govCMS / GovCMS7

Current stable release of the main Drupal 7 GovCMS distribution, with releases mirrored at https://www.drupal.org/project/govcms
https://www.govcms.gov.au/
GNU General Public License v2.0
113 stars 76 forks source link

[SA-CONTRIB-2019-020] Update Link to 7.x-1.6 (from 7.x-1.3) #788

Closed fubarhouse closed 5 years ago

fubarhouse commented 5 years ago

https://www.drupal.org/sa-core-2019-003

https://www.drupal.org/sa-contrib-2019-020

Project: Link Date: 2019-February-20 Security risk: Critical 18∕25 AC:None/A:User/CI:All/II:All/E:Theoretical/TD:Uncommon Vulnerability: Remote Code Execution Description: This resolves issues described in SA-CORE-2019-003 for this module. Not all configurations are affected. See SA-CORE-2019-003 for details.

https://www.drupal.org/project/link/releases/7.x-1.6

Release notes This resolves issues described in SA-CORE-2019-003 for this module.

Not all configurations are vulnerable. See SA-CORE-2019-003 for details.

https://www.drupal.org/project/link/releases/7.x-1.5

Release notes Importantly. Re-read the description of the module "Link" here - https://www.drupal.org/project/link, it has been changed.

If you have problems with the new version of the module, you can always use to the previous version of the module here - https://www.drupal.org/project/link/releases/7.x-1.4

