Commit 0697d574 authored by Chenu Denis's avatar Chenu Denis

Merge branch '2.06lts' of https://github.com/LimeSurvey/LimeSurvey.git into 2.06_SondagesPro

# Conflicts:
#	application/config/version.php
#	application/helpers/common_helper.php
parents 7f6b80c3 e5a00b0b
......@@ -5,6 +5,7 @@ Only partial changelog, [commit history](https://framagit.org/Shnoulle/LimeSurve
### Fix
- Language can be updated during survey
- Update to 2.6.4_lts
### Feature
- Leave partial HTML in admin email
......
......@@ -11,9 +11,9 @@
* See COPYRIGHT.php for copyright notices and details.
*/
$config['versionnumber'] = "2.6.2";
$config['versionnumber'] = "2.6.4";
$config['dbversionnumber'] = 184;
$config['buildnumber'] = 'SondagesPro 1.3.1';
$config['buildnumber'] = 'SondagesPro 1.4.0';
$config['updatable'] = false;
return $config;
......@@ -1089,10 +1089,6 @@ class responses extends Survey_Common_Action
$limit = $dtcount;
}
//NOW LETS SHOW THE DATA
if (Yii::app()->request->getPost('sql') && stripcslashes(Yii::app()->request->getPost('sql')) !== "" && Yii::app()->request->getPost('sql') != "NULL")
$oCriteria->addCondition(stripcslashes(Yii::app()->request->getPost('sql')));
if (!is_null($tokenRequest)) {
$oCriteria->addCondition('t.token = ' . Yii::app()->db->quoteValue($tokenRequest));
}
......
......@@ -129,17 +129,14 @@ function emailTokens($iSurveyID,$aResultTokens,$sType)
$sMessage = $aSurveyLocaleData[$sTokenLanguage]['surveyls_email_remind'];
}
$modsubject = Replacefields($sSubject, $fieldsarray);
$modmessage = Replacefields($sMessage, $fieldsarray);
if (isset($barebone_link))
{
$modsubject = str_replace("@@SURVEYURL@@", $barebone_link, $modsubject);
$modmessage = str_replace("@@SURVEYURL@@", $barebone_link, $modmessage);
$modsubject = str_replace("@@SURVEYURL@@", $barebone_link, $sSubject);
$modmessage = str_replace("@@SURVEYURL@@", $barebone_link, $sMessage);
}
$modsubject = Replacefields($modsubject, $fieldsarray);
$modmessage = Replacefields($modmessage, $fieldsarray);
if (isset($aTokenRow['validfrom']) && trim($aTokenRow['validfrom']) != '' && convertDateTimeFormat($aTokenRow['validfrom'], 'Y-m-d H:i:s', 'U') * 1 > date('U') * 1)
{
......
......@@ -4028,9 +4028,9 @@ function SendEmailMessage($body, $subject, $to, $from, $sitename, $ishtml=false,
$sender=$bouncemail;
}
require_once(APPPATH.'/third_party/phpmailer/PHPMailerAutoload.php');
$mail = new PHPMailer;
if (!$mail->SetLanguage($defaultlang,APPPATH.'/third_party/phpmailer/language/'))
{
$mail->SetLanguage('en',APPPATH.'/third_party/phpmailer/language/');
......
......@@ -487,7 +487,7 @@ class remotecontrol_handle
{
if (!$this->_checkSessionKey($sSessionKey)) return array('status' => 'Invalid session key');
if (!in_array($sType, array('day','hour'))) return array('status' => 'Invalid Period');
if (!hasSurveyPermission($iSurveyID, 'responses', 'read')) return array('status' => 'No permission');
if (!Permission::model()->hasSurveyPermission($iSurveyID, 'responses', 'read')) return array('status' => 'No permission');
$oSurvey=Survey::model()->findByPk($iSurveyID);
if (is_null($oSurvey)) return array('status' => 'Error: Invalid survey ID');
if (!tableExists('{{survey_' . $iSurveyID . '}}')) return array('status' => 'No available data');
......
Welcome to LimeSurvey v2.06+!
Welcome to LimeSurvey v2.6.x+!
Warranty: This program is provided "as is" without warranties of any kind, either expressed or implied,
including, but not limited to, the implied warranties of merchantability and fitness for a particular
......@@ -59,7 +59,18 @@ Thank you to everyone who helped with this new release!
CHANGE LOG
------------------------------------------------------
Changes from 2.06LTS (build 161024) to 2.6.2LTS (build 161206) Dez 6, 2016
Changes from 2.6.3LTS (build 170112) to 2.6.4LTS (build 170202) Feb 3, 2017
-Fixed issue #12078: Email sending problems with unvalidated SSL certificates (Carsten Schmitz)
-Fixed issue #12093: Error when editing email templates und using PHP7 (Carsten Schmitz)
-Fixed issue: Replacing `@@SURVEYURL@@` incorrectly in RemoteControl2 (Frederik Prijck)
-Fixed issue: [security] SQL injection vulnerability in response browse screen (LouisGac)
Changes from 2.6.2LTS (build 161206) to 2.6.3LTS (build 170112) Jan 12, 2017
-Fixed issue #11897: Ranking question opposite side to instructions (Denis Chenu)
-Fixed issue #11996: possible remote code execution (LouisGac)
-Fixed issue: [security] Undisclosed security issue in PHPMailer library - updated PHPMailer to 5.2.21 (Carsten Schmitz)
Changes from 2.6.1LTS (build 161024) to 2.6.2LTS (build 161206) Dez 6, 2016
-Fixed issue #11606: Date/Time filled does not record the answer (Olle Haerstedt)
-Fixed issue: [security] Possible session fixation on survey entry with token (Carsten Schmitz)
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment