Commit Graph
15325 Commits
Author SHA1 Message Date
Dannon Baker dfc4e52fd3 Fix size_string; this would have thrown an exception on being called due to an unimported 'util'. 2014-12-03 09:24:44 -05:00
Dannon Baker d1cde6b943 Pep8 tool_shed/util/basic_util 2014-12-03 09:23:14 -05:00
Dannon Baker b9027d69ef Bump NO_OUTPUT_TIMEOUT to 60m; Bjoern said it's causing issues w/ some tools for being too short. 2014-12-03 09:21:54 -05:00
Jeremy Goecks 24f0bd01d9 Remove debugging statement. 2014-12-02 13:30:19 -05:00
Aysam Guerler 16f4da6adc ToolForm: Add baseurl, fix dynamic drill down options 2014-12-01 01:18:16 -05:00
Aysam Guerler 436307b38c ToolForm: Fix select2 value selection 2014-12-01 00:21:40 -05:00
Aysam Guerler 3ef94d196c ToolForm: Add drill down element 2014-11-30 23:40:38 -05:00
Aysam Guerler bdff562a51 Charts: Use most recent select field style 2014-12-02 11:47:59 -05:00
Aysam Guerler 75d1da0b26 Pages: Sanitize name column in items grid 2014-12-01 12:52:01 -05:00
John Chilton 42230168d3 Merge stable. 2014-12-01 11:26:20 -05:00
Nate Coraor 0fb5ede322 Update tag latest_2014.10.06 for changeset acb2548443ae 2014-11-27 09:00:14 -05:00
John Chilton 452e3f5d41 Fix boolean parameter handling at workflow runtime.
Broken with 011c8b2118be778eaf1ba952730ff876d6447ba9.

Note to self - update pause module when merging into next-stable.
2014-11-26 12:42:00 -05:00
Aysam Guerler b4abc65c90 ToolForm: Ensure that the correct definition for booleans is used 2014-11-26 12:42:46 -05:00
John Chilton 3b8021681a Fix boolean parameter handling at workflow runtime.
Broken with 011c8b2118be778eaf1ba952730ff876d6447ba9.

Note to self - update pause module when merging into next-stable.
2014-11-26 12:42:00 -05:00
Carl Eberhard 8db0b68c9c Security, UI: minor fixes to history, dataset, and page escaping; escape js tag and annotation displays 2014-11-26 12:28:28 -05:00
John Chilton dcab7303b2 galaxy.ini.sample doc clarifications.
Fix typo caught by Martin. Add warning message about why public servers should not disable sanitize_all_html.
2014-11-26 08:57:49 -05:00
John Chilton 56b3c10ec0 Attempt fix of test/unit/test_lazy_process.py which transiently fails. 2014-11-25 23:02:05 -05:00
John Chilton 2f5f2cc2df Skip galaxy.tools.watcher test if watchdog unavailable.
Instead of failing.
2014-11-25 23:02:05 -05:00
John Chilton e2a7b51d52 Fixes for /dataset_collections API endpoint.
Guess this is not as utilized as the variant under /histories.
2014-11-25 20:52:30 -05:00
Dannon Baker ac2e40b178 Merge. 2014-11-25 15:25:25 -05:00
Martin Cech 69f1d7928f fix the behavior of masthead.js when passed an empty string as a item content (link target) 2014-11-25 15:19:08 -05:00
Dannon Baker 42b1b5345f Referer-in-logout reflective xss fix. 2014-11-25 15:14:58 -05:00
Dannon Baker bdf7e19ebd Referer-in-okmessage reflective xss fix 2014-11-25 15:14:25 -05:00
Dannon Baker 227575361d Merge. 2014-11-25 14:34:20 -05:00
Dannon Baker 7ff8092d3d Another instance of tool_id reflected xss (in data_source_redirect). 2014-11-25 14:31:55 -05:00
Carl Eberhard c9ee642ac1 Fix to 04a072e98658: remove unnecessary replace 2014-11-25 14:29:48 -05:00
Dannon Baker 1cf97e52ac Merge. 2014-11-25 14:27:04 -05:00
Dannon Baker 517593cc75 Prevent XSS in unknown tool display, update to actually use show_error_message instead of replying with plain text. 2014-11-25 14:26:52 -05:00
Carl Eberhard f9792e0b3d Sanitize tag output in tagging_common and user.tags_used; protect against closing tags in bootstrapped JSON (http://benalpert.com/2012/08/03/preventing-xss-json.html); minor fixes 2014-11-25 14:22:08 -05:00
Aysam Guerler 049fb58292 Fixes security issue 2.2 for regular grid values 2014-11-25 14:04:43 -05:00
Dannon Baker d7583052e2 Swap webhelpers to use safe dumps. 2014-11-25 13:32:15 -05:00
Nate Coraor 3fd2c1b733 Update tag latest_2014.10.06 for changeset adc4aa8b3d9a 2014-11-25 12:00:20 -05:00
Aysam Guerler ae3ea650d6 ToolForm: Handle boolean definition without modifying shared code 2014-11-24 22:34:33 -05:00
Aysam Guerler 6bfe631f2f ToolForm: More batch mode validation logic 2014-11-24 14:48:09 -05:00
Aysam Guerler b89ce4b3ce ToolForm: Adjust batch mode for collections 2014-11-24 14:31:19 -05:00
Aysam Guerler 987325569e ToolForm: Adjust batch mode submission 2014-11-24 13:36:24 -05:00
Aysam Guerler 73cb088f92 ToolForm: Allow 1 to n selection for batch mode fields 2014-11-24 12:30:29 -05:00
Aysam Guerler 43d373541a ToolForm: Fix optional parameters, add select2 fields, fix style 2014-11-24 12:08:46 -05:00
Dannon Baker dadf930e3d Merged in jmchilton/galaxy-central-fork-1/next-stable (pull request #573)
Enhanced client security.
2014-11-25 12:27:41 -05:00
Martin Cech c761bf14e7 change masthead's 'Analyze data' link target to / instead of /root/index for analytics purposes 2014-11-25 12:00:31 -05:00
Dannon Baker 00da0422a6 Remove unnecessary split on wsgi.url_scheme 2014-11-25 11:33:26 -05:00
John Chilton 1d55a9bf4d Issue session cookies using 'secure' flag for HTTPS requests.
For more information see https://www.owasp.org/index.php/SecureFlag.
2014-11-25 09:59:40 -05:00
John Chilton e1f7687894 Enable defense against clickjacking out of the box.
Look in config/galaxy.ini.sample for the option 'x_frame_options' for more information.
2014-11-25 09:59:40 -05:00
Björn Grüning e329fac938 getstring() does not exist, use get() instead 2014-11-24 16:28:25 +00:00
Aysam Guerler 7120b98eb3 ToolForm: Skip new tool form build process if disabled 2014-11-24 11:50:07 -05:00
John Chilton acd856362e Sanitize object names throughout templates. 2014-11-24 10:06:11 -05:00
Aysam Guerler d8d4521c1a JS-santization of filter options before displaying them FIX 2.2 2014-11-21 16:41:44 -05:00
Aysam Guerler cd4605d3f6 Fix boolean handling for workflow editor 2014-11-20 14:29:27 -05:00
Nate Coraor 044ee1c709 Update tag latest_2014.10.06 for changeset bb79e87274d7 2014-11-20 14:00:30 -05:00
Dannon Baker 360fadf560 Merged in jmchilton/galaxy-central-fork-1/stable (pull request #566)
[STABLE] Fix Pulsar's default HTTP transport for poster hacking up urllib.
2014-11-20 09:16:46 -05:00