MantisBT

mantisbt - Change Log

mantisbt - 1.3.x (Not Yet Released) View Issues ]
===================================

Future feature release

- 0017519: [bugtracker] Wrong label for update button on bug_update_page.php (dregad) - resolved.
- 0017506: [news] Edit news throws error (dregad) - resolved.
- 0017507: [administration] Missing button on "Workflow Thresholds" page (dregad) - resolved.
- 0017508: [administration] No display of ADOdb version on admin page (dregad) - resolved.
- 0017512: [bugtracker] Reporting a new issue throws error (dregad) - resolved.
- 0017515: [bugtracker] E_RECOVERABLE_ERROR in category API (dregad) - resolved.
- 0017380: [security] IIS: add web.config to deny access to config/ (grangeway) - resolved.
- 0016570: [bugtracker] Page content in 'Report Issue' is forgotten when user clicks [Back] button in browser (grangeway) - resolved.
- 0017412: [roadmap] Empty roadmap is confusing (vboctor) - resolved.
- 0017411: [change log] Empty change log is confusing (vboctor) - resolved.
- 0012150: [db oracle] Mantis 1.2.1 Install Error using Oracle db (dregad) - resolved.
- 0016878: [db mssql] Install triggers varchar to datetime conversion error on sql server 2008 (dregad) - resolved.
- 0015426: [db oracle] GetRowAssoc fails with Oracle DB (dregad) - resolved.
- 0017333: [db oracle] Adding a new version fails with ORA-01400 (dregad) - resolved.
- 0014852: [installation] Installation failes during install with postgres as DB (dregad) - resolved.
- 0017441: [other] PHP Notice generated by logging api (dregad) - resolved.
- 0016975: [localization] Invalid enumeration string value displayed if localized value does not exist (dregad) - resolved.
- 0005466: [bugtracker] Changes are overwritten (dregad) - resolved.
- 0017494: [bugtracker] 'Undefined index: _stats' notice on View Issues page (dregad) - resolved.
- 0017492: [bugtracker] Broken styling for Timeline box (dregad) - resolved.
- 0017384: [localization] Remove unused twitter language strings (dregad) - resolved.
- 0017458: [api soap] SOAP API does not send e-mails (dregad) - resolved.
- 0017397: [bugtracker] Add timeline to My View page (vboctor) - resolved.
- 0017189: [api soap] mc_projects_get_user_accessible() produces a mysql error (grangeway) - resolved.
- 0017376: [performance] Perf: use sprintf over utf8_str_pad (dregad) - resolved.
- 0016995: [documentation] Absolute g_manual_url becomes relative on proj_doc_page.php (dregad) - resolved.
- 0017355: [plug-ins] Table names generated by plugin_table() are incorrect (dregad) - resolved.
- 0017368: [plug-ins] Provide plugin's basename in error messages (dregad) - resolved.
- 0017366: [plug-ins] Remove direct access to global variable in plugin.php (dregad) - resolved.
- 0017359: [plug-ins] Errors when loading a plugin's page when its dependencies are not met (dregad) - resolved.
- 0017382: [security] install.php: do not send the value of crypto_master_salt over http (grangeway) - resolved.
- 0014538: [security] plugins directory must be secured/fixed. (grangeway) - resolved.
- 0017381: [security] Provide additional random number generators (grangeway) - resolved.
- 0017385: [administration] Removal of copy_fields utility (grangeway) - resolved.
- 0017378: [code cleanup] Reduce unneeded global Variables: g_api_included (grangeway) - resolved.
- 0017377: [code cleanup] Reduce unneeded global Variables: g_libraries_included (grangeway) - resolved.
- 0016955: [javascript] Uncaught Error: Syntax error, unrecognized expression: [:input (grangeway) - resolved.
- 0007126: [db oracle] For the execution of Mantis in Oracle 8i, 9i (dregad) - resolved.
- 0007644: [db oracle] Problems when creating the Mantis database schema on Oracle (dregad) - resolved.
 - 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
  - 0006895: [db oracle] install mantis with oracle (driver oci8) (dregad) - resolved.
  - 0007185: [db oracle] Empty string incompatibility mysql/oracle (dregad) - resolved.
  - 0007246: [db oracle] Not possible to use singup functionality (dregad) - resolved.
  - 0007935: [db oracle] Problem with install / connexion / filtre (dregad) - resolved.
  - 0008686: [db oracle] Pb on : "Attempting to connect to database as admin" (dregad) - resolved.
  - 0012267: [db oracle] Custom Field Title and Value render as '@', $t_custom_field, '@'; in Oracle (dregad) - resolved.
  - 0013433: [db oracle] Error ORA-00904: "PROTECTED": invalid identifier for the query (dregad) - resolved.
   - 0013438: [db oracle] adodb: Fatal error: Call to a member function FetchRow() on a non-object (dregad) - resolved.
  - 0016330: [db oracle] html_status_percentage_legend() causes error ORA-00923 (dregad) - resolved.
  - 0016331: [db oracle] Attaching file causes ORA-01400: cannot insert NULL into BLOB column (dregad) - resolved.
  - 0016336: [db oracle] File attachment to DB fails when file bigger than 4000 bytes on Oracle (dregad) - resolved.
  - 0015426: [db oracle] GetRowAssoc fails with Oracle DB (dregad) - resolved.
  - 0007126: [db oracle] For the execution of Mantis in Oracle 8i, 9i (dregad) - resolved.
 - 0013438: [db oracle] adodb: Fatal error: Call to a member function FetchRow() on a non-object (dregad) - resolved.
- 0017370: [bugtracker] Roadmap+Changelog display "0" instead of project name in error message (dregad) - resolved.
- 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0017270: [bugtracker] PHP Deprecated, Warnings and Notices kill CLI scripts (dregad) - resolved.
- 0008207: [sql] mantis_project_hierarchy_table allows duplicate rows (grangeway) - resolved.
- 0014398: [db postgresql] Support for PostgreSQL broken in 1.3 (dregad) - resolved.
 - 0015589: [db postgresql] Upgrade fails with postgresql (dregad) - resolved.
 - 0015699: [db postgresql] Upgrade 1.2.10 to 1.2.14 Issues (dregad) - resolved.
 - 0016392: [db postgresql] Bool columns in pgsql system created before MantisBT 1.1.0 have smallint type in DB (dregad) - resolved.
 - 0009701: [installation] Install/upgrade shouldn't need admin user when DB already exists (dregad) - resolved.
 - 0012248: [db postgresql] Problem updating from 1.1.8 to 1.2.0 (dregad) - resolved.
- 0006853: [db oracle] Instalation in oracle Database ... (dregad) - resolved.
 - 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0006895: [db oracle] install mantis with oracle (driver oci8) (dregad) - resolved.
- 0007185: [db oracle] Empty string incompatibility mysql/oracle (dregad) - resolved.
- 0007246: [db oracle] Not possible to use singup functionality (dregad) - resolved.
- 0007935: [db oracle] Problem with install / connexion / filtre (dregad) - resolved.
- 0008686: [db oracle] Pb on : "Attempting to connect to database as admin" (dregad) - resolved.
- 0011276: [db oracle] db_param sometimes creating duplicate (dregad) - resolved.
 - 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0012152: [db oracle] Indexes already created (dregad) - resolved.
 - 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0012267: [db oracle] Custom Field Title and Value render as '@', $t_custom_field, '@'; in Oracle (dregad) - resolved.
- 0013433: [db oracle] Error ORA-00904: "PROTECTED": invalid identifier for the query (dregad) - resolved.
- 0016330: [db oracle] html_status_percentage_legend() causes error ORA-00923 (dregad) - resolved.
- 0016331: [db oracle] Attaching file causes ORA-01400: cannot insert NULL into BLOB column (dregad) - resolved.
- 0016336: [db oracle] File attachment to DB fails when file bigger than 4000 bytes on Oracle (dregad) - resolved.
- 0007179: [db oracle] limit selection required for oracle (probleme viewed at the page my_view_page.php) (dregad) - resolved.
- 0007190: [db oracle] error in filter_api with date filter (dregad) - resolved.
- 0010488: [db oracle] Inserting strings > 4000 Bytes not working -> direct file upload and email (dregad) - resolved.
- 0010996: [db oracle] Cant use Mantis with oracle9 - var binding fails (dregad) - resolved.
 - 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0011014: [db oracle] Database creation SQL scripts may be more handy (dregad) - resolved.
- 0011265: [db oracle] Array results from Oracle have uppercase keys (dregad) - resolved.
 - 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0011270: [db oracle] db_insert_id is wrong for Oracle (dregad) - resolved.
 - 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0012151: [db oracle] Oracle database_api.php fatal error on install (dregad) - resolved.
- 0012478: [db oracle] Installation with Oracle fails (dregad) - resolved.
 - 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0013438: [db oracle] adodb: Fatal error: Call to a member function FetchRow() on a non-object (dregad) - resolved.
- 0013438: [db oracle] adodb: Fatal error: Call to a member function FetchRow() on a non-object (dregad) - resolved.
- 0016351: [db oracle] DB creation failed with ORA-01031 (dregad) - resolved.
- 0016537: [db oracle] Fatal error: Call to undefined function db_oracle_order_binds_sequentally() (dregad) - resolved.
- 0012571: [db mssql] Some configuration options cannot be saved to MS SQL Server (fix attached) (grangeway) - resolved.
- 0009314: [db mssql] ADODB GetRowAssoc does not work (dregad) - resolved.
- 0015427: [db mssql] Deploy mantis with MSSQL and UTF8 (dregad) - resolved.
- 0013713: [bugtracker] Upgrade ADOdb library to latest version (dregad) - resolved.
 - 0012837: [db postgresql] Download Attachment doesn't work; Get some header information or Jabber (dregad) - resolved.
 - 0013438: [db oracle] adodb: Fatal error: Call to a member function FetchRow() on a non-object (dregad) - resolved.
- 0016446: [api soap] Merge MantisConnect configs into MantisBT standard configs (vboctor) - resolved.
- 0017246: [custom fields] Date custom fields can't store dates pre-1970 (vboctor) - resolved.
- 0017263: [bugtracker] config_get_global() returns default value for global variables overriden in config_inc.php (dregad) - resolved.
- 0016850: [customization] Add config folder for customization files (vboctor) - resolved.
- 0017186: [mobile] Remove $g_mantistouch_url in favor of MantisTouchRedirect plugin (vboctor) - resolved.
- 0017185: [api soap] Read-only access via soap api should be available to VIEWER level (vboctor) - resolved.
- 0017184: [api soap] Anonymous authentication to soap api (vboctor) - resolved.
- 0017176: [html] Add the possibility to define the x-ua-compatible meta (dregad) - resolved.
- 0017233: [api soap] Fix the license in the SOAP API file headers (vboctor) - resolved.
- 0011549: [installation] PHP include_path change restriction (dregad) - resolved.
- 0011300: [html] Missing namespace in html tag for all pages (dregad) - resolved.
- 0017117: [localization] Plugin description translation not displayed (dregad) - resolved.
- 0016968: [db mysql] Admin checks (database) fail for mysqli (dregad) - resolved.
- 0012013: [plug-ins] Improvements for plugin ImportExportXml (and required core changes) (dregad) - resolved.
- 0016917: [customization] Manage Configuration Complex Type fails when array is terminated with a semi-color - resolved.
- 0017012: [installation] Quotes not escaped on install (dregad) - resolved.
- 0016951: [localization] String 'Due date was' is hardcoded into core files (dregad) - resolved.
- 0016970: [localization] Hardcoded file size unit 'k' (dregad) - resolved.
- 0016986: [security] file_download.php adds buffer trash to file contents (atrol) - resolved.
- 0016976: [html] bug_actiongroup_page.php leaks code. (atrol) - resolved.
- 0016969: [administration] Missing check for db_table_plugin_prefix in admin checks (dregad) - resolved.
- 0016941: [db mysql] Change default db type from mysql to mysqli (dregad) - resolved.
- 0016966: [installation] Database table prefix and suffix variables written incorrectly to config_inc.php (dregad) - resolved.
- 0011290: [feature] Create Clone access to reporters (dregad) - resolved.
- 0007737: [filters] Changed(hrs) filter (dregad) - resolved.
- 0016891: [email] Update DisposableEmailChecker to v2 and change to submodule (vboctor) - resolved.
- 0016621: [signup] Problem with session when using signup and password reset (dregad) - resolved.
- 0016584: [filters] Error when query bug by custom-field (date) in postgresql (dregad) - resolved.
- 0016871: [email] Email notifications are sent with extra blank lines (vboctor) - resolved.
- 0016890: [administration] Admin checks fail to detect deprecated db extension (dregad) - resolved.
- 0016898: [code cleanup] Dropping deprecated database API function db_query() (dregad) - resolved.
- 0016554: [bugtracker] Project privacy change from public to to private kicks manager out (dregad) - resolved.
- 0012620: [plug-ins] Plug-ins included through function (dhx) - resolved.
- 0011732: [integration] Remove built-in source code integration support (dhx) - resolved.
- 0012245: [javascript] Remove extended project browser feature (dhx) - resolved.
- 0016849: [attachments] Drop FTP support (vboctor) - resolved.
- 0010912: [installation] Move code from admin/install.php to a new API file within core (and make plugins also use this API) (dhx) - resolved.
- 0007632: [installation] Create operational database user at time of installation (dregad) - resolved.
- 0007635: [installation] Install script can't get MySQL version if database user doesn't exist or doesn't have access privileges (dregad) - resolved.
- 0016567: [authentication] New captcha does not offer a "refresh" feature (dregad) - resolved.
- 0016539: [administration] Nightly builds for master branch contain adodb 5.10 instead of 5.18 (dregad) - resolved.
- 0016610: [documentation] Suggestion for Admin Guide: Vars' default values on new line (dregad) - resolved.
- 0016810: [customization] $s_os in custom_strings_inc.php partially ignored (atrol) - resolved.
- 0016470: [html] Double-line frame around some tables in the manage pages (dregad) - resolved.
- 0016472: [html] New alternate even/odd rows CSS causes ugly or incorrect display (dregad) - resolved.
- 0016473: [administration] Existence of subprojects prevents load of manage_proj_edit_page.php (dregad) - resolved.
- 0016474: [bugtracker] Need a more specific error message in check_XXX functions (dregad) - resolved.
- 0016475: [bugtracker] bug_update.php throws access denied when updater changes status (dregad) - resolved.
- 0016477: [security] Redirect user to change password if logged in with default admin password (vboctor) - resolved.
- 0016480: [installation] Broken installer following removal of legacy db_prepare_int calls (dregad) - resolved.
- 0016481: [bugtracker] Broken category API following removal of legacy db_prepare_int calls (dregad) - resolved.
- 0016482: [bugtracker] Broken bugnote API following removal of legacy db_prepare_int calls (dregad) - resolved.
- 0016483: [bugtracker] Broken custom field API following removal of legacy db_prepare_int calls (dregad) - resolved.
- 0016486: [other] Broken summary page following removal of db_num_rows calls (atrol) - resolved.
- 0016487: [administration] Parts of manage_user_page broken (atrol) - resolved.
- 0016488: [administration] Editing of versions not possible (vboctor) - resolved.
- 0016491: [tagging] Cluttered layout on tag_view_page.php (dregad) - resolved.
- 0011927: [html] html_status_legend has code paths that forget to print closing table tags (dhx) - resolved.
- 0012288: [javascript] Minified version of bugFilter.js reverted previous fixes which removed jquery 'no conflict' references. (daryn) - resolved.
- 0012489: [bugtracker] resolution is not updated on re-open (daryn) - resolved.
- 0013937: [filters] Versions and Categories from existing filter not preselected when editing it (dregad) - resolved.
- 0014781: [html] Misaligned html elements in filter box (view.php) (dregad) - resolved.
- 0016035: [administration] Admin check issues unnecessary warning messages (dregad) - resolved.
- 0016039: [bugtracker] Login, signup and lost password pages cause error in apache log (dregad) - resolved.
- 0016495: [custom fields] Broken custom field API (atrol) - resolved.
- 0016498: [bugtracker] Bugnote API broken - adds only blank notes (dregad) - resolved.
- 0016502: [bugtracker] Unable to delete issue (dregad) - resolved.
- 0016507: [bugtracker] Adding a bugnote causes a script timeout (dregad) - resolved.
- 0016510: [installation] Wrong redirect after installation (dregad) - resolved.
- 0016514: [bugtracker] Manage users page: enabling 'Hide inactive' leads to SQL error (dregad) - resolved.
- 0016515: [custom fields] Manage custom field page crashes: Call to a member function MoveNext() on a non-object (atrol) - resolved.
- 0016516: [filters] Filters: clicking on 'Use Date Filters' leads to 'Data Type mismatch' (dregad) - resolved.
- 0016519: [preferences] My Account page: Setting the real name fails (dregad) - resolved.
- 0016527: [administration] Manage users page: Empty page when sorting by access level (dregad) - resolved.
- 0016540: [filters] 'Sticky' filter gets reset to 'No' when applying filter (dregad) - resolved.
- 0016549: [bugtracker] Mantis does not fall back to English when a localized error string is missing (dregad) - resolved.
- 0016565: [authentication] Implement new captcha library (grangeway) - resolved.
 - 0008129: [signup] Alternative to captchas (grangeway) - resolved.
 - 0008462: [feature] Captcha will benefit supporting other than jpeg format (grangeway) - resolved.
 - 0008796: [other] The letters in the catchpa on account creation page are too small (grangeway) - resolved.
 - 0010028: [security] Registrations by bots via captcha exploit (grangeway) - resolved.
 - 0010976: [bugtracker] Remove instances of pass-by-reference (deprecated in PHP 5.3.0) (dregad) - resolved.
 - 0010972: [signup] openbase_dir breaks captcha generation (grangeway) - resolved.
- 0016566: [authentication] New captcha does not work with apache (dregad) - resolved.
- 0016568: [html] Remove vendor specific CSS for rounded corners (atrol) - resolved.
- 0016410: [administration] "Delete project settings" buttons on manage config pages do not redirect properly (dregad) - resolved.
- 0016407: [bugtracker] Application error 0 when displaying project selector (dregad) - resolved.
- 0016051: [bugtracker] Selected menu item spacing not identical to that of other elements (dregad) - resolved.
- 0016047: [bugtracker] Application error 0 in manage_config_workflow_page.php (dregad) - resolved.
- 0016029: [preferences] Impossible to copy columns to/from a subproject when parent is selected (dregad) - resolved.
- 0016024: [bugtracker] When user reports an issue, the unpermitted project can be selected (dregad) - resolved.
- 0016020: [custom fields] Port Fix of 0011684 to master branch (dregad) - resolved.
- 0016010: [other] Deleted "unused" variable. Fix issue 15556 (vboctor) - resolved.
- 0016009: [other] Bug note not showing (vboctor) - resolved.
- 0015685: [bugtracker] LOG_DATABASE causes 'Array to string conversion' system notice (dregad) - resolved.
- 0015592: [administration] APPLICATION ERROR # 0 when editing configuration options (dregad) - resolved.
- 0015446: [html] Using allowed html tags in text fields causes XML parse errors (dregad) - resolved.
- 0015329: [code cleanup] Admin page bracketed submenus should use existing CSS for display (dregad) - resolved.
- 0015328: [code cleanup] Display of bracketed sub-menus differs from 1.2.x (dregad) - resolved.
- 0015327: [code cleanup] Unnecessary blank line above Account sub-menu (dregad) - resolved.
- 0014811: [html] Summary page doesn't generate properly because of special characters (dregad) - resolved.
- 0014805: [html] Left and right tables on summary page are not aligned on top (dregad) - resolved.
- 0014759: [authentication] Access Denied Page Has XML Parse Error (dregad) - resolved.
- 0014757: [html] Header text overlaps bottom div border if there are no subprojects (dregad) - resolved.
- 0014756: [code cleanup] Sub project always fails at "check_selected" method when calling print_subproject_option_list (dregad) - resolved.
- 0014748: [printing] XML Parse Error when having jpg image as attachment in summary report in HTML (dregad) - resolved.
- 0014744: [bugtracker] Unicode characters in text field prevent bug display (dregad) - resolved.
- 0014721: [printing] Error page when generate summary in HTML format (dregad) - resolved.
- 0014217: [filters] PHP error when attempting to save a filter (vboctor) - resolved.
- 0014119: [bugtracker] Use new MantisBT logo (dregad) - resolved.
- 0014099: [localization] Implement new message format for master branch at translatewiki (dregad) - resolved.
- 0014090: [html] Private are not rendered any differently than public notes (vboctor) - resolved.
- 0014089: [html] "Operation Successful" notifications are not centered (vboctor) - resolved.
- 0014087: [installation] Installation script doesn't set the crypto_master_salt causing errors (vboctor) - resolved.
- 0014086: [installation] Default administrator timezone to server timezone (dregad) - resolved.
- 0013691: [administration] misspelled XHTML in admin/system_utils.php (dregad) - resolved.
- 0013545: [administration] Admin check for PHP has incorrect logic to verify PHP errors logging (dregad) - resolved.
- 0013304: [bugtracker] Error handler causes XML Parsing Errors (dregad) - resolved.
- 0013237: [code cleanup] Incorrect call to require_once within bug_actiongroup.php (replace with require_api call) (dhx) - resolved.
- 0012906: [documentation] Admin Guide docbook fails to build (dhx) - resolved.
- 0012885: [administration] Reimplement obsolete configuration checks based on obsolete.php as part of new admin/check/ interface (dregad) - resolved.
- 0012881: [security] Add support for Strict-Transport-Security header (dhx) - resolved.
- 0012853: [authentication] Registration verification not possible (dhx) - resolved.
- 0012847: [documentation] http://docs.mantisbt.org/master/en/administration_guide.html [^] Contains misspelling "the recipient has no email address extered" (giallu) - resolved.
- 0012846: [html] Error generated structure-dom in views.php for international translate with < and > (dhx) - resolved.
- 0012718: [html] Error php-parsing in /admin/check/index.php (dhx) - resolved.
- 0012696: [documentation] Typo error on the admin config fields page in documentation (dhx) - resolved.
- 0012679: [installation] http_content_headers() xhtml headers cause issues on install.php (version 1.3) (giallu) - resolved.
- 0012641: [html] content-type not valid for IE (dhx) - resolved.
- 0012633: [html] Error generated structure-dom in bug_report_page.php (dhx) - resolved.
- 0012610: [bugtracker] my_view_page.php: error on line 347 at column 10: Opening and ending tag mismatch: tr line 0 and table (dhx) - resolved.
- 0012592: [html] not well-formed error due to missing space in collapse_api.php (on git trunk) (atrol) - resolved.
- 0012549: [bugtracker] Changing status form always creates private note (dhx) - resolved.
- 0012441: [custom fields] Unable to update custom fields due to missing function error. (daryn) - resolved.
- 0012373: [other] log_event doesn't log simple string logs (dhx) - resolved.
- 0012368: [bugtracker] Remove input side XSS validation of user real names (dhx) - resolved.
- 0012336: [graphs] Syntax error in graphviz_api.php on line 435 (dhx) - resolved.
- 0012327: [filters] Enhance plugin filters to allow developers to specify the number of columns to use in the bug filter. (daryn) - resolved.
- 0012314: [filters] Plugin filter rows are broken when more than one row of plugin filters are used. (daryn) - resolved.
- 0012300: [html] Logout button hidden behind issue # box (daryn) - resolved.
- 0011898: [html] Hyperlink issue summaries on my_view_page (dhx) - resolved.
- 0011897: [html] Refactor footer of pages using XHTML/CSS and allow user-specified copyright notice (dhx) - resolved.
- 0011896: [html] Remove [^] "open in new window" suffix from links (dhx) - resolved.
- 0011600: [html] Bugnote direct links include mismatched parenthesis (dhx) - resolved.
- 0015205: [installation] Installer should ask admin for the default timezone to use (dregad) - resolved.
- 0016357: [installation] install.php: Retry overwrites database password (dregad) - resolved.
- 0010437: [change log] APPLICATION WARNING #403: Database field "description" not found. (dregad) - resolved.
 - 0013227: [db oracle] Oracle DB support multiple issues (dregad) - resolved.
- 0015653: [bugtracker] APPLICATION ERROR 1303 when trying to reopen an issue (dregad) - resolved.
- 0006497: [filters] Setting view_filters to ADVANCED_ONLY or SIMPLE_ONLY only takes into effect after changing a filter (daryn) - resolved.
- 0016468: [html] Box "assigned" will not be shown if empty (dregad) - resolved.
- 0016062: [code cleanup] Defining new constants to replace hardcoded strings (dregad) - resolved.
- 0016471: [html] Use CSS to set alternating colors in HTML tables (grangeway) - resolved.
- 0016026: [feature] Use the 'Default project' when reporting a new bug (dregad) - resolved.
- 0010966: [bugtracker] No Errors shown at all if error_reporting=0 configured at server (dregad) - resolved.
- 0012632: [signup] Signup with empty username and e-mail is possible when display_errors[E_USER_ERROR] = 'inline' (dregad) - resolved.
- 0016025: [html] Change pages' doctype to HTML5 (dregad) - resolved.
- 0016059: [bugtracker] System should warn users when debug settings are enabled (dregad) - resolved.
- 0016061: [administration] Enable bitwise operations to set log levels (dregad) - resolved.
- 0016462: [bugtracker] Priority column header is always displayed as "P" (dregad) - resolved.
- 0016463: [bugtracker] Sort order defaults to descending (dregad) - resolved.
- 0016444: [api soap] Remove nusoap from 1.3 release (vboctor) - resolved.
- 0016411: [administration] On workflow thresholds page, changes in 'who can alter' are not color-highlighted (dregad) - resolved.
- 0016412: [administration] 'delete specific settings' button should only be displayed when there are changes to delete (dregad) - resolved.
- 0006626: [custom fields] Support "Memo" custom field type (daryn) - resolved.
- 0011396: [feature] difference between closed and resolved (dhx) - resolved.
- 0008250: [administration] Create Project - Show upload path defined in absolute_path_default_upload_folder (dhx) - resolved.
- 0009828: [bugtracker] Reopen issue access check is wrong (dhx) - resolved.
- 0010914: [code cleanup] Make db_get_table behave like plugin_table (dhx) - resolved.
 - 0016038: [bugtracker] Make db_get_table() backwards-compatible with 1.2. (dregad) - resolved.
 - 0012366: [other] core/file_api.php uses old-style db_get_table (dhx) - resolved.
- 0006447: [filters] The filter table columns shouldn't be used to divide the "Search/Filters" row at the bottom of the table. (daryn) - resolved.
- 0011320: [administration] Provide a way to disable the raw configuration management (vboctor) - resolved.
- 0011995: [html] Add CSS IDs to html elements for styling and javascript access. (daryn) - resolved.
- 0012852: [customization] Customization per project are not handled correctly on my view page. (daryn) - resolved.
- 0002814: [feature] Prefix CSS class names (daryn) - resolved.
- 0005037: [relationships] No more rel. graphs with PHP 4.3.10 and Win2K (grangeway) - resolved.
- 0005147: [filters] Suppress product version in filters too (daryn) - resolved.
- 0006700: [filters] Inconsistent behavior on filter select box (daryn) - resolved.
- 0008276: [customization] When set a filter to a value different than the default, the color could be changed (atrol) - resolved.
- 0006620: [graphs] Relationgraph is not displayed (grangeway) - resolved.
- 0006178: [graphs] relationship graph is empty (grangeway) - resolved.
- 0015678: [filters] Bad performance when filtering and using match type "Any Condition" (dregad) - resolved.
- 0010059: [relationships] Default resolution to "duplicate" if "duplicate_of" relationship exists (dhx) - resolved.
- 0010226: [email] No email on 'update->assign' (dhx) - resolved.
- 0012509: [code cleanup] replacement for file_get_extension (dhx) - resolved.
- 0013236: [plug-ins] add event to print attachment (dregad) - resolved.
- 0010730: [security] Improve random number generation with openssl_random_pseudo_bytes (dhx) - resolved.
- 0010884: [customization] Make 'edit', 'delete', and 'make private' buttons on bugnotes independently configurable (dhx) - resolved.
- 0011291: [attachments] Add support for Lighttpd's X-Sendfile method for sending attachments stored locally (dhx) - resolved.
- 0011404: [bugtracker] Record dropping of bug revisions in bug history (dhx) - resolved.
- 0011405: [bugtracker] Add link to bugnote revisions under "Updated on" line (for bugnotes that have at least 1 edit) (dhx) - resolved.
- 0011494: [bugtracker] Don't allow *_inc.php files to be called directly (dhx) - resolved.
- 0011495: [bugtracker] Cannot move core, library and language directories out of wwwroot (dhx) - resolved.
- 0011552: [bugtracker] No errors shown when actiongroup tag attaching fails (dhx) - resolved.
- 0011554: [bugtracker] Status legend should react to current filter settings (dhx) - resolved.
- 0011576: [administration] New and improved check.php for checking MantisBT installation settings/environment (dhx) - resolved.
- 0011728: [attachments] Attachments error when downloading or viewing (dhx) - resolved.
- 0011738: [authentication] $g_session_key parameter is not working (dhx) - resolved.
- 0011758: [feature] Adding a bug note should not change the status of the issue (dhx) - resolved.
- 0011804: [security] allow_reporter_reopen lets reporter make any update, not just reopen (dhx) - resolved.
- 0011826: [security] Remove all inline JavaScript from MantisBT (use external scripts instead) (dhx) - resolved.
 - 0012631: [javascript] Replace old inline dynamic filter code with jQuery equivalent (dhx) - resolved.
 - 0009117: [javascript] Please remove projax from mantis (dhx) - resolved.
- 0011893: [html] Patch: XHTML validity, semantics and styleability improvements (dhx) - resolved.
- 0011908: [html] CSS class names on View Issues page (patch) (dhx) - resolved.
- 0011967: [plug-ins] Problems with EVENT_UPDATE_BUG (dhx) - resolved.
- 0011981: [bugtracker] Do not allow to send a reminder on a private issue to users under threshold (dhx) - resolved.
- 0012085: [bugtracker] Deprecate $g_allow_close_immediately (dhx) - resolved.
- 0012094: [bugtracker] ERROR_BUG_READ_ONLY_ACTION_DENIED is not obsolete but ERROR_BUG_RESOLVED_ACTION_DENIED is (dhx) - resolved.
- 0012095: [bugtracker] bug_monitor_copy() should check users exist (dhx) - resolved.
- 0012096: [feature] On marking an issue as a duplicate add the reporter and handler to the monitor list of the destination bug (dhx) - resolved.
- 0012205: [bugtracker] Do not leave feedback status when the handler adds a note (dhx) - resolved.
- 0012253: [feature] Graphviz Graph to display workflow - PATCH (dhx) - resolved.
- 0012666: [html] Mantis uses Refresh: on IIS instead of Location: (dhx) - resolved.

[293 issues]

mantisbt - 1.2.x (Not Yet Released) View Issues ]
===================================
- 0017011: [db mssql] Graph « Cumulative by date » is not displayed in Summary > Advanced Summary (dregad) - resolved.
- 0017229: [tools] Ensure that all tests are executed on Travis (dregad) - resolved.
- 0017457: [filters] Column summary of the free text search is not prefixed by table (filter_api) (dregad) - resolved.
- 0017405: [bugtracker] proj_doc_update.php on document update crashes if new file is not uploaded (dregad) - resolved.
- 0017407: [bugtracker] Missing error param when updating project doc (dregad) - resolved.
- 0017292: [code cleanup] Use of deprecated PREG_REPLACE_EVAL ('e') pattern modifier (dregad) - resolved.
- 0017322: [attachments] Warning in bug report when attachments are disabled (dregad) - resolved.
 - 0017324: [attachments] Debug output displayed when adding files (dregad) - resolved.
- 0017289: [documentation] Code allows display of Resolution and Status in bug report page, but doc says it's not allowed (dregad) - resolved.
- 0017075: [migration] Import plugins should be able to set last_updated field to a date in the past (vboctor) - resolved.
- 0017076: [bugtracker] Issue history show date submitted and last updated as integers rather than dates (vboctor) - resolved.
- 0017073: [other] Incorrect $specific_where (dregad) - resolved.

[12 issues]

mantisbt - 1.2.17 (Released 2014-03-03) View Issues ]
=======================================

MantisBT 1.2.17 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are strongly advised to upgrade to this release.

- 0016940: [news] undefined function db_params() in core/news_api.php (dregad) - closed.
- 0016989: [other] The bug_get_bugnote_count() function in the bug API always returns 0 (atrol) - closed.
- 0017007: [webpage] duplicate "<a " tag (atrol) - closed.
- 0017055: [security] CVE-2014-2238: SQL injection vulnerability in adm_config_report.php (dregad) - closed.

[4 issues]

mantisbt - 1.2.16 (Released 2014-02-06) View Issues ]
=======================================

MantisBT 1.2.16 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are strongly advised to upgrade to this release.

- 0016341: [db postgresql] Impossible to retrieve attachments from DB with PostgreSQL >= 9.0 (dregad) - closed.
- 0014563: [db oracle] Use of literal SQL statement causes ORA-01704 error when uploading attachments (dregad) - closed.
- 0016126: [tools] Setup integration testing on Travis CI (rombert) - closed.
- 0016880: [security] CVE-2014-1609: SQL injection vulnerabilities (dregad) - closed.
- 0014301: [documentation] Add SOAP API documentation in the administration guide (rombert) - closed.
- 0015572: [attachments] diskfile_is_name_unique() can return non-unique filename (dregad) - closed.
- 0015762: [email] email_regex_simple() case sensitive, leading to incorrect e-mail links (dregad) - closed.
- 0015775: [other] Wrong reporter when copying an issue (atrol) - closed.
- 0015777: [other] Wrong value in field "Date Submitted" when copying issues (atrol) - closed.
- 0015791: [other] System notice when json_url() retrieves non-existent member (dregad) - closed.
- 0015807: [api soap] Support standard filters like ones in My View page in SOAP API (vboctor) - closed.
- 0015812: [documentation] Wrong example code for custom validation functions (atrol) - closed.
- 0009936: [api soap] add history information (rombert) - closed.
- 0015496: [attachments] Script to move attachments from db to disk not working (dregad) - closed.
- 0015774: [attachments] Incorrect number of attached files (dregad) - closed.
- 0015893: [email] It should not be possible to reset a user's password if e-mail is blank (dregad) - closed.
- 0015920: [administration] Missing config file causes cli scripts to fail silently (dregad) - closed.
- 0015921: [code cleanup] Temp variables defined in global scope should be unset() after use (dregad) - closed.
- 0015958: [email] Upgrade PHPMailer to 5.2.6 (dregad) - closed.
 - 0014543: [email] Emails are not sent to addresses with single subdomain (dregad) - closed.
 - 0015953: [email] 'Could not instantiate mail function' error with safe mode=ON (dregad) - closed.
- 0015959: [api soap] SOAP: raw XML when browsing the WSDL (dregad) - closed.
- 0016028: [api soap] Adding note via webservice generates wrong email content for assigned user (rombert) - closed.
- 0016120: [email] Cannot modify Receive Reminder threshold on Manage Threshold Page (atrol) - closed.
- 0009876: [performance] Performance problem with a lot of projects (dregad) - closed.
- 0016174: [tools] Travis CI: set up PHP 5.5 build alongside 5.4 (rombert) - closed.
- 0012955: [attachments] After updating a project documentation the file is damaged (dregad) - closed.
- 0014541: [code cleanup] Remove calls to deprecated functions db_prepare* in "Docs" update page (dregad) - closed.
- 0016158: [api soap] mc_filter_get_issues does not populate monitors fiels for retrieved issues (rombert) - closed.
- 0016187: [administration] Application error on fresh install (dregad) - closed.
- 0016202: [tools] Travis CI: set up PHP 5.3 build (atrol) - closed.
- 0016204: [tools] User Test fails when bugnote_order is not set to default (dregad) - closed.
- 0016205: [tools] Issue History tests fail when history order is descending (dregad) - closed.
- 0016203: [tools] Issue History tests randomly fail (dregad) - closed.
- 0010071: [administration] Manage Workflow Threshold page: 'Who can alter this value' is not saved (dregad) - closed.
- 0012470: [custom fields] Custom fields names aren't translated in several places (dregad) - closed.
- 0012480: [bugtracker] Editing a bug with no assigned user and no access to edit assigned to field shows 'user0' (dregad) - closed.
- 0015770: [security] When $g_limit_reporters = ON; it is still possible to change reporter (dregad) - closed.
- 0015790: [other] url_get() cURL should set User Agent (dregad) - closed.
- 0015817: [api soap] SOAP API unit test failures (dregad) - closed.
- 0016175: [tools] Customize Travis notifications (dregad) - closed.
- 0016252: [api soap] API SOAP provides no answer after MantisBT upgrade (rombert) - closed.
- 0016259: [bugtracker] When sorting issues by due_date, unset values should be listed at the end (dregad) - closed.
- 0016337: [administration] Creating the first project on a fresh install causes error 2800 (dregad) - closed.
- 0016340: [db db2] Error 401 for Manage Tags (dregad) - closed.
- 0016342: [bugtracker] The g_html_valid_tags_single_line configuration variable seems to be ignored <ul><li>in favor of g_html_valid_tags</li></ul> (dregad) - closed.
- 0016348: [code cleanup] Duplicated code in MantisCoreFormatting (dregad) - closed.
- 0016408: [customization] config_eval() fails on configs that reference array values (vboctor) - closed.
- 0016416: [installation] Improve first login experience by auto-redirecting to create project page (vboctor) - closed.
- 0016431: [installation] Numerous "Invalid argument supplied for foreach()" errors when installing with DB script printed to screen (grangeway) - closed.
- 0016484: [tagging] SOAP: Impossible to attach tags to issues (dregad) - closed.
- 0016485: [api soap] SOAP API test failure for due date (dregad) - closed.
- 0010873: [roadmap] Change Log/Roadmap do not work with inherited versions. (dregad) - closed.
- 0014458: [other] Track third party libs as github repos (dregad) - closed.
- 0015196: [api soap] Create history entries when creating issues with non-default status and resolution (rombert) - closed.
- 0016376: [customization] Not able to change status without having update issue rights (dregad) - closed.
- 0016420: [preferences] Editing user preferences when no project exists triggers application error 20 (dregad) - closed.
- 0016513: [security] CVE-2013-4460: XSS in account_sponsor_page.php project names (atrol) - closed.
- 0016607: [documentation] Wrong option html_tags in Admin Guide (atrol) - closed.
- 0016767: [upgrade] upgrade_unattended script is no longer working (vboctor) - closed.
- 0016768: [mobile] Default mantistouch_url correctly when MantisTouch is installed in 'm' subfolder (vboctor) - closed.
- 0016769: [mobile] MantisTouch redirect can break soap api based on user agent sent (vboctor) - closed.
- 0016770: [mobile] Redirect from MantisBT issue to MantisTouch should go to the same issue page on MantisTouch (vboctor) - closed.
- 0011785: [code cleanup] Comment for access_compare_level in access_api.php is bogus (atrol) - closed.
- 0015648: [email] add event signalling to email_build_subject() function (dregad) - closed.
 - 0015647: [email] email subject is build manually in function email_bug_info_to_one_user() (atrol) - closed.
- 0016706: [plug-ins] Plugin pages can be accessed directly when schema upgrade is needed (dregad) - closed.
- 0016812: [bugtracker] Moving issue to child->child changes category to default (dregad) - closed.
- 0016848: [bugtracker] Remove main page from main menu when news feature is OFF (vboctor) - closed.
- 0006343: [bugtracker] Change status using actiongroup does not send email notifiation (dregad) - closed.
- 0013659: [email] e-mail notification about priority change is not sent when using bug_actiongroup_page.php (dregad) - closed.
- 0016879: [security] CVE-2014-1608: soap:Envelope SQL injection attack (dregad) - closed.

