e17ddf9 (commit) from 35de0db1e6c61c0fcb104144a6c31c3304efc79b (commit)
- Log ----------------------------------------------------------------- commit 0881b0a7c2d5b2ab4b0ded1c0f68ef2687e775f0 Merge: 35de0db b5686c6 Author: Marc Delisle marc@infomarc.info Date: Wed Aug 24 12:46:31 2011 -0400
Merge branch 'MAINT_3_4_4' into STABLE
-----------------------------------------------------------------------
Summary of changes: ChangeLog | 20 + Documentation.html | 4 +- README | 2 +- db_operations.php | 11 - export.php | 1 + js/export.js | 25 +- js/functions.js | 4 +- js/indexes.js | 12 +- js/server_privileges.js | 1 + js/sql.js | 5 +- libraries/Config.class.php | 2 +- libraries/config.default.php | 5 +- libraries/core.lib.php | 8 +- libraries/display_export.lib.php | 11 +- libraries/display_import.lib.php | 6 +- libraries/display_tbl.lib.php | 2 +- libraries/export/codegen.php | 340 ++-- libraries/export/xml.php | 43 +- libraries/header.inc.php | 5 +- libraries/sanitizing.lib.php | 18 + libraries/schema/Dia_Relation_Schema.class.php | 1 + libraries/schema/Eps_Relation_Schema.class.php | 1 + libraries/schema/Pdf_Relation_Schema.class.php | 2 + libraries/schema/Svg_Relation_Schema.class.php | 1 + libraries/schema/Visio_Relation_Schema.class.php | 1 + libraries/select_lang.lib.php | 2 + libraries/sqlparser.lib.php | 4 +- po/af.po | 2 +- po/ar.po | 118 +- po/az.po | 2 +- po/be.po | 2 +- po/be@latin.po | 2 +- po/bg.po | 316 ++-- po/bn.po | 2 +- po/{ug.po => br.po} | 2140 +++++++++++----------- po/bs.po | 2 +- po/ca.po | 2 +- po/cs.po | 2 +- po/cy.po | 2 +- po/da.po | 1294 ++++++++----- po/de.po | 2 +- po/el.po | 2 +- po/en_GB.po | 2 +- po/es.po | 2 +- po/et.po | 2 +- po/eu.po | 2 +- po/fa.po | 2 +- po/fi.po | 2 +- po/fr.po | 2 +- po/gl.po | 2 +- po/he.po | 2 +- po/hi.po | 2 +- po/hr.po | 2 +- po/hu.po | 2 +- po/id.po | 2 +- po/it.po | 2 +- po/ja.po | 2 +- po/ka.po | 2 +- po/ko.po | 2 +- po/lt.po | 2 +- po/lv.po | 2 +- po/mk.po | 2 +- po/ml.po | 2 +- po/mn.po | 2 +- po/ms.po | 2 +- po/nb.po | 2 +- po/nl.po | 2 +- po/pl.po | 2 +- po/pt.po | 2 +- po/pt_BR.po | 111 +- po/ro.po | 2 +- po/ru.po | 2 +- po/si.po | 2 +- po/sk.po | 67 +- po/sl.po | 2 +- po/sq.po | 2 +- po/sr.po | 2 +- po/sr@latin.po | 2 +- po/sv.po | 2 +- po/ta.po | 2 +- po/te.po | 2 +- po/th.po | 2 +- po/tr.po | 2 +- po/tt.po | 2 +- po/ug.po | 2 +- po/uk.po | 94 +- po/ur.po | 2 +- po/uz.po | 2 +- po/uz@latin.po | 2 +- po/zh_CN.po | 2 +- po/zh_TW.po | 2 +- setup/index.php | 4 +- setup/lib/index.lib.php | 2 +- sql.php | 2 +- tbl_get_field.php | 3 +- tbl_indexes.php | 14 +- tbl_structure.php | 8 +- tbl_tracking.php | 75 +- transformation_wrapper.php | 2 +- 99 files changed, 2717 insertions(+), 2184 deletions(-) copy po/{ug.po => br.po} (87%)
diff --git a/ChangeLog b/ChangeLog index 05d5fe5..cc9c6f8 100644 --- a/ChangeLog +++ b/ChangeLog @@ -1,6 +1,26 @@ phpMyAdmin - ChangeLog ======================
+3.4.4.0 (2011-08-24) +- bug #3323060 [parser] SQL parser breaks AJAX requests if query has unclosed quotes +- bug #3323101 [parser] Invalid escape sequence in SQL parser +- bug #3348995 [config] $cfg['Export']['asfile'] set to false does not select asText option +- bug #3340151 [export] Working SQL query exports error page +- bug #3353649 [interface] "Create an index on X columns" form not validated +- bug #3350790 [interface] JS error in Table->Structure->Index->Edit +- bug #3353811 [interface] Info message has "error" class +- bug #3357837 [interface] TABbing through a NULL field in the inline mode resets NULL +- remove version number in /setup +- bug #3367993 [usability] Missing "Generate Password" button +- bug #3363221 [display] Missing Server Parameter on inline sql query +- bug #3367986 [navi] Drop field -> lost active table +- remove misleading comment on the "Rename database" interface +- bug #3374374 [interface] Fix footnote for inexact count while browsing +- bug #3372807 [interface] Fix security warning link in setup +- bug #3374347 [display] Backquotes in normal text on import page +- bug #3358750 [core] With Suhosin, urls are too long in edit links +- [security] Missing sanitization on the table, column and index names leads to XSS vulnerabilities, see PMASA-2011-13 + 