List of changes from the previous version: Issue #2945139: options(&$options) deprecated since views2. Issue #2945137: Unused variables Issue #2945133: Warning: Method call uses 2 parameters, but method signature uses 1 parameters Issue #2945131: Fix coding standards module. Issue #2945128: Fix coding standard test parts Issue #2901656 and #2210297 by nightwalkr, mfernea: validates that the input on the URL field actually exists as a path alias. Theme_link_formatter_link_default() doesn't work with classes defined in a preprocess function. Issue #2216399 by jemond: Provide Formatter to remove http:// or https:// from URL Issue #1836632 by jmart: Double HTML escaping when using plain_title formatter Modification for bug fixes related to HTML entities in title and no protocol for url display format Issue #2480723 by krystalcode, naidim, rrrob, sumitmadan, Argus, diqidoq, RenatoG, jbitdrop: Avoid warning in diff integration for links without title Issue #2911860 by RenatoG: Fix tests items results Issue #2911860 by RenatoG: Fix tests items results Issue #2911860 by RenatoG: Fix tests items results Issue #2244041 by alberto56, RenatoG: Undefined index: widget in link.module on line 1341 Issue #2743401 by RenatoG, MHuebner: Use parent directory in internal url Issue #2897563 by RenatoG: Fix Coding Standards, Best Practices and Insert Documentation in Comments for Tests Issue #2897348 by RenatoG: Update documentation in README file for nre template of Drupal.org Issue #2897332 by RenatoG: Fix all items of Code Review for Link Issue #2166459 by j0rd, mstef: Notice: Undefined index: error_element in link_field_widget_error() (line 328 of link.module) Issue #2889683 by Yago Elias, RenatoG: Protocol-less URLs should be cleaned for use Issue #2558497 by joachim, RenatoG: property type for 'url' entity metadata property should not be 'url' Issue #2299657 by RenatoG, egfrith, ChuChuNaKu, idebr, jtsnow, rootwork, kristiaanvandeneynde, GoddamnNoise, Leeteq, jcfiala, Remon, drumm, tobiberlin, brantwynn, klonos, Vacilando, quicksketch, mikeytown2, samuel.mortenson, brice_gato, katjam, kenorb, ultimike, Graber, rv0, othermachines, r0nn1ef, DamienMcKenna, doraf, jmart, reptilex, Berliner-dupe, jp.stacey, JonMcL: Allow any TLD because site admins can never keep up with ICANN Issue #2499165 by jcnventura, RenatoG: Validate all latin accented chars Issue #1295132 by Scyther, RenatoG: Unnecessary variables in link.install Issue #1335424 by claudiu.cristea, RenatoG: Title as a select Issue #2612176 by FluxSauce, pcambra, RenatoG: PHP Fatal error: Class 'MigrateFieldHandler' not found Issue #2693731 by Antonnavi, RenatoG: Tokens replaced on "Static title" when "Allow user-entered tokens" not enabled Issue #2140087 by olofjohansson, maximpodorov, mistermoper, RenatoG: Allow '0' as the link title Issue #1418762 by num37, RenatoG, rvilar, jcfiala, randyhook: Provide default title when title is optional Issue #2553705 by Trav84, aguilarm, michaelfavia, reshma.i, RenatoG, roopeshnaik: Static Title does not show up when using 'Optional URL' + 'Static Title' with an empty URL Issue #2323441 by paolomainardi, sumitmadan, SylvainM, brockfanning, rob_johnston, RenatoG, mikeryan: [Patch] Migrate language argument array handling Issue #2299657 by egfrith, RenatoG, ChuChuNaKu, idebr, jtsnow, rootwork, kristiaanvandeneynde, GoddamnNoise, Leeteq, jcfiala, Remon, drumm, tobiberlin, brantwynn, klonos, Vacilando, quicksketch, mikeytown2, samuel.mortenson, brice_gato, katjam, kenorb, ultimike, Graber, rv0, othermachines, r0nn1ef, DamienMcKenna, doraf, jmart, reptilex, jp.stacey, JonMcL: Allow any TLD because site admins can never keep up with ICANN Issue #1909788 by mthomas, jesss, csc4, Kpolymorphic, RenatoG: Add an entity token for the display_url Issue #2650956 by loopduplicate, amitmaity, karsumit94, RenatoG: Code standards are not followed for array modified in 2367069 Issue #2299657 by egfrith, RenatoG, ChuChuNaKu, idebr, jtsnow, rootwork, kristiaanvandeneynde, GoddamnNoise, Leeteq, jcfiala, Remon, drumm, tobiberlin, brantwynn, klonos, Vacilando, quicksketch, mikeytown2, samuel.mortenson, brice_gato, katjam, kenorb, ultimike, Graber, rv0, othermachines, r0nn1ef, DamienMcKenna, doraf, jmart, reptilex, Berliner-dupe, jp.stacey, JonMcL, peter-majmesku: Allow any TLD because site admins can never keep up with ICANN Issue #2299657 by egfrith, ChuChuNaKu, RenatoG, idebr, jtsnow, rootwork, Leeteq, kristiaanvandeneynde, GoddamnNoise, tobiberlin, Remon, drumm, jcfiala, klonos, brantwynn, quicksketch, mikeytown2, samuel.mortenson, brice_gato, Vacilando, katjam, kenorb, ultimike, Graber, rv0, DamienMcKenna, doraf, jmart, reptilex, jp.stacey, JonMcL: Allow any TLD because site admins can never keep up with ICANN Issue #2890057 by RenatoG: All content of file commented "link.views.inc" should be use @codingStandardsIgnoreFile tag Issue #2299657 by egfrith, ChuChuNaKu, RenatoG, idebr, jtsnow, Leeteq, GoddamnNoise, tobiberlin, kristiaanvandeneynde, Remon, jcfiala, rootwork, drumm, klonos, brice_gato, quicksketch, brantwynn, mikeytown2, Vacilando, reptilex, samuel.mortenson, DamienMcKenna, ultimike, Graber, rv0, doraf, jp.stacey, kenorb, jmart, JonMcL, katjam: Allow any TLD because site admins can never keep up with ICANN Issue #2890013 by RenatoG: Fix codings standards for Link Issue #2889755 by RenatoG: Fixed Best practice in Drupal Issue #2566443 by ohthehugemanatee, RenatoG: Broken description text when used through Form API Issue #2888582 by RenatoG: Resolved unused variables in install file Issue #2723993 by dhruveshdtripathi, rahul.shinde, jeevanbhushetty, RenatoG: help hook is not there Issue #2578521 by kala4ek, arialvix, soapboxcicero, ervit, RenatoG: Validation error Issue #2889755 by RenatoG: Fixed Best practice in Drupal Issue #2566443 by ohthehugemanatee, RenatoG: Broken description text when used through Form API Issue #2888582 by RenatoG: Resolved unused variables in install file Issue #2723993 by dhruveshdtripathi, rahul.shinde, jeevanbhushetty, RenatoG: help hook is not there Issue #2578521 by kala4ek, arialvix, soapboxcicero, ervit, RenatoG: Validation error Issue #2888510 by RenatoG: Create tip for token on install Issue #2888480 by RenatoG: Fixed documentation links in new window target "blank" Issue #2888461 by RenatoG: Clear variable "link_extra_domains" on uninstall Issue #2843813 by idebr, klausi, michael_wojcik, clemens.tolboom: Fix failing tests due to missing 'administer fields' permission

https://www.drupal.org/project/link/releases/7.x-1.4

Release notes Issue #2470377 by rhclayto: Adding a class with underscores, the class gets rendered with hyphens Issue #609560 by Boobaa: Provide token for hostname Issue #2632728 Apply patch: link-field_link_validate_overrites_langcode-2632728.patch Issue #2247261 by heddn, sumitmadan: URLs are not validated Issue #2513706 by rrfegade: Spelling errors in D7 Issue #2470968: Add README.txt Issue #2055111 by joelpittet, mikeytown2: skip over re-loading entities for tokens in link field attributes unless there's a token to process. Issue #2367069 by jcfiala:Fixed entity_token for link after node_view was called. Added setup function to LinkValidateUrlLight to enable link module, which was failing drupal.org qa testbot. Issue #2364673 by jcfiala: Replaced drupal_html_class() with drupal_clean_css_identifier() so that link field classes are not forced to lower case. Added tests to test entity_token token with link.