[72 issues]

mantisbt - 1.2.15 (Released 2013-04-11) View Issues ]
=======================================

MantisBT 1.2.15 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are strongly advised to upgrade to this release.

- 0015573: [security] CVE-2013-1883: One query can be issued via current Mantis interface to take down site (dregad) - closed.
- 0002971: [bugtracker] Reminders are not added to bug history (dregad) - closed.
- 0015470: [bugtracker] Reminders recipient list is truncated (dregad) - closed.
- 0010047: [documentation] Adding new statuses section is missing a step (dregad) - closed.
- 0010118: [documentation] lang_get_current() returns wrong language if $g_default_language overwritten (dregad) - closed.
- 0010372: [feature] Don't allow reminders to be sent if the user doesn't have an email address specificed (dregad) - closed.
- 0013054: [installation] Installer displays a blank page if core.php encounters a critical error (dregad) - closed.
- 0015357: [bugtracker] uninitialized library path (dregad) - closed.
- 0015471: [bugtracker] bug_reminder.php does not handle unsent reminders (dregad) - closed.
 - 0015472: [bugtracker] email_bug_reminder() API's return array is always full list of recipients (dregad) - closed.
- 0015481: [custom fields] Custom fields values are not sorted in the main filter (dregad) - closed.
- 0015528: [printing] Custom fields user has no access to should not be displayed on print pages (dregad) - closed.
- 0015538: [bugtracker] Issues list is not displayed when $g_limit_reporters is ON (dregad) - closed.
- 0015540: [documentation] Wrong example code for custom status translation (atrol) - closed.
- 0015558: [bugtracker] url_get() does not fall back to other methods when no data is retrieved (dregad) - closed.
- 0015575: [documentation] Turning on $g_show_queries_list causes Mantis to crash with an error (dregad) - closed.
- 0015659: [localization] Appears @70@ and @80@ in the list of resolutions in the "view Issues" page when mantis is in catalan. (dregad) - closed.
- 0015691: [administration] Config report: retrieval of saved project filter from cookie does not work (dregad) - closed.
- 0015453: [security] CVE-2013-1930: Close button is shown on webpage despite 'close' is not a valid status by workflow (dregad) - closed.
- 0015511: [security] CVE-2013-1931: XSS vulnerability when deleting a version (atrol) - closed.
- 0015698: [bugtracker] 'extract() expects parameter 1 to be array, boolean given' in '/srv/www/bugs/account_prof_edit_page.php' line 48 (dregad) - closed.
- 0015704: [documentation] Wrong description of writing custom_functions (atrol) - closed.
- 0015744: [bugtracker] Reminder bugnote with list of recipients not added if no text provided (dregad) - closed.
- 0015451: [api soap] Incorrect invocations of SoapObjectsFactory::newSoapFault (rombert) - closed.
- 0015517: [api soap] mc_project_get_versions() result can't be parsed by C# (dregad) - closed.
- 0015522: [api soap] mc_project_get_issues does not report due_date (dregad) - closed.

[26 issues]

mantisbt - 1.2.14 (Released 2013-01-28) View Issues ]
=======================================

MantisBT 1.2.14 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are strongly advised to upgrade to this release.

Please refer to the release notes for details.

- 0015411: [performance] Huge memory consumption for print_user_option_list() (dregad) - closed.
- 0015415: [security] CVE-2013-1932: XSS vulnerability on Configuration Report page (dregad) - closed.
- 0015416: [security] CVE-2013-1934: XSS issue in adm_config_report.php when displaying complex value (dregad) - closed.

[3 issues]

mantisbt - 1.2.13 (Released 2013-01-21) View Issues ]
=======================================

MantisBT 1.2.13 had to be withdrawn shortly after release, as it introduced a bug
(#15411) causing the View Issues page to consume significantly more memory for
instances with large numbers of users (order 10k+), leading to system crashes,
as well as an XSS issue (#15415) in the Configuration Report page.

We recommend not to use 1.2.13, and deploy version 1.2.14 instead.

- 0015201: [db postgresql] Summary page fail (dregad) - closed.
- 0013298: [preferences] commas and multi-dimensional arrays in adm_config_set (dregad) - closed.
- 0015258: [security] CVE-2013-1811 Reporter can change issue status to 'new' (dregad) - closed.
- 0014009: [administration] admin/check.php fatal error on PHP 5.1.x (undefined function timezone_identifiers_list()) (dregad) - closed.
- 0014157: [api soap] Array to string conversion error on soap request with PHP 5.4 (rombert) - closed.
- 0012128: [administration] Configuration Report should be sortable (atrol) - closed.
- 0014559: [administration] Adding filter for "Configuration report" (dregad) - closed.
- 0014871: [api soap] Add support for the built-in soap extension in addition to nusoap (rombert) - closed.
- 0003693: [bugtracker] Make the username in Manage Projects a clickable link to edit that user (dregad) - closed.
- 0007586: [customization] generic configuration editor cannot 'EDIT' an option (dregad) - closed.
- 0010130: [filters] Filter "Assigned to" does not display usernames when project "All Projects" is selected (dregad) - closed.
- 0011854: [documentation] Parameter $g_default_timezone" is not mentioned in administration_guide (dregad) - closed.
- 0013680: [performance] Configuration page takes a very long time to load (dregad) - closed.
- 0015199: [other] Update json api error format (rombert) - closed.
- 0015384: [security] CVE-2013-1810 XSS vulnerability on summary page (dhx) - closed.
- 0015247: [administration] Protected account change still sends email (dregad) - closed.
- 0015248: [email] The order of sending emails is inverted when using cron (dregad) - closed.
- 0015255: [bugtracker] Date filter fields are disabled when $g_use_javascript = OFF (dregad) - closed.
- 0015257: [filters] Inconsistent use of numeric vs text month in date filter selection fields (dregad) - closed.
- 0015260: [bugtracker] access_get_status_threshold() returns incorrect value for NEW (dregad) - closed.
- 0015264: [custom fields] custom_field_get_id_from_name() broken since 1.2.12 (dregad) - closed.
- 0015265: [custom fields] custom_field_get_id_from_name() doesn't cache result of obsolete custom field names (dregad) - closed.
- 0015280: [code cleanup] Form in manage_columns_inc.php has misleading name and unnecessary multipart encoding (dregad) - closed.
- 0015320: [filters] Date filters broken since 1.2.12 (rombert) - closed.
- 0015360: [bugtracker] Add Missing config 'reminder_receive_threshold' in workflow threshold page (dregad) - closed.
- 0015370: [bugtracker] When a bug is resolved on report, default the handler to the current user (rombert) - closed.
- 0015373: [security] CVE-2013-0197 XSS vulnerability with match_type filter (dhx) - closed.
- 0015382: [email] Additional improvements to email logging (dregad) - closed.
- 0015388: [filters] Update the match_type parameter to be XSS-safe by itself (dregad) - closed.
- 0015389: [filters] Display of match_type filter property for unknown types (dregad) - closed.
- 0015356: [api soap] improve error handling in mc_issue_api.php (rombert) - closed.
- 0014672: [api soap] Slow performance of SOAP calls due to nusuoap (rombert) - closed.
- 0015222: [api soap] mc_project_delete_category fails to delete category (rombert) - closed.

[33 issues]

mantisbt - 1.2.12 (Released 2012-11-09) View Issues ]
=======================================

MantisBT 1.2.12 resolves over 70 issues mainly in the following categories:
security, MS SQL and PostgreSQL databases support, Change Log page, custom
fields, installation, attachments, SOAP API, XML import/export plugin,
e-mail (including update of the PHPMailer library to version 5.2.1) and others.

In addition, it also brings several enhancements:
 - filter page now allows 'OR' logic and to query by notes' authors
 - improved e-mail logging (see #14630)
 - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event
 - updated Admin Guide
 - translations in many languages


- 0014385: [db postgresql] Impossible to create a new project with fresh install on PostgreSQL (dregad) - closed.
- 0014466: [db postgresql] New Signup user has protected account (dregad) - closed.
- 0014574: [db mssql] sql server info during installation (dregad) - closed.
- 0014774: [db mssql] Fix issue in tag api with odbc_mssql driver (dregad) - closed.
- 0014678: [bugtracker] Allow resolving a bug when it is reported (rombert) - closed.
- 0014631: [email] Email validation needs to be consistent (dregad) - closed.
- 0014496: [security] CVE-2012-5522 Workflow Transitions: Minimal Access Level to Change to this status has no correct 'default' (dregad) - closed.
- 0014650: [code cleanup] Improve comments for check custom field length in custom_field_delete_all_values() (dregad) - closed.
- 0009826: [bugtracker] Single project user should default to the project, not All Projects (dregad) - closed.
- 0014453: [email] email validation regex does not accept addresses with single subdomain (dregad) - closed.
- 0014356: [graphs] the statistics result in summary is wrong (dregad) - closed.
- 0006263: [customization] Incomplete documentation for $g_send_reset_password (dregad) - closed.
- 0006479: [feature] Direct project link (dregad) - closed.
- 0006491: [filters] After applying a filter, the name of the applied filter is replaced by [Reset filter], which leads to misinterpretation (daryn) - closed.
- 0009159: [other] CSS-Classes missing on Buttons (dregad) - closed.
- 0009368: [email] Reminder emails not logged when logging is on (dregad) - closed.
- 0010126: [plug-ins] Add a plug-in event to bug_change_status_page.php (daryn) - closed.
- 0011029: [plug-ins] XML Import (and export) plugin do not work (giallu) - closed.
- 0011114: [plug-ins] XML Import/Export : unable to associate with category created in the main project (dregad) - closed.
- 0011115: [email] phpmailer 2.3 breaks mail transmission (dregad) - closed.
- 0011605: [filters] When a category has a ' in his name, then the filter is not applied (dregad) - closed.
- 0011687: [attachments] Bugs with attachments that are moved will lose attachments (dregad) - closed.
- 0011782: [bugtracker] allow_reporter_reopen should only apply to users with reporter access (dregad) - closed.
- 0011928: [bugtracker] Categories duplicated on summary_page.php (dregad) - closed.
- 0012112: [plug-ins] XML Import fails: Column 'profile_id' cannot be null (dregad) - closed.
- 0012170: [bugtracker] SQL syntax error occurs when sorting it by the custom field where special character is included. (dregad) - closed.
- 0012187: [plug-ins] XML Import does not work (dregad) - closed.
- 0012580: [bugtracker] Issue x not found (for bug y) (dregad) - closed.
- 0013265: [change log] Issues counted more then one time if they have multiple relations (dregad) - closed.
- 0013415: [attachments] cloning issue with attachments doesn't work (rombert) - closed.
- 0014032: [feature] Allow setting the type of Gravatar identicon (dregad) - closed.
- 0014081: [installation] Use of DIRECTORY_SEPARATOR in URLs (dregad) - closed.
- 0014192: [email] Add Exchange header for automessage (rombert) - closed.
- 0014329: [plug-ins] Updating bug status should provide event to display mandatory plug-in fields (dregad) - closed.
- 0014655: [tagging] Filtering of tags starting with '0' not possible (atrol) - closed.
- 0014387: [bugtracker] $g_max_failed_login_count Enabled Prevents User from logging after passwd reset (dregad) - closed.
- 0014399: [installation] Lack of detailed error message during schema creation (dregad) - closed.
- 0014418: [customization] Alternate text for logo image is hardcoded (atrol) - closed.
- 0014420: [bugtracker] captcha error (dregad) - closed.
- 0014442: [ldap] LDAP binding calls are made even if $g_login_method <> LDAP (dregad) - closed.
- 0014443: [feature] Status changed to resolved and not to the desired value (dregad) - closed.
- 0014446: [customization] System warning in html_status_legend() with custom status (dregad) - closed.
- 0014447: [other] URLs longer than 152 characters are causing problems (dregad) - closed.
- 0014448: [attachments] 'Undefined index: jpg' in '.../core/file_api.php' line 917 (atrol) - closed.
- 0014478: [administration] The global category "General" can be deleted, but the $g_default_category_for_moves must be protected from suppression (dregad) - closed.
- 0014516: [upgrade] Custom field needs value when reporting following upgrade to 1.2.11 (dregad) - closed.
- 0014547: [bugtracker] Email hrefs in bugnotes should include the 'mailto:' prefix (dregad) - closed.
- 0014552: [installation] Add a system check to ensure that the ADOdb extension is not loaded (dregad) - closed.
- 0014587: [custom fields] Dynamic value lists of enumeration custom fields not working for category (atrol) - closed.
- 0014630: [email] Improve email logging (dregad) - closed.
- 0014632: [email] Email validation always successful when $g_use_ldap_email = ON (dregad) - closed.
- 0014673: [ldap] LDAP login performs unnecessary SQL updates (rombert) - closed.
- 0014677: [other] Summary: developer names should be links (rombert) - closed.
 - 0006809: [administration] Using an 'Or' filter logic (rombert) - closed.
  - 0014735: [filters] Permalink does not work when using "Match Type" (rombert) - closed.
  - 0014737: [filters] Date filters do not work with match type = any condition (rombert) - closed.
 - 0009725: [filters] Filter on "Note By" by a reporter (rombert) - closed.
- 0014684: [localization] Bad french translation for " Show Disabled" (dregad) - closed.
- 0014701: [administration] Missing project override in project edit page (dregad) - closed.
- 0014700: [administration] Admin > Edit Project Page : Upload Path when stored in DB (dregad) - closed.
- 0014704: [security] CVE-2012-5523 Clone and Move issue with Copy bug notes - user get email notice from project without access (dregad) - closed.
- 0014706: [bugtracker] Last updated date not bumped when custom field changed from view issues page (dregad) - closed.
- 0014718: [attachments] Clone cannot find attachments (dregad) - closed.
- 0014723: [attachments] Force validation of upload path if file_upload_method == DISK (dregad) - closed.
- 0014724: [bugtracker] $g_project_override = ALL_PROJECTS does not work (dregad) - closed.
- 0014725: [code cleanup] Manage Project Create and Edit pages are not consistent (dregad) - closed.
- 0014731: [filters] No display of selected filter values when using filter "Note By" (atrol) - closed.
- 0014764: [bugtracker] Custom fields from disabled projects are displayed in view issues page (dregad) - closed.
- 0014765: [sql] Usage of db_query in custom fields api (dregad) - closed.
- 0014766: [code cleanup] Optimize custom_field_update() function (dregad) - closed.
- 0014767: [custom fields] Errors triggered when updating custom fields do not inform user what caused it (dregad) - closed.
- 0014772: [custom fields] Excel export with custom fields are all letters converted to lower case (dregad) - closed.
- 0014788: [change log] Change Log must consistently rely on fixed_in_version (dregad) - closed.
- 0014842: [bugtracker] Incorrect matching of versions in print_version_option_list() (dregad) - closed.
- 0014869: [other] Provide a simple API for outputting JSON (rombert) - closed.
- 0015200: [authentication] Anonymous access is broken (vboctor) - closed.
- 0012562: [email] Mail sent without from address set in config (dregad) - closed.
- 0011230: [api soap] High-ascii characters in fields will cause invalidity in XML. (rombert) - closed.
- 0014550: [api soap] Incorrect values for date_order field when using mc_project_version_add() (rombert) - closed.
- 0014558: [api soap] Monitors get lost when calling mc_issue_update via SOAP (rombert) - closed.
- 0014573: [api soap] Updating an issue note view state always sets it to private (rombert) - closed.
- 0013445: [api soap] Add mc_login() for login and to return user data (vboctor) - closed.
- 0013900: [api soap] Improve documentation for mc_project_get_issues and similar (rombert) - closed.
- 0014412: [api soap] Calling mc_issue_update creates erroneous "Note View State changed" items in history (issue 0013377 not fixed) (dregad) - closed.

[84 issues]

mantisbt - 1.2.11 (Released 2012-06-06) View Issues ]
=======================================

MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release.

This release also contains numerous minor bug fixes to MantisBT, enhancements to the admin guide and improved translations in many languages.


- 0014288: [db postgresql] Manage User not reachable due to error in PostgreSQL (dregad) - closed.
- 0007633: [bugtracker] Saving an edited note should touch bug's last_updated timestamp (dregad) - closed.
- 0011661: [administration] "closed issue become readonly" doesn't work (dregad) - closed.
- 0011726: [administration] Add a "Hide Disabled" filter option to the Manage Users page. (dregad) - closed.
- 0012129: [administration] workflow transition to status reopened is always checked for some status on workflow transition page (dregad) - closed.
- 0012293: [graphs] Not all the categories are displayed (rombert) - closed.
- 0012781: [bugtracker] Links in the comments look broken (dregad) - closed.
- 0013542: [graphs] in MantisGraph, function "Show as Table" try to open an iframe and fail (rombert) - closed.
- 0014015: [security] Users with access level REPORTER cannot delete own attachments despite allow_delete_own_attachments = ON; (dhx) - closed.
- 0014016: [security] CVE-2012-2692 Users with access level >= update_bug_threshold can delete any attachment (atrol) - closed.
- 0014105: [time tracking] Access to undefined variable in bugnote_api.php (atrol) - closed.
- 0014122: [bugtracker] In-appropriate time-out message when reporting an issue needs is shown (dregad) - closed.
- 0014155: [documentation] Add new Troubleshooting chapter in Admin Guide (dregad) - closed.
- 0014156: [bugtracker] Add Close button for Reporter if allow_reporter_close is enabled (dregad) - closed.
- 0014185: [plug-ins] Only first 100 rows of plug-in columns loaded when exporting to Excel (dregad) - closed.
- 0014191: [bugtracker] SYSTEM NOTICE: 'Undefined variable: t_project' in html_api.php (dregad) - closed.
- 0014193: [graphs] in MantisGraph, function "Show as Graph" produce an unusable result, axis can't be read (rombert) - closed.
- 0014216: [administration] The filter in managed_user_page.php is not persistent (dregad) - closed.
- 0014238: [bugtracker] translation files refers a constant that is not defined (atrol) - closed.
- 0014279: [documentation] Bad layout of the Customizing Status Values chapter of Admin Guide (dregad) - closed.
- 0014260: [authentication] Unable to reset administrator passwords. APPLICATION ERROR #1901. (dregad) - closed.
- 0014272: [bugtracker] Revision history for extended info fields has wrong date+author (dregad) - closed.
- 0014273: [code cleanup] Unnecessary use of array_reverse to display bug revisions (dregad) - closed.
- 0014285: [documentation] Revamp Admin Guide / Installation chapter (dregad) - closed.
 - 0011597: [documentation] No Upgrade instructions from 1.1.x to 1.2 are available (dregad) - closed.
- 0014306: [administration] Tabbing is not functioning as expected (atrol) - closed.
- 0014333: [other] mantis bt switches to https from http (dregad) - closed.
- 0014340: [security] CVE-2012-2691 Reporters can update notes of other users by using SOAP API (dhx) - closed.
- 0014343: [api soap] Undefined property: BugnoteData::$bugnote_text_id (rombert) - closed.
- 0014094: [api soap] mc_issue_add project['name'] is not used (vboctor) - closed.
- 0014188: [api soap] SOAP API update function accesses undefined variable in error handling (atrol) - closed.
- 0014309: [api soap] Log all SOAP errors to the server's web log (rombert) - closed.
- 0014341: [api soap] SOAP API is failing due to PHP errors that are ignored by the web app (vboctor) - closed.
- 0014342: [api soap] mc_issue_api function calls to update and modify issues via SOAP do not check for read only issues (dhx) - closed.

[34 issues]

mantisbt - 1.2.10 (Released 2012-04-01) View Issues ]
=======================================

MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release.

- 0005228: [attachments] Attaching multiple files in one go. (dregad) - closed.
- 0004465: [security] Turn off 'save login' feature (dregad) - closed.
- 0013785: [other] Include filename and line number in system notices and warnings (dregad) - closed.
- 0013998: [bugtracker] Logo is not present on new instalation. (vboctor) - closed.
- 0014013: [customization] System notice in bug_check_workflow() (vboctor) - closed.
- 0014014: [filters] Search with number > 2147483647 fails on 64-bit systems with PostgreSQL (dregad) - closed.
- 0014017: [csv] Exporting Descriptions, Additional Information, etc. fails. (dregad) - closed.
- 0014097: [other] German 'Umlaute' with closing question mark failed (dregad) - closed.
- 0014118: [documentation] Manual is not packaged with 1.2.9 release (jreese) - closed.

[9 issues]

mantisbt - 1.2.9 (Released 2012-03-03) View Issues ]
======================================

MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. All installations that are currently running any 1.2.x version are advised to upgrade to this release.

- 0011744: [db mssql] Failure getting tag candidates on MSSQL (rombert) - closed.
- 0011776: [db mssql] Support for Sql Server Native driver (sqlsrv) (dregad) - closed.
- 0012081: [db mssql] call function config_set error (dregad) - closed.
- 0012082: [db mssql] call function token_create error (dregad) - closed.
- 0013363: [db mssql] Application Failure when trying to select an issue (rombert) - closed.
- 0007994: [bugtracker] New Mantis Logo (vboctor) - closed.
- 0013446: [api soap] Add tags support to soap api (rombert) - closed.
- 0013736: [security] mc_issue_get_id_from_summary incorrectly checks for permissions (rombert) - closed.
- 0013740: [bugtracker] Support auto-redirection from MantisBT to MantisTouch for mobile browsers (vboctor) - closed.
- 0007802: [documentation] $g_show_attachments_indicator incorrect in manual (atrol) - closed.
- 0004516: [bugtracker] my_view_inc.php ignores config-option bug_count_hyperlink_prefix (rombert) - closed.
- 0008504: [bugtracker] Edit project settings form has default 'space' in foldername field (dregad) - closed.
- 0009034: [csv] CSV Export with special chars dont work properly (rombert) - closed.
- 0010124: [security] Bug in access_has_bug_level (dregad) - closed.
- 0011124: [filters] The 'sticky_issues' value stored in the mantis_filter_table is not always stored correctly. (dhx) - closed.
- 0011457: [code cleanup] Wrong comment LDAP field in config_defaults_inc.php (rombert) - closed.
- 0011459: [code cleanup] Wrong comment delete_other_bug_threshold in config_defaults_inc.php (rombert) - closed.
- 0011662: [time tracking] Decimal cost causes error in time tracking/billing (dregad) - closed.
- 0011706: [bugtracker] Do not show release and obsolete versions (dregad) - closed.
- 0011730: [attachments] Attachments do not show properly in View Issues List (atrol) - closed.
- 0011801: [bugtracker] Permission error when clearing a version field of multiple bugs (dregad) - closed.
- 0011806: [code cleanup] not necessary instructionss (dregad) - closed.
- 0011916: [bugtracker] List of user profiles not sorted alphabetically (dregad) - closed.
- 0011923: [other] Wrong display of user's access level in notes (dregad) - closed.
- 0012006: [plug-ins] Mantis Graphs - Configuration - jpgraph library path not saved (atrol) - closed.
- 0012029: [custom fields] minimum length of custom fields of type numeric is not checked (rombert) - closed.
- 0012199: [customization] Cannot add 'eta' to bug_report_page_fields (rombert) - closed.
- 0012324: [administration] Cannot assign multiple issues with mass manipulation tool (dregad) - closed.
- 0012371: [security] XSS in print_all_bug_page_word.php when printing project and category names (giallu) - closed.
- 0012393: [graphs] MantisGraph graph_api.php:error_text() is broken when using JpGraph (rombert) - closed.
- 0012404: [custom fields] custom field sort issue on view issues page (dregad) - closed.
- 0012450: [bugtracker] default relation type is hardcoded on bug_report_page.php (dregad) - closed.
- 0012680: [custom fields] Custom field name with paranthesis leads to db error message when sorting "view issues" (dregad) - closed.
- 0013060: [authentication] links from excel to mantis (dregad) - closed.
- 0013083: [graphs] Only 50 bugs (default) are shown (rombert) - closed.
- 0013096: [custom fields] Spurious Target Version Behaviour. (dregad) - closed.
- 0013661: [bugtracker] Improve messages when errors occur in bug group actions (dregad) - closed.
- 0013193: [administration] Files served by plugins do not have a Content-Type header set (rombert) - closed.
- 0013256: [other] do not distribute .gitignore file on released tar.gz (jreese) - closed.
- 0013276: [attachments] missing "attachments" column header in view_all_bug_page (dregad) - closed.
- 0013280: [custom fields] Sort by accented custom field produces incorrect log entries (dregad) - closed.
- 0013303: [attachments] File attachments cannot be uploaded when PHP's "file_uploads" configuration directive equals "On" (dregad) - closed.
- 0013315: [localization] After Spanish traslator: Application Warning #300: cadena 'directionality' no encontrada (dregad) - closed.
- 0013328: [time tracking] Time tracking cost column has wrong font size (dregad) - closed.
- 0013331: [ldap] Email lookup against non-existing LDAP account displays warning (dregad) - closed.
- 0013341: [bugtracker] Moving issues with no category (g_allow_no_category = ON) (dregad) - closed.
- 0013344: [bugtracker] Username for Categories' default handler is not printed in standard way (dregad) - closed.
- 0013346: [plug-ins] Enhanced function plugin_config_get() to allow usage of user_id and project_id (dregad) - closed.
- 0013370: [csv] CSV export specifies incorrect MIME type (rombert) - closed.
- 0013406: [custom fields] Default values for custom fields are not written to database (dregad) - closed.
- 0013435: [administration] The obsolete checks should also verify configs in the db (dregad) - closed.
- 0013439: [attachments] Wrong Content-type for various MSOffice documents (rombert) - closed.
- 0013491: [email] Mark generated e-mails with 'auto-generated' according to RFC 3834 (rombert) - closed.
- 0013531: [localization] error in slovak translation (dregad) - closed.
- 0013538: [bugtracker] API auth check on specific functions rework / not needed (dregad) - closed.
- 0013644: [sponsorships] Deleting an issue with assigned sponsorship throws error (atrol) - closed.
- 0013643: [administration] Definition of MANTIS_ERROR strings in plugin language file causes check in test_lang.php to fail (dregad) - closed.
- 0013662: [bugtracker] Allow selection of subproject versions in bug group action (dregad) - closed.
- 0013683: [bugtracker] Unchanged workflow settings highlighted as overridden (dregad) - closed.
- 0013684: [code cleanup] SYSTEM NOTICE: Undefined variable: t_version_suffix in admin/index.php (dregad) - closed.
- 0013696: [bugtracker] Project path (atrol) - closed.
- 0013714: [email] "$g_notify_flags" config option in web config interface: problem for relationship change (dregad) - closed.
- 0013715: [plug-ins] Export to csv and excel does not work for plugin columns ? (dregad) - closed.
- 0013728: [customization] Various display issues of custom enums cross-project (dregad) - closed.
 - 0011323: [customization] Cross project relationships not picking up custom statuses (dregad) - closed.
 - 0013682: [customization] Color codes for custom statuses not displayed cross-project (dregad) - closed.
 - 0013707: [customization] Custom resolutions not displayed cross-project (dregad) - closed.
 - 0013718: [customization] Custom severity not displayed cross-project (dregad) - closed.
- 0013735: [html] Corners of plus and minus icons are not transparent (dhx) - closed.
- 0013765: [csv] Excel Export ends in infinite loop if number of viewing issues mod 100 = 0 (dregad) - closed.
- 0013935: [filters] Version based filtering not possible (dregad) - closed.
- 0013938: [bugtracker] Error when editing issue having version not existing in current project (dregad) - closed.
- 0013941: [printing] Missing newlines in Word export (atrol) - closed.
- 0013958: [csv] Extra column in csv export when sponsorship_total >= 1000 (dregad) - closed.
- 0013959: [csv] Fatal error: Call to undefined function excel_format_sponsorship_total() (dregad) - closed.
- 0013993: [administration] Support search by email in manage users page (vboctor) - closed.
- 0013992: [bugtracker] Use Gravatar generated patterns based on email hash for users who don't have avatar (vboctor) - closed.
- 0013994: [bugtracker] Use rounded edges for avatars (vboctor) - closed.
- 0013561: [security] Any manager can delete global categories (dregad) - closed.
- 0013816: [security] Enhance history when copying issues (dregad) - closed.
- 0013656: [security] Reporters have read/write access to existing data of other users (rombert) - closed.
- 0013690: [ldap] When using LDAP, administrator can't reset "failed_login_count" any more (dregad) - closed.
- 0013748: [security] Can't move bugs from projects with access < report_bug_threshold (dregad) - closed.
- 0013901: [security] SOAP API allows invoking methods without proper authentication (grangeway) - closed.
- 0013496: [api soap] Send all dates in the GMT timezone (rombert) - closed.
- 0013528: [api soap] SOAP API accesses undefined variable in error handling (atrol) - closed.
- 0013646: [api soap] Support profile fields (rombert) - closed.
- 0013647: [api soap] Support sticky field (rombert) - closed.
- 0013789: [api soap] Invalid usage of function mci_soap_fault_access_denied (atrol) - closed.
- 0013324: [api soap] Adding or updating issue with mylyn causes error #13 (rombert) - closed.
- 0013339: [api soap] Email notifications through mantis mylyn connector / SOAP (rombert) - closed.
- 0013377: [api soap] Calling mc_issue_update creates erroneous "Note View State changed" items in history (rombert) - closed.
- 0013526: [api soap] It is not possible to retrieve issues for 'All Projects' (rombert) - closed.
- 0013571: [api soap] SOAP Api / mci_get_user_id() : added possibility to find user id by email (rombert) - closed.

[94 issues]

mantisbt - 1.2.8 (Released 2011-09-06) View Issues ]
======================================

Security release.

- 0013191: [security] XSS vulnerability dues to usage of PHP_SELF (grangeway) - closed.
- 0012361: [sub-projects] Can see private bug in MyView / ViewIssues but then 'access denied' when I view it (dhx) - closed.
- 0013140: [authentication] cloning an issue uses incorrect permissions during actual submit operation (dhx) - closed.
- 0013141: [bugtracker] wrong args passed to config_get in filter_db_get_filter (dhx) - closed.
- 0013272: [installation] Hardcoded table name mantis_config_table in install.php (dregad) - closed.
- 0013281: [security] MantisBT Security Vulnerabilities Notification (dhx) - closed.
 - 0013282: [security] bug_actiongroup_ext_page.php does not properly sanitise action parameter before including local files (dhx) - closed.
 - 0013283: [security] bug_actiongroup_ext_page.php remote file inclusion: action parameter (dhx) - closed.
- 0013290: [csv] Allow more control over excel export format (rombert) - closed.

[9 issues]

mantisbt - 1.2.7 (Released 2011-08-22) View Issues ]
======================================

Security release.

- 0010367: [customization] Moving attachments while cloning issue (rombert) - closed.
- 0011338: [tools] Build internal documentation using phpDoc. (rombert) - closed.
- 0011458: [attachments] Missing attachments can not be deleted (dregad) - closed.
- 0012759: [plug-ins] Error loading language string when plugin is not current (dregad) - closed.
- 0013144: [localization] German explanation for sending Reminders is wrong ($s_reminder_explain) (atrol) - closed.
- 0013167: [bugtracker] Clone task: allow copying of notes (rombert) - closed.
- 0013181: [ldap] ldap_port obsolete... but not anymore? (dregad) - closed.
- 0013190: [bugtracker] View page doesn't honor view_handler_threshold threshold (vboctor) - closed.
- 0013192: [plug-ins] Gracefully handle empty return for hook EVENT_MENU_FILTER (rombert) - closed.
- 0013225: [attachments] Inconsistent handling of project file upload path (dregad) - closed.
- 0013226: [attachments] check.php should verify that default file upload path has trailing slash (dregad) - closed.
- 0013228: [time tracking] APPLICATION ERROR 0000401 Bug in SQL query in bugnote_api.php (dregad) - closed.
- 0013245: [security] Cross site scripting and remote SQL injection vulnerabilities (dhx) - closed.

[13 issues]

mantisbt - 1.2.6 (Released 2011-07-26) View Issues ]
======================================

MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included.


- 0011282: [db oracle] For 1.3.0 - ORA-00918: column ambiguously defined for the query: SELECT DISTINCT m_bug_tbl.* (dregad) - closed.
- 0013007: [sub-projects] Moving an issue to a sub-project changes the category to the default category (dhx) - closed.
- 0005926: [administration] 'None' filter on checkbox field doesn't return bugs with a blank custom field value (as opposed to null/undefined values) (dregad) - closed.
- 0007952: [time tracking] Minor Improvement - Add label near time used (dregad) - closed.
- 0008553: [time tracking] Suggestion: Change menu "Billing" to "Timetrack" (dregad) - closed.
- 0012167: [ldap] LDAP port parameter is ignored (dhx) - closed.
- 0012190: [localization] Typos and confusion in French / English (dregad) - closed.
- 0012259: [preferences] Default sub-project not selected in extended project browser (dhx) - closed.
- 0012443: [bugtracker] allows to move a bug into a project with viewer access level (dhx) - closed.
- 0012927: [installation] Does not install with MySQL 5 (dhx) - closed.
- 0012960: [ldap] Email / Realname lookups against LDAP spew warning when account is not in LDAP (rombert) - closed.
- 0012998: [authentication] Reset Button with HTTP_AUTH authentication (dhx) - closed.
- 0013021: [printing] not able to disallow Issue History in printview (atrol) - closed.
- 0013062: [html] Make strong a valid html tag by default (rombert) - closed.
- 0013085: [tagging] Manage Tag menu should only work for users with global role (dhx) - closed.
- 0013123: [time tracking] Bug notes of type "reminder" display time tracking information (rombert) - closed.
- 0013124: [time tracking] Getting time tracking info yields application error (dregad) - closed.
- 0013130: [time tracking] When getting Time Tracking, scroll bug view page to the section (dregad) - closed.
- 0013131: [time tracking] Time tracking should print user/real name depending on $g_show_realname (dregad) - closed.
- 0013132: [time tracking] Print the time tracking information sorted by username (dregad) - closed.
- 0013133: [time tracking] Time tracking shows entries for users without actual time spent (dregad) - closed.
- 0013146: [time tracking] Time tracking reporting is only available when billing is enabled (dregad) - closed.
- 0013150: [time tracking] Getting time tracking when no time tracking notes exist generates warning (dregad) - closed.
- 0013163: [authentication] Remove limitation on password length with MD5 authentication (dregad) - closed.
- 0013168: [html] my_view_page.php: wide legend causes resized issue boxes to shift off-screen (dregad) - closed.
- 0013171: [administration] Resetting columns configuration in My Account asks for reauthentication (dregad) - closed.
- 0013174: [installation] Wrong error message when running admin/check.php (atrol) - closed.
- 0010323: [api soap] mc_issue_update() will set optional fields to default values rather than leave them with current values (rombert) - closed.
- 0012694: [api soap] mc_project_version_update - add parameter 'obsolete' (rombert) - closed.
- 0012794: [api soap] Java Exception when the Issue has an attached file (using mantis plugin in Hudson/Jenkins) (rombert) - closed.
- 0012795: [api soap] Handle the 'user_id' property of attachments (rombert) - closed.
- 0012887: [api soap] mc_issue_get_biggest_id do wrong (rombert) - closed.
- 0012928: [api soap] Expose note_type and note_attr bug note fields to the SOAP API (rombert) - closed.
- 0012932: [api soap] Error triggered when adding a task relationship (rombert) - closed.
- 0012946: [api soap] mc_user_pref_get_pref, user_pref_get_pref API call (rombert) - closed.
- 0012991: [api soap] mc_filter_get_issues returns incorrect results for page_number > page_count (rombert) - closed.
- 0013000: [api soap] Add soap feature : update a note of a specific issue (rombert) - closed.
- 0013103: [api soap] Error when connecting to API via Mylin (rombert) - closed.