3.4.3.2 (2011-07-23) - [security] Fixed XSS vulnerability, see PMASA-2011-9 - [security] Fixed local file inclusion vulnerability, see PMASA-2011-10 diff --git a/Documentation.html b/Documentation.html index 15f8000..fd0f6b8 100644 --- a/Documentation.html +++ b/Documentation.html @@ -9,7 +9,7 @@ vim: expandtab ts=4 sw=4 sts=4 tw=78 <link rel="icon" href="./favicon.ico" type="image/x-icon" /> <link rel="shortcut icon" href="./favicon.ico" type="image/x-icon" /> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> - <title>phpMyAdmin 3.4.3.2 - Documentation</title> + <title>phpMyAdmin 3.4.4 - Documentation</title> <link rel="stylesheet" type="text/css" href="docs.css" /> </head>
@@ -17,7 +17,7 @@ vim: expandtab ts=4 sw=4 sts=4 tw=78 <div id="header"> <h1> <a href="http://www.phpmyadmin.net/">php<span class="myadmin">MyAdmin</span></a> - 3.4.3.2 + 3.4.4 Documentation </h1> </div> diff --git a/README b/README index 65f7c52..ab29c94 100644 --- a/README +++ b/README @@ -1,7 +1,7 @@ phpMyAdmin - Readme ===================
-Version 3.4.3.2 +Version 3.4.4
A set of PHP-scripts to manage MySQL over the web.
diff --git a/db_operations.php b/db_operations.php index f48ba27..ebd9333 100644 --- a/db_operations.php +++ b/db_operations.php @@ -405,17 +405,6 @@ if ($db != 'mysql') { ?> </legend> <input id="new_db_name" type="text" name="newname" size="30" class="textfield" value="" /> - <?php - echo '(' . __('Command') . ': '; - /** - * @todo (see explanations above in a previous todo) - */ - //if (PMA_MYSQL_INT_VERSION >= XYYZZ) { - // echo 'RENAME DATABASE'; - //} else { - echo 'INSERT INTO ... SELECT'; - //} - echo ')'; ?> </fieldset> <fieldset class="tblFooters"> <input id="rename_db_input" type="submit" value="<?php echo __('Go'); ?>" /> diff --git a/export.php b/export.php index 7da25fc..100269f 100644 --- a/export.php +++ b/export.php @@ -343,6 +343,7 @@ if (!$save_on_server) { // (avoid rewriting data containing HTML with anchors and forms; // this was reported to happen under Plesk) @ini_set('url_rewriter.tags',''); + $filename = PMA_sanitize_filename($filename);
header('Content-Type: ' . $mime_type); header('Expires: ' . gmdate('D, d M Y H:i:s') . ' GMT'); diff --git a/js/export.js b/js/export.js index 1cf9de5..3fd3c00 100644 --- a/js/export.js +++ b/js/export.js @@ -89,18 +89,23 @@ $(document).ready(function() { /** * Toggles the disabling of the "save to file" options */ +function toggle_save_to_file() { + if($("#radio_dump_asfile:checked").length == 0) { + $("#ul_save_asfile > li").fadeTo('fast', 0.4); + $("#ul_save_asfile > li > input").attr('disabled', 'disabled'); + $("#ul_save_asfile > li> select").attr('disabled', 'disabled'); + } else { + $("#ul_save_asfile > li").fadeTo('fast', 1); + $("#ul_save_asfile > li > input").removeAttr('disabled'); + $("#ul_save_asfile > li> select").removeAttr('disabled'); + } +} + $(document).ready(function() { + toggle_save_to_file(); $("input[type='radio'][name='output_format']").change(function() { - if($("#radio_dump_asfile:checked").length == 0) { - $("#ul_save_asfile > li").fadeTo('fast', 0.4); - $("#ul_save_asfile > li > input").attr('disabled', 'disabled'); - $("#ul_save_asfile > li> select").attr('disabled', 'disabled'); - } else { - $("#ul_save_asfile > li").fadeTo('fast', 1); - $("#ul_save_asfile > li > input").removeAttr('disabled'); - $("#ul_save_asfile > li> select").removeAttr('disabled'); - } - }); + toggle_save_to_file(); + }); });
/** diff --git a/js/functions.js b/js/functions.js index eea8573..75fd677 100644 --- a/js/functions.js +++ b/js/functions.js @@ -1117,6 +1117,7 @@ function changeMIMEType(db, table, reference, mime_type) */ $(document).ready(function(){ $(".inline_edit_sql").live('click', function(){ + var server = $(this).prev().find("input[name='server']").val(); var db = $(this).prev().find("input[name='db']").val(); var table = $(this).prev().find("input[name='table']").val(); var token = $(this).prev().find("input[name='token']").val(); @@ -1132,7 +1133,8 @@ $(document).ready(function(){ $(this).click(function(){ sql_query = $(this).prev().val(); window.location.replace("import.php" - + "?db=" + encodeURIComponent(db) + + "?ser + encodeURIComponent(db) ; >" />