Skip to content
Snippets Groups Projects
  1. Apr 16, 2020
  2. Apr 15, 2020
    • Alexander Schnitzler's avatar
      [TASK] Update rector/rector to 0.7.14 · 7c7ec6e8
      Alexander Schnitzler authored
      composer remove rector/rector
      
      Package operations: 0 installs, 8 updates, 4 removals
        - Removing tracy/tracy (v2.7.2)
        - Removing rector/rector (v0.7.0)
        - Removing phpstan/phpstan-phpunit (0.12.6)
        - Removing ondram/ci-detector (3.1.1)
        - Updating composer/xdebug-handler (1.4.0 => 1.4.1)
        - Updating nette/robot-loader (v3.2.1 => v3.2.3)
        - Updating symplify/package-builder (v7.2.2 => v7.2.12)
        - Updating symplify/auto-bind-parameter (v7.2.2 => v7.2.12)
        - Updating nette/http (v3.0.3 => v3.0.4)
        - Updating symplify/autowire-array-parameter (v7.2.2 => v7.2.12)
        - Updating symplify/smart-file-system (v7.2.2 => v7.2.12)
        - Updating symplify/set-config-resolver (v7.2.2 => v7.2.12)
      
      composer require rector/rector:"^0.7.14" --dev
      
      Package operations: 5 installs, 0 updates, 0 removals
        - Installing tracy/tracy (v2.7.4)
        - Installing phpstan/phpstan-phpunit (0.12.7)
        - Installing ondram/ci-detector (3.3.0)
        - Installing jetbrains/phpstorm-stubs (v2019.3)
        - I...
      7c7ec6e8
  3. Apr 09, 2020
  4. Apr 01, 2020
  5. Mar 29, 2020
  6. Mar 27, 2020
  7. Mar 23, 2020
  8. Mar 06, 2020
  9. Mar 05, 2020
  10. Mar 04, 2020
  11. Mar 03, 2020
  12. Feb 25, 2020
  13. Feb 24, 2020
  14. Feb 19, 2020
  15. Feb 15, 2020
  16. Feb 14, 2020
  17. Feb 13, 2020
    • Benni Mack's avatar
      [FEATURE] Implement SameSite option for TYPO3 cookies · de29dc2d
      Benni Mack authored
      This change introduces a new security option for setting the SameSite
      option to all cookies sent by TYPO3 Core.
      
      Namely:
      - Frontend User Sessions ("lax" by default)
      - Backend User Sessions ("strict" by default)
      - Install Tool Sessions ("strict", none-configurable)
      - Last Login Provider in Backend ("strict", non-configurable)
      
      This means that these can only be accessed by scripts and requests
      by the same site, and not by any third-party scripts.
      
      Since we're talking about actual cookies for a user, and not
      ads-related or third-party login-dependant cookies, the default
      options fit just perfectly.
      
      All modern browsers except Internet Explorer respect this option
      to be set. Please note that Firefox and Chrome will have "SameSite=lax"
      set in Q1/2020 by default if NO SameSite option is set at all. This change
      allows to configure this.
      
      Backend and Frontend User Cookies can be configured to "strict", "lax"
      or "none" (= same as before), whereas "none" only works for secure
      connections (= HTTPS).
      
      If "strict" is in place, security via CSRF is not needed anymore, and can
      be dropped in the future.
      
      Resolves: #90351
      Releases: master, 9.5, 8.7
      Change-Id: I8095e2a552faa9d1fd4fa7855297302a9ec6a75f
      Reviewed-on: https://review.typo3.org/c/Packages/TYPO3.CMS/+/63183
      
      
      Tested-by: default avatarAnja Leichsenring <aleichsenring@ab-softlab.de>
      Tested-by: default avatarTYPO3com <noreply@typo3.com>
      Tested-by: default avatarGeorg Ringer <georg.ringer@gmail.com>
      Reviewed-by: default avatarAnja Leichsenring <aleichsenring@ab-softlab.de>
      Reviewed-by: default avatarGeorg Ringer <georg.ringer@gmail.com>
      de29dc2d
  18. Feb 12, 2020
  19. Feb 02, 2020
  20. Jan 22, 2020
  21. Jan 17, 2020
  22. Jan 16, 2020
  23. Dec 19, 2019
  24. Dec 13, 2019
  25. Dec 10, 2019
  26. Dec 03, 2019
  27. Dec 02, 2019
  28. Nov 29, 2019
  29. Nov 28, 2019
  30. Nov 27, 2019
  31. Nov 26, 2019
  32. Nov 25, 2019
  33. Nov 22, 2019
  34. Nov 21, 2019