[38 issues]

mantisbt - 1.2.5 (Released 2011-04-05) View Issues ]
======================================

MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release.

- 0012628: [api soap] Update last change date for both bugs when updating a relationship (rombert) - closed.
- 0011684: [custom fields] Incorrect error "A necessary field "MyField" was empty. Please recheck your inputs." when submitting new issue (vboctor) - closed.
- 0012570: [bugtracker] print_api and file_api produces invalid xhtml code (dhx) - closed.
- 0012735: [upgrade] Update upgrade script to handle retries in case of timeouts for large databases (vboctor) - closed.
- 0010156: [filters] Categories "[any] / General". (daryn) - closed.
- 0005859: [filters] "Sort by" can't handle more than one custom field in combination (daryn) - closed.
- 0012765: [api soap] Include the filter url when returning filters (rombert) - closed.
- 0008768: [api soap] webservice call which returns timezone information (vboctor) - closed.
- 0012772: [csv] Fatal error: Call to undefined function csv_format_sponsorship_total() (dhx) - closed.
- 0012418: [filters] SQL error when a field has a ? (daryn) - closed.
- 0012884: [installation] Checks for obsolete config fails to report error (dhx) - closed.
- 0012667: [bugtracker] Moving issues between projects doesn't update the category (vboctor) - closed.
- 0010850: [feature] Gravatar code wrong (jreese) - closed.
- 0012534: [ldap] When using LDAP, the "Reset Password" function should be disabled (dhx) - closed.
- 0012262: [api soap] Mylyn-Mantis 3.1.4 attach a context error (rombert) - closed.
- 0012879: [bugtracker] Gravatars don't appear in Firefox 4 (dhx) - closed.
- 0011909: [upgrade] Database query failed - problems with ticket revisions (dhx) - closed.
- 0011983: [csv] Excel export don't work on all station (dhx) - closed.
- 0012547: [attachments] Error when file upload fails is incorrect (dhx) - closed.
- 0012552: [authentication] Use of a period "." in $g_cookie_prefix results in login error (dhx) - closed.
- 0012553: [attachments] Mantis user can not delete their own attachments (dhx) - closed.
- 0012568: [bugtracker] Visibility on who is monitoring an issue is not consistently enforced (dhx) - closed.
- 0012622: [other] Changing reporter doesn't work in version 1.2.4 anymore (dhx) - closed.
- 0012630: [security] print_bugnote_inc.php XSS with reminders sent to users with malformed usernames (dhx) - closed.
- 0012613: [api soap] [patch]: Get list of subprojects ID for a specific project (rombert) - closed.
- 0012617: [bugtracker] Move / Delete operations are not available for resolved issues (vboctor) - closed.
- 0012635: [bugtracker] The "#bug_number" doens't work correctly in bug summaries (dhx) - closed.
- 0012638: [integration] function url_get doesn't support 'allow_url_fopen'='Off' (dhx) - closed.
- 0012646: [email] No email with LDAP (dhx) - closed.
- 0012669: [filters] Ordering of version fields in filter area is not ideal (vboctor) - closed.
- 0012739: [administration] Can not delete global category from edit page (manage_proj_cat_edit_page.php) (atrol) - closed.
- 0008558: [api soap] SOAP API needs ability to Monitor a Task (rombert) - closed.
- 0012517: [api soap] Users can view private bugs (rombert) - closed.
- 0012582: [api soap] SQL fail when uploading file via mantis connect API (rombert) - closed.
- 0012615: [api soap] mc_enum_api does not obey user language preferences (rombert) - closed.
- 0012747: [ldap] Better log message for LDAP auth errors (vboctor) - closed.
- 0011011: [custom fields] Can't add UTF8 custom fields to the Manage columns enumeration (dhx) - closed.
- 0012727: [administration] Updating username when old username = realname results in error 807 (dhx) - closed.
- 0012760: [administration] Manage User page filter is case sensitive for some database backends (dhx) - closed.
- 0012166: [ldap] LDAP logging confusing text (dhx) - closed.
- 0012675: [upgrade] Error while trying to upgrade from 1.2.0 --> 1.2.4 (PostgreSQL) (dhx) - closed.
- 0012910: [html] due_date is limited to 10 characters in Opera and Chrome (dhx) - closed.

[42 issues]

mantisbt - 1.2.4 (Released 2010-12-14) View Issues ]
======================================

MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release.

- 0010995: [graphs] Graphs Plugin: Unable to read/find font (dhx) - closed.
- 0012462: [documentation] Wrong instruction order for new installations (atrol) - closed.
- 0011563: [plug-ins] Fatal error importing issues (dhx) - closed.
- 0012601: [upgrade] Upgrading scripts sometimes fails with a server error in case of large databases (vboctor) - closed.
- 0012174: [administration] Manage Columns not saving (daryn) - closed.
- 0011502: [bugtracker] No Close button for Reporter if allow_reporter_close is enabled (dhx) - closed.
- 0011351: [administration] User Real Name and E-Mail values deleted (dhx) - closed.
- 0007328: [other] ini_get_number() interprets K and M suffixes incorrectly (dhx) - closed.
- 0009338: [csv] CSV export does not escape all characters (dhx) - closed.
- 0011299: [security] "IRC Chat" URL not correctly encoded (dhx) - closed.
- 0012286: [filters] When advanced filter "Project" is set to "All Projects", sub projects are excluded (dhx) - closed.
- 0012362: [tagging] When confirming Delete Tag goes to View Issues screen. (dhx) - closed.
- 0012354: [html] HTML validation error (dhx) - closed.
- 0003767: [custom fields] Enumeration Custum fields with html-special chars get unselected on bug-update (grangeway) - closed.
- 0009663: [roadmap] Wrong underline-charcount when Project-Name contains htmlspecialchars (dhx) - closed.
- 0012061: [other] Status percentage bar counts issues hidden to user (dhx) - closed.
- 0012344: [administration] In manage_user_page.php changing page resets sort criteria (atrol) - closed.
- 0012383: [html] Use of invalid color "brown" in CSS (atrol) - closed.
- 0012474: [security] bug_report XSS issue when report_stay=1 (dhx) - closed.
- 0009036: [localization] Translation fault / translation confusion (confirm_custom_field_unlinking) (siebrand) - closed.
- 0010887: [localization] button names don't describe what it does very well (siebrand) - closed.
- 0012363: [time tracking] billing report seems not to include enddate (dhx) - closed.
- 0012471: [graphs] Relationships graph doesn't cope well with custom bug id formats (dhx) - closed.
- 0012500: [localization] Missing localization in extended project browser (siebrand) - closed.
- 0012504: [administration] Error on email and realname fields in Edit User page accessed by username (dhx) - closed.
- 0012528: [documentation] Change to INSTALL doc file (atrol) - closed.
- 0012566: [documentation] Time Tracking: copy wiki note in administration_guide (giallu) - closed.
- 0012607: [security] LFI/FD and XSS in the 'upgrade_unattended.php' (vboctor) - closed.
- 0012360: [api soap] [PATCH] Get id of project with specified name via SOAP API (rombert) - closed.
- 0012540: [api soap] mc_issue_attachment_get does not use the path for the file (rombert) - closed.

[30 issues]

mantisbt - 1.2.3 (Released 2010-09-14) View Issues ]
======================================

MantisBT 1.2.3 is a security update for the stable 1.2.x branch, including another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications.

- 0012304: [filters] If plugins set a params value for plugin filters the values are dropped. (daryn) - closed.
- 0012217: [email] Email is not sent when assigning new issue (jreese) - closed.
- 0012246: [api soap] API call to mc_enum_get produces soap fault (rombert) - closed.
- 0011930: [administration] No display of unused and new users when using non english account settings (dhx) - closed.
- 0011364: [installation] on installl.php 1.2.0rc2 SYSTEM WARNING: htmlentities() expects parameter 1 to be string, array given (dhx) - closed.
- 0011852: [authentication] Forgotton password feature prevents admin password reset (dhx) - closed.
- 0012033: [installation] check.php tests views if they are utf8 like tables (dhx) - closed.
- 0012084: [bugtracker] Excel export does not work when Due Date is included in the Columns (dhx) - closed.
- 0012231: [security] XSS vulnerability when uninstalling maliciously named plugins (dhx) - closed.
- 0012234: [security] XSS issues when using custom field String values (dhx) - closed.
- 0012249: [html] g_error_send_page_header condition check always evaluates to true (dhx) - closed.
- 0011654: [csv] Excel export does not encode '&' character as entity (atrol) - closed.
- 0012312: [security] NuSOAP WSDL XSS (cross-site scripting vulnerability) in Mantis 1.2.2 (dhx) - closed.
- 0011919: [administration] Users copy from one project to another doesn't work (dhx) - closed.
- 0012230: [security] XSS vulnerability when deleting maliciously named categories (dhx) - closed.
- 0012232: [security] Multiple XSS issues with custom field enumeration values (dhx) - closed.
- 0012238: [security] XSS in print_all_bug_page_word.php when printing project and category names (dhx) - closed.
- 0012309: [security] XSS issues when viewing Summary page (dhx) - closed.
- 0011913: [api soap] [patch] Update project description, status, name of a specific project using SOAP API (rombert) - closed.

[19 issues]

mantisbt - 1.2.2 (Released 2010-07-29) View Issues ]
======================================

MantisBT 1.2.2 is a security update for the stable 1.2.x branch, including a range of translation updates, regression fixes, bug fixes, and multiple SOAP API-related bugs and regressions.

- 0011764: [db mssql] View Issues gives "ORDER BY id DESC" error (dhx) - closed.
- 0011917: [webpage] CSS not working on pages in /admin (jreese) - closed.
- 0011862: [administration] Access Level will always be set to "reporter" when editing user (dhx) - closed.
- 0010021: [tools] Run PHPUnit tests using Phing (rombert) - closed.
- 0011956: [bugtracker] Regression in 1.2.1 : no longer obeys Default Value for Workflow Transitions (jreese) - closed.
- 0011839: [time tracking] The "Get Time Tracking Information" button is gone when viewing issues (dhx) - closed.
- 0011840: [time tracking] Clicking "Get Time Tracking Information" button raises APPLICATION ERROR #200 (dhx) - closed.
- 0011590: [api soap] Couple of bugs in api/soap/mc_file_api.php - mc_file_add() (rombert) - closed.
- 0011594: [webpage] attachment_count column shift registers in View Issues (dhx) - closed.
- 0011857: [api soap] Update to NuSOAP 0.9.5 (rombert) - closed.
- 0011868: [api soap] returned compressed data corrupt (rombert) - closed.
- 0011873: [api soap] [patch] Add and delete category of a specific project using SOAP API (rombert) - closed.
- 0011907: [localization] wrong translation for $s_add_user_title in german localization (atrol) - closed.
- 0011933: [security] XSS via project_id_filter_target when selecting projects to filter by in advanced filter view (dhx) - closed.
- 0011934: [installation] Display all current SQL upgrade instructions on execution failure (rombert) - closed.
- 0011952: [security] Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks (dhx) - closed.
- 0011954: [localization] Typo in sticky field name (french) (atrol) - closed.
- 0011151: [api soap] Can't upload attachment to issue via soap interface (rombert) - closed.
- 0012092: [api soap] Wrong URL in E-Mail notifications by changes via webservice (jreese) - closed.
- 0012119: [localization] $s_new_account_greeting_admincreated (atrol) - closed.

[20 issues]

mantisbt - 1.2.1 (Released 2010-04-23) View Issues ]
======================================

First stable maintenance release for the 1.2.x series. Includes fixes to URL and path detection, upgrades from previous versions of MantisBT, and updated translations.

- 0011389: [plug-ins] [patch] set_project does not jump properly to a plugin page (dhx) - closed.
- 0011824: [security] Implement X-Frame-Options clickjacking protection (dhx) - closed.
- 0011166: [administration] new configuration option of 'complex' type is created with string type (dhx) - closed.
- 0011825: [security] Support X-Content-Security-Policy (CSP) (dhx) - closed.
- 0011560: [installation] adodb warning - check.php (dhx) - closed.
- 0010877: [printing] Word Export causes Error Message (dhx) - closed.
- 0004170: [feature] Possibility to disable Profile and all of its fields (grangeway) - closed.
- 0011561: [custom fields] Filtering for custom field types multilist and checkbox does not work (dhx) - closed.
- 0011362: [attachments] Picture dowload fails wit exhausted memory error with firefox 3.5.7 but not with IE8 (dhx) - closed.
- 0010482: [custom fields] the custom fields don't remember chosen state (dhx) - closed.
- 0011803: [code cleanup] "<?" causes parse error in PHP 5.3.2 (jreese) - closed.
- 0011812: [administration] Manage configuration page displays wrong error message (jreese) - closed.
- 0011813: [filters] Project '0' not found when viewing bugs for all projects - no bugs shown (jreese) - closed.
- 0011294: [administration] System notice in checking (dhx) - closed.
- 0011427: [api soap] Undefined index: id (rombert) - closed.
- 0011492: [administration] What is BASE_PATH in check.php (dhx) - closed.
- 0011553: [bugtracker] Status legend doesn't show final workflow states (dhx) - closed.
- 0011569: [administration] Error when visiting the "manage users" page (dhx) - closed.
- 0011376: [localization] New Simplified Chinese translation (siebrand) - closed.
- 0011556: [upgrade] Upgrade from 1.1.7 to 1.2.0 empties categories auto.assignment (jreese) - closed.
- 0011565: [bugtracker] $g_enable_profiles not respected on bug report page (dhx) - closed.
- 0011571: [administration] Cannot edit some versions (dhx) - closed.
- 0011610: [custom fields] Regular expressions to validate custom list field (dhx) - closed.
- 0011624: [bugtracker] Updating version name in parent project does not update references in child projects (jreese) - closed.
- 0011628: [custom fields] Error 0001303 / Custom Field (Checkbox) evaluated as mandantory even when it is not (dhx) - closed.
- 0011688: [localization] $s_bug_view_title missing in localization to Czech language (siebrand) - closed.
- 0011065: [documentation] Links in 'The MantisBT Manual (v1.2.x)' are broken (jreese) - closed.
- 0011298: [localization] encoding bug line 841 of strings_french.txt (siebrand) - closed.
- 0011415: [security] checking for "is_Readable" does not correclty validate that the admin folder is inaccessible (dhx) - closed.
- 0011530: [security] Support multiple access levels above manage_user_threshold (dhx) - closed.
- 0011727: [bugtracker] "APPLICATION ERROR #1100 when clicking on a link which points to a already deleted note (dhx) - closed.
- 0011729: [bugtracker] Preselect next highest status in bug_change_status (dhx) - closed.
- 0011773: [plug-ins] Plugin init process can leave some plugins behind (jreese) - closed.
- 0011534: [webpage] Incorrect url/path detection (jreese) - closed.
- 0011641: [bugtracker] Updating version name in project should update issues history (jreese) - closed.
- 0011817: [html] [Patch]New event for adding raw menulinks to issues (jreese) - closed.
- 0011819: [api soap] Mylyn Mantis Task Update Failure (rombert) - closed.
- 0011830: [plug-ins] No EVENT_UPDATE_BUG call on bug data update (jreese) - closed.
- 0011797: [administration] Errors in mantis/admin/check.php against adodb and zend optimizer (dhx) - closed.
- 0011829: [plug-ins] Missing EVENT_MENU_MANAGE_CONFIG call (jreese) - closed.

[40 issues]

mantisbt - 1.2.0 (Released 2010-02-22) View Issues ]
======================================

This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible.


- 0011326: [attachments] Invalid form security token error displayed instead of file upload size too large error (dhx) - closed.
- 0010969: [api soap] The issue closed can not be found by mc_project_get_issues API? (rombert) - closed.
- 0004843: [filters] feature request: improving fulltext search (jreese) - closed.
- 0006816: [localization] Rename "save login" string to reduce confusion about what it does (dhx) - closed.
- 0003730: [bugtracker] Change status upon feedback (vboctor) - closed.
- 0009071: [customization] Action buttons not visible (atrol) - closed.
- 0009211: [administration] Manage User Page should provide ability to find a user by user name (atrol) - closed.
- 0011481: [feature] Confusing combo on View Issue page (dhx) - closed.
- 0003865: [feature] Ability to change fields subset and fields order in view_all_bug_page using config-files only (atrol) - closed.
- 0010644: [localization] Date filters with international format (atrol) - closed.
- 0006150: [bugtracker] Should Category inheritance be a preference? (atrol) - closed.
- 0008942: [time tracking] due date feature (atrol) - closed.
- 0010491: [api soap] mc_issue_add incorrect access level check (vboctor) - closed.
- 0003391: [bugtracker] Set assign_to when resolving bug (vboctor) - closed.
- 0004280: [customization] Add a custom function hook for bugnotes (jreese) - closed.
- 0007259: [customization] Include version timestamp on change log (atrol) - closed.
- 0007695: [customization] Version default for project (atrol) - closed.
- 0005389: [feature] Add unit description to refresh and redirect delay in user preferences. (atrol) - closed.
- 0006415: [feature] Enh Request: Add Ability to customize View Items display columns (atrol) - closed.
- 0007157: [feature] Default to allow in-line images (atrol) - closed.
- 0008200: [feature] Hope a feature to support attach and display a picture in a issue (giallu) - closed.
- 0003468: [bugtracker] Steps to Reproduce on Simple Report OR Ability to customize report bug page (atrol) - closed.
- 0006082: [administration] Deleting old project categories (atrol) - closed.
- 0008539: [rss] Special (nominally HTML) characters are not parsed correctly in RSS feed output (dhx) - closed.
- 0003994: [bugtracker] Custom Fields on "View Bugs" page and Exported to Excel (vboctor) - closed.
- 0004686: [change log] Add a HTML anchor in Change Log page per Version (vboctor) - closed.
- 0006156: [administration] Show reporter in the view issues pane (atrol) - closed.
- 0011372: [attachments] Can't open .msg-files (atrol) - closed.
- 0011394: [authentication] Lost password not working, no message output, no mail (dhx) - closed.
- 0011105: [api soap] mc_issue_get redirects to login page on login failure (rombert) - closed.
- 0010188: [email] E-mail subject partially wrong (Bithunter) - closed.
- 0006792: [bugtracker] Option to update the severity of selected bugs (vboctor) - closed.
- 0011053: [other] Using real names and monitoring (vboctor) - closed.
- 0011059: [sql] APPLICATION ERROR 0000401 by editing a Version (jreese) - closed.
- 0011060: [documentation] Document the testing process (vboctor) - closed.
- 0011061: [api soap] SOAP issue tests fail (vboctor) - closed.
- 0011066: [bugtracker] Need a parameter added to a EVENT (jreese) - closed.
- 0011068: [plug-ins] Wrong parameter being passed to print_column_plugin() from custom_function_default_print_column_value function (vboctor) - closed.
- 0011078: [ldap] LDAP realname is not always picked up -- pull data from LDAP to local database on login (vboctor) - closed.
- 0005920: [bugtracker] Issue History updated for each custom field when submitting a new bug (jreese) - closed.
- 0009775: [upgrade] Unable to download attachments with spaces in the filename (dhx) - closed.
- 0010947: [rss] Entries in RSS feed show theusername@example.com (vboctor) - closed.
- 0011098: [administration] Zend check is not correct IMHO (vboctor) - closed.
- 0011116: [plug-ins] Creating permalinks broken for plugins defining filters of type FILTER_TYPE_MULTI* (jreese) - closed.
- 0011117: [attachments] Unable to get files attached to ALL_PROJECTS (vboctor) - closed.
- 0011155: [other] user is directed to my view after uploading a file : being redirected back to viewed bug is expected (dhx) - closed.
- 0011046: [email] notification emails send to an unassigned user (vboctor) - closed.
- 0011223: [code cleanup] RSS image has wrong rights (dhx) - closed.
- 0011253: [bugtracker] Cannot enable projection on view/update page without enabling product_build (jreese) - closed.
- 0010023: [bugtracker] duplicate_id maxlength is hardcoded in bug_change_status_page.php (vboctor) - closed.
- 0011196: [localization] Mantis Graph plugin's Japanese localization is incomplete (siebrand) - closed.
- 0011289: [localization] wrong german translation of "Minimum Access Level to cahnge to this Status" (siebrand) - closed.
- 0011292: [signup] Not able to create new account in MantisBT own tracker (jreese) - closed.
- 0011332: [tools] Allow tests to run on PHP 5.3 (rombert) - closed.
- 0011413: [localization] The string"version" in the view.php's "Issue History" is not in the language file (dhx) - closed.
- 0010670: [custom fields] Custom fields required do not work (vboctor) - closed.
- 0010780: [email] language of emails could be wrong in specific situations (grangeway) - closed.
- 0011266: [api soap] mc_issue_update() does not transport all field date (rombert) - closed.
- 0011293: [customization] View report page is ignoring project specific config settings (jreese) - closed.
- 0011455: [api soap] Wrong comment of API SOAP function mc_project_get_attachments (rombert) - closed.
- 0010878: [api soap] bugnotes should be updated when mc_issue_update (vboctor) - closed.
- 0010979: [ldap] New user creation when using LDAP authentication enters plain text password user entered into the database. (vboctor) - closed.
- 0010974: [bugtracker] ereg() is deprecated in PHP 5.3.0, use preg_match() instead (jreese) - closed.
- 0005022: [other] user-names must not contain dots [.] (vboctor) - closed.
- 0007917: [administration] Extra update/submit buttons on bug pages. (dhx) - closed.
- 0010476: [custom fields] Logic incorrect for minimum length on custom string field (dhx) - closed.
- 0010592: [api soap] mc_enum functions doesn't take customization into account (rombert) - closed.
- 0010615: [api soap] API Failure (rombert) - closed.
- 0010754: [bugtracker] One-digit redirect delay can be too short (dhx) - closed.
- 0010838: [administration] APPLICATION WARNING #300: String 'configuration_corrupted' not found. (dhx) - closed.
- 0010841: [administration] Target Version not cleared when Version is deleted (vboctor) - closed.
- 0010982: [api soap] NuSOAP not playing nice in combination with PHP 5.3.0 (rombert) - closed.
- 0011021: [bugtracker] Bug history does not display new value (dhx) - closed.
- 0011086: [bugtracker] project_id column shows a number instead of the project name (dhx) - closed.
- 0011015: [api soap] mc_issue_update erases 'Due date' field (rombert) - closed.
- 0011081: [api soap] Username not printed correctly when failing to enter a bug via SOAP API (rombert) - closed.
- 0011100: [api soap] SOAP API login fails with LDAP (rombert) - closed.
- 0011102: [news] Disable News feature by default - should move a plugin in the future (vboctor) - closed.
- 0011125: [authentication] Auto-focus on password field when re-authenticating address (vboctor) - closed.
- 0008612: [api soap] MantisConnect does not expose Time Tracking on Notes or Issues (rombert) - closed.
- 0010535: [authentication] I have error to login to MantisBT (dhx) - closed.
- 0011090: [plug-ins] Used in plugin api (jreese) - closed.
- 0011103: [bugtracker] Disable Project Documentation feature by default - should move to a plugin in the future (vboctor) - closed.
- 0011133: [api soap] Mantis Connector: PHP Fatal error: Cannot use object of type BugData as array (rombert) - closed.
- 0011137: [api soap] Error when trying to retrieve bug via SOAP that is not in a category (rombert) - closed.
- 0011138: [api soap] Error when retrieving bug via SOAP (rombert) - closed.
- 0011141: [other] message "Access Denied." appears on bug_reminder_page.php, not clear to what it is referring (vboctor) - closed.
- 0011099: [email] Signup email notifications are not encoded correctly (vboctor) - closed.
- 0011156: [api soap] Restore the advanced flag in CustomFieldDefinitionData (rombert) - closed.
- 0011234: [security] user_ensure_realname_valid() is not checked on account_page.php (dhx) - closed.
 - 0011235: [security] XSS on manage_tags_page.php with user Real Name field (dhx) - closed.
 - 0011236: [security] XSS on view_all_bug_page.php (specifically the filters form) with user Real Name field (dhx) - closed.
 - 0011237: [security] XSS on tag_view_page.php with user Real Name field (dhx) - closed.
 - 0011238: [security] XSS on tag_update_page.php with user Real Name field (dhx) - closed.
 - 0011239: [security] XSS on view_user_page.php with user Real Name field (dhx) - closed.
 - 0011240: [security] XSS on bug_revision_view_page.php with user Real Name field (dhx) - closed.
 - 0011241: [security] XSS on manage_proj_page.php with user Real Name field (dhx) - closed.
 - 0011242: [security] XSS on manage_proj_edit_page.php with user Real Name field (dhx) - closed.
 - 0011232: [security] XSS on summary_page.php with user Real Name field (dhx) - closed.
 - 0011233: [security] XSS on adm_config_report.php with user Real Name field (dhx) - closed.
- 0011243: [security] Default to sanitising column values on view_all_bug_page.php to prevent XSS attacks (dhx) - closed.
- 0011244: [security] XSS on change log and roadmap pages due to unsanitised project names (dhx) - closed.
- 0011245: [security] Sanitise project name in print_column_category_id() function to prevent XSS flaw (dhx) - closed.
- 0011246: [security] XSS bug in category dropdown selector (dhx) - closed.
- 0011247: [security] XSS in various management pages due to unsanitised project names (dhx) - closed.
- 0011031: [authentication] Can not view changelog page without login as user (jreese) - closed.
- 0011207: [scripting] javascript/min/projax/sound.js is missing in default installation (dhx) - closed.
- 0011215: [api soap] tns:AttachmentData download_url does not encode ampersands (rombert) - closed.
- 0011260: [security] Attribute/XSS injection in permalink_page.php (dhx) - closed.
- 0011261: [security] Don't rely on MantisCoreFormatting to provide string sanitisation for HTML output that can occur prior to plugins loading (dhx) - closed.
- 0011262: [security] XSS issues in various print_X_option_list functions (OS, platform, etc) (dhx) - closed.
- 0011045: [attachments] Display of attached files (vboctor) - closed.
- 0011075: [attachments] File downloading - IE vs non-IE filename bugs (dhx) - closed.
- 0011088: [email] Update emails show @0@ instead of the access level of each bugnote author (rombert) - closed.
- 0011101: [attachments] Headers are sent too late in file_download.php (after content has been written) (dhx) - closed.
- 0011358: [localization] The string"category_id" in the filter is not in the language file (dhx) - closed.
- 0011361: [localization] " bytes" in the proj_doc_page.php is not localised (dhx) - closed.
- 0004654: [administration] In manage_user_page.php changing prefix letter resets sort criteria (dhx) - closed.
- 0010818: [bugtracker] SYSTEM WARNING: in_array() [function.in-array]: Wrong datatype for second argument (dhx) - closed.
- 0011041: [bugtracker] set_status_threshold doesn't work on a per-project basis (dhx) - closed.
- 0011352: [customization] Custom icon path ignored (dhx) - closed.
- 0011373: [html] UI error in view_all_bug_page.php (dhx) - closed.
- 0011375: [relationships] Users that are monitoring a bug should be transferred if the bug is closed as a duplicate (dhx) - closed.
- 0011382: [code cleanup] view_all_set.php has typo for require_api (dhx) - closed.
- 0011397: [security] XSS with project names in relationship table (dhx) - closed.
- 0011400: [security] Increase default $g_view_configuration_threshold to ADMINISTRATOR (dhx) - closed.
- 0011402: [sub-projects] SYSTEM WARNING: in_array() [function.in-array]: Wrong datatype for second argument (dhx) - closed.
- 0011403: [bugtracker] Bugnote view state change history item doesn't format bugnote IDs (dhx) - closed.
- 0011417: [plug-ins] EVENT_MENU_* does not allow to return null (dhx) - closed.
- 0011420: [localization] The string"Loading..." in the bug_update_page.php's "Reporter" is not in the language file (dhx) - closed.
- 0011426: [localization] The string"Start" and "R" in the view.php's "Time tracking" area is not in the language file (dhx) - closed.
- 0011429: [localization] The string "attachment missing" in the view.php's "Attached Files" area is not in the language file (dhx) - closed.
- 0010779: [bugtracker] due date is filled in by default on cloning while in the cloned report it was empty (dhx) - closed.
- 0011026: [bugtracker] Notes text is centered vertically rather than placed at top (dhx) - closed.
- 0011272: [email] Account Registration Message (dhx) - closed.
- 0011444: [custom fields] 57% of queries are redundant when including two custom fields on View Issues page (vboctor) - closed.
- 0011449: [bugtracker] application error 0000401 when resolving as a duplicate (dhx) - closed.
- 0011451: [other] [patch]: Honour enable_profiles on account page (jreese) - closed.
- 0011482: [html] [patch] print_page_links/print_page_number: allow ? in $p_page parameter (dhx) - closed.
- 0011484: [security] XSS on view_filters_page.php when displaying dropdown list of custom string field values (dhx) - closed.
- 0011485: [bugtracker] string_shorten function doesn't trim long strings which don't contain word boundaries (dhx) - closed.
- 0011518: [signup] Application error #1904 on invalid signup captcha has no error description (dhx) - closed.
- 0011263: [filters] return_dynamic_filters.php produces non-standard error messages (dhx) - closed.
- 0011487: [sql] Unnecessary Index in Database Model (dhx) - closed.
- 0011498: [javascript] jscalendar references non existing image (dhx) - closed.
- 0011517: [code cleanup] Unnecessary code line in bug_api.php (dhx) - closed.
- 0011520: [html] Duplicate footers printed at bottom of bug_relationship_graph.php (dhx) - closed.
- 0011527: [tagging] tag_attach_threshold not checked when adding many tags via bug_actiongroup (dhx) - closed.
- 0011528: [code cleanup] Don't call config_flush_cache() in bug_actiongroup_ext.php (dhx) - closed.

[149 issues]

mantisbt - 1.2.0rc2 (Released 2009-10-06) View Issues ]
=========================================

Second release candidate for the 1.2 branch. Includes some major changes and improvements to Mantis, as well as many bug fixes.

- 0010889: [security] Anonymous users can modify account preferences and columns (dhx) - closed.
- 0010627: [security] Ensure all forms use CSRF protection (dhx) - closed.
- 0010691: [customization] Missing form security token for delete button on manage_proj_ver_edit_page.php (dhx) - closed.
- 0010712: [security] Secure cookie flag is not used for all cookies when browsing via HTTPS (dhx) - closed.
- 0010694: [graphs] graph by category broken (thraxisp) - closed.
- 0011267: [api soap] mc_project_get_issues() does not transport field 'target_version' (rombert) - closed.
- 0011182: [rss] RSS broken in 1.2.0rc1 (vboctor) - closed.
- 0010930: [signup] User verification results in redirection loop (jreese) - closed.
- 0007620: [ldap] ldap_search: Operation Error (vboctor) - closed.
- 0009084: [preferences] Error when saving Column Preferences (vboctor) - closed.
- 0010655: [bugtracker] Private notes cause the view page to stop rendering (vboctor) - closed.
- 0010973: [bugtracker] split() is deprecated in PHP 5.3.0, use preg_split() instead (dhx) - closed.
- 0010975: [bugtracker] eregi_replace() is deprecated in PHP 5.3.0, use preg_replace() with the 'i' modifier instead (dhx) - closed.
- 0005012: [bugtracker] Comments relating to $g_show_sticky_issues (vboctor) - closed.
- 0010631: [graphs] bug_graph_page.php missing from Graph plugin (grangeway) - closed.
- 0010634: [bugtracker] Fixed In Version in View Issues reads @fixed_in_version@ After 1.2.0rc1 Upgrade (grangeway) - closed.
- 0007432: [ldap] LDAP integration with Active Directory (vboctor) - closed.
- 0008025: [ldap] Email field verification when using ldap email (vboctor) - closed.
- 0008861: [ldap] Hide password boxes when using LDAP (vboctor) - closed.
- 0010135: [bugtracker] Downloading large attachments results in Internal Server Error - 500 (vboctor) - closed.
- 0010681: [printing] Print issue page is not consistent with View Issue page relating to version handling (vboctor) - closed.
- 0010686: [ldap] Provide a way to simulate LDAP connection (vboctor) - closed.
- 0010689: [ldap] Support pulling realname from LDAP (vboctor) - closed.
- 0010690: [ldap] Reporter username link in View Issue page is incorrect in case of LDAP (vboctor) - closed.
- 0010692: [graphs] Graphs not works (grangeway) - closed.
- 0010698: [bugtracker] Refactor simple / advanced update pages for consistency (vboctor) - closed.
- 0010728: [bugtracker] Refactor reporting page to allow controlling which fields should be visible (vboctor) - closed.
- 0010734: [bugtracker] Refactor print page and make it consistent with view / update (vboctor) - closed.
- 0010741: [bugtracker] Additional Information field doesn't seem to populate in latest git master-1.2.x (jreese) - closed.
- 0005595: [ldap] LDAP authentication requires accounts to be manually created first (vboctor) - closed.
- 0010138: [api soap] i can't add any Issue via .NET SOAP API (vboctor) - closed.
- 0010760: [filters] Filtering on Priority doesn't work (giallu) - closed.
- 0010845: [api soap] mc_issue_update erases Additional info and steps to reproduce (vboctor) - closed.
- 0010623: [customization] Coding typo in documented config parameter $g_reminder_recipients_monitor_bug (dhx) - closed.
- 0010624: [security] Anyone can reset the account preferences of any other user (dhx) - closed.
- 0010625: [authentication] The anonymous user account should always be a protected account (dhx) - closed.
- 0010626: [documentation] Improve documentation relating to anonymous user accounts (dhx) - closed.
- 0010632: [customization] Cannot update global default columns - project 0 not found (dhx) - closed.
- 0010638: [localization] Units of file size can not translate (dhx) - closed.
- 0010647: [bugtracker] bug_update access denied error when user hasn't got permission to update roadmap (dhx) - closed.
- 0005175: [ldap] LDAP e-mail and My Account (vboctor) - closed.
- 0005753: [bugtracker] CGI PHP (with FCGI) with EMPTY PHP_SELF (dhx) - closed.
- 0010494: [html] National characters in filename of attaches (dhx) - closed.
- 0010646: [bugtracker] Simple view shows description, additional info, steps to reproduce as single lines of text only (dhx) - closed.
- 0010665: [html] css/calendar-blue.css not included (thraxisp) - closed.
- 0010685: [bugtracker] Undefined variable: t_bug_id on bug creation (vboctor) - closed.
- 0010688: [signup] Signup doesn't work if anonymous login is not allowed (vboctor) - closed.
- 0010697: [customization] Provide the ability to control visibility of 'Target Version' and 'Fixed in Version' (vboctor) - closed.
- 0010709: [security] Use HttpOnly cookie flag to protect cookies from client-side Javascript manipulation/theft (dhx) - closed.
- 0010710: [security] Improve form token lookup performance beyond O(n) (jreese) - closed.
- 0010711: [security] Don't seed mt_rand - PHP will do this for us (jreese) - closed.
- 0010717: [bugtracker] Add user to monitor list button appears even when user doesn't have access to add others to the monitor list (dhx) - closed.
- 0003917: [feature] ability to add/remove other persons to/from monitor list in a bug (dhx) - closed.
- 0010393: [feature] SQL error with "hide inactive filter" feature on manage_user_page.php (dhx) - closed.
- 0010650: [email] Mantis ignore e-mail notification setting for "e-mail on new" in account preferences (dhx) - closed.
- 0010687: [administration] Administrators shouldn't be allowed to delete their own account (dhx) - closed.
- 0010700: [attachments] APPLICATION ERROR #15 (grangeway) - closed.
- 0010746: [bugtracker] Viewing Issues (start - end/total) does not show correct values (dhx) - closed.
- 0010758: [graphs] Graph Plugin pages do not use "width" (dhx) - closed.
- 0010761: [graphs] jpgraph code must be copied into mantis tree (thraxisp) - closed.
- 0010814: [bugtracker] Reproducibility column in view issues causes an undefined variable error (dhx) - closed.
- 0010815: [preferences] columns_api exposes some useless columns to the user (dhx) - closed.
- 0010696: [code cleanup] Refactor simple / advanced / change status view for consistency (vboctor) - closed.
- 0010767: [email] email addresses containing upper case characters are considered invalid (jreese) - closed.
- 0010816: [bugtracker] Projection column shows integer value instead of string (dhx) - closed.
- 0010817: [bugtracker] View status column shows integer value instead of string (dhx) - closed.
- 0010829: [custom fields] Remove "Display only on Advanced Page" option for custom fields (dhx) - closed.
- 0010844: [bugtracker] When viewing bugnote revisions, the heading is always "View Revisions: Note 0" (dhx) - closed.
- 0010859: [bugtracker] Add hyperlinks for bugnote IDs (dhx) - closed.
- 0010879: [plug-ins] Cannot uninstall plugins: attempted use of undefined index within g_plugin_cache_protected (jreese) - closed.
- 0010886: [tools] Use php_sapi_name to determine if script is running in CLI environment (dhx) - closed.
- 0010890: [bugtracker] Remove all references to advanced view, report and update pages (dhx) - closed.
- 0010900: [other] Using a Permalink without beeing loged in -> Error #200 (dhx) - closed.
- 0010903: [tagging] hide_status_id is hardcoded for links from tag_view_page.php (dhx) - closed.
- 0010905: [plug-ins] BUGNOTE_ADD event not sent when bugnote is added from edit report page (dhx) - closed.
- 0010906: [plug-ins] Add new event to allow plugins to preprocess bugnote content (dhx) - closed.
- 0010918: [bugtracker] Due date feature: undefined reference to $t_null_date on bug_update_advanced_page.php (dhx) - closed.
- 0010922: [bugtracker] Prevent jscalendar from being imported more than once (dhx) - closed.
- 0010940: [bugtracker] Clicking 'Reopen' button while viewing an issue returns an 'Application Error #200' (dhx) - closed.
- 0010956: [bugtracker] string_nl2br() wraps in the middle of words for preformatted text (dhx) - closed.
- 0010959: [bugtracker] Renaming a tag fails to update associated reports (dhx) - closed.
- 0010703: [attachments] attachment_count column shows @attachment_count@ for each row (dhx) - closed.
- 0010748: [time tracking] due_date field does not display properly in View Issues and Print Issues (dhx) - closed.
- 0010775: [api soap] [regression] Unable to update issue using SOAP API (jreese) - closed.
- 0010776: [api soap] Retrieving an attachment with the SOAP API fails due to SYSTEM NOTICE (vboctor) - closed.
- 0010863: [html] vertical-align is not inheritable from tr elements (dhx) - closed.
- 0010915: [printing] Description field data not shown *on any table* (dhx) - closed.
- 0010929: [localization] Use localizeable function strftime() instead of date() (dhx) - closed.
- 0010955: [api soap] Data loss after updating issues using mc_issue_update() (jreese) - closed.
- 0010963: [db mysql] slow query to table called "mantis_project_hierarchy_table" (jreese) - closed.
- 0010967: [code cleanup] Remove ini_set()'s as this function is often blocked by hoster (dhx) - closed.
- 0010971: [bugtracker] Email about new bug sent before plugins are notified (dhx) - closed.
- 0010977: [bugtracker] Use of invalid viewing_bug_advanced_details_title string within print_all_bug_page_word.php (dhx) - closed.
- 0010978: [filters] Advanced filters with multiselects break permalink generation (jreese) - closed.
- 0010998: [plug-ins] Add missing EVENT_BUGNOTE_ADD_FORM event to extra pages (dhx) - closed.
- 0011000: [bugtracker] Add EVENTS to Tag attach/detach (dhx) - closed.
- 0011006: [email] When changing an email address and using $g_limit_email_domain get App Error # 1200 - Invalid Email Address (dhx) - closed.

