[Michal Čihař] Sent CSP headers for phpinfo

[Michal Čihař] Send CSP headers on changelog

[Michal Čihař] Avoid possible path traversal using MySQL username

[Michal Čihař] Generate valid PHP code even when table/database name contains PHP

[Michal Čihař] Use phpMyAdmin version in PHP export header

[Michal Čihař] Fix PHP export tests

[Michal Čihař] Adjust test to not use HTML escaping layer

[Michal Čihař] Properly escape generated XML export

[Michal Čihař] Improve cookie encryption

[Michal Čihař] Use https for wiki links

[Michal Čihař] Use https for wiki links

[Michal Čihař] Properly escape MySQL status variables

[bennetch] Add Secure and HttpOnly flags for session cookie setup in examples

[Michal Čihař] Make proxy IP parsing aware of multiple proxies

[Michal Čihař] Remove not needed include

[Michal Čihař] Move PMA_getIp to core

[Michal Čihař] Use PMA_getIp instead of REMOTE_ADDR to get user address

[Michal Čihař] Remove Swekey support

[Michal Čihař] Include only relative path in backtrace

[Michal Čihař] Remove debugging code

[madhura.cj] Fix XSS in tbl_gis_visualization.php

[madhura.cj] Fix XSS in server_replication.php

[Michal Čihař] Use whitelist rather than blacklist for URL filtering

[Michal Čihař] Fix wrong merge resolution

[Michal Čihař] Add rel="noopener noreferrer" to all target="_blank" links

[Michal Čihař] Adjust tests to recent changes

[Michal Čihař] Use _blank target instead of invalid _new

[Michal Čihař] Escape HTML in Mediawiki comments

[Michal Čihař] Ensure last version is numeric

[Michal Čihař] Hide session error messages to avoid FPD

[Michal Čihař] Do not allow symlinks in UploadDir

[Michal Čihař] Use phpseclib's Crypt module to generate encryption keys

[Michal Čihař] Use iframe sandbox for rendering HTML in transformation

[Michal Čihař] Prefer curl over file_get_contents

[Michal Čihař] Sanitize MySQL host name before connecting

[Michal Čihař] Validate serialized data before unserializing

[Michal Čihař] Escape suggested database name

[Michal Čihař] Ensure page number is integer

[Michal Čihař] Correctly escape MySQL username in queries

[Michal Čihař] Fix merge error in po file

[Michal Čihař] Validate image scaling dimensions

[Michal Čihař] Add missing escaping to the export type

[Michal Čihař] Do not try to create non existing classes

[Michal Čihař] Properly handle newlines in SQL comments

[Michal Čihař] Properly escape partition removal query

[Michal Čihař] Do not use empty MIME type

[Michal Čihař] Escape HTML markup in transformation wrapper

[Michal Čihař] Add missing escaping in user group queries

[Michal Čihař] Properly escape error input in the message

[Michal Čihař] Ensure widht and height are integers

[Michal Čihař] Ensure widht and height are integers

[Michal Čihař] Ensure widht and height are integers

[Michal Čihař] Properly escape foreign key selection

[Michal Čihař] HML encode embedded JSON data

[Michal Čihař] Fix tests for transformations

[Michal Čihař] Fix exporting multiline comments

[Michal Čihař] Fix tests for transformations

[Michal Čihař] Fix exporting multiline comments

[bennetch] Add missing escaping in navigation pane

[Michal Čihař] Use https to access phpmyadmin.net

[Michal Čihař] Add tests for PMA_isAllowedDomain

[Michal Čihař] Improve URL filtering in url.php

[Michal Čihař] Use hash_hmac for MAC rather than plain SHA1

[Michal Čihař] Use different secret for MAC than encryption

[Michal Čihař] Validate input data from cookies

[Michal Čihař] Merge pmaServer and pmaPass cookies

[Michal Čihař] Do not generate too long session secret

[Michal Čihař] Remove hashing of blowfish secret

[Michal Čihař] Document recommended length of 32 for blowfish_secret

[Michal Čihař] Improve Blowfish secret generation in setup script