[97 issues]

mantisbt - 1.1.9 (Released 2009-07-06) View Issues ]
======================================

Maintenance release.

- 0012370: [security] Multiple XSS issues with custom field enumeration values (giallu) - closed.
- 0012432: [security] XSS issues when viewing Summary page (giallu) - closed.
- 0011229: [security] XSS on /view_all_bug_page.php?tag_string=<XSS> (dhx) - closed.
- 0010770: [localization] Bulgarian localization files (both windows_1251 and utf-8) (siebrand) - closed.
- 0010664: [localization] Czech localization for Mantis stable version 1.1.8 (siebrand) - closed.
- 0010714: [bugtracker] Got PHP notice due to session already started (jreese) - closed.

[6 issues]

mantisbt - 1.2.0rc1 (Released 2009-06-23) View Issues ]
=========================================

This release marks the first "stable" release in the 1.2.x series of MantisBT.

- 0010446: [db postgresql] PgSQL error on "WHERE 1" in manage_tags_page.php (jreese) - closed.
- 0009086: [localization] email_queue_add fails with long UTF-8 relationship text (grangeway) - closed.
- 0010136: [email] wrong email charset (grangeway) - closed.
- 0008571: [db mysql] Using db_param() inside db_helper_like() causes SQL error (grangeway) - closed.
- 0007484: [localization] [he] Language file for Hebrew UTF-8 (siebrand) - closed.
- 0010263: [bugtracker] Implement g_bug_closed_status_threshold option to allow custom closed status (jreese) - closed.
- 0009827: [security] Note link exposes other users, authors of private notes (grangeway) - closed.
- 0010082: [tagging] Deleting a tag does after filtering by that tag results in error 2200 (jreese) - closed.
- 0009167: [graphs] GD Should check for antialiasing in JPGraph (grangeway) - closed.
- 0010234: [bugtracker] List of profiles not sorted alphabetically (grangeway) - closed.
- 0009744: [security] Users behind proxy will get 'ERROR_SESSION_NOT_VALID' (jreese) - closed.
- 0010303: [localization] Create and use string_api wrappers for multibyte string functions (jreese) - closed.
 - 0007400: [localization] [all lang] When using UTF8 for encoding all reports some fields' contents are incorrectly truncated. (siebrand) - closed.
 - 0008572: [localization] multibyte str pad problem (jreese) - closed.
- 0009235: [bugtracker] history should not be written for custom fields when a new issue is created (vboctor) - closed.
- 0006145: [graphs] Undefined constant FF_VERA (grangeway) - closed.
- 0007344: [documentation] config_defaults_inc.php: comment about inclusion of jpgraph actually wrong (grangeway) - closed.
- 0007790: [bugtracker] Links protected by brackets are not processed properly (jreese) - closed.
- 0009997: [installation] Add check for Zend Optimizer version (grangeway) - closed.
- 0010056: [upgrade] Category national character (jreese) - closed.
- 0007574: [graphs] Modified graph_api.php to modify summary_graph_cumulative_bydate axis allocation (grangeway) - closed.
- 0008909: [graphs] jpgraph extension does not respect $g_show_realname setting (grangeway) - closed.
- 0010103: [plug-ins] EVENT_MENU_ACCOUNT not work? (jreese) - closed.
- 0010134: [filters] Permalink will be shown even with $g_create_permalink_threshold = NOBODY; (grangeway) - closed.
- 0010150: [other] Account for Office 2007 file extensions to show non generic icons for uploaded files (thraxisp) - closed.
- 0010220: [other] $p_lang = portugese (jreese) - closed.
- 0010026: [tagging] Need tag management interface (jreese) - closed.
- 0003436: [bugtracker] cannot configure threshold for documentation edit access - closed.
- 0003484: [email] check_mx_record fails on windows platforms (grangeway) - closed.
- 0004723: [filters] Add new capability to "My View".... "Issues I've added Notes To" (daryn) - closed.
- 0005196: [scripting] core/print_api.php print_successful_redirect function calls html_api functions in wrong order (grangeway) - closed.
- 0005850: [localization] [CJK] Section titles are garbled under Japanese. (siebrand) - closed.
- 0006833: [bugtracker] Incorrect handling of some UTF-8 strings (grangeway) - closed.
- 0007064: [localization] [zh_TW] APPLICATION ERROR 0000401 Database query failed. Error received from database was #1406: (siebrand) - closed.
- 0008074: [localization] utf8 output problem with mysql-5.0.41-win32 (vboctor) - closed.
- 0008411: [localization] Localize "All Projects" in sub-project dropdown menu (siebrand) - closed.
- 0008444: [installation] APPLICATION ERROR 0000401 (grangeway) - closed.
- 0008763: [localization] Russian characters not shown correctly (siebrand) - closed.
- 0008814: [printing] problem posting FTP access string (jreese) - closed.
- 0008925: [email] wrong wordwrap in email for bugnote body(php+utf8 bug?) (grangeway) - closed.
- 0008972: [localization] Excel Export via XML utf-8 problem (siebrand) - closed.
- 0009077: [administration] [PATCH] Mantis does not handle forwarded protocol correclty when behind a proxy (jreese) - closed.
- 0009080: [ldap] Report LDAP queries for Performance Debugging (grangeway) - closed.
- 0009081: [ldap] Implement caching in ldap_api.php (grangeway) - closed.
- 0009108: [localization] strtoupper works incorrectly with non-ASCII utf-8 characters (grangeway) - closed.
- 0009157: [other] 'Change status to' combo shows @@ when the status list is empty. (grangeway) - closed.
- 0009269: [installation] On installation mantis create database with default collation settings. (grangeway) - closed.
- 0009422: [performance] Custom field ids (or info) should be cached (grangeway) - closed.
- 0009472: [api soap] Issues updating duplicates notes (vboctor) - closed.
- 0009856: [feature] Implement method for tracking changes to Description, Steps to Reproduce, and Additional Info (jreese) - closed.
- 0009917: [scripting] Issue with session with scheduled script (jreese) - closed.
- 0010170: [performance] MantisEnum class is inefficient when dealing with more than a few tuples (grangeway) - closed.
- 0010228: [other] No way to avoid or escape the rendering plugin for part of a text (jreese) - closed.
- 0010250: [filters] sorting doesn't work in the View Issues page (grangeway) - closed.
- 0010294: [bugtracker] Bugnote add reads bug_readonly_status_threshold from current project not the bug's one (grangeway) - closed.
- 0010306: [localization] "E-mail on note Added" => "E-mail on Note Added" (grangeway) - closed.
- 0010329: [upgrade] Receive duplicate key on upgrade from 1.1.6 to 1.2.0a3 if existing categories exist with a leading or tailing space (grangeway) - closed.
- 0010505: [authentication] On Login failure, keep user name populated and place the focus in the password field (vboctor) - closed.
- 0010506: [news] Provide the ability to disable the News feature (vboctor) - closed.
- 0010544: [email] Email bug note ordering. (jreese) - closed.
- 0010558: [change log] Wrong sorting on changelog/roadmap (jreese) - closed.
- 0010559: [customization] Missing "session_delete" function in "session_api.php" (jreese) - closed.
- 0010562: [printing] Printing Bug does not work with configuration $g_show_view= SIMPLE_ONLY; (vboctor) - closed.
- 0010568: [bugtracker] "Reproducibility" column is shown as numbers in issue list (vboctor) - closed.
- 0004084: [localization] [all lang] Use UTF-8 codepage (siebrand) - closed.
 - 0007472: [localization] [th] Thai chars are broken on Excel export; column header doesn't show (siebrand) - closed.
- 0004772: [administration] Changing username doesn't advice user (dhx) - closed.
- 0004811: [localization] The end of summary string in UTF-8 enconding gets cut off sometimes (siebrand) - closed.
- 0007488: [localization] [all lang] Creating user from an administrator account sends e-mail in admin's language instead of system-default language (siebrand) - closed.
- 0007496: [localization] Cannot sort on custom field containing non-ASCII characters - closed.
- 0009102: [api soap] webservice api call causes SYSTEM NOTICEs (vboctor) - closed.
- 0009127: [localization] Application error 18 with russian language (siebrand) - closed.
- 0009132: [api soap] mc_issue_add does not set values for all submitted fields (vboctor) - closed.
- 0009212: [localization] Error Message when missing to specify needed fields should say which field(s) is/are missing (siebrand) - closed.
- 0009217: [localization] Can't create CATEGORY in russian language (siebrand) - closed.
- 0009851: [localization] string_french.txt : french translation for $s_users_added_bugnote (siebrand) - closed.
- 0009925: [localization] Export to excel encoding problem (siebrand) - closed.
- 0009965: [localization] Wrong characters in notification email of account registration (siebrand) - closed.
- 0010067: [localization] Updated file for the Brazilian Portuguese language (siebrand) - closed.
- 0010088: [signup] Confirmation Link incorrect (grangeway) - closed.
- 0010116: [localization] Non-english Excell export show mess from DB (siebrand) - closed.
- 0010127: [preferences] Real Name chosen matches another user's login name (thraxisp) - closed.
- 0010145: [localization] Changelog and localisation of released (siebrand) - closed.
- 0010189: [other] wrong translation Billing in mainmenu (siebrand) - closed.
- 0010217: [preferences] Added ability to have the html buttons bar at the top, bottom or both of the bug view page. (jreese) - closed.
- 0010262: [localization] Update Catalan translation (siebrand) - closed.
- 0010265: [bugtracker] Bug view advanced page spacing bug when no versions defined for project (siebrand) - closed.
- 0010269: [email] Incorrect email subjects (grangeway) - closed.
- 0010273: [other] Links with Umlauts to local server (grangeway) - closed.
- 0010274: [bugtracker] Display target release date next to target version (dhx) - closed.
- 0010281: [bugtracker] Empty target version field is shown in advanced bug report screen when no versions exist for a project (grangeway) - closed.
- 0010330: [bugtracker] Remove all hardcoded enum levels from within Mantis code (dhx) - closed.
 - 0010597: [bugtracker] Remove hardcoded use of ADMINISTRATOR constant (dhx) - closed.
  - 0006524: [administration] Patch: 'manage users' link is displayed only to admins (dhx) - closed.
 - 0008137: [bugtracker] Custom constants do not work (dhx) - closed.
 - 0010008: [customization] Default resolution value should be configurable (dhx) - closed.
 - 0003973: [bugtracker] "Reporter effectiveness" on summary calculated wrongly in case of using custom-severity attributes (dhx) - closed.
- 0010421: [csv] Default filename corrupted if project name contains special chars (grangeway) - closed.
- 0010420: [csv] Custom fields with newline break CSV export (grangeway) - closed.
- 0010541: [localization] Some german strings (files attached) (siebrand) - closed.
- 0010565: [migration] User input date strings are munged with new schema (grangeway) - closed.
- 0010578: [administration] Admin created user accounts should get different confirmation e-mail (siebrand) - closed.
- 0010579: [localization] add russian to MantisBT Core Formating and XMLImportExport (siebrand) - closed.
- 0010585: [plug-ins] string not found manage_import_issues_link (grangeway) - closed.
- 0010595: [filters] Allow plugins to define and add new filters (jreese) - closed.
- 0010596: [filters] Allow plugins to define new column typess (jreese) - closed.
- 0010598: [localization] Shorten HTML button strings shown when viewing/updating a bug (dhx) - closed.
- 0010600: [email] Send Mail how task scheduler and accent (siebrand) - closed.
- 0010611: [localization] Attach not recognize correctly (dhx) - closed.
- 0010612: [api soap] mc_project_get_issue_headers returns an empty response (this bugtracker) (grangeway) - closed.
- 0010614: [bugtracker] assigned issue not assigned (jreese) - closed.
- 0010618: [customization] Add option to disable projection field (dhx) - closed.

[112 issues]

mantisbt - 1.1.8 (Released 2009-06-08) View Issues ]
======================================

Final bugfix and translation update release for the 1.1.x series.

- 0010184: [custom fields] APPLICATION ERROR 0001303 when optional custom date field is left blank (jreese) - closed.
- 0010405: [localization] Arabic language and RTL (siebrand) - closed.
- 0010445: [other] Wrong copyright (siebrand) - closed.
- 0010448: [localization] Syntax error in polish translation (siebrand) - closed.
- 0010570: [printing] Printing Bug does not work with configuration $g_show_view= SIMPLE_ONLY; (vboctor) - closed.

[5 issues]

mantisbt - 1.1.7 (Released 2009-04-20) View Issues ]
======================================

Bugfix maintenance release, cleaning up most of the remaining issues with 1.1.x series.

- 0010192: [sub-projects] Repeated Target versions (jreese) - closed.
- 0010235: [api soap] mc_issue_attachment_add corrupts attachments (giallu) - closed.
- 0007465: [printing] Customizing fields to be printed (rolfkleef) - closed.
- 0009979: [custom fields] Function gpc_isset always return false for a custom date field (thraxisp) - closed.
- 0010187: [security] Using dession destroy and unset for logout (jreese) - closed.
- 0009888: [bugtracker] Issue History Problem... build, os, os_version, and platform are not looking right and are not effected by language files. (jreese) - closed.
- 0009986: [administration] APPLICATION ERROR #2800 using "Delete Project Specific Settings" (jreese) - closed.
- 0010011: [customization] date_submitted is not set properly in bug object (thraxisp) - closed.
- 0010038: [tagging] Problems attaching tags in Chrome (jreese) - closed.
- 0010050: [time tracking] All leves have access to billing reports - Access level required to run reports does not function (giallu) - closed.
- 0006848: [administration] Bugs in manage_config_*_set.php (grangeway) - closed.
- 0009606: [custom fields] Custom fields not enforced. (thraxisp) - closed.
- 0010154: [custom fields] Custom field enum values are getting the first and last characters truncated when displayed. (thraxisp) - closed.
- 0010200: [email] \n not replaced in registration e-mail (siebrand) - closed.
- 0010270: [localization] escaped double quotes in localization files (siebrand) - closed.
- 0010231: [feature] Assigned bug status cannot be changed to new? (jreese) - closed.
- 0010299: [html] Invalid HTML (jreese) - closed.
- 0009999: [bugtracker] APPLICATION ERROR #2800 - While submit a new bug (jreese) - closed.
- 0010035: [custom fields] Custom multi-selection list fields don't allow deselection (thraxisp) - closed.

[19 issues]

mantisbt - 1.2.0a3 (Released 2009-01-15) View Issues ]
========================================

The next development release towards the 1.2.0 milestone. Large features of this release include enhanced security and browser caching, as well as a greatly improved and expanded plugin system. A great many bugs have also been found and fixed since the a2 release.

- 0009972: [db postgresql] Different problems in Boolean definition (grangeway) - closed.
- 0009792: [db mssql] SQL function DESCRIBE does not exist for MSSQL 2000 (thraxisp) - closed.
- 0008857: [localization] Typo in account registration e-mail (siebrand) - closed.
- 0009216: [localization] Problems with Russian language (siebrand) - closed.
- 0009473: [localization] Errors reported by admin/test_langs.php (siebrand) - closed.
- 0009504: [bugtracker] Can not add note (rolfkleef) - closed.
- 0009337: [api soap] [patch] Target version is not erased anymore when using the SOAP API (vboctor) - closed.
- 0009659: [localization] Bad display for french characters (siebrand) - closed.
- 0009745: [bugtracker] Making bugnote private, access check is wrong (jreese) - closed.
- 0009161: [upgrade] Can't upgrade from version 1.0.5 to svn head (jreese) - closed.
- 0008284: [api soap] SOAP API doesn't support target_version (vboctor) - closed.
- 0003543: [email] Some fields are missing from email notifications (vboctor) - closed.
- 0008076: [webpage] Wrong color order in the news_menu_page.php (grangeway) - closed.
- 0008883: [other] error_api.php: error_handled() returns true after an 'ignored' error, like a E_NOTICE (grangeway) - closed.
- 0009008: [integration] Segmentation Fault in core/checkin.php (grangeway) - closed.
- 0009114: [other] SYSTEM WARNING: escapeshellcmd() has been disabled for security reasons (grangeway) - closed.
- 0009121: [api soap] SOAP API incorrectly exports Relationship types (grangeway) - closed.
- 0009995: [api soap] Unable to update version, fixed_in_version and target_version (jreese) - closed.
- 0009245: [api soap] target_version not passed through via SOAP (vboctor) - closed.
- 0009320: [api soap] mc_filter_get broken after refactoring api/soap/mc_filter_api.php for 1.2.0a1 [patch] (vboctor) - closed.
- 0009396: [tagging] Wrong error message for tag attach (grangeway) - closed.
- 0009509: [custom fields] Custom fields with spaces are not handled correctly (grangeway) - closed.
- 0009590: [preferences] Empty option in email preferences menu breaks XHTML compliance (grangeway) - closed.
- 0009637: [db mysql] Does not work with MySQL 6 (thraxisp) - closed.
- 0009715: [printing] No Target Version in the word/excel/ie export (vboctor) - closed.
- 0009743: [bugtracker] sorting doesn't work in the View Issues page (vboctor) - closed.
- 0009749: [integration] Integrate the IE and Firefox search plugin into Mantis out-of-the-box (vboctor) - closed.
- 0009758: [tagging] Tag detach access check is wrong (grangeway) - closed.
- 0009762: [bugtracker] THIS INSTALLATION: All database queries seem to fail with "SYSTEM WARNING: preg_match()" (jreese) - closed.
- 0009804: [other] history_get_events not working (grangeway) - closed.
- 0009882: [preferences] Unknown unit for redirect and refresh delay. (vboctor) - closed.
- 0009914: [change log] add link to changelog/roadmap page to display a filtered list of 'view issues' for the version selected (grangeway) - closed.
- 0009920: [feature] The 'Select Profile' and profile-related information is taking a lot of space when unused on bug report advanced page. (grangeway) - closed.
- 0009921: [bugtracker] Not all the options you usually get when doing normal updates (ie resolve, close, etc) are available when doing mass updates. (grangeway) - closed.
- 0009610: [localization] Fixed Japanese translation (siebrand) - closed.
- 0009683: [other] Redirect error on login (grangeway) - closed.
- 0009688: [other] Issue ID in note link (vboctor) - closed.
- 0009705: [localization] [update] lang/string_swedish.txt (siebrand) - closed.
- 0009728: [administration] Project-Manager cannot update Project-Categories (jreese) - closed.
- 0009737: [bugtracker] bugnote_add.php contains undefined t_note_type (vboctor) - closed.
- 0009746: [bugtracker] Bugnotes are messed up when some are invisible (private) (vboctor) - closed.
- 0009747: [upgrade] upgrade_unattended.php refers to upgrade_inc.php which no longer exists (vboctor) - closed.
- 0009946: [code cleanup] Refactor enumeration handling and add unit tests for it (vboctor) - closed.
- 0009949: [localization] Error descriptions do not display properly. (jreese) - closed.
- 0004195: [email] Mails do not show national characters correctly (siebrand) - closed.
- 0004742: [localization] [all lang] Mix languages in messages (siebrand) - closed.
- 0005424: [administration] user_is_name_unique(): "Real Name" and "Real Name" (first name has one space, second name two) (thraxisp) - closed.
- 0005853: [localization] [CJK] In CJK languages, 'Report Issue' pages, the width of the left column is too small. (siebrand) - closed.
- 0006155: [localization] [all lang] Using different language can cause mantis posted issues not to be viewable. (siebrand) - closed.
- 0006661: [filters] Sorting on two custom fields results in SQL errors (daryn) - closed.
- 0007727: [localization] Hungarian letters with "hungarumlaut" aren't displayed (siebrand) - closed.
- 0007880: [administration] Create new user with same name is allowed. Editting the user reports an error. (thraxisp) - closed.
- 0008227: [db mysql] MySQL compatibility (siebrand) - closed.
- 0008588: [feature] adaptable status legend (thraxisp) - closed.
- 0009388: [localization] Russian translation fixes and additions (siebrand) - closed.
- 0009424: [localization] Polish translation - missing strings (siebrand) - closed.
- 0009476: [other] Can not update bug when using Internet Explorer 7 (IE7) (jreese) - closed.
- 0009501: [filters] view_filters_page.php misses target_version (daryn) - closed.
- 0009506: [plug-ins] Plugin schema option "InsertData" is not a valid callback for call_user_func_array() (jreese) - closed.
- 0009508: [filters] Adding Filters with Apostrophe saves Backslash in the database (daryn) - closed.
- 0009518: [bugtracker] Error 203 after editing a bugnote (thraxisp) - closed.
- 0009532: [news] News items with paragraph breaks adds \r\n (jreese) - closed.
- 0009546: [localization] Updated french strings for promotion (siebrand) - closed.
- 0009547: [other] "Update Category" command in "View Issues" not working (jreese) - closed.
- 0009548: [administration] dangerous probem with categories for issues moved from one project to another (jreese) - closed.
- 0009563: [news] Headline field blank error / escaping errors when adding / updating News entries (vboctor) - closed.
- 0009613: [localization] Update of Lithuanian translation (siebrand) - closed.
- 0009614: [localization] $g_language_auto_map for portugese localization contains spelling error in config_defaults_inc.php (siebrand) - closed.
- 0009661: [filters] It should be possible to switch off short_url usage (vboctor) - closed.
- 0009671: [localization] Missing field names in strings_german.txt (siebrand) - closed.
- 0009676: [administration] The "Inherit Global Categories" checkbox does not work when creating a new project (jreese) - closed.
- 0009677: [administration] SQL Error when deleting a project with no categories (jreese) - closed.
- 0005896: [administration] Allow developers to let other users monitor issues (vboctor) - closed.
- 0009200: [bugtracker] Support a threshold access level for users to show up in reminder picker (vboctor) - closed.
- 0009280: [time tracking] Display of the time tracking input format string (HH:MM) (grangeway) - closed.
- 0009298: [upgrade] upgrade from 1.1.2 to 1.2.0a1 fails (jreese) - closed.
- 0009475: [other] Error 403 and 401 trying to update bug catery from "View issues" page (daryn) - closed.
- 0009519: [other] disabled projects; duplicate of 5514 (jreese) - closed.
- 0009524: [security] Mantis should use secure sessions on https connections (grangeway) - closed.
- 0009559: [authentication] Wrong behaviour in Session API (session_save_path error message) (jreese) - closed.
- 0009596: [localization] Update of Icelandic translation (vboctor) - closed.
- 0009665: [authentication] Logout without unsetting session cookie (jreese) - closed.
- 0009708: [change log] Support linking to a changelog for a specific version (vboctor) - closed.
- 0009709: [roadmap] Support linking to a roadmap for a specific version (vboctor) - closed.
- 0009712: [administration] Applications should be able to check for latest updates against Mantis (vboctor) - closed.
- 0009724: [bugtracker] Issue history is missing (vboctor) - closed.
- 0009772: [administration] Add logging event to allow for plugins to log to custom sources (vboctor) - closed.
- 0009787: [bugtracker] Update default status colors to use a better color palette (jreese) - closed.
- 0009847: [administration] Make it easier to manage user for installations with large number of users (vboctor) - closed.
- 0009848: [change log] Ability to link to a changelog while specifying a project name / version name (vboctor) - closed.
- 0009849: [roadmap] Ability to link to a roadmap while specifying a project name / version name (vboctor) - closed.
- 0009908: [email] Support SMTP servers with ports other than 25 (e.g. gmail) (vboctor) - closed.
- 0009944: [other] Undefined index 'project_id' in summary page (vboctor) - closed.
- 0009975: [bugtracker] Setting the category using massive updates (actiongroup) results in bad history for the affected bugs. (jreese) - closed.
- 0009991: [other] Skip search engines indexing of login page, sign up page, and forgot password (vboctor) - closed.
- 0010003: [plug-ins] plugin_file.php cannot access subdirectories. (jreese) - closed.
- 0010013: [auth openid] Don't send verification emails for Open Id signups (vboctor) - closed.
- 0010015: [auth openid] OpenId integration fails on Windows. (vboctor) - closed.
- 0008821: [filters] Filtering on tags not quite working (daryn) - closed.
- 0009894: [other] Inconsistent uses of file extension configuration settings. (jreese) - closed.
- 0009971: [plug-ins] InsertData in plugin schema not working as the wiki describes. (jreese) - closed.
- 0010022: [tagging] Tag attachment lists tags multiple times (jreese) - closed.
- 0010045: [customization] APPLICATION WARNING #2400: Event "EVENT_MANAGE_PROJECT_FORM" has not yet been declared. (jreese) - closed.
- 0005263: [feature] Add the ability to report issues in unreleased product versions (thraxisp) - closed.
- 0009831: [bugtracker] Wrong status is used for Reopen Status (jreese) - closed.
- 0009905: [administration] Simplify the process of moving the attachments folder (vboctor) - closed.
- 0010052: [bugtracker] System notice in "Add Note" action group (jreese) - closed.
- 0009973: [localization] [portuguese_brazil] missing string translation (siebrand) - closed.
- 0009988: [bugtracker] Invalid character used in text string ("/>"). adm_config_report.php line 183 (grangeway) - closed.
- 0009989: [html] Undefined attribute name (border) in <tr> file: account_sponsor_page.php line: 175, 277 (grangeway) - closed.
- 0010039: [bugtracker] config_get in log_event (grangeway) - closed.
- 0008914: [rss] Since the 0008908 issue I can't read the RSS Flow (grangeway) - closed.

[112 issues]

mantisbt - git trunk (Released 2008-12-31) View Issues ]
==========================================

The tip of the git master branch.

- 0009384: [db postgresql] Cannot create new user (type error, integer instead of boolean) (grangeway) - closed.
- 0010334: [db postgresql] Unable to create user on postgres (grangeway) - closed.
- 0010490: [db oracle] Some queries don't work due to the use of "AS" in table alias (grangeway) - closed.
- 0012369: [security] XSS vulnerability when deleting maliciously named categories (giallu) - closed.
- 0010747: [time tracking] User summary enhancement for billing page (grangeway) - closed.

[5 issues]

mantisbt - 1.1.6 (Released 2008-12-09) View Issues ]
======================================

This release fixes once and for all the caching troubles from previous stable releases, some access permissions bugs, and a few various other issues. This release also improves the existing source control integration by allowing remote checkins.

- 0009893: [administration] Users can change status on ViewOnly Tasks (jreese) - closed.
- 0008847: [integration] Revamp SVN and CVS integration (jreese) - closed.
- 0009869: [bugtracker] application error 2800 still in version 1.1.5 (jreese) - closed.
- 0009890: [bugtracker] Case of extension for inline image is not ignored (jreese) - closed.
- 0009928: [other] Inconsistent uses of file extension configuration settings. (jreese) - closed.
- 0009651: [other] Version copy from parent project copies incorrect date (jreese) - closed.
- 0009815: [bugtracker] gpc_get_string_array() sometimes returns non-arrays (thraxisp) - closed.
- 0009900: [customization] Allowing update issue status disables the function to administrator (thraxisp) - closed.
- 0009892: [bugtracker] IE 6 still lacks of caching problems (jreese) - closed.

[9 issues]

mantisbt - 1.1.5 (Released 2008-11-21) View Issues ]
======================================

This release solves more issues relating to the security fixes introduced by 1.1.3, as well as various other minor bugs.

- 0009713: [authentication] Users are unable to confirm registration (jreese) - closed.
- 0008397: [localization] Localize bug_graph_bystatus (thraxisp) - closed.
- 0009863: [upgrade] Manage Projects: SYSTEM WARNING: array_key_exists() (grangeway) - closed.
- 0009714: [csv] Error message/warning, if HTTP_USER_AGENT is not set (jreese) - closed.
- 0009748: [bugtracker] Port 9737: bugnote_add.php contains undefined t_note_type (vboctor) - closed.
- 0009017: [bugtracker] SYSTEM WARNING implode() [function.implode]: Bad arguments. (jreese) - closed.
- 0009738: [bugtracker] Browser caching should be enabled on bug_change_status_page.php (jreese) - closed.
- 0009760: [other] Mantis checks $g_allow_browser_caching setting incorrectly (jreese) - closed.
- 0009780: [tagging] Changing project in Tag Details view gives "APPLICATION ERROR #200" (jreese) - closed.
- 0009803: [tagging] Tags field in filter should not be shown when user has no access to tags (jreese) - closed.
- 0009808: [db mysql] Linking Sub-Projects to a project -> APPLICATION ERROR #200 (jreese) - closed.
- 0009754: [bugtracker] Failed to report issue (APPLICATION ERROR #2800) (jreese) - closed.

[12 issues]

mantisbt - 1.1.4 (Released 2008-10-18) View Issues ]
======================================

We had to withdraw 1.1.3 because of a serious flaw affecting the bug_report*
pages. This new release fixes that problem and a newly discovered security issue.

- 0009704: [security] Remote Code Execution in manage_proj_page.php (giallu) - closed.
- 0009690: [other] Wrong parameter count for session_set_cookie_params() (jreese) - closed.
- 0009691: [bugtracker] Failed to report issue.(Always APPLICATION ERROR #2800) (jreese) - closed.
- 0009693: [webpage] Generated HTML contains multiple hostnames when proxied (jreese) - closed.

[4 issues]

mantisbt - 1.1.3 (Released 2008-10-14) View Issues ]
======================================

In this release we fixed a couple of nasty bugs sneaked into 1.1.2, where sending bugnotes email notifications would fail and browser caching was not functional.
We also refined the implementation of form security tokens and closed a couple of security issues, an information disclosure (with no CVE) and a session hijacking (CVE-2008-3102).

- 0009323: [bugtracker] Browser caching broken since 1.1.2 (jreese) - closed.
- 0009664: [security] Logout without unsetting session cookie (jreese) - closed.
- 0009321: [security] Users can get title and status of issues that they don't have access to. (vboctor) - closed.
- 0008882: [other] Gravatar causes annoying security popups on IE when using Mantis over HTTPS/SSL (jreese) - closed.
- 0009286: [administration] stray "2" in manage_user_prune.php (vboctor) - closed.
- 0009309: [email] Problems with e-mail notifications about bugnotes [PATCH] (giallu) - closed.
- 0009343: [scripting] form security token prevents changing relationship while resolving bug (jreese) - closed.
- 0009361: [other] php session fail created cause mantis app error. (jreese) - closed.
- 0009430: [graphs] bug_graph_bystatus shows heading by_category (thraxisp) - closed.
- 0009431: [localization] no localization for usage of open, resolved, closed in bug_graph_bystatus.php (thraxisp) - closed.
- 0009470: [bugtracker] Tags filter not filling into text field when selecting from list using Internet Explorer (jreese) - closed.
- 0009493: [custom fields] Removing custom fields from project causes application error 2800 (giallu) - closed.
- 0009533: [security] Mantis should use secure sessions on https connections (jreese) - closed.
- 0009560: [other] Wrong behaviour in Session API (session_save_path error message) (jreese) - closed.
- 0009672: [other] Fixing form error by going back fails because of security token (jreese) - closed.
- 0004678: [filters] Filter combos don't fill up on if switched to 'All Projects' - closed.

[16 issues]

mantisbt - 1.2.0a2 (Released 2008-08-04) View Issues ]
========================================

This is the second alpha release on the road to version 1.2.0, and includes
the same security fixes we released in 1.1.2.
As usual with alpha releases, it is intended to be a technology preview aimed
at early adopters, testers, translators etc.
We do not recommend using it in production environments.