[Michal Čihař] Document 32 chars length for blowfish_secret

[Michal Čihař] Use MAC to verify IV as well

[Michal Čihař] Delete temporary file before reporting error

[Michal Čihař] Sanitize filename on SHP import

[Michal Čihař] Properly escape NavigationTreeDbSeparator in queries

[Michal Čihař] Send standard set of HTTP headers on redirect

[Michal Čihař] Use consistent iv and encrypted text concatenation as other libs

[Michal Čihař] Improve secrets splitting

[Michal Čihař] Avoid calculating strlen twice

[Michal Čihař] Move return to correct place

[Michal Čihař] Revert "Move return to correct place"

[Michal Čihař] Fix test errors

[Michal Čihař] Limit maximal numver of fields to 4096

[Michal Čihař] Simplify fields number calcualtion

[Michal Čihař] Remove no longer used code

[Michal Čihař] Enable LOAD DATA LOCAL INFILE only when needed

[Michal Čihař] Escape routine privileges listing

[Michal Čihař] Ensure GIS point coordinates are numeric

[Michal Čihař] Remove file path from the session error message

[Michal Čihař] Properly mark requests to lint as AJAX request

[Michal Čihař] Remove option to show phpinfo() ($cfg['ShowPhpInfo'])

[Michal Čihař] Move generator scripts out of the code

[Michal Čihař] Do not allow to set too long password

[Michal Čihař] Escape string when showing confirmation message

[Michal Čihař] Adjust code to new code base

[Michal Čihař] Add login and token validation to version_check

[Michal Čihař] Do not try to wrap output in case response handling is disabled

[Michal Čihař] Move hostname sanitization to correct place

[raghuram.vadapalli] Fixes #12330 - Shortcut for closing console

[pavel2000] Translation improvements * Improved Russian translation * Added lost

[pavel2000] Partitions editor: Allow to edit partition names; Add 'COLUMNS

[pavel2000] When editing table records, display readonly inputs for fields without

[devenbansod.bits] Reload Navigation if no prev entry stored

[bennetch] Release 4.6.4

[weblate] Translated using Weblate (German)

[bennetch] Prepare for 4.6.5

[devenbansod.bits] Fix "Error: Token mismatch" error in reloading navigation

[devenbansod.bits] Use URL::getCommon() for all params to be included in the urls

[weblate] Translated using Weblate (German)

[Michal Čihař] Remove potentionally license problematic sRGB profile

[Michal Čihař] Remove sRGB.icc when creating release

[Michal Čihař] Strip barcodes from TCPDF

[Michal Čihař] Revert "Strip barcodes from TCPDF"

[Michal Čihař] Document how to set up credentials on Docker

[Michal Čihař] Add changelog entries

[Michal Čihař] Update po files

[Michal Čihař] Update po files

[Michal Čihař] Changelog entry for issue #12430

[weblate] Translated using Weblate (Turkish)

[weblate] Translated using Weblate (Italian)

[weblate] Translated using Weblate (Estonian)

[weblate] Translated using Weblate (Dutch)

[weblate] Translated using Weblate (Estonian)

[weblate] Translated using Weblate (Turkish)

[Michal Čihař] Changelog for issue #12330

[Michal Čihař] Use https when available

[Michal Čihař] Avoid problems with PHP comparison

[devenbansod.bits] Fix tests after 44760ac

[Michal Čihař] Crossreference docs for PmaAbsoluteUri

[Michal Čihař] Reintroduce PmaAbsoluteUri setting

[Michal Čihař] Use PmaAbsolueUri for cookie path

[Michal Čihař] Rename getCookiePath() to getRootPath()

[Michal Čihař] Use PmaAbsoluteUri for isHttps

[Michal Čihař] Reintroduced simplified PmaAbsoluteUri configuration directive

[Michal Čihař] Ensure PmaAbsoluteUri ends with /

[weblate] Translated using Weblate (Dutch)

[weblate] Translated using Weblate (Italian)

[weblate] Translated using Weblate (Polish)

[weblate] Translated using Weblate (Slovenian)