- 0006236: [db postgresql] Escaping error in PostgreSQL (grangeway) - closed.
- 0008675: [db postgresql] Incorrect use of boolean in postgres 8.2.4 (grangeway) - closed.
- 0008699: [db postgresql] Get Time Tracking Information return a SQL query error (grangeway) - closed.
- 0009387: [db postgresql] Cannot create new user (invalid input syntax for type boolean: "2") (jreese) - closed.
- 0009348: [bugtracker] Monitoring/unmonitoring an issue should update it's last modified date (vboctor) - closed.
- 0009060: [bugtracker] “Open and assigned to me:” and “Open and reported by me:” links on the “Main” page are incorrect. (grangeway) - closed.
- 0009266: [upgrade] webpath to the mantis installation is calculated wrong, if mantis is installed in the root directory of a webserver (grangeway) - closed.
- 0009133: [security] "APPLICATION ERROR #19" when switching project in revision 5250 (thraxisp) - closed.
- 0008764: [security] Remove mantis version number from publicly searchable pages (grangeway) - closed.
- 0008977: [security] Port 0008974: XSS Vulnerability in filters (thraxisp) - closed.
- 0008980: [security] Port: Remote Code Execution in adm_config (giallu) - closed.
- 0009187: [security] arbitrary file inclusion through user preferences page (giallu) - closed.
- 0009247: [security] A reporter can update an incidence (jreese) - closed.
- 0009322: [security] Port of 0009321: Users can get title and status of issues that they don't have access to. (vboctor) - closed.
- 0006235: [administration] Impossible to select a user with empty user name (grangeway) - closed.
- 0009040: [administration] Missing category_id column (vboctor) - closed.
- 0009115: [administration] Removing user's access to a private project doesn't work (vboctor) - closed.
- 0009364: [administration] SYSTEM WARNING message received when deleting a project (jreese) - closed.
- 0008606: [api soap] Problem with categories (planser) - closed.
- 0009141: [bugtracker] summary_page error when DB is empty (giallu) - closed.
- 0009228: [bugtracker] THIS INSTALLATION: sorting of notes does not work any more (jreese) - closed.
- 0009258: [api soap] Adding bug throws fault for undefined "due_date" field (vboctor) - closed.
- 0009346: [bugtracker] Due Date is shown in history even if user doesn't have access to view due dates (vboctor) - closed.
- 0009347: [bugtracker] Due Date should be disabled by default (vboctor) - closed.
- 0009349: [bugtracker] Tagging/untagging an issue should update it's last modified date (vboctor) - closed.
- 0009395: [bugtracker] Summary page generates incorrect filter links for categories (daryn) - closed.
- 0009223: [bugtracker] auto-assigned in parent project categories doesn't work (jreese) - closed.
- 0009251: [bugtracker] Issue history contains the '@' symbol as the old value when certain fields of the bug report are modified (grangeway) - closed.
- 0009275: [bugtracker] Tags filter not filling into text field when selecting from list using Internet Explorer (jreese) - closed.
- 0009461: [bugtracker] History of status changes broken (grangeway) - closed.
- 0009001: [change log] memory exhausted on changelog (giallu) - closed.
- 0009087: [change log] Renaming a version doesn't update the corresponding issue fields (jreese) - closed.
- 0009285: [custom fields] bad named function in /core/excel_api.php file (vboctor) - closed.
- 0003786: [feature] deleting a category that is in use should issue a warning (jreese) - closed.
- 0007508: [filters] Custom fields should have a additional flag, if they should be avaliable as filter or not. (daryn) - closed.
- 0008916: [filters] Monitor by filter ignores show_monitor_list_threshold (daryn) - closed.
- 0008933: [documentation] Bad link in source code. (grangeway) - closed.
- 0009099: [filters] using advanced filtering leads to APPLICATION ERROR 0000401 (daryn) - closed.
- 0009345: [documentation] Document PHP extensions required by Mantis (vboctor) - closed.
- 0009370: [documentation] User Documentation link is wrong (jreese) - closed.
- 0008160: [filters] filter for notes (daryn) - closed.
- 0009043: [installation] Invalid link to login page after installation (bug + patch) (jreese) - closed.
- 0009104: [filters] Last page of search results not showing because of error 401 (daryn) - closed.
- 0009166: [graphs] JPGraph - Array keys Should be checked with isset() - especially when error reporting is E_ALL (grangeway) - closed.
- 0008192: [integration] Twitter message has wrong escaping for quotation marks (vboctor) - closed.
- 0008827: [localization] Some modifications in strings_french.txt (vboctor) - closed.
- 0009100: [news] RSS Feeds do no include date posted (grangeway) - closed.
- 0009281: [localization] czech translation (vboctor) - closed.
- 0009288: [integration] Twitter updates don't show category correctly (always []) (vboctor) - closed.
- 0009312: [integration] wiki integration and undefined function auth_is_user_authenticated (with patch) (jreese) - closed.
- 0009377: [installation] Installation: upgrade_list.php does not exist (grangeway) - closed.
- 0009094: [other] Insert page break between issues when exporting Microsoft Word DOC format (vboctor) - closed.
- 0009170: [other] Fix for 0008981 (protection against multiple submissions) broken IE and Opera support (vboctor) - closed.
- 0003241: [other] On Excel, no column headings display. (vboctor) - closed.
- 0002963: [performance] manage_proj_edit_page executes more than 5000 queries (grangeway) - closed.
- 0008372: [performance] Control Page Overload (grangeway) - closed.
- 0008908: [other] Incorrectl dropdown menu while $g_show_extended_project_browser is on (grangeway) - closed.
- 0009138: [other] Submit Report doesn't work (grangeway) - closed.
- 0009265: [plug-ins] Add an event to allow adding links to View Issues page (vboctor) - closed.
- 0009267: [plug-ins] URL for updating plugin settings is wrong. (jreese) - closed.
- 0009392: [other] Remove ?> from the end of config_defaults_inc.php and config_inc.php to avoid errors due to blank lines (vboctor) - closed.
- 0009448: [plug-ins] Move the Freemind feature to a plugin (vboctor) - closed.
- 0006731: [rss] Date not shown in RSS (grangeway) - closed.
- 0008761: [scripting] compress_handler called before defined (grangeway) - closed.
- 0009237: [sql] When using g_limit_reporters produces SQL error for reporters (daryn) - closed.
- 0009332: [relationships] Remove auth_get_current_user_id from relationship_api.php (vboctor) - closed.
- 0008353: [tagging] Handling accentuated tags (giallu) - closed.
- 0008843: [time tracking] Ignores tracking_reporting_threshold (daryn) - closed.
- 0009451: [tagging] Tags with single quotes and double quotes are escaped more than once (vboctor) - closed.
- 0007953: [time tracking] Time Tracking assigment lost, when changing issue status without note text (daryn) - closed.
- 0008357: [time tracking] "Total time for issue" is shown even for users under threshold (daryn) - closed.
- 0008849: [time tracking] Emails ignore time tracking view threshold (daryn) - closed.
- 0003838: [webpage] HTML Beautification (rainmkr) - closed.
- 0006796: [webpage] Webpages generated do not produce "Valid HTML" (grangeway) - closed.
- 0009383: [webpage] Wrong URL directory path computed (CSS & images and JS not accessible) (grangeway) - closed.

[75 issues]

mantisbt - 1.1.2 (Released 2008-06-17) View Issues ]
======================================

This release focused on fixing few security issues; also includes assorted fixes for translations, usability and compatibility (most notably, with postgres) and a nasty memory leak on the string API causing incomplete rendering of pages. All users are advised to upgrade.

- 0008880: [db postgresql] Problem with date formatting in db_prepare_date function (giallu) - closed.
- 0009176: [db postgresql] Port 0008699: Get Time Tracking Information return a SQL query error (vboctor) - closed.
- 0009207: [tagging] Several actions lead into Application Error #19 (schoenfeld) - closed.
- 0004570: [filters] Option to show all users in All Projects filter - closed.
- 0008830: [installation] set_time_limit() doesn't work in PHP safe mode (daryn) - closed.
- 0009181: [time tracking] Port 0008362: Note text is mandatory for time tracking while closing bug (daryn) - closed.
- 0009180: [time tracking] Port 0007971: time tracking information only saved on added comment (daryn) - closed.
- 0009179: [time tracking] Port 0007953: Time Tracking assigment lost, when changing issue status without note text (daryn) - closed.
- 0009182: [bugtracker] Port 0008509: Empty Note is added when updating issue (daryn) - closed.
- 0009082: [localization] Hungarian translate error (Bithunter) - closed.
- 0008976: [security] Remote Code Execution in adm_config (giallu) - closed.
- 0008974: [security] XSS Vulnerability in filters (thraxisp) - closed.
- 0008975: [security] CSRF Vulnerabilities in user_create (jreese) - closed.
- 0009154: [security] arbitrary file inclusion through user preferences page (giallu) - closed.
- 0008858: [integration] DokuWiki integration: EMail notification on wiki page changes not working (vboctor) - closed.
- 0008886: [change log] Change Log shows duplicate entries (jreese) - closed.
- 0008924: [bugtracker] Port 8245: Target Version value lost in update issue page (giallu) - closed.
- 0008123: [administration] Adding a user requires "$g_lost_password_feature = ON" (giallu) - closed.
- 0008774: [localization] Complete Hungarian retranslation (vboctor) - closed.
- 0008853: [roadmap] Issue appears more than once in the Roadmap for a release. (jreese) - closed.
- 0008931: [relationships] Circle Relations cause roadmap to malfunction (jreese) - closed.
- 0009177: [filters] Port 0008916: Monitor by filter ignores show_monitor_list_threshold (vboctor) - closed.
- 0009178: [other] Fix memleak in string api (vboctor) - closed.
- 0009183: [time tracking] Port 0008357: "Total time for issue" is shown even for users under threshold (vboctor) - closed.
- 0009184: [time tracking] Port 0008849: Emails ignore time tracking view threshold (vboctor) - closed.
- 0009185: [time tracking] Port 0008621: The expand icon is inverted for the Time tracking section (vboctor) - closed.
- 0009186: [localization] Port 0009046: French translation for $s_bug_assign_to_button (vboctor) - closed.
- 0007764: [scripting] APPLICATION WARNING #100: Configuration option 'category_enum_string' not found (vboctor) - closed.
- 0009208: [other] Several actions on bug update page lead into System Warning and App. Error (daryn) - closed.

[29 issues]

mantisbt - 1.2.0a1 (Released 2008-04-18) View Issues ]
========================================
- 0007716: [db mssql] Can not handel Querry with over 3000 bugs (grangeway) - closed.
- 0008757: [integration] Add wiki integration for TWiki (vboctor) - closed.
- 0008435: [feature] Implement Global and Inheriting Categories Structure (jreese) - closed.
 - 0008771: [bugtracker] Port 0008738: Allow bugs to have no category (jreese) - closed.
- 0008518: [custom fields] Enumerated Custom Field limited to 255 (grangeway) - closed.
- 0007808: [feature] Strike a resolved bug in notes and links (jreese) - closed.
- 0008791: [custom fields] Custom fields in all projects instead of only the linked (vboctor) - closed.
- 0008706: [email] Bad email headers for notifications (giallu) - closed.
- 0008938: [authentication] Allow site administrators to customize or disable reauthentication timeout. (jreese) - closed.
- 0008577: [email] Long utf-8 encoded subject fails (phpmailer bug) (giallu) - closed.
- 0008799: [graphs] Top logo (mantis_logo.gif) and URL it points to shall be configurable (jreese) - closed.
- 0009046: [localization] French translation for $s_bug_assign_to_button (Bithunter) - closed.
- 0008621: [time tracking] The expand icon is inverted for the Time tracking section (vboctor) - closed.
- 0008995: [security] CSRF Vulnerabilities in user_create (thraxisp) - closed.
- 0007463: [bugtracker] Issue with many child issues produced performance problem (grangeway) - closed.
- 0008486: [tools] No database stat of tag table displayed (zakman) - closed.
- 0008565: [other] Formatting of summary in My View is not consistent with View Issues page (vboctor) - closed.
- 0006666: [other] SIGSEGV in pcre_config (grangeway) - closed.
- 0008136: [bugtracker] Some <pre></pre> texts may cause php crash without error message (grangeway) - closed.
- 0008569: [installation] Errors when default language = auto ? (grangeway) - closed.
- 0008576: [email] Wrong links to comments in email notifications (grangeway) - closed.
- 0008578: [webpage] Wrong style class used in if ... else (vboctor) - closed.
- 0008660: [administration] Provide a way to hide/show users with global access in manage project page (vboctor) - closed.
- 0008710: [custom fields] display past years in Custom date field (vboctor) - closed.
- 0008740: [other] print_all_bug_page_word.php uses raw SQL rather than API (vboctor) - closed.
- 0003911: [bugtracker] Mantis violates RFC2616 when redirecting (giallu) - closed.
- 0007712: [db mysql] mantis_config_table (thraxisp) - closed.
- 0008748: [db mysql] phpMyAdmin reports a warning message (thraxisp) - closed.
- 0008778: [bugtracker] Add newly reported issues to last visited (vboctor) - closed.
- 0008797: [localization] Improve the german translation to avoid baby talk (MartinFuchs) - closed.
- 0007130: [customization] Unbranding Mantis (jreese) - closed.
- 0007158: [feature] Change Mantis top logo link to internal link (giallu) - closed.
- 0008536: [webpage] Top header logos are all distorted to the same size (giallu) - closed.
- 0008766: [plug-ins] Move text processing and formatting to an official plugin (jreese) - closed.
- 0008795: [localization] strtoupper() fail on localized strings (thraxisp) - closed.
- 0008826: [localization] german localization (and maybe other languages, too): blocking and blocked relation text is swapped (MartinFuchs) - closed.
- 0008369: [email] Making phpMail work with Gmail (giallu) - closed.
- 0008491: [feature] Would like label for 'check for more issues' (giallu) - closed.
- 0008535: [other] Replace RSS icon with Universal feed icon (jreese) - closed.
- 0008771: [bugtracker] Port 0008738: Allow bugs to have no category (jreese) - closed.
- 0008787: [feature] WikkaWiki Integration (vboctor) - closed.
- 0008865: [db mysql] Wrong format for insert into Database (jreese) - closed.
- 0008873: [other] Bug print / Word export should include the URL for downloading attachments (vboctor) - closed.
- 0008874: [customization] Provide the ability to add "build" column to View Issues, Print Issues, and CSV export (vboctor) - closed.
- 0008890: [bugtracker] Add group action for updating "product build" field for multiple issues (vboctor) - closed.
- 0008245: [bugtracker] Target Version value lost in update issue page (giallu) - closed.
- 0008891: [administration] change version's released property's default value to unreleased (jreese) - closed.
- 0008922: [bugtracker] Support including 'description', 'steps_to_reproduce', 'additional_information' as columns (vboctor) - closed.
- 0008923: [bugtracker] Ability for users and administrators to customize columns for View Issues, Print Issues, CSV, and Excel (vboctor) - closed.
- 0008927: [filters] "Create Permalink" is controlled by $g_view_filters (vboctor) - closed.
- 0004491: [relationships] Deleting duplicate relationshilp left value in 'duplicate_id' field (vboctor) - closed.
- 0008346: [documentation] Use DocBook for Mantis manual (giallu) - closed.
- 0008514: [other] Support a dynamic and lightweight plugin system (jreese) - closed.
- 0008875: [integration] Refactor Wiki integration engines to achieve better consistency (jreese) - closed.
- 0008887: [graphs] Graph legend displays default status names (thraxisp) - closed.
- 0008937: [bugtracker] Users with privileges below Administrator cannot see subprojects. (jreese) - closed.
- 0008965: [api soap] Adding/Updating/Deleting versions using SOAP API requires ADMINISTRATOR rights (vboctor) - closed.
- 0008969: [bugtracker] Can't switch off Inherit Global Categories (jreese) - closed.
- 0008970: [bugtracker] project delete failed due to category changes (jreese) - closed.
- 0003816: [sponsorships] Include total sponsorships for an issue in csv export (vboctor) - closed.
- 0008920: [bugtracker] Visual mark to differentiate "none" and "normal" priorities (vboctor) - closed.
- 0001910: [bugtracker] Provide ability to make version obsolete (vboctor) - closed.
- 0008981: [bugtracker] Multiple bug submissions (vboctor) - closed.
- 0007634: [custom fields] Support relative default for Date Custom Fields (e.g. {tomorrow}, {+2 days}, {next week}) (vboctor) - closed.
- 0009004: [custom fields] Support enumeration custom fields exposed as radio buttons (vboctor) - closed.
- 0009025: [javascript] Enhance Collapse API for Extensiblity and Plugin Usage (jreese) - closed.
- 0008651: [change log] Display release date in changelog for released version (jreese) - closed.
- 0009050: [other] Add support for "Copy Columns From/To" when customizing columns to view in View Issues, Print Issues, CSV, Excel (vboctor) - closed.

[67 issues]

mantisbt - 1.1.1 (Released 2008-01-19) View Issues ]
======================================

Mantis 1.1.1

- 0008064: [graphs] Problem with JpGraph (thraxisp) - closed.
- 0007976: [graphs] Convergence Reports System (thraxisp) - closed.
- 0008756: [security] "Most active bugs" summary XSS vulnerability (giallu) - closed.
- 0008681: [upgrade] Mantis 1.1.0 has a dependency on stripos which was added in PHP 5 (vboctor) - closed.
- 0008684: [installation] UPGRADING file missing in doc (thraxisp) - closed.
- 0008707: [filters] "My View" shows warnings about "sort" / "dir" not defined (vboctor) - closed.
- 0008708: [graphs] graph fails with error claiming bad colour name (thraxisp) - closed.
- 0008662: [bugtracker] Unneeded executable bits on mantis modules (giallu) - closed.
- 0008692: [localization] Russian translation update. (vboctor) - closed.
- 0008695: [api soap] Error with attachments - Method DISK (planser) - closed.
- 0008721: [upgrade] css and icon paths incorrect (vboctor) - closed.
- 0008732: [graphs] Many options on bug_graph_page.php broken, inconsistent, incomplete (thraxisp) - closed.
- 0008742: [localization] "actiongroup_error_issue_is_readonly" isn't defined (vboctor) - closed.
- 0008758: [localization] Application error 18 with russian language (vboctor) - closed.
- 0008683: [api soap] mc_projects_get_user_accessible raises SYSTEM NOTICE, but it should not (vboctor) - closed.
- 0008738: [bugtracker] Could not create bug if project have not categorys and g_default_bug_category is empty (vboctor) - closed.
- 0008759: [api soap] Improve error handler to report location of errors (vboctor) - closed.
- 0008767: [api soap] incorrect date and time handling in mc_project_version_add and mc_project_version_update (planser) - closed.
- 0008770: [email] Sending queued emails is still attempted even if email notifications are turned OFF, causing errors (vboctor) - closed.

[19 issues]

mantisbt - 1.0.9 (Released 2007-12-31) View Issues ]
======================================
- 0008153: [security] CVE-2007-3215: PHPMailer vulnerability (thraxisp) - closed.
- 0008122: [bugtracker] Port 8044: Edit/Delete bugnote buttons missing (giallu) - closed.
- 0008024: [other] Summary Page - Longest open Issue (giallu) - closed.
- 0008256: [installation] Install process fails creating db tables. regression: 1.0.7 works. (giallu) - closed.

[4 issues]

mantisbt - 1.1.0 (Released 2007-12-19) View Issues ]
======================================

This is Mantis 1.1.0 Gold Release. All users with pre-release 1.1.0x releases and with 1.0.x releases are encouraged to upgrade to this release. For users who are using non-latin character sets, a manual upgrade process is necessary.

- 0008679: [security] XSS Vulnerability in view.php , Attached Files (vboctor) - closed.
- 0001032: [feature] Project-wide profiles (atrol) - closed.
- 0006582: [feature] Scheduling features for versions (atrol) - closed.
- 0007990: [time tracking] Total amount of worked time (vboctor) - closed.
- 0008499: [graphs] Many graphs show "not enough data to create graph" after upgrading from 1.1.0a2 (jreese) - closed.
- 0006948: [filters] Not able to filter by project (vboctor) - closed.
- 0008645: [roadmap] Issue appears more than once in the Roadmap for a release. (jreese) - closed.
- 0008602: [api soap] Provide a SOAP friendly error handler (vboctor) - closed.
- 0008604: [api soap] Wrong URL in E-Mail notifications by changes via webservice (vboctor) - closed.
- 0008617: [api soap] mc_version() should return the Mantis version (vboctor) - closed.
- 0008437: [localization] Update to italian translation (giallu) - closed.
- 0008567: [installation] cannot install on shared webserver, core/*.php inconsistent use of require_once($t_core_dir) (vboctor) - closed.
- 0008591: [api soap] Error in api/soap/mc_filter_api.php#mc_filter_get() (planser) - closed.
- 0008644: [api soap] Many errors of type SYSTEM NOTICE are thrown (planser) - closed.
- 0008661: [bugtracker] Possible crash condition leading to blank or incomplete page (giallu) - closed.
- 0008674: [email] Php script for sending mail via cronjob raise error when lang set to auto (vboctor) - closed.

[16 issues]

mantisbt - 1.1.0rc3 (Released 2007-11-23) View Issues ]
=========================================

This is the third release candidate for Mantis 1.1.0, we believe we are now very close to the final release. This release has several fixes relating to SOAP API, DB2, and others. All users running 1.1.0x releases are encouraged to update to this release.

- 0008509: [bugtracker] Empty Note is added when updating issue (giallu) - closed.
- 0008238: [filters] urldecode() error on creating PermaLink (MartinFuchs) - closed.
- 0008063: [other] mantis_version shouldn't be in the configuration file (jreese) - closed.
- 0008511: [email] send_emails.php is missing <?php at the start of the file (giallu) - closed.
- 0007646: [bugtracker] Show content link should change to Hide content when clicked (giallu) - closed.
- 0008494: [api soap] Remove backward compatibility code from SOAP API (vboctor) - closed.
- 0008524: [integration] core/checkin.php is missing toplevel <? causing the script to fail. (vboctor) - closed.
- 0008525: [api soap] mc_projects_get_user_accessible() shouldn't return ALL_PROJECTS (vboctor) - closed.
- 0008541: [api soap] $g_mc_error_when_version_not_found is not defined (vboctor) - closed.
- 0008566: [api soap] mc_project_version_add() doesn't set the date_order field correctly (vboctor) - closed.
- 0008589: [bugtracker] file_download.php doesn't work with attachment names that contain accentuated characters when using Firefox (vboctor) - closed.
- 0008263: [scripting] smaller issue in email address recognition (jreese) - closed.
- 0008519: [api soap] Name collision between NuSoap SoapClient and PHP 5 Soap extension (vboctor) - closed.
- 0008564: [db db2] Attempting installation of MANTIS400, table not being created (slashsplat) - closed.
- 0008592: [api soap] Error in api/soap/mc_file_api.php#mc_file_add() (vboctor) - closed.

[15 issues]

mantisbt - 1.1.0rc2 (Released 2007-10-04) View Issues ]
=========================================

This is the second release candidate for 1.1.0 release. It is recommended that all users with 1.1.0x releases upgrade to this version. This is mainly a bug fixes release.

- 0008453: [bugtracker] Sub-project My View highlights all issues as recent (jreese) - closed.
- 0007787: [feature] Robust threading of e-mails using MIME headers (giallu) - closed.
- 0008480: [security] XSS Vulnerability in Tag details, Attach Tags (jreese) - closed.
- 0008463: [localization] re-authentication button does not appear in user's language (jreese) - closed.
- 0008467: [security] Users can login using the MD5 hash of the password (vboctor) - closed.
- 0008446: [localization] Update Estonian Language (vboctor) - closed.
- 0007497: [other] Summary page is little of Garble (vboctor) - closed.
- 0008443: [tagging] creating new tags for multi-selection (jreese) - closed.
- 0008454: [time tracking] time tracking sum on request wrong (vboctor) - closed.
- 0007999: [other] Project list view corrupted (vboctor) - closed.
- 0008459: [localization] Update catalan translation (vboctor) - closed.
- 0008461: [signup] signup_page and lost_pwd_page don't work if anonymous access not enabled (vboctor) - closed.
- 0008254: [integration] Gravatar integration should handle empty email addresses (giallu) - closed.
- 0008378: [other] Select custom avatar for default Gravatar image. (giallu) - closed.
- 0005612: [other] Redirect time ignored in preferences (giallu) - closed.
- 0008475: [printing] Function used two times in the same file (only one is necessary) (vboctor) - closed.
- 0008476: [other] Add a service to disposable email address checker (zakman) - closed.
- 0008468: [localization] $s_select_option is missing in german language (vboctor) - closed.
- 0008457: [administration] Removing a userdefined field from project results in APPLICATION ERROR #203 (vboctor) - closed.
- 0008492: [api soap] Add attachment succeeds but creates broken attachment if upload path not found (vboctor) - closed.
- 0008493: [api soap] Attachments created via SOAP API don't honor attachments_file_permissions config option (vboctor) - closed.
- 0008489: [localization] Update Japanese Localization for 1.1.0rc2 (vboctor) - closed.
- 0008490: [administration] Undefined variable: t_version in manage_proj_ver_copy.php (vboctor) - closed.
- 0008465: [filters] collapse filter section as default (giallu) - closed.
- 0008241: [customization] Disable Roadmap (vboctor) - closed.
- 0008500: [other] Empty entry in "Category" drop down (vboctor) - closed.

[26 issues]

mantisbt - 1.1.0rc1 (Released 2007-08-02) View Issues ]
=========================================

Mantis 1.1.0rc1 is the first release candidate for Mantis 1.1.0 release. This release follows for alpha releases. It includes features like db2 support, XWiki integration and tagging. It also has security improvements and some localization updates. All users of Mantis 1.1.0aX are encouraged to upgrade.

Installations that use non-latin character sets should check the website for the upgrade path.

The code is branched along with this release, hence, the 1.1.0 branch will take fixes that are needed to release 1.1.0 gold. New features will go into CVS HEAD which will go into 1.2.0 release.

- 0007690: [db mssql] number_format(); bad for SQL statments (vboctor) - closed.
- 0007995: [other] Confusion in product_version values due to string comparisons with == operator (zakman) - closed.
- 0008188: [other] Consistent use of collapse_api.php (DGtlRift) - closed.
- 0008396: [tagging] Don't allow creating tags if user can't attach them (jreese) - closed.
- 0006850: [localization] obsolete MANTIS_ERROR (giallu) - closed.
- 0008231: [bugtracker] Summary "By Date" shows suspicious totals (giallu) - closed.
- 0008206: [integration] Add (gr)avatars for users (giallu) - closed.
- 0008233: [bugtracker] Long standing issues report on summary page (giallu) - closed.
- 0008246: [upgrade] Add support for running arbitrary functions (thraxisp) - closed.
- 0008252: [feature] Gravatars and case sensitivity of email addresses (giallu) - closed.
- 0008283: [other] $g_show_notices and $g_show_warnings should be marked as obsolete (vboctor) - closed.
- 0008285: [other] File Download generates an E_NOTICE (vboctor) - closed.
- 0008286: [security] Add .htaccess to block access to core/, doc/, lang/, packages/ (vboctor) - closed.
- 0008291: [administration] check.php: Use of undefined constant db_is_connected - assumed 'db_is_connected' (vboctor) - closed.
- 0008292: [other] my_view_inc: syntax error (vboctor) - closed.
- 0008237: [graphs] Error in dependency graphs (vboctor) - closed.
- 0008269: [roadmap] Reporting a new issue, ADMIN/MANAGER/DEVELOPER should see field "Target Version" (jreese) - closed.
- 0008274: [tagging] Implement Keyword Tagging Features (jreese) - closed.
- 0008311: [tagging] System Notice: Undefined index 'tag_select' in view_all_bug_page.php (jreese) - closed.
- 0007846: [relationships] APPLICATION ERROR #1802: Relationship not found (vboctor) - closed.
- 0008312: [security] Install script shouldn't include password in the form (jreese) - closed.
- 0008324: [administration] Rendering of "Manage Users" menu link ignores $g_manage_user_threshold (giallu) - closed.
- 0007996: [custom fields] Confusion in string values of enumerated custom field due to non strict comparison of strings (zakman) - closed.
- 0008337: [tagging] Blank page (no data) when invalid tag filter chosen (jreese) - closed.
- 0008341: [other] Xwiki integration (vboctor) - closed.
- 0008327: [documentation] show_extended_project_browser can only be set to OFF or ON (vboctor) - closed.
- 0008340: [security] Changing password should create a new cookie_string (vboctor) - closed.
- 0008343: [administration] Admin created users bypass realname validity check (vboctor) - closed.
- 0007809: [custom fields] Filter "none" on custom fields doesn't work (giallu) - closed.
- 0008344: [other] Tokens API Clean-up and Changes (jreese) - closed.
- 0008371: [db db2] Use "days" instead of "to_days" when comparing dates for db2 (vboctor) - closed.
- 0004614: [relationships] Relationship graph: sometimes arrows direction is not correct (vboctor) - closed.
- 0005093: [webpage] Rights in custom menu does not work (vboctor) - closed.
- 0008384: [db db2] db_table_exists() doesn't work in case of DB2 (vboctor) - closed.
- 0008385: [db db2] ADODB_db2._insert_id doesn't work (vboctor) - closed.
- 0008386: [db db2] ADODB_db2 uses an invalid time format which is not accepted by db2 (vboctor) - closed.
- 0008387: [db db2] adodb2-db2.DBTimeStamp uses TO_DATE() which doesn't work on DB2 (vboctor) - closed.
- 0007855: [localization] Priority colum header String not taken from strings file (vboctor) - closed.
- 0008388: [other] Undefined variable $p_this_var in helper_api.php (vboctor) - closed.
- 0008389: [db db2] Remove references to odbc_db2 driver from code (we only support db2) (vboctor) - closed.
- 0008295: [printing] Include the bug history in the printout (zakman) - closed.
- 0008336: [security] Require re-login for high impact tasks (jreese) - closed.
- 0008368: [tagging] "Access Denied." when trying to attach a tag to an issue I reported (vboctor) - closed.
- 0008395: [bugtracker] Recently Visited is not displayed. (jreese) - closed.
- 0008380: [administration] Deleting old user Account results in Database inconsistency (vboctor) - closed.
- 0008407: [performance] Add caller function info to queries list (giallu) - closed.
- 0008412: [performance] When showing queries show the time spent in SQL vs. PHP (vboctor) - closed.
- 0008413: [performance] Provide a way to show queries for an access level threshold (vboctor) - closed.
- 0008423: [localization] Update German Localization (vboctor) - closed.
- 0007647: [localization] [de] Translation change from "Problem" (problem) to "Eintrag" (issue) (vboctor) - closed.
- 0008425: [localization] Update portuguese_brazil localization (vboctor) - closed.
- 0008428: [localization] Update French Localization (vboctor) - closed.
- 0007720: [localization] Japanese language translation patch (vboctor) - closed.
- 0008421: [other] Recently visted is showing some serialized filter instead of bug ids (vboctor) - closed.
- 0008429: [localization] fix miscellanious errors in the german translation files (vboctor) - closed.

[55 issues]

mantisbt - 1.1.0a4 (Released 2007-08-01) View Issues ]
========================================

This is the fourth alpha release for Mantis 1.1.0. It is likely to be the last alpha. The next release is planned to be an rc1 release with which we will branch the code and implement a feature freeze. This release has more than 100 features and bug fixes including addition of MantisConnect SOAP API, Twitter integration, permalink filters, MediaWiki integration, custom relationships, more reporting in summary page, project info page, 6 security fixes and a lot of other fixes and improvements. It is a recommended upgrade for all 1.1.0aX installations.

- 0005544: [db mssql] MSSQL APPLICATION ERROR 0000401 When Uploading Files (grangeway) - closed.
- 0007140: [db mssql] Upload File Less than 8 K (grangeway) - closed.
- 0007912: [db mssql] Time tracking doesn't work- SQL syntax error (grangeway) - closed.
- 0008220: [db mssql] New summary item contains invalid sql (giallu) - closed.
- 0007849: [custom fields] filters on custom date field causes SQL error (giallu) - closed.
- 0007871: [bugtracker] Move "Add Note" pane below previous notes (giallu) - closed.
- 0008130: [relationships] Custom relationships (grangeway) - closed.
- 0008002: [custom fields] Unable to report issue. Error "data too long" on custom field name (grangeway) - closed.
- 0008091: [csv] csv_export doesn't work when project name contains accentuated characters (vboctor) - closed.
- 0002996: [other] page link from email (in browser) - display more than "access denied" (grangeway) - closed.
- 0008154: [security] Port: CVE-2007-3215: PHPMailer vulnerability (thraxisp) - closed.
- 0008164: [security] Potential URL redirection flaw in set_project.php (grangeway) - closed.
- 0008165: [security] Potential URL redirection flaw in account_prefs_reset.php (grangeway) - closed.
- 0008166: [security] Potential URL redirection flaw in permalink_page.php (grangeway) - closed.
- 0008180: [security] Potential URL redirection flaw in login.php (grangeway) - closed.
- 0008181: [security] Display of database error message could be used to generate Cross site scripting issue (grangeway) - closed.
- 0006725: [filters] Filtering on "duplicate of" fails while "has duplicate" works (giallu) - closed.
- 0006772: [other] Bugnote ids are numeric, which is not valid HTML (giallu) - closed.
- 0006782: [sql] MantisBT should do "SET NAMES $charset" on connect to database (vboctor) - closed.
- 0007125: [bugtracker] Application Error #200 (grangeway) - closed.
- 0007842: [bugtracker] File attachment permissions (giallu) - closed.
- 0007885: [other] System logging constants (vboctor) - closed.
- 0007895: [bugtracker] Recently Visited when logged in as Anonymous shows issues i have not visited (giallu) - closed.
- 0007907: [installation] Allow using system adodb (vboctor) - closed.
- 0007938: [rss] Replace non free RSS creation class (vboctor) - closed.
- 0007944: [time tracking] 'Update Perfs' error in 1.1.0a3 (vboctor) - closed.
- 0007965: [time tracking] Time tracking information not shown on email notifications (vboctor) - closed.
- 0008044: [bugtracker] Edit/Delete bugnote buttons missing (giallu) - closed.
- 0008150: [bugtracker] Summary By Date could show also resolved bugs count (giallu) - closed.
- 0008174: [bugtracker] & is displayed as & stopping us from using Unicode Characters (grangeway) - closed.
- 0008120: [installation] all the files and directories has permission 777 in mantis-1.0.8.tar.gz (vboctor) - closed.
- 0007531: [bugtracker] Get a wrong (?) error message by upload a big file (grangeway) - closed.
- 0007931: [time tracking] $g_time_tracking_hours config option is never used (davidnewcomb) - closed.
- 0007985: [administration] Database Schema that is more up-to-date than code is reported as out-of-date (vboctor) - closed.
- 0007984: [bugtracker] Wrong default value for additional info during report (vboctor) - closed.
- 0007986: [custom fields] Removing a custom field to project link from manage_custom_field_edit_page.php returns to wrong page (vboctor) - closed.
- 0007987: [custom fields] Projects that a custom field can be linked to in manage_custom_field_edit_page.php shouldn't include ALL PROJECTS (vboctor) - closed.
- 0007993: [filters] "Create Permalink" should show URL in a Mantis page (vboctor) - closed.
- 0005333: [other] Invalid zip file core/adodb/adodb-time.zip in CVS (giallu) - closed.
- 0007992: [filters] "Create Permalink" should support custom fields (vboctor) - closed.
- 0008018: [bugtracker] Add configuration option to allow/disallow free text in platform, os, and os_build (vboctor) - closed.
- 0007981: [custom fields] Manage projects custom field: Link custom field to project Errors (vboctor) - closed.
- 0008016: [email] Check Email broken in 1.1.0a3 (vboctor) - closed.
- 0008023: [localization] [all lang] Wrong URL on summary (vboctor) - closed.
- 0008031: [localization] Update simplified chinese localization to 1.1.0a3 (giallu) - closed.
- 0008047: [db db2] DB2 Support (experimental) (vboctor) - closed.
- 0006217: [localization] [all lang] Wrong fIlename on download (vboctor) - closed.
- 0007947: [roadmap] when bulk assigning target version I get permission messages (vboctor) - closed.
- 0007982: [filters] "Create Permlink" not reliable (vboctor) - closed.
- 0008005: [bugtracker] items cannot be added to projects without categories (vboctor) - closed.
- 0008054: [other] Mediawiki integration (vboctor) - closed.
- 0008077: [email] Block use of disposable email addresses (vboctor) - closed.
- 0006773: [relationships] When cloning an issue, cannot make it "not related" to parent issue (vboctor) - closed.
- 0008051: [localization] [all lang] Wrong fIlename on print report (zakman) - closed.
- 0008084: [localization] Spelling mistake in value of string $s_this_bug file lang/strings_spanish.txt (zakman) - closed.
- 0008094: [administration] Managing versions / release schedule accross multiple projects. (vboctor) - closed.
- 0008105: [time tracking] Total time on billing page (vboctor) - closed.
- 0003477: [bugtracker] print_mantis_error() function does not display msg. (grangeway) - closed.
- 0004831: [installation] accessing mantis webserver through a proxy websserver (vboctor) - closed.
- 0008067: [bugtracker] show status legend on top AND bottom (zakman) - closed.
- 0008113: [localization] Error typo $s_signup_link in Spanish traslation ..... (zakman) - closed.
- 0008115: [integration] Implement Twitter Integration (vboctor) - closed.
- 0003902: [bugtracker] all logins fail with "Cannot modify header information" (grangeway) - closed.
- 0005138: [email] Bugnote Id doesn't appear in emails (vboctor) - closed.
- 0007417: [documentation] operating mysql user needs DELETE privilege (grangeway) - closed.
- 0007928: [bugtracker] print_column_eta function missing (vboctor) - closed.
- 0008131: [upgrade] install/upgrade tries to use "set schema" on a non db2 installation. (vboctor) - closed.
- 0008144: [administration] Remove obsolete CSS edit tool (vboctor) - closed.
- 0002950: [bugtracker] Hide Edit or Delete Profile when not needed (grangeway) - closed.
- 0007255: [rss] APPLICATION WARNING #user_get_field() for NO_USER (grangeway) - closed.
- 0008147: [bugtracker] 'continue' while outside loop in function print_news_string_by_news_id() (grangeway) - closed.
- 0006116: [rss] "Issues" RSS feed doesn't work when $g_anonymous_account = '' (grangeway) - closed.
- 0007487: [graphs] wrong title of dependency-graph (grangeway) - closed.
- 0007548: [relationships] Status is underlined using a deprecated HTML element (giallu) - closed.
- 0008111: [bugtracker] No space between date and username in email notifications (grangeway) - closed.
- 0008159: [scripting] Provide MantisConnect webservice out of the box as the Mantis SOAP API (vboctor) - closed.
- 0008168: [localization] german localisation in the current installation at www.mantisbt.org/bug (giallu) - closed.
- 0007733: [ldap] when using LDAP auth blank page upon login if LDAP extension not loaded (grangeway) - closed.
- 0008103: [bugtracker] Cannot modify the bugnote order. (giallu) - closed.
- 0008176: [email] Email Server offline causes a delay in mantis interface (grangeway) - closed.
- 0006063: [scripting] APPLICATION ERROR 0000401 on MSSQL while uploading files (grangeway) - closed.
- 0007138: [other] pages are not valid xhtml 1.0 transitional (giallu) - closed.
- 0008101: [feature] List of involved developers (vboctor) - closed.
- 0008195: [bugtracker] Create Project Info Page (vboctor) - closed.
- 0007346: [custom fields] Copy custom fields from one project to another (zakman) - closed.
- 0007681: [localization] [es] Full review of spanish translation (Bithunter) - closed.
- 0007961: [localization] Spanish translation (Bithunter) - closed.
- 0008177: [localization] Extra characters in lang/strings_spanish.txt (giallu) - closed.
- 0008201: [localization] Sync italian messages (giallu) - closed.
- 0006836: [filters] Switching to "Advanced Filters" (or "Simple Filters") forgets the ?filter=N setting (grangeway) - closed.
- 0007340: [webpage] my view: status percentage legend shown on top and not as stated (giallu) - closed.
- 0007597: [email] Notification e-mail contain no messages. (grangeway) - closed.
- 0008190: [bugtracker] Showing Access Level in Note details (giallu) - closed.
- 0008194: [roadmap] Roadmap and Changelog list nesting for parent/child issues (grangeway) - closed.
- 0006468: [filters] My View page incorrectly sets filters (grangeway) - closed.
- 0007730: [localization] [de] Translation change from "Aktualisieren" to "Bearbeiten" (zakman) - closed.
- 0007735: [filters] Filters are lost when clicking on page navigation (vboctor) - closed.
- 0007812: [bugtracker] Remove white box around jump button in main menu (zakman) - closed.
- 0006633: [change log] Editing a bug in advanced bug update page (grangeway) - closed.
- 0008121: [custom fields] Error message doesn't show field name after entering invalid value in custom field (zakman) - closed.
- 0008208: [bugtracker] Most popular bug table on summary page (giallu) - closed.
- 0008214: [change log] Change Log displays the version description as many times as the number of issues show (grangeway) - closed.
- 0008215: [sql] APPLICATION ERROR 401 on MySQL with file_upload_method = DISK (1.1.0a4-CVS) (giallu) - closed.
- 0008138: [other] Add more services to disposable email address checker (zakman) - closed.
- 0008221: [localization] Sync italian messages (vboctor) - closed.
- 0008224: [authentication] anonymous login is not automatic (vboctor) - closed.

[106 issues]

mantisbt - 1.0.8 (Released 2007-07-01) View Issues ]
======================================

Mantis 1.0.8 is a maintenance release for the 1.0.x stable releases branch. This release was mainly focused on fixing an application error that caused users to sometimes get a blank screen and some minor fixes that were requested by packagers for Linux distributions. It is a recommended updated for all 1.0.x users.

- 0007939: [rss] Port 7738: Replace non free RSS creation class (vboctor) - closed.
- 0008019: [other] Port 5333: Invalid zip file core/adodb/adodb-time.zip in CVS (giallu) - closed.
- 0008020: [installation] Port 7907: Allow using system adodb (giallu) - closed.
- 0008029: [localization] Spelling mistake in value of string $s_by_severity file lang/strings_spanish.txt (giallu) - closed.
- 0007902: [bugtracker] constant_inc is missing statement in 1.0.7 (vboctor) - closed.

[5 issues]

mantisbt - 1.1.0a3 (Released 2007-05-08) View Issues ]
========================================

This alpha release includes about 50 enhancements and bug fixes. One of the major highlights of this release is the time tracking feature. There is also enhanced management for custom fields, support for URL to express filter criteria, and many others. Similar to 1.1.0a2, the upgrade path to non-English installations is not yet implemented, hence, this alpha release SHOULD ONLY BE USED FOR ENGLISH installations. This release implements database schema changes and hence the install script will need to be run.

- 0007817: [db postgresql] text search with PostgreSQL is always case sensitive (vboctor) - closed.
- 0007758: [db mssql] Error 0000401 when trying to view summary_page.php (grangeway) - closed.
- 0004428: [time tracking] Time Tracking (davidnewcomb) - closed.
- 0007680: [signup] Successful Sign up should set login count to 1 (vboctor) - closed.
- 0007914: [bugtracker] Can't download attachments with IE over SSL (grangeway) - closed.
- 0007521: [email] wrong Message-ID when "Mail Queuing" is used. (vboctor) - closed.
- 0007795: [security] Port 7784: XSS vulnerabilities (vboctor) - closed.
- 0006244: [filters] Filter table has a little displacement in column (zakman) - closed.
- 0007008: [filters] "current project" in advanced filters always displays empty list (vboctor) - closed.
- 0007557: [filters] Dynamic filter selection (XMLHTTPRequest) broken when using IE7 (vboctor) - closed.
- 0007613: [filters] Advanced filters are not implemented until moving back to simple filters. (vboctor) - closed.
- 0007631: [bugtracker] Notes appear in the wrong order (vboctor) - closed.
- 0007636: [installation] PHP requirements incorrect (vboctor) - closed.
- 0007650: [roadmap] "Issues done" in roadmap should be included for each release, not for each project. (vboctor) - closed.
- 0007651: [roadmap] Support ability to set target release for multiple issues (vboctor) - closed.
- 0007658: [custom fields] Adding the option to manage the projects custum field will be added to. (vboctor) - closed.
- 0007662: [change log] Support ability to set fixed in version for multiple issues (vboctor) - closed.
- 0007663: [upgrade] Add support for unattended upgrades (vboctor) - closed.
- 0007682: [roadmap] Add progress bar to Roadmap (vboctor) - closed.
- 0007760: [other] Missing text.gif file (vboctor) - closed.
- 0007819: [sql] It works very slow (function diskfile_is_name_unique) (vboctor) - closed.
- 0007875: [custom fields] Port 7774: custom fields not stored correctly in bug history (vboctor) - closed.
- 0007921: [localization] Add Greek UTF-8 translation (vboctor) - closed.
- 0007645: [localization] [de] Translation for new Roadmap feature (achumakov) - closed.
- 0007648: [localization] [de] Translation change from "Wirklicher Name" to "Vollständiger Name" (ryandesign) - closed.
- 0007686: [roadmap] Update "target version" in all entries field after changing the target version strings (vboctor) - closed.
- 0007677: [localization] [ru] Russian language translation patch (achumakov) - closed.
- 0007683: [localization] [it] Little fixes and update of strings_italian.txt (achumakov) - closed.
- 0007685: [localization] [de] Localization strings for target release (achumakov) - closed.
- 0007689: [localization] Little fixes and update of strings_italian.txt (achumakov) - closed.
- 0006830: [customization] custom_function_override_issue_delete_notify and custom_function_override_issue_update_notify are not being triggered (vboctor) - closed.
- 0007794: [security] Port 7772: Email notifications bypass security on custom fields (vboctor) - closed.
- 0007801: [bugtracker] Category field should be empty and required (vboctor) - closed.
- 0007811: [other] Reporter name is not crossed out for disabled users on update pages (vboctor) - closed.
- 0007816: [bugtracker] Excel export needs htmlspecialchars() on description, steps_to_reproduce, additional_info (vboctor) - closed.
- 0007468: [bugtracker] Mantis displays one bug 10 times in My View 'monitored by me' list (vboctor) - closed.
- 0007813: [other] logging_api.php does not need the require_once call (zakman) - closed.
- 0007545: [administration] config values are not escaped (zakman) - closed.
- 0007823: [change log] APPLICATION ERROR #1100 Issue 0 not found in change_log page with access-level 'reporter' (zakman) - closed.
- 0007546: [email] patch allowing real name in From: header (zakman) - closed.
- 0007653: [relationships] Html tags in issue title are not escaped when shown in "relationship" area (vboctor) - closed.
- 0007667: [feature] Use $_GET parameters instead of $_POST for searches (vboctor) - closed.
- 0007900: [customization] Provide an easy mechanism to extend custom group actions (vboctor) - closed.
- 0007901: [bugtracker] Implement the "Add Note" group action (vboctor) - closed.
- 0007908: [filters] Support filtering by Platform, OS, OS Version (vboctor) - closed.
- 0007909: [administration] Implement auto-complete for Platform, OS and OS Version (vboctor) - closed.
- 0007936: [time tracking] Unnecessary core/bugnote_stats_api.php (grangeway) - closed.
- 0007770: [graphs] Antialias disable (grangeway) - closed.
- 0007925: [bugtracker] Access level is displayed twice in "login info" if realname is not set (grangeway) - closed.
- 0007131: [change log] Skip Blank Changelogs (grangeway) - closed.
- 0007514: [administration] wrong variable used in user_api.php (grangeway) - closed.

[51 issues]

mantisbt - 1.1.0a2 (Released 2006-12-08) View Issues ]
========================================

In this alpha release, localization files has been changed to all use the UTF-8 encoding. This allows the use of several languages within the same Mantis instance. The upgrade path to non-English installations is not yet implemented, hence, this alpha release SHOULD ONLY BE USED FOR ENGLISH installations. Among the major updates is the roadmap feature. There has been a database schema changes since 1.1.0a1 release, hence, the install script will need to be executed.

- 0006566: [localization] [patch] Update for strings_dutch.txt (siebrand) - closed.
- 0008178: [localization] Missing $s_status_enum_string values in lang/strings_spanish.txt (Bithunter) - closed.
- 0007639: [other] Revert back to mantisbt.org (vboctor) - closed.
- 0003160: [bugtracker] Please use ISO dates in this installation (achumakov) - closed.
- 0006724: [custom fields] CVE-2006-6574: Issue history ignores custom field read/write access (thraxisp) - closed.
- 0006721: [bugtracker] Can't set an sticky issue to unsticky (vboctor) - closed.
- 0007429: [bugtracker] display wiki link when $g_wiki_enable = OFF in config_*.php (vboctor) - closed.
- 0007436: [bugtracker] Detect missing attachments in case of DISK file upload method (vboctor) - closed.
- 0006529: [bugtracker] default.css doesn't validate (vboctor) - closed.
- 0007375: [localization] Italian UTF8 localization file (vboctor) - closed.
- 0007437: [bugtracker] Add recently visited issues to bug_change_status_page.php (vboctor) - closed.
- 0007448: [localization] [all lang] Unlocalizable text (achumakov) - closed.
- 0007449: [localization] Hard-coded capitalization in stats page breaks localization (vboctor) - closed.
- 0007462: [bugtracker] bugnote_delete.php redirection fails again (vboctor) - closed.
- 0004988: [feature] Private bug notes/relationships in "issue history" (thraxisp) - closed.
- 0006726: [custom fields] Access level read in Issue History not used (thraxisp) - closed.
- 0005050: [custom fields] Custom Fields display in bug history (thraxisp) - closed.
- 0007317: [other] Issue History (thraxisp) - closed.
- 0007345: [bugtracker] Bug history shows records of private notes. (thraxisp) - closed.
- 0007364: [security] Custom field visible in history independent from user role (thraxisp) - closed.
- 0003375: [security] Bughistory bypasses security on custom fields (thraxisp) - closed.
- 0005716: [localization] [de] New german lang strings (achumakov) - closed.
- 0007396: [localization] [hu] SYSTEM WARNING: charset `iso-8859-2' not supported, assuming iso-8859-1 (achumakov) - closed.
- 0006494: [webpage] charset iso-8859-2 not supported (achumakov) - closed.
- 0006410: [localization] [CJK] Email address detecting error when text in non-latin language. (achumakov) - closed.
- 0007167: [localization] [all lang] feeds in utf-8 are invalid xml (achumakov) - closed.
- 0007490: [localization] update strings_catalan.txt (achumakov) - closed.
- 0007502: [localization] [all lang] Dates should use ISO format by default (achumakov) - closed.
- 0005218: [customization] Bad default date format (achumakov) - closed.
- 0005163: [security] Default value for $g_bug_reminder_threshold should be higher than "reporter" (vboctor) - closed.
- 0007526: [localization] japanese_utf8 is more suitable than japanese_sjis ($g_language_auto_map) (vboctor) - closed.
- 0005766: [relationships] Graphviz Error on WIndows (grangeway) - closed.
- 0004711: [roadmap] Create roadmap from feature requests in versions (vboctor) - closed.
- 0007638: [email] When a queued email causes an error, it can hold up others mails (vboctor) - closed.
- 0007641: [other] New Mantis Logo (vboctor) - closed.

[35 issues]

mantisbt - 1.0.7 (Released 2006-10-28) View Issues ]
======================================
- 0007784: [security] XSS vulnerabilities (vboctor) - closed.
- 0007783: [filters] Port: Dynamic filter selection (XMLHTTPRequest) broken when using IE7 (vboctor) - closed.
- 0007772: [security] email notifications bypass security on custom fields (vboctor) - closed.
- 0007743: [security] Port: CVE-2006-6574 (vboctor) - closed.
- 0007774: [custom fields] custom fields not stored correctly in bug history (vboctor) - closed.

[5 issues]

mantisbt - 1.0.6 (Released 2006-10-28) View Issues ]
======================================

This is another maintenance release for the 1.0.x branch. It is recommended for all Mantis installations up to 1.0.5 to upgrade to this release.

- 0007412: [other] Update Mantis to refer to new website (vboctor) - closed.
- 0007466: [security] Port: 6719: Manager of a project can assign the Administrator role to a user. (vboctor) - closed.
- 0007467: [administration] Port 6637: Disabled projects don't appear under parent project (vboctor) - closed.
- 0007527: [localization] Port 7526: japanese_utf8 is more suitable than japanese_sjis ($g_language_auto_map) (vboctor) - closed.
- 0007470: [localization] [all lang] Port latest localization files from Mantis 1.1 to Mantis 1.0.x (vboctor) - closed.
- 0007530: [localization] Port:: New Languages: bulgarian, catalan, czech_utf8, french_utf8, italian_utf8, polish_utf8, russian_utf8, slovene_utf8 (vboctor) - closed.
- 0007543: [security] Port 5163: Default value for $g_bug_reminder_threshold should be higher than "reporter" (vboctor) - closed.

[7 issues]

mantisbt - 1.1.0a1 (Released 2006-09-11) View Issues ]
========================================

This is the alpha release for Mantis 1.1, it is not recommended for production use. The list of issues below are relative to Mantis 1.0.0rc2, hence, some of the fixes, specially the security ones, would be available in the 1.0.x releases. This release has about 100 enhancements and fixes, some of the highlights include wiki integration, web based configuration (general/per user/per project), customizing columns for view/print/csv issues can now be done through the web interface and can be per user or project, email queuing, and authenticated RSS feeds.

- 0005209: [db oracle] Bugtracker and Oracle (vboctor) - closed.
- 0006519: [db oracle] Error on opening Change Log (vboctor) - closed.
- 0006559: [db mssql] "Prune Accounts" function doesn't work with MS SQL (vboctor) - closed.
- 0006888: [db mssql] Changelog doesn't work on MS SQL (vboctor) - closed.
- 0006952: [db mssql] MS SQL Error on View Filters Page (vboctor) - closed.
- 0006957: [db mssql] installtion fails - administrator have no rights on db (vboctor) - closed.
- 0006977: [db mssql] PHP Notice: Only variables should be assigned by reference (vboctor) - closed.
- 0004102: [bugtracker] Category field should be empty by default or default specified (vboctor) - closed.
- 0006512: [bugtracker] Specify multiple relationships at one time (vboctor) - closed.
- 0006860: [bugtracker] Can send remonders to all recipients (thraxisp) - closed.
- 0007324: [filters] Sorting of issues list (filters) does not work after upgrade to MySQL 4.1.21 (vboctor) - closed.
- 0006953: [ldap] LDAPv3-Support (vboctor) - closed.
- 0007075: [bugtracker] Wiki integration with Mantis (vboctor) - closed.
- 0003150: [bugtracker] More flexible CSV export (vboctor) - closed.
- 0005816: [localization] Unlocalized field in view_issues page in russian language (achumakov) - closed.
- 0006049: [localization] ru: My account (achumakov) - closed.
- 0005685: [localization] Application error when sending notification (achumakov) - closed.
- 0006459: [security] Port 0006457: SQL Injection in manage user page (TKADV2005-11-002) (vboctor) - closed.
- 0006490: [security] Port Injection Vulnerabilities in Filters (TKADV2005-11-002) (thraxisp) - closed.
- 0006510: [security] Port: Additional XSS Vulnerabilities in Filter (thraxisp) - closed.
- 0006558: [security] XSS Vulnerability in manage_user (TKADV2005-11-002) (thraxisp) - closed.
- 0006564: [security] Port XSS Vulnerability in project documents (TKADV2005-11-002) (thraxisp) - closed.
- 0006570: [security] XSS Vulnerability in saved queries (TKADV2005-11-002) (thraxisp) - closed.
- 0006664: [security] Port 0006659: Cross site scripting vulnerability (thraxisp) - closed.
- 0006665: [security] Port 0006044: 'Return' _GET is not checked (thraxisp) - closed.
- 0006462: [security] Port 0006460: HTTP Header CRLF Injection (TKADV2005-11-002) (vboctor) - closed.
- 0006629: [security] Port: code injection (thraxisp) - closed.
- 0006667: [security] Adodb and phpmailer update .... (vboctor) - closed.
- 0006637: [administration] Disabled projects don't appear under parent project (vboctor) - closed.
- 0006719: [security] Manager of a project can assign the Administrator role to a user. (vboctor) - closed.
- 0007426: [other] Update Mantis to refer to new website (vboctor) - closed.
- 0006837: [localization] translations into spanish missing (vboctor) - closed.
- 0006866: [customization] User redirection after logging out (vboctor) - closed.
- 0006867: [filters] Call to undefined function: string_strip_tags() in query_store_page.php (thraxisp) - closed.
- 0006500: [feature] favicon (vboctor) - closed.
- 0006715: [installation] wrong display of a "validate_email = OFF"-warning (vboctor) - closed.
- 0006764: [localization] Typo in the dutch translation (vboctor) - closed.
- 0006824: [bugtracker] Need URL for bookmarking project page (vboctor) - closed.
- 0006886: [other] Export to Word and Excel times out if process takes more than 30 seconds (vboctor) - closed.
- 0006887: [administration] Updating user details and preferences should re-direct back to the same page (vboctor) - closed.
- 0006679: [other] Attachment download always opens "Save As" dialog even when a .png (thraxisp) - closed.
- 0006969: [administration] Show released flag on the version table in manage_proj_edit_page.php (vboctor) - closed.
- 0006972: [administration] Implement a Configuration Report to show all configs in database (vboctor) - closed.
- 0006973: [administration] Provide a way to set configuration via Mantis interface (vboctor) - closed.
- 0006974: [bugtracker] JS helper for the Jump text input box (vboctor) - closed.
- 0004019: [performance] Ability to update reporter increases update page size dramatically (vboctor) - closed.
- 0006252: [feature] Control over display size of inlined images (vboctor) - closed.
- 0007096: [administration] fields too short in table "mantis_bug_history_table" (vboctor) - closed.
- 0007109: [other] Add more file icons + move icons to images/fileicons/ (vboctor) - closed.
- 0006319: [customization] Option to customise columns on View Issues (vboctor) - closed.
 - 0007110: [customization] Option to customise columns on CSV export (vboctor) - closed.
- 0006701: [csv] Show custom fields in CSV export (vboctor) - closed.
- 0007088: [bugtracker] bugnote_delete.php redirection fails (vboctor) - closed.
- 0007111: [customization] Option to customise columns on Print Issues page (vboctor) - closed.
- 0007009: [change log] Fixed_in_version abbreviated hide version in Change Log (vboctor) - closed.
- 0007089: [bugtracker] Priority is not shown as text in "My view" (vboctor) - closed.
- 0007097: [email] Link in e-Mail notifications is broken. (vboctor) - closed.
- 0007103: [customization] Added column resolution in view issues wrong content (vboctor) - closed.
- 0007114: [bugtracker] tabindex in duplicate in bug_report_advanced_page (vboctor) - closed.
- 0007003: [csv] Error in version 1.1.0-CVS when exporting to CSV (vboctor) - closed.
- 0007076: [other] checkin.php needs array_unique() (vboctor) - closed.
- 0007212: [feature] Quick Full Text Search implementation (vboctor) - closed.
- 0007257: [bugtracker] Port: Fix for 0006869 / 0007034 removes quoted "?" from arguments (thraxisp) - closed.
- 0007333: [localization] access_levels_enum_string not translated in manage_config_workflow_page.php (vboctor) - closed.
- 0006253: [feature] Inlining of other types of files (vboctor) - closed.
- 0004460: [bugtracker] Show last visited N issues (vboctor) - closed.
- 0006627: [performance] Very slow performance when filing a new issue or adding a note (vboctor) - closed.
- 0007348: [customization] no print_column_date_submitted() in columns_api.php (vboctor) - closed.
- 0007356: [webpage] There is an extra "</a>" closing tag. (vboctor) - closed.
- 0005549: [other] Misc XHTML compliance fixes and more (patch) (ryandesign) - closed.
- 0006986: [bugtracker] Remember login always redirects to main_page.php (vboctor) - closed.
- 0003424: [bugtracker] Save login feature does not work (vboctor) - closed.
- 0004213: [rss] Request: Ability to log in to RSS feed via GET so that RSS would be available to registered users (vboctor) - closed.
- 0004641: [rss] RSS support for "View Issues" pages (vboctor) - closed.
- 0006488: [customization] Should be able to remove severity and reproducibility (vboctor) - closed.
- 0006757: [rss] Allow RSS syndication without allowing anonymous login. (vboctor) - closed.
- 0006987: [rss] Add $g_rss_enabled configuration option (vboctor) - closed.
- 0007012: [other] Word and Excel files are exported as _word and _excel (vboctor) - closed.
- 0007021: [upgrade] fixed_in_version is renamed to Fixed_in_version during database migration (vboctor) - closed.
- 0007026: [localization] Add Bulgarian Localisation (thanks to Alex Stanev) (vboctor) - closed.
- 0006843: [installation] is_writable never success in install.php (thraxisp) - closed.
- 0006868: [printing] wrong strpos function call (thraxisp) - closed.
- 0006869: [administration] bug in string_sanitize_url() (thraxisp) - closed.
- 0006921: [feature] Global Profiles list not sorted (vboctor) - closed.
- 0007000: [filters] SYSTEM WARNING: Argument 1 to array_multisort() is expected to be an array or a sort flag (vboctor) - closed.
- 0007006: [security] Login with disabled account possible (vboctor) - closed.
- 0007013: [installation] newbie admins may be redirected to blank page (vboctor) - closed.
- 0005408: [bugtracker] Suggestion: Tooltip (title) with text for priority icon (ryandesign) - closed.
- 0006292: [localization] Add Catalan language (vboctor) - closed.
- 0006248: [bugtracker] In menu lists, embedded spaces should be non-breaking (ryandesign) - closed.
- 0004746: [localization] New Korean UTF8 must be added to language list (ryandesign) - closed.
- 0005925: [email] Upgrade to PHPMailer 1.73 (vboctor) - closed.
- 0006355: [bugtracker] "Time Stats For Resolved Issues" is global, even if a specific project is selected (grangeway) - closed.
- 0006366: [bugtracker] Summary By Project: Open bugs (grangeway) - closed.
- 0006451: [installation] Upgrading Mantis packaging script (vboctor) - closed.
- 0006472: [bugtracker] Alternate method for selecting projects with many subprojects (jlatour) - closed.
- 0006453: [security] Make note private has no effect when resolving bug (thraxisp) - closed.
- 0006504: [bugtracker] Extended Project browser crash when selecting back "All Projects" (jlatour) - closed.
- 0006507: [filters] Allow filtering of issues in multiple (unrelated) projects (jlatour) - closed.
- 0006380: [filters] Filter returns private issues when it should not (thraxisp) - closed.
- 0006571: [filters] port Filters on custom fields failing (thraxisp) - closed.
- 0006647: [filters] Port 0006634: [filters] Filter does not work with profiles (vboctor) - closed.

[102 issues]

mantisbt - 1.0.5 (Released 2006-07-23) View Issues ]
======================================
- 0007301: [upgrade] Login page inaccessible after upgrade to 1.0.4 (thraxisp) - closed.

[1 issue]

mantisbt - 1.0.4 (Released 2006-07-22) View Issues ]
======================================
- 0007143: [other] Port: checkin.php needs array_unique() (vboctor) - closed.
- 0007051: [bugtracker] Fix for 0006869 / 0007034 removes quoted "?" from arguments (thraxisp) - closed.
- 0007298: [bugtracker] Port: bugnote_delete.php redirection fails (vboctor) - closed.
- 0007299: [bugtracker] Port: Save login feature does not work (vboctor) - closed.
- 0007300: [bugtracker] Port: Remember login always redirects to main_page.php (vboctor) - closed.

[5 issues]

mantisbt - 1.0.3 (Released 2006-05-07) View Issues ]
======================================

This is the third Mantis maintenance release to Mantis 1.0.0 release. The main focus of this release is to fix installation and MS SQL Server issues. It also includes one security fix.

- 0007030: [db mssql] Port: installtion fails - administrator have no rights on db (vboctor) - closed.
- 0007032: [db mssql] Port: Error on opening Change Log (vboctor) - closed.
- 0007039: [db mssql] Notice: Only variables should be assigned by reference in \core\adodb\adodb.inc.php on line 2931 (vboctor) - closed.
- 0007028: [db mssql] Port: "Prune Accounts" function doesn't work with MS SQL (vboctor) - closed.
- 0007029: [db mssql] Port: MS SQL Error on View Filters Page (vboctor) - closed.
- 0006979: [customization] View Bug page >> Status (thraxisp) - closed.
- 0007027: [upgrade] Port: fixed_in_version is renamed to Fixed_in_version during database migration (vboctor) - closed.
- 0007031: [installation] Port: is_writable never success in install.php (vboctor) - closed.
- 0007033: [printing] Port: wrong strpos function call (vboctor) - closed.
- 0007034: [bugtracker] Port: bug in string_sanitize_url() (vboctor) - closed.
- 0007035: [feature] Port: Global Profiles list not sorted (vboctor) - closed.
- 0007037: [security] Port: Login with disabled account possible (vboctor) - closed.
- 0007038: [filters] Port: SYSTEM WARNING: Argument 1 to array_multisort() is expected to be an array or a sort flag (vboctor) - closed.
- 0007041: [installation] Port: newbie admins may be redirected to blank page (vboctor) - closed.

[14 issues]

mantisbt - 1.0.2 (Released 2006-03-16) View Issues ]
======================================

bug fix release on 1.0.1

- 0006859: [security] Can send reminders to all recipients (thraxisp) - closed.
- 0006902: [security] XSS in mantis bug track system .... (thraxisp) - closed.
- 0006638: [sql] Can't submit issues after upgrading from 0.18.2 - SQL error #1364 (thraxisp) - closed.

[3 issues]

mantisbt - 1.0.1 (Released 2006-02-04) View Issues ]
======================================
- 0006668: [filters] Parse error while saving new filter: Call to undefined function: string_strip_tags() (thraxisp) - closed.
- 0006672: [installation] install.php assumes mysql extension, fails with mysqli extension (thraxisp) - closed.
- 0006722: [installation] Remaining mysqli_ install problems (ref. 0006672): mysqli_real_escape_string() expects parameter 1 to be link (thraxisp) - closed.

[3 issues]

mantisbt - 1.0.0 (Released 2006-02-04) View Issues ]
======================================

This is the stable Mantis 1.0.0 release.

- 0004416: [customization] Roadmap - Move configurations to database (thraxisp) - closed.
- 0005460: [administration] Critical Issues to Fix for Mantis 1.0.0 Release (vboctor) - closed.
- 0005289: [sql] Use ADODB DataDict for DB Creation / Upgrade (grangeway) - closed.
- 0006044: [security] 'Return' _GET is not checked (thraxisp) - closed.
- 0006650: [security] ADOdb can be exploited to execute arbitrary SQL code (vboctor) - closed.
- 0006659: [security] Cross site scripting vulnerability (thraxisp) - closed.
- 0006634: [filters] Filter does not work with profiles (vboctor) - closed.

[7 issues]

mantisbt - 0.19.5 (Released 2006-01-08) View Issues ]
=======================================
- 0006544: [security] XSS Vulnerability in project name (TKADV2005-11-002) (thraxisp) - closed.
- 0006556: [security] XSS Vulnerability in manage_user (TKADV2005-11-002) (thraxisp) - closed.
- 0006568: [security] XSS Vulnerability in saved queries (TKADV2005-11-002) (thraxisp) - closed.
- 0006542: [filters] [Filter By Custom Fields] Now i can't (thraxisp) - closed.
- 0006553: [filters] view_filter_page: Filter By Custom Fields (thraxisp) - closed.

[5 issues]

mantisbt - 1.0.0rc5 (Released 2005-12-13) View Issues ]
=========================================
- 0006436: [administration] code injection (thraxisp) - closed.
- 0006509: [security] Port: Additional XSS Vulnerabilities in Filter (thraxisp) - closed.
- 0006557: [security] XSS Vulnerability in manage_user (TKADV2005-11-002) (thraxisp) - closed.
- 0006563: [security] Port XSS Vulnerability in project documents (TKADV2005-11-002) (thraxisp) - closed.
- 0006569: [security] XSS Vulnerability in saved queries (TKADV2005-11-002) (thraxisp) - closed.
- 0006565: [filters] Filters on custom fields failing (thraxisp) - closed.
- 0006501: [filters] Categories can't be selected for filter-setting (thraxisp) - closed.
- 0006585: [documentation] don't see the documentation (thraxisp) - closed.
- 0006594: [bugtracker] config_flush_cache does not work correctly (thraxisp) - closed.

[9 issues]

mantisbt - 0.19.4 (Released 2005-12-13) View Issues ]
=======================================
- 0006420: [security] Injection Vulnerabilities in Filters (TKADV2005-11-002) (thraxisp) - closed.
- 0006460: [security] HTTP Header CRLF Injection (TKADV2005-11-002) (vboctor) - closed.
- 0006486: [security] Port XSS Vulnerability in filters (TKADV2005-11-002) (thraxisp) - closed.
- 0006508: [security] Additional XSS Vulnerabilities in Filter (thraxisp) - closed.
- 0006419: [security] File Upload Vulnerability (TKADV2005-11-002) (thraxisp) - closed.
- 0006457: [security] SQL Injection in manage user page (TKADV2005-11-002) (vboctor) - closed.

[6 issues]

mantisbt - 1.0.0rc4 (Released 2005-12-13) View Issues ]
=========================================
- 0006458: [security] Port 0006457: SQL Injection in manage user page (TKADV2005-11-002) (vboctor) - closed.
- 0006485: [security] XSS Vulnerability in filters (TKADV2005-11-002) (thraxisp) - closed.
- 0006489: [security] Port Injection Vulnerabilities in Filters (TKADV2005-11-002) (thraxisp) - closed.
- 0006421: [security] Private bugs show up in public RSS feed (vboctor) - closed.
- 0006461: [security] Port 0006460: HTTP Header CRLF Injection (TKADV2005-11-002) (vboctor) - closed.
- 0006379: [filters] Filter returns private issues when it should not (thraxisp) - closed.
- 0006432: [bugtracker] error processing does not work! (jlatour) - closed.
- 0006254: [localization] strings_korean_utf8.txt has UTF-8 byte-order marker (ryandesign) - closed.
- 0006268: [localization] strings_chinese_simplified_utf8.txt has UTF-8 byte-order marker (ryandesign) - closed.
- 0006304: [localization] [PATCH] Major overhaul of strings_dutch.txt (jlatour) - closed.
- 0006358: [localization] Updated Dutch localization (Wanderer) - closed.
- 0006474: [localization] Calls to htmlspecialchars should take into account the current charset (jlatour) - closed.
- 0006492: [security] Port 0006453: Make note private has no effect when resolving bug (thraxisp) - closed.

[13 issues]

mantisbt - 0.19.3 (Released 2005-10-11) View Issues ]
=======================================

This is a maintenance release that mainly contains security fixes. All 0.19.x are advised to upgrade
to this version.

- 0006330: [bugtracker] System warning in login_page.php when no new installation (vboctor) - closed.
- 0006332: [security] Port 0005751 to 0.19.3: Javascript XSS vulnerability (vboctor) - closed.
- 0006333: [security] Port 0005959 to 0.19.3: Cross Site Scripting Vulnerabilty in the mantis/view_all_set.php Script (vboctor) - closed.
- 0006334: [security] Port 0006097 to 0.19.3: user ID is cached indefinately (vboctor) - closed.
- 0006335: [security] Port 0006273 to 0.19.3: File Inclusion Vulnerability (vboctor) - closed.
- 0006336: [security] Port 0006275 to 0.19.3: SQL injection (vboctor) - closed.
- 0006331: [security] Port 0005247 to 0.19.3: Real email addresses are visible when using reminders (vboctor) - closed.

[7 issues]

mantisbt - 1.0.0rc3 (Released 2005-09-11) View Issues ]
=========================================
- 0006273: [security] File Inclusion Vulnerability (vboctor) - closed.
- 0006275: [security] SQL injection (vboctor) - closed.
- 0006234: [filters] Filter sometimes returns no results (thraxisp) - closed.
- 0006288: [filters] Patch against CVS HEAD for Saved filter problem with view_state (thraxisp) - closed.
- 0006295: [filters] Old filters and view_state problems. (thraxisp) - closed.
- 0006296: [filters] Filter sql includes unnecessary links to custom_field_string_table for date custom fields (thraxisp) - closed.
- 0006297: [filters] sorting on custom field, bring MySQL to deadlock loop (thraxisp) - closed.

[7 issues]

mantisbt - 1.0.0rc2 (Released 2005-09-11) View Issues ]
=========================================

A release candidate that has more than 50 issues fixed. It is recommended for all users with 1.0.0x releases to upgrade to this release.

- 0005998: [filters] Sorting by sponsorship no longer works (thraxisp) - closed.
- 0006001: [localization] Add chinese_simplified_utf8 localisation (vboctor) - closed.
- 0005969: [bugtracker] Incorrect recipients for notifications (thraxisp) - closed.
- 0006003: [bugtracker] Sponsoring need to be verified (thraxisp) - closed.
- 0006012: [bugtracker] Mantis redirects to install.php if MANTIS_CONFIG env var is used (vboctor) - closed.
- 0005861: [administration] APPLICATION ERROR 0000700 on manage_proj_edit_page.php?project_id=xx (thraxisp) - closed.
- 0006015: [administration] setting 'who can change notifications' fails (thraxisp) - closed.
- 0006027: [sponsorships] In view.php, 'sponsorship_total' was displayed. (thraxisp) - closed.
- 0006028: [localization] chinese_traditional & chinese_traditional_utf8 localisation (vboctor) - closed.
- 0006030: [localization] Update Japanese Localisations (euc, sjis, utf8) (vboctor) - closed.
- 0003634: [localization] wrong charset in error messages (jlatour) - closed.
- 0004127: [bugtracker] Unnecessary dash in title when window title is empty string (jlatour) - closed.
- 0006020: [sql] Database query failure - click on Docs link - MSSQL (grangeway) - closed.
- 0006052: [localization] Apply update to Spanish language provided by zylk.net (vboctor) - closed.
- 0006054: [installation] Bad call to print_test_result in admin/install.php (vboctor) - closed.
- 0005257: [relationships] Strange Error-Message: APPLICATION WARNING \#403: Database field 'status' not found (thraxisp) - closed.
- 0005932: [administration] Manage eMail notification access rigths (thraxisp) - closed.
- 0006021: [installation] Mantis installation issues under sql server (thraxisp) - closed.
- 0006053: [administration] How to delete all the "Project Specific Settings" from the "Workflow Thresholds" page ?? (thraxisp) - closed.
- 0006059: [documentation] MySQL 4.1.1 or later by default uses long passwords which don't work with php4 (thraxisp) - closed.
- 0005786: [filters] Strange behaviour when applying filter (thraxisp) - closed.
- 0006073: [installation] administrator account must not be created as protected (thraxisp) - closed.
- 0006077: [scripting] Still uninitialized values in core/user_pref_api.php (thraxisp) - closed.
- 0006078: [bugtracker] Assigning bugs via group action not working properly (thraxisp) - closed.
- 0006089: [localization] Setting default language to 'auto' fails (thraxisp) - closed.
- 0006093: [bugtracker] Additional views in My View page (thraxisp) - closed.
- 0004368: [administration] Login page doesn't redirect to followed link, if the first login attempt fails (ryandesign) - closed.
- 0005261: [bugtracker] Reproducing newlines and br tags when cloning (ryandesign) - closed.
- 0006091: [bugtracker] 'priority' selection is always ignored (thraxisp) - closed.
- 0006092: [bugtracker] CVS link gets mangled if filename is followed by a newline (ryandesign) - closed.
- 0006094: [filters] Filter lost when ordering on view_all_bug_page.php (thraxisp) - closed.
- 0006097: [security] user ID is cached indefinately (thraxisp) - closed.
- 0006100: [administration] Creating a new project shows "Create New Subproject" page (thraxisp) - closed.
- 0006098: [administration] bug_report*.php uses "handle_bug_threshold" to display the Assign To combo box? (instead of "update_bug_assign_threshold") (thraxisp) - closed.
- 0006108: [preferences] Changing Account Preferences generates APPLICATION ERROR #200 (thraxisp) - closed.
- 0006104: [filters] Filtering private issues: behavior depending on access level (thraxisp) - closed.
- 0006112: [bugtracker] user see the 'Assigned to' value while capability 'View Assigned To' have been disable (thraxisp) - closed.
- 0006115: [bugtracker] "$g_delete_attachments_threshold" not working (thraxisp) - closed.
- 0006130: [documentation] spell error in CVS Integration manual (thraxisp) - closed.
- 0006131: [documentation] Problem in installation sequence: offline page disappears. (thraxisp) - closed.
- 0006132: [documentation] [/code] visible (thraxisp) - closed.
- 0005336: [bugtracker] Summary does not combine categories (thraxisp) - closed.
- 0006139: [documentation] system logging documentation in config_defaults_inc.php (thraxisp) - closed.
- 0006140: [sql] MSSQL: Ambiguous column name when trying to open Summary page (thraxisp) - closed.
- 0006142: [sql] PostgreSQL: creation of user failed (thraxisp) - closed.
- 0005684: [other] Summary over projects evaluates wrong results (thraxisp) - closed.
- 0006118: [sql] Database query failure - click on Docs link - MySQL 3.23 (thraxisp) - closed.
- 0006164: [rss] RSS feed does not validate (ryandesign) - closed.
- 0006176: [customization] Cannot deselect everything on manage_config_email_page.php (thraxisp) - closed.
- 0005559: [bugtracker] Wrong dateformat displayed in issue history (thraxisp) - closed.
- 0006189: [security] List of users (in filter) visible for unauthorized users. (thraxisp) - closed.
- 0006213: [administration] Saving "Status to set auto-assigned issues to" don´t work (thraxisp) - closed.

[52 issues]

mantisbt - 1.0.0rc1 (Released 2005-07-23) View Issues ]
=========================================
- 0005928: [performance] Pre-cache the available projects speeds up every page significantly (thraxisp) - closed.
- 0005931: [administration] APPLICATION WARNING #300: String 'bugnote_order_' not found. (thraxisp) - closed.
- 0005959: [security] Cross Site Scripting Vulnerabilty in the mantis/view_all_set.php Script (thraxisp) - closed.
- 0005956: [security] Database system scanner via variable poisoning (vboctor) - closed.
- 0005974: [localization] Some fields are missing in dutch language (vboctor) - closed.
- 0006025: [localization] Updated Dutch localisation (Wanderer) - closed.
- 0005809: [sponsorships] Sponsorship should track payment state (thraxisp) - closed.
- 0005473: [other] Issue Status Percentage in My View incorrect when changed subprojects (thraxisp) - closed.
- 0005975: [bugtracker] My View page does not include Sub-Project item assigned to me (thraxisp) - closed.
- 0005687: [filters] Hide Status of "none" doesn't render properly (thraxisp) - closed.
- 0005689: [upgrade] After upgrading to 1.0.0a3 Mantis not working correct (thraxisp) - closed.
- 0005700: [filters] Hide Status of "none" doesn't render properly for old filters (thraxisp) - closed.
- 0005696: [bugtracker] Custom Field not shown in manage_custom_field_page.php after creation (thraxisp) - closed.
- 0005476: [documentation] [Access Level Problem] Can see all docs (thraxisp) - closed.
- 0005693: [localization] Use English language if a string is not found in other languages (vboctor) - closed.
- 0005703: [bugtracker] HTML layout problems (Table column numbers mismatch) (thraxisp) - closed.
- 0005712: [custom fields] Entered custom fields are not stored into the database at status change (thraxisp) - closed.
- 0005535: [filters] Date filters does not work (thraxisp) - closed.
- 0005719: [filters] System warning when trying to filter custom date field (thraxisp) - closed.
- 0005741: [bugtracker] PHP notice generated when a priority is not defined $g_status_icon_arr (vboctor) - closed.
- 0005742: [bugtracker] bugnote_add() checks access to current project rather than current issue. (vboctor) - closed.
- 0005743: [scripting] bugnote_add() doesn't allow specifying an author other than the current logged in user (vboctor) - closed.
- 0005724: [bugtracker] "Report Issue" page has no menu bar (vboctor) - closed.
- 0005725: [csv] Fatal error: Maximum execution time of 30 seconds exceeded during CSV export (vboctor) - closed.
- 0005745: [csv] CSV export is corrupt (vboctor) - closed.
- 0005756: [localization] Support for French Canadian localization (vboctor) - closed.
- 0005720: [filters] Sort doesnt work (thraxisp) - closed.
- 0005751: [security] Javascript XSS vulnerability (thraxisp) - closed.
- 0005769: [other] Inconsistency in file upload logic (thraxisp) - closed.
- 0005771: [customization] Support custom actions in issue group actions (vboctor) - closed.
- 0005773: [localization] Add a way to test all localisation files for syntax errors (vboctor) - closed.
- 0005772: [localization] Add Icelandic localisation (vboctor) - closed.
- 0005775: [customization] Support custom actions in the issue view page (vboctor) - closed.
- 0005792: [feature] Add a configuration variable for "default additional information" value (vboctor) - closed.
- 0005793: [feature] Add a configuration variable for "steps to reproduce" field (vboctor) - closed.
- 0005795: [other] Enhancements relating to SVN integration (vboctor) - closed.
- 0005788: [filters] Related to filter is cleaned after changing e.g. Assigned To (thraxisp) - closed.
- 0005432: [bugtracker] Viewing a bug should change the "current project" (thraxisp) - closed.
- 0005297: [custom fields] performance problem when filtering on custom fields (thraxisp) - closed.
- 0005808: [filters] The reporter field in advance filter is not ordered corectly (thraxisp) - closed.
- 0005754: [rss] RSS Feed does not validate (vboctor) - closed.
- 0005811: [localization] Simplified Chinese Language for 1.0.0a3 (vboctor) - closed.
- 0005817: [rss] Escape hyperlinks in rss feeds (vboctor) - closed.
- 0005818: [rss] Don't use relative urls for issue links and issue notes links (vboctor) - closed.
- 0005819: [rss] Don't include issue status in rss issue links since it may be obsolete (vboctor) - closed.
- 0005523: [feature] add option to put filter at bottom of display, or eliminate entirely (vboctor) - closed.
- 0005791: [administration] Projects marked as "private" can still be seen in Add as Subproject dropdown (thraxisp) - closed.
- 0005844: [scripting] The order of issue notes is random if submitted timestamp is the same (vboctor) - closed.
- 0005848: [bugtracker] Allowing preview attachment with jpeg extension (vboctor) - closed.
- 0005697: [filters] Simple filter on [Reporter] doesn't work any more (thraxisp) - closed.
- 0005858: [upgrade] Upgrade from 0.17.5 to 1.0.0a3 fails (thraxisp) - closed.
- 0005869: [customization] Custom button with issue id in the link (vboctor) - closed.
- 0005870: [sponsorships] Error when setting a sponsorship on an issue (vboctor) - closed.
- 0005918: [bugtracker] Update issue Pen Icon always displayed in my_view_page even if not allowed (thraxisp) - closed.
- 0005927: [performance] null checking failure in user_get_accessible_subprojects (user_api.php) (thraxisp) - closed.
- 0005522: [other] Emailed activation codes are always incorrect (thraxisp) - closed.
- 0005948: [performance] user_pref initialization makes many database queries (thraxisp) - closed.
- 0005889: [sql] What's with all these queries (thraxisp) - closed.
- 0005952: [preferences] Resetting preferences causing an error in lang_load() (vboctor) - closed.
- 0005953: [bugtracker] Error "issue 0 not found" on report pages (vboctor) - closed.
- 0004439: [bugtracker] Mailto links include an unneccessary 'target="_new"' (grangeway) - closed.
- 0004927: [filters] On MSSQL sorting and filtration does not work. (grangeway) - closed.
- 0005909: [filters] Can't sort or filter using MSSQL (grangeway) - closed.
- 0005919: [sql] ODBC_MSSQL driver does not format escape characters correctly (grangeway) - closed.
- 0005949: [bugtracker] signing up is a bit too restrictive (thraxisp) - closed.
- 0005957: [administration] check.php generates php warnings when checking obselete configs (thraxisp) - closed.
- 0005655: [bugtracker] Problems creating a new account (similar to 0005653) (thraxisp) - closed.
- 0005708: [bugtracker] HTML layout problems (Small buttons in bugnotes, et al) (vboctor) - closed.
- 0005934: [rss] Rss fails when XML has '&' in it (vboctor) - closed.
- 0005939: [administration] No double Real Names are allowed (thraxisp) - closed.
- 0005962: [administration] undefined function: config_get_global() when upgrading string escaping (thraxisp) - closed.
- 0005963: [administration] system_utils.php has refresh view that refers to string escaping (vboctor) - closed.
- 0005972: [filters] Sorting using column titles is broken (thraxisp) - closed.
- 0005976: [bugtracker] Add a "Project: " label next to the switch project combobox (vboctor) - closed.
- 0005978: [administration] "Remove All" users no longer works on manage project page (vboctor) - closed.
- 0005979: [sponsorships] Enhancements to My Sponsorship page (thraxisp) - closed.
- 0005980: [bugtracker] View submitted issue after reporting should open in same window (vboctor) - closed.
- 0005671: [printing] Summary printing to excel and word empty report (thraxisp) - closed.
- 0005943: [filters] I can't print some selected Issues (only all) (thraxisp) - closed.
- 0005768: [localization] Missing new string for strings_german.txt added (vboctor) - closed.
- 0005914: [filters] My View doesnt list assigned bugs of child projects (thraxisp) - closed.
- 0005888: [bugtracker] error in user_get_accessible_projects (thraxisp) - closed.
- 0005451: [localization] Danish translation not updatet in CVS (vboctor) - closed.
- 0005997: [localization] Add chinese_traditional_utf8 localization (vboctor) - closed.

[84 issues]

mantisbt - 1.0.0a3 (Released 2005-04-25) View Issues ]
========================================
- 0004245: [email] Automatic (CATEGORY) assigned issue (thraxisp) - closed.
- 0005506: [printing] code appears in excel view... (thraxisp) - closed.
- 0005634: [rss] Ability to get the issues feed sorted by last_updated or submit_date (vboctor) - closed.
- 0005635: [rss] Support for feeds for filters (vboctor) - closed.
- 0005568: [webpage] Can't update Issues on mantisbt.org (thraxisp) - closed.
- 0003315: [bugtracker] Allow user to add custom fields in Reports, Exports and Bugs View (vboctor) - closed.
- 0004828: [bugtracker] workflow: defaults for status values (thraxisp) - closed.
- 0003384: [bugtracker] $g_path setting in config_inc.php will NOT override default (thraxisp) - closed.
- 0004762: [bugtracker] Preformatted text is misbehaving. (thraxisp) - closed.
- 0004925: [other] "Not an issue" resolution is extremely WRONG term (thraxisp) - closed.
- 0005148: [filters] DHTML Filters do not work with Firefox 1.0 (only IE) (thraxisp) - closed.
- 0005500: [filters] which button to update the filter ? (thraxisp) - closed.
- 0005503: [localization] Updated language dutch file for 1.0.0a2 (Wanderer) - closed.
- 0005513: [bugtracker] on close issue, don`t set resolution = resolve (thraxisp) - closed.
- 0005520: [localization] Error in strings_russian.txt (Wanderer) - closed.
- 0003907: [rss] Bad RSS link on http://bugs.mantisbt.org/ [^] (vboctor) - closed.
- 0005046: [rss] Unreadable RSS data (vboctor) - closed.
- 0005507: [bugtracker] Reporting page doesn't render... (thraxisp) - closed.
- 0005508: [bugtracker] Summary -> Access denied. (thraxisp) - closed.
- 0005512: [rss] "XML Parsing Error: undefined entity" in issues rss feed (vboctor) - closed.
- 0005526: [bugtracker] current_user_is_anonymous() returns true when it should not (vboctor) - closed.
- 0005528: [rss] Issue category in the issues rss was set to the issue summary (vboctor) - closed.
- 0003756: [other] Opening webpages in same window (thraxisp) - closed.
- 0005304: [bugtracker] "duplicate", "unable to duplicate" -> "unable to reproduce" (thraxisp) - closed.
- 0005446: [administration] Configuration control should show defaults (thraxisp) - closed.
- 0005480: [bugtracker] Change wording of note in workflow transitions management interface when editing rules for all projects (thraxisp) - closed.
- 0005492: [feature] APPLICATION ERROR #500 after updated from 0.19.2 (thraxisp) - closed.
- 0005514: [administration] unable to manage inactive Projects (thraxisp) - closed.
- 0005519: [localization] Missing localization in manage_config_email_page.php (thraxisp) - closed.
- 0005527: [bugtracker] Acknowledgement does not work with custom fields (thraxisp) - closed.
- 0005534: [email] not sending email on new (thraxisp) - closed.
- 0005540: [sql] PostgreSQL script does not match MySQL script (vboctor) - closed.
- 0005545: [relationships] On resolve issue can set the "Duplicate ID" with the ID of current issue (thraxisp) - closed.
- 0005546: [other] Invalid HTML: missing <tr></tr> in bugnote_view.inc.php (patch) (vboctor) - closed.
- 0005547: [other] Problem with non-escaped "</" in inline JavaScript code (patch) (vboctor) - closed.
- 0005554: [administration] Implement an administration feature for database statistics (vboctor) - closed.
- 0005556: [scripting] Separate logic from GUI in file_list_attachments() (vboctor) - closed.
- 0005569: [filters] +/- button on Filter does not remember. (thraxisp) - closed.
- 0005572: [filters] +/- button to show/hide filters doesn't work with IE5.5 (thraxisp) - closed.
- 0005589: [other] [HELP] Can't acces to uploaded files :-( (thraxisp) - closed.
- 0005598: [filters] Add filter for profile (jlatour) - closed.
- 0005599: [filters] Version filters do not show versions in subprojects (jlatour) - closed.
- 0003729: [bugtracker] When using the browser's back button, the form is cleared out. (thraxisp) - closed.
- 0005533: [installation] Problem Downloading The Uploaded Documents (thraxisp) - closed.
- 0005606: [bugtracker] Support prefetching of web page for Google Web Accelerator and Browsers (vboctor) - closed.
- 0005610: [bugtracker] Actiongroup assign action: wrong permissions check (thraxisp) - closed.
- 0005621: [bugtracker] Are you sure you wish to delete this file? --> "Remove User" (masc) - closed.
- 0005622: [localization] There is a wrong chartset in strings_croatian.txt (vboctor) - closed.
- 0005623: [localization] Dutch translation (Wanderer) - closed.
- 0004000: [bugtracker] Cannot export more than 50 items (masc) - closed.
- 0004432: [performance] Allow caching of attached files (thraxisp) - closed.
- 0004899: [filters] [ Custom Fields ] Display in "all projects" (thraxisp) - closed.
- 0005169: [printing] Exporting to Exel file - field names are not selected by language (masc) - closed.
- 0005639: [printing] Sort is not working in print_all_bug_page.php (vboctor) - closed.
- 0005652: [administration] email logging fails in email_notify_new_account (masc) - closed.
- 0005653: [bugtracker] Account signup confirmation (masc) - closed.
- 0005587: [custom fields] Custom field date type reset to blank (thraxisp) - closed.
- 0005678: [administration] Hide empty sections in manage_user_page.php (vboctor) - closed.
- 0005680: [customization] Unknown fields are not handled correctly in View Issues (vboctor) - closed.

[59 issues]

mantisbt - 1.0.0a2 (Released 2005-04-25) View Issues ]
========================================

This is the second alpha release for Mantis 1.0.0, it mainly concentrates on fixing installation and upgrade bugs. It also adds support for RSS news feeds for issues for all projects or specific project.

- 0004722: [administration] Move email settings into Mantis interface (thraxisp) - closed.
- 0004564: [webpage] an issue of own mantis database defends complete display (thraxisp) - closed.
- 0005469: [customization] Updated language dutch file (Wanderer) - closed.
- 0005453: [sponsorships] Sponsorship total is missing from view all bugs (thraxisp) - closed.
- 0005450: [sql] db_generate.sql gives syntax errors (thraxisp) - closed.
- 0005456: [upgrade] PRIMARY KEY not null error on upgrade (thraxisp) - closed.
- 0005457: [installation] At least MySQL 4.1.x for this version (thraxisp) - closed.
- 0005461: [localization] lang directory / strings_french.txt : error in $s_account_reset_msg (vboctor) - closed.
- 0005207: [performance] Improve performance of "My View" (thraxisp) - closed.
- 0005471: [bugtracker] view_all_bug_page.php not working (thraxisp) - closed.
- 0005472: [localization] Some hardcoded text in 1.0.0a1 (thraxisp) - closed.
- 0005483: [bugtracker] Auto-linked URLs have target="blank", should have target="_blank" (thraxisp) - closed.
- 0005422: [email] Error when Update Configuration is pressed on Email Configuration Page (thraxisp) - closed.
- 0005485: [change log] Change log only shows users reported issues, even if user is an admin if limit_reporters is set (thraxisp) - closed.
- 0005470: [administration] Copyright date in footer incorrect (vboctor) - closed.
- 0002686: [bugtracker] switch project often goes back to the main page (thraxisp) - closed.
- 0004578: [installation] Can't delete administration account without email/name (thraxisp) - closed.
- 0005126: [email] Email notification about resolved related issue contains duplicated title (thraxisp) - closed.
- 0005502: [rss] Implement an RSS feed for issues (vboctor) - closed.

[19 issues]

mantisbt - 1.0.0a1 (Released 2005-04-18) View Issues ]
========================================
- 0005839: [webpage] entered URL (from browser) inserted gets displayed malformed/uncallable (grangeway) - closed.
- 0003169: [sql] Database dont use indexes. (grangeway) - closed.
- 0004527: [customization] Want to customize just $g_db_table_prefix, not $g_mantis_*_table (thraxisp) - closed.
- 0004289: [installation] Check various file size parameters (thraxisp) - closed.
- 0005068: [custom fields] Custom fields showing up unexpectedly while doing "Change Status to:" (vboctor) - closed.
- 0004937: [bugtracker] Mantis 1.0.0a1 Release (vboctor) - closed.
 - 0005319: [localization] Syntax error in strings_japanese_sjis.txt on line 1085 (Wanderer) - closed.
 - 0004315: [filters] Show filter without reloading whole page (thraxisp) - closed.
 - 0004982: [administration] Mantis fails converting nested URLs into hyperlinks (bpfennig) - closed.
 - 0004986: [graphs] Graphs should cache data (thraxisp) - closed.
 - 0004929: [graphs] Inscriptions on the graphs on Apache for Microsoft Windows for CP1251 do not hatch. (thraxisp) - closed.
 - 0004992: [bugtracker] Use of is_uploaded_file() in file_add() prevents use in importer PHP script. (thraxisp) - closed.
 - 0004994: [graphs] Two "system font directories" in configuration (bpfennig) - closed.
 - 0004960: [customization] Show parameter name in gpc_api.php error messages (thraxisp) - closed.
 - 0005013: [bugtracker] html_status_percentage_legend() generates notices (vboctor) - closed.
 - 0004664: [other] Can't upload project documents for "All Projects" (masc) - closed.
 - 0004996: [sql] "Open and assigned to me" shows wrong number (thraxisp) - closed.
 - 0004551: [feature] Sticky issues (bpfennig) - closed.
 - 0004998: [filters] Can't use Date Filters in the filters screens (thraxisp) - closed.
 - 0005031: [localization] Typos in Norwegian translation (Wanderer) - closed.
 - 0004983: [administration] HTML should not be allowed in the Summary field, even if it is part of the allowed HTML list in the configuration (thraxisp) - closed.
 - 0004976: [email] Relationship section uses the language of the person who did the action (thraxisp) - closed.
 - 0004952: [scripting] some issues with script authentication support (thraxisp) - closed.
 - 0004978: [feature] g_notify_flags + reopened and owner (thraxisp) - closed.
 - 0004979: [printing] Images not shown while printing bug details (bpfennig) - closed.
 - 0004971: [graphs] Bargraphs show lines - this is incorrect (thraxisp) - closed.
 - 0004959: [bugtracker] "Delete Issue" should show information identifying issue to be deleted (bpfennig) - closed.
 - 0004314: [feature] Bug status percentage (bpfennig) - closed.
 - 0004962: [other] URL not parsing after ? in any link (bpfennig) - closed.
 - 0004787: [bugtracker] Issue Summary is marked as updated when it contains 'quotes' or "double quotes" (thraxisp) - closed.
 - 0005434: [sql] More SELECT DISTINCT (in filter_api.php) (vboctor) - closed.
 - 0005023: [localization] Typo in french localization - "bug courrant" should be "bug courant" (Wanderer) - closed.
 - 0004853: [filters] Add the ability to filter by relationship (thraxisp) - closed.
 - 0004589: [administration] Administrator cannot manage projects to which he/she is assigned. (thraxisp) - closed.
 - 0005113: [relationships] include duplicate-of and has-duplicate relationship options when creating a clone (thraxisp) - closed.
 - 0005416: [custom fields] mandatory custom field: problem when updating an "Display when Reporting Issues" only bug (thraxisp) - closed.
 - 0005445: [administration] You can delete the last administrator in the system. (thraxisp) - closed.
 - 0004964: [bugtracker] Backdoor for assigning sponsored issues (bpfennig) - closed.
- 0005398: [other] URL-Quoting in bugnotes doesn't work (grangeway) - closed.
- 0004896: [documentation] Updating project documentation entry needs upload (masc) - closed.
- 0004950: [administration] "Prune Accounts" should confirm before deleting user accounts (masc) - closed.
- 0003512: [graphs] I have alot of categories and several category graphs show up very small with illegible text. Need feature to autosize & colors (thraxisp) - closed.
- 0003922: [graphs] Add in ability to have certain graphs in large size (thraxisp) - closed.
- 0004651: [graphs] Legend of two summary graphs not properly set-up (thraxisp) - closed.
- 0001890: [graphs] summary displays '0' where not supposed to (thraxisp) - closed.
- 0005001: [other] click-through on summary page requested (thraxisp) - closed.
- 0004997: [other] HTML special characters in Summary field incorrectly displayed in My View (thraxisp) - closed.
- 0004995: [other] Sign up for a new account no longer works... (masc) - closed.
- 0005004: [bugtracker] Relationship table doesn't show whether an issue is private or not. (masc) - closed.
- 0005011: [other] Delete file attached bug instead of project doc (masc) - closed.
- 0003401: [documentation] remove project doc (masc) - closed.
- 0005033: [administration] Turkish translation Email notifications fail. (thraxisp) - closed.
- 0003581: [bugtracker] "Manage" menu item not consequently available for project managers (vwegert) - closed.
- 0005292: [localization] spelling errors in german $s_signup_info (Wanderer) - closed.
- 0005322: [localization] Delete attachment shows empty text and button in German-Version (Wanderer) - closed.
- 0005380: [sql] Invalid LEFT JOIN syntax for Oracle (thraxisp) - closed.
- 0003364: [bugtracker] Unassigned public projects are not listed on manage_user_edit_page.php (jlatour) - closed.
- 0005343: [bugtracker] File download does not use filename in Konqueror / download script should set disposition type (thraxisp) - closed.
- 0005394: [filters] select multiple 'assigned to' then change 'hide status' and value is ignored (thraxisp) - closed.
- 0005396: [bugtracker] It shows only administrators in "assign to" dropdown and "manage project" page for private projects (thraxisp) - closed.
- 0004595: [administration] file upload in error report doesnt work (thraxisp) - closed.
- 0004857: [bugtracker] Upgraded to 0.19.1 - DISK Upload failed - No error message (thraxisp) - closed.
- 0004908: [bugtracker] Missing error alert when file upload fails (Report Issue only) (thraxisp) - closed.
- 0005247: [security] Real email addresses are visible when using reminders (thraxisp) - closed.
- 0005282: [other] Inappropriate error when Uploading a File without a file (thraxisp) - closed.
- 0005346: [bugtracker] misleading error message and inconsistent user interface (thraxisp) - closed.
- 0005411: [localization] New polish translation (Wanderer) - closed.
- 0005419: [sql] Odd use of SELECT DISTINCT (thraxisp) - closed.
- 0005423: [bugtracker] Status change doesn't appear in bug history when issue is automatically assigned to a person (thraxisp) - closed.
- 0004897: [custom fields] SQL standardization in custom_field_api.php (grangeway) - closed.
- 0004975: [administration] Confirmation message in admin area (masc) - closed.
- 0005044: [administration] No warning message for missing strings (thraxisp) - closed.
- 0005051: [localization] Column names in permissions report aren't localized (thraxisp) - closed.
- 0003882: [bugtracker] Private notes on public bugs notify people below private threshold (extesnion of 0003824) (thraxisp) - closed.
- 0005060: [localization] New danish translation (Wanderer) - closed.
- 0005061: [email] e-mail recipients not removed in case of corresponding email_on_xxxaction not defined in db (thraxisp) - closed.
- 0005063: [webpage] Checkbox graphic unclear, Solution is included in this bug (thraxisp) - closed.
- 0004729: [email] No [ENTER] after "The following issue..." in MS OUTLOOK (thraxisp) - closed.
- 0005045: [administration] windows specific path bug in move_db2disk (thraxisp) - closed.
- 0005065: [administration] Added Info about Who can assign issues in Permissions Report (thraxisp) - closed.
- 0005079: [bugtracker] Reopen Issue - Show Assign to only if Access level >= update_bug_assign_threshold (thraxisp) - closed.
- 0005080: [bugtracker] Close Issue - Show Fixed in Version only if Access level >= handle_bug_threshold (thraxisp) - closed.
- 0004874: [bugtracker] Assign to (users) fails from the View_all_bug_page.php Issues screen - I found out why, too. (thraxisp) - closed.
- 0005087: [administration] language changes if bug report is incomplete (thraxisp) - closed.
- 0004718: [filters] Not possible to select blank fields in filter (thraxisp) - closed.
- 0004932: [filters] In advanced filter mode, display 'empty' values in drop-down lists as '[empty]' istead showing blank list box entry (thraxisp) - closed.
- 0005095: [bugtracker] Close bug page needs to show resolution dropdown... (thraxisp) - closed.
- 0005097: [email] email recipients not computed correctly (thraxisp) - closed.
- 0005092: [sponsorships] Users sponsoring bug (thraxisp) - closed.
- 0005099: [administration] French translation (patch) (Wanderer) - closed.
- 0005100: [administration] "confirmation has been sent to your email address" when reseting other user's password (thraxisp) - closed.
- 0005021: [custom fields] Custom fields don't get updated in version 0.19.2 (thraxisp) - closed.
- 0005074: [printing] Bugnote Id doesn't appear when printing note (thraxisp) - closed.
- 0005119: [printing] print preview does not show, if note has been edited (thraxisp) - closed.
- 0005130: [bugtracker] bug_view_page.php always shows Product Version (thraxisp) - closed.
- 0004544: [filters] Impossible to filter on category which name contains " ' " (thraxisp) - closed.
- 0005132: [email] Can't suppress messages on change of handler (thraxisp) - closed.
- 0005057: [webpage] PHP 5/Mysql 4.0/Apache 2.0 - Index page fails to load (vboctor) - closed.
- 0005146: [change log] "Version not found" error on changelog page (thraxisp) - closed.
- 0005153: [bugtracker] Divide by 0 error in status_percentage_legend (thraxisp) - closed.
- 0005110: [sql] Slow SQL statement on my view page (thraxisp) - closed.
- 0005134: [other] My View Page "Assigend to me" (vboctor) - closed.
- 0005143: [change log] Possibility to extend the changelog (vboctor) - closed.
- 0005171: [sql] Upgrade adodb to v4.60 (latest) (thraxisp) - closed.
- 0005131: [filters] Trim filter values (thraxisp) - closed.
- 0005179: [custom fields] Support setting a custom field value for multiple issues (vboctor) - closed.
- 0005180: [custom fields] Support custom fields with dynamic possible values (vboctor) - closed.
- 0003791: [custom fields] Additional Custom-Field-Type "version" (vboctor) - closed.
- 0003961: [feature] Add the ability to custom enumerations by project (vboctor) - closed.
- 0004683: [custom fields] Is there a way to localize enumations of custom fields? (vboctor) - closed.
- 0004842: [feature] we should be able to giva a target for a given bug. (vboctor) - closed.
- 0000934: [feature] Would be nice to select what columns to view (vboctor) - closed.
- 0005187: [bugtracker] Breaks HTML links incorrectly (grangeway) - closed.
- 0004695: [feature] Set View-Status of bugnote when change status through button (thraxisp) - closed.
- 0005170: [customization] Issues list sorting (thraxisp) - closed.
- 0005199: [scripting] Mantis mangles URLS (grangeway) - closed.
- 0005120: [filters] APPLICATION ERROR 0000401 when Reporter uses shared filter (thraxisp) - closed.
- 0005225: [other] Dropdown lists for Real Name sorted by first name not by last name (thraxisp) - closed.
- 0005226: [filters] When setting filters for ALL Projects, no reporters, developers, etc.. listed when project_user_list is empty (thraxisp) - closed.
- 0003343: [bugtracker] Manager cannot see Project after creating it as "Private". (vboctor) - closed.
- 0005236: [installation] check.php not working (jlatour) - closed.
- 0005237: [bugtracker] Support for subprojects that can be linked to several parent projects (jlatour) - closed.
- 0005250: [bugtracker] Subprojects listed multiple times in project selection drop-down (jlatour) - closed.
- 0005251: [bugtracker] Subprojects not shown in 'project menu bar' (jlatour) - closed.
- 0005252: [bugtracker] Subprojects not listed in category field when outside 'All Projects' (jlatour) - closed.
- 0003070: [feature] Standard Profiles for all users to use (jlatour) - closed.
- 0005286: [administration] Copy user permissions from one project to another (jlatour) - closed.
- 0005287: [administration] Permissions listed on 'Manage Project' page are global, not per-project. (jlatour) - closed.
- 0005246: [feature] Allow file:/// [^] to become a clickable link. (grangeway) - closed.
- 0005290: [relationships] Relationship box invalid in View.php page (thraxisp) - closed.
- 0005052: [bugtracker] Sort by ID bug (vwegert) - closed.
- 0005307: [webpage] URL not parsed correct after 'X' (grangeway) - closed.
- 0004611: [bugtracker] "&" displayed as "&" in summary categories (grangeway) - closed.
- 0004793: [filters] Some filters are lacking the [none] selection (vwegert) - closed.
- 0005314: [bugtracker] updater cannot reopen issue even though $g_reopen_bug_threshold = UPDATER; (thraxisp) - closed.
- 0005267: [bugtracker] Reopen issues are not marked as "reopened" (thraxisp) - closed.
- 0005341: [bugtracker] Allow thresholds to take on discrete values (thraxisp) - closed.
- 0003498: [bugtracker] allow signup with deactivated email-support, new user should be able to set a password (vwegert) - closed.
- 0005075: [filters] Add additional standard filter attributes (thraxisp) - closed.
- 0005345: [relationships] Quotes and ampersands are corrupted in issues names in relationships list ("test & test") (vwegert) - closed.
- 0004860: [other] File downloads via HTTPS with IE6 do not work (thraxisp) - closed.
- 0005377: [localization] german: text changes (Wanderer) - closed.
 - 0005206: [localization] Changing some German strings (Wanderer) - closed.
- 0005417: [administration] Can't set the real name to the login name (thraxisp) - closed.
- 0005439: [bugtracker] the mantis_config_table needs a primary key (thraxisp) - closed.

[145 issues]

mantisbt - 0.19.2 (Released 2004-12-11) View Issues ]
=======================================

This is mainly a maintenance release, but it is also the first release that is officially tested on PHP 5, Apache 2, and the MySqli extension. All Mantis users are encouraged to upgrade.

- 0003352: [other] no error when creating a new user that already exsists (vwegert) - closed.
- 0004902: [news] Create href links (vwegert) - closed.
- 0004819: [administration] Use of persistent connections prevents upgrade (grangeway) - closed.
- 0004911: [sql] db_prepare_string() doesn't work with mysqli (vboctor) - closed.
- 0004961: [graphs] Wrong cumulative by date graph (thraxisp) - closed.
- 0004687: [custom fields] Closing an item deletes custom-field-value if type of custom-field is CHECKBOX or MULTILIST (grangeway) - closed.
- 0004887: [administration] reset password sent email to user with extral texts (thraxisp) - closed.
- 0002064: [bugtracker] filedownload seems to change file content (thraxisp) - closed.
- 0003113: [security] LDAP authentication failure (vboctor) - closed.
- 0003457: [webpage] PHP5 issues (vboctor) - closed.
- 0004830: [relationships] missing <?php in relationship_api.php (grangeway) - closed.
- 0004856: [bugtracker] Close immediately doesn't (vboctor) - closed.
- 0004861: [change log] Fixed by user0 (vboctor) - closed.
- 0004872: [customization] CSV export uses , as separator but excel only recognizes ; in non-english locales (vboctor) - closed.
- 0004878: [scripting] filter_get_bug_rows() does not take project_id and user_id (vboctor) - closed.
- 0004909: [printing] Printing bugnotes regardless of user rigth and bugnote status (thraxisp) - closed.
- 0004923: [bugtracker] Updating bug not possible for certain roles (thraxisp) - closed.
- 0004941: [graphs] Cumulative by date graph doesn't show x-label (thraxisp) - closed.
- 0004584: [bugtracker] In bug_actiongroup_page.php use status color coding (vboctor) - closed.
- 0004764: [other] Url detection issue (grangeway) - closed.
- 0004765: [other] url detection issue (grangeway) - closed.
- 0004779: [feature] MySQL 5 support using mysqli extension (grangeway) - closed.
- 0004822: [administration] Error (?) in graphviz_api (grangeway) - closed.
- 0004834: [bugtracker] When you reopen an issue (after the issue has been RESOLVED), resolution is not set to REOPENED as it should be (vboctor) - closed.
- 0004957: [administration] installation check issue: switch "send reset password" no more recognized? (thraxisp) - closed.
- 0004450: [localization] Real name was changed to "¹ÜÀíÔ±" (jlatour) - closed.
- 0004525: [customization] $g_bug_link_tag doesn't work when it contains "/" (grangeway) - closed.
- 0004808: [graphs] Not exactly true data shown in graphs (thraxisp) - closed.
- 0004829: [bugtracker] bugnotes of deleted users cause error (vboctor) - closed.
- 0004855: [administration] Account Update page shows header twice when there is an error (vboctor) - closed.
- 0004865: [custom fields] Email address custom fields not displayed correctly when viewing an issue (grangeway) - closed.
- 0004889: [bugtracker] Ask user for confirmation when deleting an attachment - closed.
- 0004894: [bugtracker] Close immediately appears on Change Status to Closed page (vboctor) - closed.
- 0004901: [administration] When $g_create_project_threshold = MANAGER, and manager creates project, he should automatically be added to project as manager (vboctor) - closed.
- 0004910: [sql] Upgrade ADODB from v3.50 to v4.54 (jlatour) - closed.
- 0004912: [bugtracker] Reminders are not handled in print_bugnote_inc.php (thraxisp) - closed.
- 0004914: [bugtracker] On reopen, notification mail is sent to the old handler instead of the new handler. (thraxisp) - closed.
- 0004916: [administration] Workflow checking is not implemented on bulk Update Status (selecting multiple issues on View Issues) (thraxisp) - closed.
- 0004917: [email] A bug concerning mail notification is found in function bug_update of ../core/bug_api.php. (vboctor) - closed.
- 0004921: [security] Webmaster email address is exposed to SPAM in html_api.php (vboctor) - closed.
- 0004922: [documentation] Defaults for Workflow contain "Superfluous arc to itself" (vboctor) - closed.
- 0004924: [bugtracker] Who is mythical "user0" in Changelog Page? (vboctor) - closed.
- 0004942: [other] Possible redirect loop in autenthication (masc) - closed.
- 0004946: [administration] After adding a user redirect to manage_user_edit_page rather than manage_user_page (vboctor) - closed.
- 0004947: [administration] "Never Logged In" and "New Accounts" use inconsistent sorting order (vboctor) - closed.
- 0004948: [administration] Hyperlink user names in "New Users" and "Never Logged In" (vboctor) - closed.
- 0004949: [administration] Remove extra colon at the end of "New Users" and "Never Logged In" (vboctor) - closed.
- 0004954: [localization] $s_delete_attachment_sure_msg missing from strings_english.txt (masc) - closed.
- 0004958: [printing] print_all_bug_page_word.php -> date displayed wrong (thraxisp) - closed.

[49 issues]

mantisbt - 0.19.1 (Released 2004-11-06) View Issues ]
=======================================
- 0004652: [bugtracker] Fixed in Version not applyed to Bug at CLOSE (thraxisp) - closed.
- 0004625: [relationships] Relationship graph: crash when the bug has no relationship (masc) - closed.
- 0004382: [graphs] Some texts in first 2 graphs of Advanced summary are harcoded (thraxisp) - closed.
- 0004602: [bugtracker] Mismatch between Assign To dropdown and Assigned To whil updating (thraxisp) - closed.
- 0004775: [bugtracker] German 'Umlaut' incorrect (vboctor) - closed.
- 0004672: [bugtracker] Problem with roles in a specific project different from the main roles (thraxisp) - closed.
- 0003176: [bugtracker] number notes (vboctor) - closed.
- 0004526: [other] Spaces needed after colons on main page (vboctor) - closed.
- 0002091: [bugtracker] Bugnotes containing urls with the '@' sign in them get mangled (bpfennig) - closed.
- 0004326: [bugtracker] Links protected by brackets are not processed properly (bpfennig) - closed.
- 0004383: [localization] Editing a note has language specific note at end of note (bpfennig) - closed.
- 0004558: [custom fields] Custom Fields doesn't display links (bpfennig) - closed.
- 0004394: [feature] Add link to remove all users from project (bpfennig) - closed.
- 0004437: [bugtracker] Filenames of uploaded attached files are damaged (thraxisp) - closed.
- 0004572: [bugtracker] Change automatic links not to include a dot (if present) after the URI. (bpfennig) - closed.
- 0004576: [administration] Simplify display options for error handler (thraxisp) - closed.
- 0004440: [feature] It should be possible to define an assigned to at "Change Status To" (thraxisp) - closed.
- 0004538: [bugtracker] $g_bug_resolved_status_threshold doesn't work correctly with additional status (thraxisp) - closed.
- 0004171: [bugtracker] Make all text area widths the same as for 'Add Note' (bpfennig) - closed.
- 0004407: [administration] History Column Titles do not match table text formating (bpfennig) - closed.
- 0004363: [bugtracker] "Add user to project" should have an additional button (bpfennig) - closed.
- 0004393: [feature] Version should be add with advanced options (bpfennig) - closed.
- 0004528: [localization] Error on logout page with language=auto (thraxisp) - closed.
- 0004604: [localization] There is a word missing. (Wanderer) - closed.
- 0003983: [graphs] Graphs should use $s_orct localization string (bpfennig) - closed.
- 0003117: [security] Summary shows info about projects that are not assigned to this user (bpfennig) - closed.
- 0001466: [bugtracker] How about having [prev] / [next] bugs buttons in the view_* pages as well? (grangeway) - closed.
- 0004434: [relationships] Relationship (dependency) graphs (grangeway) - closed.
- 0004537: [bugtracker] "Change Status To" shows @@ sometimes (thraxisp) - closed.
- 0004540: [bugtracker] Mismatch between status and resolution (thraxisp) - closed.
- 0004542: [bugtracker] Updater cannot reopen issue and cannot close his own issues (thraxisp) - closed.
- 0004548: [email] status_bug_new missing? (thraxisp) - closed.
- 0004229: [sql] Missing parameter "port" in the ADOConnection implementation (grangeway) - closed.
- 0004241: [bugtracker] Misleading string "Login" used (Wanderer) - closed.
- 0004258: [other] Username used instead of real name. (thraxisp) - closed.
- 0004173: [feature] sorting of real- and user-names (thraxisp) - closed.
- 0003276: [feature] Add bugnote numbering and bugnote links. (bpfennig) - closed.
- 0004539: [bugtracker] Realnames shown inconsequent (thraxisp) - closed.
- 0004615: [bugtracker] Issues can have two attachments with the same display name (thraxisp) - closed.
- 0004616: [bugtracker] Variable $g_port generates a warning (grangeway) - closed.
- 0004620: [relationships] File bug_create_child.php no more used (vboctor) - closed.
- 0004292: [administration] Sign-up sends a password for LDAP (thraxisp) - closed.
- 0004521: [other] Extra text emitted from checkin.php (thraxisp) - closed.
- 0004555: [administration] Warnings on set_time_limit() in safe mode (vboctor) - closed.
- 0004646: [bugtracker] Notes always added as private, if default_bugnote_view_status = VS_PRIVATE (vboctor) - closed.
- 0003774: [custom fields] Only administrator can manage custom fields, because link is missing (thraxisp) - closed.
- 0004649: [customization] Why available statuses are sorted on "bug view" page in "change status to" dropdown? (thraxisp) - closed.
- 0004658: [change log] Changelog should support project_id parameter (vboctor) - closed.
- 0004400: [change log] Changelog should view release notes (vboctor) - closed.
- 0004341: [security] Users removed from projects are still listed as 'monitoring' bugs (DGtlRift) - closed.
- 0004659: [feature] FTP unload don't work fine (thraxisp) - closed.
- 0004655: [feature] removing an attachment don't remove file in FTP server (thraxisp) - closed.
- 0004224: [relationships] Can't resolve issue as duplicate of other with existing "related to" relationship (masc) - closed.
- 0004387: [bugtracker] reminders are localized (thraxisp) - closed.
- 0004184: [relationships] Related issues resolved email should be more informative (masc) - closed.
- 0004484: [relationships] Show which project a related issue belongs to (masc) - closed.
- 0004506: [relationships] When cloning a bug you should be able to set the relationship (masc) - closed.
- 0004505: [filters] Search in bugnotes not possible ( anymore? ) (Narcissus) - closed.
- 0004573: [localization] Missing 'finnish' language choice in config_defaults_inc.php (vboctor) - closed.
- 0004667: [localization] croatian and latvian languages missing from config_defaults_inc.php (vboctor) - closed.
- 0004606: [localization] emails have non-english strings in relationship section (thraxisp) - closed.
- 0004662: [feature] required fields on bug report/update (thraxisp) - closed.
- 0004648: [feature] Assign To independent of $g_update_bug_threshold (thraxisp) - closed.
- 0004675: [documentation] If you upload a file (using 'edit' on a exisiting document) the filename will not be obfuscated (thraxisp) - closed.
- 0004698: [bugtracker] Config $g_reopen_bug_threshold marked obsolete but still present (thraxisp) - closed.
- 0004701: [localization] Add Ukrainian language (vboctor) - closed.
- 0004004: [bugtracker] unable to download large size attachment (thraxisp) - closed.
- 0004724: [bugtracker] Is there a way to control the display of the history? (vboctor) - closed.
- 0004668: [other] Detect If host is a Unix or Windows-Box (thraxisp) - closed.
- 0004669: [printing] Space missing between 2 fields (thraxisp) - closed.
- 0004725: [bugtracker] (0001466) Broken HTML / Misaligned links on top of view pages (thraxisp) - closed.
- 0004168: [other] Languages in "My Account"/"Preferences" are not sorted (DGtlRift) - closed.
- 0004743: [localization] parse error in $s_reminder_monitor (strings_german.txt) (Wanderer) - closed.
- 0004761: [documentation] Update documentation timestamp on new upload (thraxisp) - closed.
- 0004758: [feature] Support RSS autodiscovery on all Mantis pages (vboctor) - closed.
- 0004760: [administration] version_is_unique() called with wrong parameters (vboctor) - closed.
- 0004745: [other] PHP 5 array_merge() change causes errors (vboctor) - closed.
- 0004749: [feature] Uploading large files fails & slogs Apache (thraxisp) - closed.
- 0004769: [bugtracker] limit_reporter does not work on Jump to Bug (masc) - closed.
- 0004623: [administration] Add access level summary report (masc) - closed.
- 0004770: [change log] $g_limit_reporters does not work on the changelog (masc) - closed.
- 0004773: [bugtracker] bug_view_advanced history link points to not-advanced bug_view (masc) - closed.
- 0004774: [filters] Problem with Simple Text Search and Bug ID (masc) - closed.
- 0004497: [filters] Add filter for priority (DGtlRift) - closed.
- 0004802: [localization] In adm_permissions_report.php line199, "lang_get" is not used. (masc) - closed.
- 0004803: [relationships] when the relation "child of" was delteted, in issue "parent of" was displayed. (masc) - closed.

[86 issues]

mantisbt - 0.19.0 (Released 2004-09-12) View Issues ]
=======================================

This is a stable release that followed a couple of alpha releases + a release candidate. Compared to 0.18.3 this release has over 250 enhancements and fixes. These include some major additions to Mantis including issue relationships, sponsorships, advanced filters, changelog, workflow control, my-view, using ADODB as a database abstraction layer (only MySQL supported at the moment), "forgot password" support, more secure signup with captcha image, security fixes, and various other fixes and enhancements. All users of previous releases are encouraged to upgrade to this release.

- 0003846: [email] Email on status change does not respect user preference (thraxisp) - closed.
- 0003987: [bugtracker] Mantis 0.19.0 Release (vboctor) - closed.
 - 0004426: [email] Email notifications to users with language set to "auto" causes errors (thraxisp) - closed.
 - 0004480: [administration] admin/check.php - Check email failing. (thraxisp) - closed.
 - 0004495: [bugtracker] Warning in bug_actiongroup_page.php when risolving (thraxisp) - closed.
 - 0004464: [graphs] Pie graphs display as error if no issue exist for a specific project (thraxisp) - closed.
 - 0004463: [graphs] pie chart of summary graph per category wrong when viewing allprojects) (thraxisp) - closed.
 - 0004509: [localization] Request rather than "Provide Feedback to Issue" (thraxisp) - closed.
 - 0004431: [relationships] Relationship removal is always "duplicate of" in history (masc) - closed.
- 0004423: [localization] Parse error in strings_hungarian.txt line 974 (vboctor) - closed.
- 0004425: [bugtracker] Action group page exceeds max execution time (vboctor) - closed.
- 0004429: [localization] Slovene national characters not displayed correctly (jlatour) - closed.
- 0004435: [other] Auto-preview of attached images is broken (vboctor) - closed.
- 0004445: [localization] New Spanish strings file (Wanderer) - closed.
- 0004448: [email] Custom severity and status shown in mail as code (thraxisp) - closed.
- 0004458: [localization] Small fixes to the French file (Wanderer) - closed.
- 0004459: [localization] Typos in German and English strings (Wanderer) - closed.
- 0004321: [localization] New german lang strings (bpfennig) - closed.
- 0003896: [security] Change default value of $g_view_summary_threshold to MANAGER (vboctor) - closed.
- 0004470: [other] Strange changes of "Resolution" value (thraxisp) - closed.
- 0004478: [upgrade] database upgrade from 0.18.3 problem: upgrade-ID "filters-db1" does not work on mySQL4.1.3b-beta (jlatour) - closed.
- 0004479: [bugtracker] Reporters can't close or reopen issues they reported (thraxisp) - closed.
- 0004498: [localization] Swedish translation updated for 0.19.0rc1 (Wanderer) - closed.
- 0004507: [graphs] No time-line in the summary for cumulative by days (thraxisp) - closed.
- 0004511: [graphs] Summary Graph "Cumulative by Date" is blank (process expires) (thraxisp) - closed.
- 0004481: [graphs] Query counts are incorrect in graphs (thraxisp) - closed.
- 0004519: [localization] Updated the Italian language strings file to 0.19.0rc1 (Wanderer) - closed.
- 0004523: [filters] SYSTEM NOTICE: Undefined variable: t_target_field in view_filters_page.php (vboctor) - closed.

[28 issues]

mantisbt - 0.19.0rc1 (Released 2004-08-28) View Issues ]
==========================================

This is the first release candidate for 0.19.0, it requires database upgrade. We consider this release considerably more stable than the 0.19.0a2. This is a feature complete release, hence, 0.19.0 is not expected to include new features, but only bug fixes.

- 0003344: [email] New Account Emails are being sent even when email notification is off (jlatour) - closed.
- 0004130: [bugtracker] Viewing bug: JavaScript error pops up (vboctor) - closed.
- 0003760: [bugtracker] difficult to authenticate from command line script (vboctor) - closed.
- 0004062: [security] Multiple Cross Site Scripting Vulnerabilities (vboctor) - closed.
- 0004183: [security] another xss issue (Narcissus) - closed.
- 0004269: [security] cross site scripting issue (jlatour) - closed.
- 0003540: [security] Arbitrary code execution through uploads (thraxisp) - closed.
- 0004063: [security] Possible E-Mail Bomber (masc) - closed.
- 0004276: [security] cross site scripting issue (jlatour) - closed.
- 0004277: [security] cross site scripting issue (jlatour) - closed.
- 0004239: [security] Remote PHP Code execution (grangeway) - closed.
- 0004153: [bugtracker] "Fixed in version" field on Batch Resolve page (thraxisp) - closed.
- 0003997: [sql] CVS: SQL error on View Bugs with certain filters (Narcissus) - closed.
- 0003299: [email] Email notifications have blank lines in header (jlatour) - closed.
- 0004073: [filters] Edit filter page now too wide. 'Apply filter' button is drawn off screen (Narcissus) - closed.
- 0004122: [relationships] Upgrade script seems to swap the duplicate relationship (masc) - closed.
- 0003880: [filters] Ordering doesnt take last_updated into account (Narcissus) - closed.
- 0004083: [sponsorships] Users without email address must not be able to sponsor issues (thraxisp) - closed.
- 0004093: [filters] Custom field values are a larger type size in view_all_bug_page (Narcissus) - closed.
- 0004137: [feature] Support a simple "view" URL (vboctor) - closed.
- 0004145: [feature] Mantis pages should have descriptive titles (vboctor) - closed.
- 0004141: [localization] Relationship strings have a useless '%id' string (grangeway) - closed.
- 0004150: [filters] Custom field names are not localised in filters (vboctor) - closed.
- 0004142: [filters] Filter by category results in N pages with 1 issue in each page (Narcissus) - closed.
- 0004154: [bugtracker] "Product version" and "Fixed in Version" do not get updated on rename (vboctor) - closed.
- 0004175: [bugtracker] Links are not hyperlinked properly if containing '[' or ']' (vboctor) - closed.
- 0003714: [upgrade] Please add in a way to transfer attachments from the database to disk (thraxisp) - closed.
- 0004108: [filters] "Use Date Filters" in advanced filters (Narcissus) - closed.
- 0003945: [filters] Give the ability to "Update Fixed in Version" in view_all_bug_page.php (Narcissus) - closed.
- 0003877: [email] Upgrade to PHPMailer 1.72 (vboctor) - closed.
- 0002220: [installation] usage of consistent naming schema for images (vboctor) - closed.
- 0002861: [bugtracker] misleading 'copyright' at the pages' bottom (vboctor) - closed.
- 0004182: [other] print_all_bug_page should show all issues matching current filter (vboctor) - closed.
- 0003787: [documentation] Stale reference in doc/INSTALL (grangeway) - closed.
- 0004185: [customization] Support custom menu options (vboctor) - closed.
- 0004158: [sql] Sql Error in bug_copy (grangeway) - closed.
- 0004139: [email] SYSTEM NOTICE: Undefined index: email_bug_view_url (grangeway) - closed.
- 0004031: [bugtracker] Hiding/removing fixed_in_versions (thraxisp) - closed.
- 0004121: [filters] Filters saved while "All Projects" is the active project, should have all projects active (Narcissus) - closed.
- 0004125: [filters] Attempting to filter on issues fixed in version 0.19.0a2 does not work (Narcissus) - closed.
- 0003710: [bugtracker] time stats in summary to use resolved (thraxisp) - closed.
- 0004204: [filters] Lines per page field left empty (Narcissus) - closed.
- 0003948: [bugtracker] Will not jump to bug when following link in mail (vboctor) - closed.
- 0004212: [filters] Default for Quantity is 0 -> N pages needed to display N issues (vboctor) - closed.
- 0002214: [bugtracker] When Viewing a Bug, window title should change (grangeway) - closed.
- 0004207: [filters] Mantis forgets user filter after logout (Narcissus) - closed.
- 0001146: [bugtracker] PRE tags in text (thraxisp) - closed.
- 0004163: [other] Unreadable error messages in some languages (vboctor) - closed.
- 0004136: [localization] Updated strings for Korean (Wanderer) - closed.
- 0004222: [sql] Should mantis_project_category_table.user_id be UNSIGNED? (vboctor) - closed.
- 0004146: [relationships] Summary doesn't unescape(?) characters (masc) - closed.
- 0004161: [relationships] Relations to private issues must only appear to user with appropriate access level (masc) - closed.
- 0004157: [bugtracker] allow custom fields to be hidden when reporting/updating bugs (grangeway) - closed.
- 0004248: [customization] mantis_project_file_table hardcoded in proj_doc_add.php (grangeway) - closed.
- 0004255: [localization] Wrong value of $g_language_auto_map (vboctor) - closed.
- 0003772: [bugtracker] Status updating should be different from bug updating (thraxisp) - closed.
- 0004131: [bugtracker] Closing bugs when you're not allowed to. (thraxisp) - closed.
- 0004260: [filters] APPLICATION ERROR 0000401 when searching (vboctor) - closed.
- 0004138: [bugtracker] Add validation / notifications hooks for issue create/update/delete (thraxisp) - closed.
- 0004262: [bugtracker] Updating an issue shows the wrong status (thraxisp) - closed.
- 0003970: [bugtracker] Reopen issue logic was broken for ustom reopen statuses (thraxisp) - closed.
- 0004259: [localization] Wrong value for $s_product_build (Wanderer) - closed.
- 0004237: [localization] s_monitored_by must be in lang-files, otherwise empty string used (Wanderer) - closed.
- 0003371: [feature] CVS Integration (patch included) (vboctor) - closed.
- 0004266: [feature] Update project documentation file (jlatour) - closed.
- 0004133: [filters] "Summary stats are links to filters for view_all_bugs" feature is broken (jlatour) - closed.
- 0004193: [bugtracker] Broaden the ldap features to work with (A.D.) - patch included (jlatour) - closed.
- 0003307: [installation] check.php always checks mail() rather than the config (thraxisp) - closed.
- 0003483: [upgrade] some admin users permissions not completly upgraded from 0.17.5 to 0.18.0 (vboctor) - closed.
- 0003689: [bugtracker] index.php is sending wrong HTTP header if not logged in. (jlatour) - closed.
- 0004279: [bugtracker] My View makes bad use of available space (tazza70) - closed.
- 0004043: [email] Preference to exclude old bugnotes from notification (bpfennig) - closed.
- 0004186: [upgrade] Some upgrade scripts do not read table names from config (jlatour) - closed.
- 0004270: [bugtracker] Change status in mass treatment ignore defined workflow rules (thraxisp) - closed.
- 0003995: [bugtracker] My View: Clickable links for sections. (tazza70) - closed.
- 0003942: [bugtracker] print_options_page doesn't show real data about selected fields (jlatour) - closed.
- 0003904: [sql] cache missing 'user pref' rows (thraxisp) - closed.
- 0003853: [filters] Filters sometime generate an invalid query (vboctor) - closed.
- 0000633: [feature] email lost password page (masc) - closed.
- 0004164: [news] Announcement news don't remain on top (masc) - closed.
- 0002416: [security] Block Denied Access (masc) - closed.
- 0004140: [filters] Unable to view closed issues in View Issues page (Narcissus) - closed.
- 0004147: [email] Receiving emails in foreign languages (thraxisp) - closed.
- 0004236: [customization] Support of custom_strings_inc.php broken somehow (thraxisp) - closed.
- 0004107: [email] email w/o recipient sent (thraxisp) - closed.
- 0004111: [email] Notify admins when new account setup. (masc) - closed.
- 0004128: [custom fields] Custom field data lost on resolve and close of issue (grangeway) - closed.
- 0004343: [localization] german string incorrect (Wanderer) - closed.
- 0004355: [localization] Incorrect and incomplete Dutch translations (Wanderer) - closed.
- 0004362: [localization] Section titles are not localized in My View page (Wanderer) - closed.
- 0004156: [filters] Sql error (grangeway) - closed.
- 0004342: [bugtracker] Developers unable to submit bugs (thraxisp) - closed.
- 0003822: [bugtracker] basedir restriction on some servers (grangeway) - closed.
- 0004311: [administration] User deletion confirm page should include user name (bpfennig) - closed.
- 0004009: [custom fields] New custom field type "multiple select" (grangeway) - closed.
- 0004317: [bugtracker] "Report stay" should print out the submitted bug number together with the "report more bugs" (bpfennig) - closed.
- 0004293: [localization] Lang variable names broken (thraxisp) - closed.
- 0003938: [localization] Untranslatable string (jlatour) - closed.
- 0004367: [email] E-mail notification on relationship deletion results in "relationship added" email (thraxisp) - closed.
- 0004353: [other] "Select all issues" in some clicks (bpfennig) - closed.
- 0003766: [email] status notifications are confused and confusing (thraxisp) - closed.
- 0004374: [localization] Russian Language parse error (Wanderer) - closed.
- 0004376: [bugtracker] "assigned to" buttons don't obey $g_set_status_threshold (thraxisp) - closed.
- 0004375: [localization] Russian Language parse error (Wanderer) - closed.
- 0004386: [bugtracker] Changelog doesn´t respect user rights (vboctor) - closed.
- 0004357: [webpage] added issue ID to summary is a bit confusing (thraxisp) - closed.
- 0004402: [localization] String missing in lang/strings_dutch.txt (Wanderer) - closed.
- 0004348: [performance] Show queries with runtime (thraxisp) - closed.
- 0004381: [custom fields] History updates when custom field unchanged. (grangeway) - closed.
- 0004397: [bugtracker] broken captcha if ttf not available (grangeway) - closed.

[110 issues]

mantisbt - 0.19.0a2 (Released 2004-07-07) View Issues ]
=========================================

This is the second alpha release for 0.19.0a, if there is not much issues with it then rc1 will probably follow. The main features in this release are issue relationships and simple workflow control. Also version handling was almost re-implemented to support released vs. future versions and also allow adding a description to versions.

- 0004018: [security] Real name field allows potentially dangerous HTML (int2str) - closed.
- 0004044: [security] Cross Site Scripting Vulnerability (int2str) - closed.
- 0004109: [bugtracker] Optional old filter interface? (vboctor) - closed.
- 0004058: [bugtracker] Bug should be associated with a version by reference (vboctor) - closed.
- 0004209: [email] missing variable $s_email_notification_title_for_action_bug_updated (Wanderer) - closed.
- 0004005: [other] signup for new account - invalid username generates crash (int2str) - closed.
- 0004020: [bugtracker] Database field 'realname' not found after plain installation (vboctor) - closed.
- 0004027: [filters] Database query error in 0.19 alpha1 (Narcissus) - closed.
- 0004038: [sponsorships] Add icon to sponsorships to attract attention (vboctor) - closed.
- 0004040: [sponsorships] Sponsorship timestamp is not displayed correctly in sponsorship list (vboctor) - closed.
- 0003805: [filters] Add ability to filter on bugs monitored by a user (Narcissus) - closed.
- 0003804: [filters] Add ability to filter by view state (private/public) (Narcissus) - closed.
- 0003944: [filters] Give the ability to filter on : Fixed in Version value (Narcissus) - closed.
- 0004014: [localization] Italian Version: Build Translated as Version (vboctor) - closed.
- 0004053: [localization] Italian - Missing $s_monitored_by (vboctor) - closed.
- 0004036: [bugtracker] Changelog should not display versions with no issues (vboctor) - closed.
- 0004041: [sponsorships] Empty "Users sponsoring this issue" (vboctor) - closed.
- 0004056: [custom fields] Displaying/Reporting Issue -> Application Warning - lang_exists() missing arg 2 (vboctor) - closed.
- 0004064: [other] Links are not hyperlinked properly if containing '(' or ')' (vboctor) - closed.
- 0004065: [other] Issues are not hyperlinked in Changelog if $g_bug_link_tag is not # (vboctor) - closed.
- 0004052: [bugtracker] Not all the buttons are marked as class="button" (vboctor) - closed.
- 0001210: [feature] Project Version could use some more details!!! (vboctor) - closed.
- 0004016: [feature] Automatic language selection based on browser preferences (int2str) - closed.
- 0004066: [feature] Support "future" versions and a description field (vboctor) - closed.
- 0003974: [feature] Make Mantis issues searchable by Search Engine (int2str) - closed.
- 0004057: [feature] Add "notes" for versions (vboctor) - closed.
- 0004072: [webpage] Make sponsorships and relationships collapsible (int2str) - closed.
- 0004081: [upgrade] mantis_upgrade_table.upgrade_id too small (vboctor) - closed.
- 0003996: [bugtracker] My View: how about monitored by me? (tazza70) - closed.
- 0003275: [bugtracker] Low priority is not marked in list of bugs (vboctor) - closed.
- 0004071: [filters] advanced filtering with status=any fails (Narcissus) - closed.
- 0004104: [feature] Product Version Field in simple View (vboctor) - closed.
- 0003993: [bugtracker] String missing in strings_english.txt file (email title on updated bug) (vboctor) - closed.
- 0004118: [filters] Make filter display at top of View Issues collapsible (vboctor) - closed.
- 0004120: [feature] Add issue id before summary in issue view pages (vboctor) - closed.
- 0004021: [bugtracker] The filter section is duplicated on the print page (tazza70) - closed.
- 0003959: [localization] fixed_in_version not translated in history (masc) - closed.
- 0003969: [feature] Issue Relationships Support (masc) - closed.
- 0004088: [filters] My View: Unassigned block shows assigned items (Narcissus) - closed.
- 0003984: [feature] Support definining and enforcing custom workflow (thraxisp) - closed.

[40 issues]

mantisbt - 0.19.0a1 (Released 2004-07-07) View Issues ]
=========================================

This is an alpha version of 0.19.0, it is not recommended for production use. Users are encouraged to test it on a backup copy of their data and provide feedback to development team.

Users installing Mantis for the first time should sql/db_generate.sql to create the database, then run the http://www.example.com/mantis/admin and run the upgrade scripts. Already existing users will need to backup their database, then run upgrade.

- 0003638: [feature] the bugtracker should be able to produce a changelog (vboctor) - closed.
- 0002022: [feature] Using hyperlinks to get to filtered bug views (Narcissus) - closed.
- 0002934: [bugtracker] New Plain-Text-View (vboctor) - closed.
- 0004096: [bugtracker] Double 1101 ID in error list (core/constants) (vboctor) - closed.
- 0003808: [feature] Ability to sponsor (fund) a bug or feature request (vboctor) - closed.
- 0003867: [bugtracker] Give the user control whether to open hyperlink in new or current window (vboctor) - closed.
- 0003851: [bugtracker] Ability to change the view status for a group of bugs (vboctor) - closed.
- 0003852: [localization] OK button in View Issues page is not localised (vboctor) - closed.
- 0003811: [bugtracker] allow private flag to be unset on resolved bugs (vboctor) - closed.
- 0003821: [sql] create statements syntax incorrect (vboctor) - closed.
- 0002250: [bugtracker] Versions at project manage (vboctor) - closed.
- 0003724: [other] Problems with deleting a project (vboctor) - closed.
- 0003397: [email] Delete notification should be off when deleting a project (vboctor) - closed.
- 0002200: [feature] Add Version (and possibly platform) to simple bug (vboctor) - closed.
- 0003645: [bugtracker] RSS Feed says "Access Denied" (vboctor) - closed.
- 0003723: [news] No ability to edit or even delete news is associated project was deleted (vboctor) - closed.
- 0003302: [bugtracker] Add global defaults for view state (vboctor) - closed.
- 0003688: [feature] Add threshold for changing the bug/bugnote view status (vboctor) - closed.
- 0003322: [bugtracker] Error displayed when admin dir is removed (vboctor) - closed.
- 0003737: [bugtracker] Summery stats are links to filters for view_all_bugs (vboctor) - closed.
- 0003300: [bugtracker] Add global defaults for priotity and severity of new bugs (vboctor) - closed.
- 0003673: [bugtracker] New filter code does not let user disable 'Hide Closed' (vboctor) - closed.
- 0003629: [bugtracker] Duplicate Error ID (vboctor) - closed.
- 0003662: [bugtracker] Provide more config vars to control viewing/downloading/deleting bug attachments (vboctor) - closed.
- 0003614: [installation] SYSTEM WARNING: Missing argument 2 for config_obsolete() (vboctor) - closed.
- 0003494: [bugtracker] Filter by Date Submited and Filter by Custom Fields (Narcissus) - closed.
- 0003690: [feature] Request for directly setting reminders private (vboctor) - closed.
- 0002123: [bugtracker] Closed bugs do not appear on open view bug search (vboctor) - closed.
- 0002559: [bugtracker] Need a way to filter on Product Version in the view_all_bug_page filters (vboctor) - closed.
- 0003800: [bugtracker] "assigned to" field changes to whoever resolves or closes bug (vboctor) - closed.
- 0003641: [other] 'Date submited' in reports is always '12-31-69' (vboctor) - closed.
- 0003780: [documentation] misspelling in doc/README - "administraton" (vboctor) - closed.
- 0003837: [bugtracker] Bugs can be edited after being closed (vboctor) - closed.
- 0003164: [bugtracker] Added "fixed in version" field, set when resolving a bug (vboctor) - closed.
- 0003622: [bugtracker] Print Bug page and SQL (Narcissus) - closed.
- 0003657: [localization] A couple of errors in the danish translation (jlatour) - closed.
- 0003781: [installation] bad link to php.net on admin/check.php (int2str) - closed.
- 0003505: [bugtracker] add a BugNote to a resolved bug (vboctor) - closed.
- 0003633: [bugtracker] Possible adodb patch for mantis (jlatour) - closed.
- 0003567: [bugtracker] Reminders can be added for a readonly bug (vboctor) - closed.
- 0003824: [bugtracker] private bug reports and bugnotes are sent out as notifications to everyone (vboctor) - closed.
- 0003735: [bugtracker] New CSS class for HTML Form Buttons (jlatour) - closed.
- 0003713: [bugtracker] User Email Severities (Narcissus) - closed.
- 0003094: [bugtracker] Switch project clears the "Hide Resolved" filter (Narcissus) - closed.
- 0003801: [feature] Add "myself" meta filters (Narcissus) - closed.
- 0003422: [feature] Add a reset all button (Narcissus) - closed.
- 0003159: [bugtracker] Change case of usernames doesn't work (int2str) - closed.
- 0003826: [bugtracker] Cannot edit project name if only the case is changed (int2str) - closed.
- 0003676: [filters] Use status threshold rather than hide resolved/closed in filter (Narcissus) - closed.
- 0003663: [bugtracker] remember sort/filter when changing projects (Narcissus) - closed.
- 0003840: [bugtracker] Why strip the leading spaces from Description? (vboctor) - closed.
- 0003504: [bugtracker] project cookie not cleared at logout (vboctor) - closed.
- 0003152: [bugtracker] Adding notes and documents to resolved bugs (vboctor) - closed.
- 0001873: [feature] Filter by date (Narcissus) - closed.
- 0003519: [bugtracker] Feature req: Allow 'advanced' filter that will allow multiple selection (Narcissus) - closed.
- 0003866: [bugtracker] URLs that include bookmark are not hyperlinked correctly (vboctor) - closed.
- 0003274: [bugtracker] Delete a single attachment (vboctor) - closed.
- 0003765: [bugtracker] change title on bug details page to bug summary line (vboctor) - closed.
- 0003870: [plug-ins] Support for custom functions which provides hooks for customizing behaviour (vboctor) - closed.
- 0003841: [feature] Add real name ability to mantis (vboctor) - closed.
- 0003879: [bugtracker] Bugs can be moved to 0 project (int2str) - closed.
- 0003806: [bugtracker] Timestamp in project management isn't shown as configured (int2str) - closed.
- 0003296: [bugtracker] pasting MSword on bug report breaks $_POST data (int2str) - closed.
- 0003885: [bugtracker] LangAPI (probably) problems (int2str) - closed.
- 0003747: [bugtracker] Feature req: allow switching a bug's project (int2str) - closed.
- 0003889: [bugtracker] Small issues related to 'Real Name' changes (int2str) - closed.
- 0003828: [bugtracker] with phpMailer, must have a "to" address (yarick123) - closed.
- 0003903: [sql] optimisation of lang_load_default() (vboctor) - closed.
- 0003920: [graphs] Two graphs are missing (Narcissus) - closed.
- 0003924: [graphs] Graphs should show query counts (Narcissus) - closed.
- 0003925: [feature] New Bug Group Action: Copy (Narcissus) - closed.
- 0003553: [bugtracker] Cannot download attached files with IE5.5 or better over SSL (rfoster) - closed.
- 0003937: [filters] Custom Field Filters show all projects (Narcissus) - closed.
- 0003960: [localization] Updated the Italian language strings file (vboctor) - closed.
- 0003946: [bugtracker] Allow bugnotes on resolved or closed bugs (vboctor) - closed.
- 0003914: [feature] CSV Export : incorrect date_submitted and last_updated (vboctor) - closed.
- 0003947: [localization] Spelling mistakes in chinese_simplified (vboctor) - closed.
- 0003963: [localization] A full simplified Chinese localization for mantis 0.18.3 (vboctor) - closed.
- 0003473: [bugtracker] g_bug_resolved_status_threshold variable ignored (vboctor) - closed.
- 0003923: [graphs] SQL Intensive Graphs (Narcissus) - closed.
- 0003951: [bugtracker] Add Bugnote - Link (vboctor) - closed.
- 0003957: [filters] Refresh not working with IE5.5 after filtering (Narcissus) - closed.
- 0003554: [custom fields] Custom fields on resolve bug (grangeway) - closed.
- 0003971: [localization] Chinese: changing Issue to Bug, Bugnote to Note (vboctor) - closed.
- 0003972: [documentation] Remove [?] links till they are linked to new manual or forever (vboctor) - closed.
- 0003950: [bugtracker] Wrong Date in Report (grangeway) - closed.
- 0003981: [custom fields] New custom field features not in database (grangeway) - closed.
- 0003883: [bugtracker] Report-Timestamp in print word report is wrong (grangeway) - closed.
- 0003830: [filters] Temporary filters with IIS - Blank page / crash (grangeway) - closed.
- 0003741: [bugtracker] GIF images are corrupted in 0.18.2 (grangeway) - closed.
- 0003632: [bugtracker] Wrong "date submitted" value (grangeway) - closed.
- 0003578: [other] Word 2000 reports "The dimensions after resizing are too small or too large." trying to open word document from Mantis (grangeway) - closed.
- 0003114: [bugtracker] can't get summary print reports to work, no output (grangeway) - closed.
- 0003407: [bugtracker] can not login (grangeway) - closed.
- 0003990: [bugtracker] Add: Filter by Resolution (vboctor) - closed.
- 0003895: [feature] Icon_api.php - Needs NONE constant added in "constants_inc.php" where "directions" are defined. (grangeway) - closed.
- 0003266: [bugtracker] possible patches against cvs head (vboctor) - closed.
- 0004006: [localization] wrong translation in CVS (vboctor) - closed.
- 0003833: [bugtracker] Special Chars entered in bug_report_page.php cause application error (int2str) - closed.
- 0004015: [localization] Localized emails are sent in the wrong language. (vboctor) - closed.
- 0004012: [bugtracker] Problem with Custom Fields in Report (vboctor) - closed.
- 0003739: [bugtracker] Portal for viewing bug status lists and summaries after login (tazza70) - closed.

[102 issues]

mantisbt - 0.18.0 (Released 2003-12-13) View Issues ]
=======================================
- 0001906: [feature] Web entrance to specific project (grangeway) - closed.

[1 issue]


MantisBT 1.2.17 [^]
Copyright © 2000 - 2014 MantisBT Team
Time: 2.5252 seconds.
memory usage: 18,030 KB
Powered by Mantis Bugtracker