mantisbt - Change Log

mantisbt - 1.1.3 (not yet released)
===================================

This is the next planned release from the 1.1.X branch.

- 0009343: [scripting] form security token prevents changing relationship while resolving bug (jreese) - resolved.
- 0009309: [email] Problems with e-mail notifications about bugnotes [PATCH] (giallu) - resolved.
- 0009286: [administration] stray "2" in manage_user_prune.php (vboctor) - resolved.
[3 issues]

mantisbt - 1.1.2 (released 2008-06-17)
======================================

This release focused on fixing few security issues; also includes assorted fixes for translations, usability and compatibility (most notably, with postgres) and a nasty memory leak on the string API causing incomplete rendering of pages. All users are advised to upgrade.

- 0009207: [tagging] Several actions lead into Application Error #19 (schoenfeld) - resolved.
- 0009181: [time tracking] Port 0008362: Note text is mandatory for time tracking while closing bug (daryn) - closed.
- 0009180: [time tracking] Port 0007971: time tracking information only saved on added comment (daryn) - closed.
- 0009179: [time tracking] Port 0007953: Time Tracking assigment lost, when changing issue status without note text (daryn) - closed.
- 0009182: [bugtracker] Port 0008509: Empty Note is added when updating issue (daryn) - closed.
- 0009082: [localization] Hungarian translate error (Bithunter) - closed.
- 0008976: [security] Remote Code Execution in adm_config (giallu) - closed.
- 0008975: [security] CSRF Vulnerabilities in user_create (jreese) - closed.
- 0009154: [security] arbitrary file inclusion through user preferences page (giallu) - closed.
- 0008974: [security] XSS Vulnerability in filters (thraxisp) - closed.
- 0008830: [installation] set_time_limit() doesn't work in PHP safe mode (daryn) - closed.
- 0008924: [bugtracker] Port 8245: Target Version value lost in update issue page (giallu) - closed.
- 0008886: [change log] Change Log shows duplicate entries (jreese) - closed.
- 0008880: [db postgresql] Problem with date formatting in db_prepare_date function (giallu) - closed.
- 0008858: [integration] DokuWiki integration: EMail notification on wiki page changes not working (vboctor) - closed.
- 0009183: [time tracking] Port 0008357: "Total time for issue" is shown even for users under threshold (vboctor) - closed.
- 0009184: [time tracking] Port 0008849: Emails ignore time tracking view threshold (vboctor) - closed.
- 0009185: [time tracking] Port 0008621: The expand icon is inverted for the Time tracking section (vboctor) - closed.
- 0009186: [localization] Port 0009046: French translation for $s_bug_assign_to_button (vboctor) - closed.
- 0008123: [administration] Adding a user requires "$g_lost_password_feature = ON" (giallu) - closed.
- 0008774: [localization] Complete Hungarian retranslation (vboctor) - closed.
- 0008931: [relationships] Circle Relations cause roadmap to malfunction (jreese) - closed.
- 0008853: [roadmap] Issue appears more than once in the Roadmap for a release. (jreese) - closed.
- 0009178: [other] Fix memleak in string api (vboctor) - closed.
- 0009177: [filters] Port 0008916: Monitor by filter ignores show_monitor_list_threshold (vboctor) - closed.
- 0009176: [db postgresql] Port 0008699: Get Time Tracking Information return a SQL query error (vboctor) - closed.
- 0009208: [other] Several actions on bug update page lead into System Warning and App. Error (daryn) - closed.
- 0007764: [scripting] APPLICATION WARNING #100: Configuration option 'category_enum_string' not found (vboctor) - closed.
[28 issues]

mantisbt - 1.2.0a2 (not yet released)
=====================================
- 0009395: [bugtracker] Summary page generates incorrect filter links for categories (daryn) - resolved.
- 0009392: [other] Remove ?> from the end of config_defaults_inc.php and config_inc.php to avoid errors due to blank lines (vboctor) - resolved.
- 0009258: [api soap] Adding bug throws fault for undefined "due_date" field (vboctor) - resolved.
- 0009043: [installation] Invalid link to login page after installation (bug + patch) (jreese) - resolved.
- 0009387: [db postgresql] Cannot create new user (invalid input syntax for type boolean: "2") (jreese) - resolved.
- 0009166: [graphs] JPGraph - Array keys Should be checked with isset() - especially when error reporting is E_ALL (grangeway) - resolved.
- 0008606: [api soap] Problem with categories (planser) - resolved.
- 0009345: [documentation] Document PHP extensions required by Mantis (vboctor) - resolved.
- 0008699: [db postgresql] Get Time Tracking Information return a SQL query error (grangeway) - resolved.
- 0009187: [security] arbitrary file inclusion through user preferences page (giallu) - resolved.
- 0009370: [documentation] User Documentation link is wrong (jreese) - resolved.
- 0007953: [time tracking] Time Tracking assigment lost, when changing issue status without note text (daryn) - resolved.
- 0009364: [administration] SYSTEM WARNING message received when deleting a project (jreese) - resolved.
- 0009312: [integration] wiki integration and undefined function auth_is_user_authenticated (with patch) (jreese) - resolved.
- 0009349: [bugtracker] Tagging/untagging an issue should update it's last modified date (vboctor) - resolved.
- 0009348: [bugtracker] Monitoring/unmonitoring an issue should update it's last modified date (vboctor) - resolved.
- 0009347: [bugtracker] Due Date should be disabled by default (vboctor) - resolved.
- 0009332: [relationships] Remove auth_get_current_user_id from relationship_api.php (vboctor) - resolved.
- 0009346: [bugtracker] Due Date is shown in history even if user doesn't have access to view due dates (vboctor) - resolved.
- 0008372: [performance] Control Page Overload (grangeway) - resolved.
- 0009138: [other] Submit Report doesn't work (grangeway) - resolved.
- 0009288: [integration] Twitter updates don't show category correctly (always []) (vboctor) - resolved.
- 0008192: [integration] Twitter message has wrong escaping for quotation marks (vboctor) - resolved.
- 0009281: [localization] czech translation (vboctor) - resolved.
- 0009285: [custom fields] bad named function in /core/excel_api.php file (vboctor) - resolved.
- 0003241: [other] On Excel, no column headings display. (vboctor) - resolved.
- 0009267: [plug-ins] URL for updating plugin settings is wrong. (jreese) - resolved.
- 0009265: [plug-ins] Add an event to allow adding links to View Issues page (vboctor) - resolved.
- 0009237: [sql] When using g_limit_reporters produces SQL error for reporters (daryn) - resolved.
- 0008849: [time tracking] Emails ignore time tracking view threshold (daryn) - resolved.
- 0009228: [bugtracker] THIS INSTALLATION: sorting of notes does not work any more (jreese) - resolved.
- 0008160: [filters] filter for notes (daryn) - resolved.
- 0009099: [filters] using advanced filtering leads to APPLICATION ERROR 0000401 (daryn) - resolved.
- 0008980: [security] Port: Remote Code Execution in adm_config (giallu) - resolved.
- 0008977: [security] Port 0008974: XSS Vulnerability in filters (thraxisp) - resolved.
- 0009170: [other] Fix for 0008981 (protection against multiple submissions) broken IE and Opera support (vboctor) - resolved.
- 0008357: [time tracking] "Total time for issue" is shown even for users under threshold (daryn) - resolved.
- 0008916: [filters] Monitor by filter ignores show_monitor_list_threshold (daryn) - resolved.
- 0009141: [bugtracker] summary_page error when DB is empty (giallu) - resolved.
- 0009133: [security] "APPLICATION ERROR #19" when switching project in revision 5250 (thraxisp) - resolved.
- 0002963: [performance] manage_proj_edit_page executes more than 5000 queries (grangeway) - resolved.
- 0008675: [db postgresql] Incorrect use of boolean in postgres 8.2.4 (grangeway) - resolved.
- 0009115: [administration] Removing user's access to a private project doesn't work (vboctor) - resolved.
- 0009040: [administration] Missing category_id column (vboctor) - resolved.
- 0007508: [filters] Custom fields should have a additional flag, if they should be avaliable as filter or not. (daryn) - resolved.
- 0009087: [change log] Renaming a version doesn't update the corresponding issue fields (jreese) - resolved.
- 0009001: [change log] memory exhausted on changelog (giallu) - resolved.
- 0008843: [time tracking] Ignores tracking_reporting_threshold (daryn) - resolved.
- 0009094: [other] Insert page break between issues when exporting Microsoft Word DOC format (vboctor) - resolved.
[49 issues]

mantisbt - 1.2.0a1 (released 2008-04-18)
========================================
- 0008791: [custom fields] Custom fields in all projects instead of only the linked (vboctor) - resolved.
- 0007808: [feature] Strike a resolved bug in notes and links (jreese) - resolved.
- 0009046: [localization] French translation for $s_bug_assign_to_button (Bithunter) - closed.
- 0008621: [time tracking] The expand icon is inverted for the Time tracking section (vboctor) - closed.
- 0008995: [security] CSRF Vulnerabilities in user_create (thraxisp) - closed.
- 0008565: [other] Formatting of summary in My View is not consistent with View Issues page (vboctor) - closed.
- 0008486: [tools] No database stat of tag table displayed (zakman) - closed.
- 0007463: [bugtracker] Issue with many child issues produced performance problem (grangeway) - closed.
- 0007716: [db mssql] Can not handel Querry with over 3000 bugs (grangeway) - closed.
- 0008518: [custom fields] Enumerated Custom Field limited to 255 (grangeway) - closed.
- 0006666: [other] SIGSEGV in pcre_config (grangeway) - closed.
- 0008576: [email] Wrong links to comments in email notifications (grangeway) - closed.
- 0008136: [bugtracker] Some
 texts may cause php crash without error message (grangeway) - closed.
- 0008578: [webpage] Wrong style class used in if ... else (vboctor) - closed.
- 0008660: [administration] Provide a way to hide/show users with global access in manage project page (vboctor) - closed.
- 0008569: [installation] Errors when default language = auto ? (grangeway) - closed.
- 0008740: [other] print_all_bug_page_word.php uses raw SQL rather than API (vboctor) - closed.
- 0008710: [custom fields] display past years in Custom date field (vboctor) - closed.
- 0003911: [bugtracker] Mantis violates RFC2616 when redirecting (giallu) - closed.
- 0007712: [db mysql] mantis_config_table (thraxisp) - closed.
- 0008778: [bugtracker] Add newly reported issues to last visited (vboctor) - closed.
- 0008748: [db mysql] phpMyAdmin reports a warning message (thraxisp) - closed.
- 0008797: [localization] Improve the german translation to avoid baby talk (MartinFuchs) - closed.
- 0008799: [graphs] Top logo (mantis_logo.gif) and URL it points to shall be configurable (jreese) - closed.
- 0008826: [localization] german localization (and maybe other languages, too): blocking and blocked relation text is swapped (MartinFuchs) - closed.
- 0007130: [customization] Unbranding Mantis (jreese) - closed.
- 0007158: [feature] Change Mantis top logo link to internal link (giallu) - closed.
- 0008795: [localization] strtoupper() fail on localized strings (thraxisp) - closed.
- 0008766: [plug-ins] Move text processing and formatting to an official plugin (jreese) - closed.
- 0008536: [webpage] Top header logos are all distorted to the same size (giallu) - closed.
- 0008865: [db mysql] Wrong format for insert into Database (jreese) - closed.
- 0008873: [other] Bug print / Word export should include the URL for downloading attachments (vboctor) - closed.
- 0008874: [customization] Provide the ability to add "build" column to View Issues, Print Issues, and CSV export (vboctor) - closed.
- 0008771: [bugtracker] Port 0008738: Allow bugs to have no category (jreese) - closed.
- 0008757: [integration] Add wiki integration for TWiki (vboctor) - closed.
- 0008787: [feature] WikkaWiki Integration (vboctor) - closed.
- 0008890: [bugtracker] Add group action for updating "product build" field for multiple issues (vboctor) - closed.
- 0008491: [feature] Would like label for 'check for more issues' (giallu) - closed.
- 0008706: [email] Bad email headers for notifications (giallu) - closed.
- 0008369: [email] Making phpMail work with Gmail (giallu) - closed.
- 0008535: [other] Replace RSS icon with Universal feed icon (jreese) - closed.
- 0008927: [filters] "Create Permalink" is controlled by $g_view_filters (vboctor) - closed.
- 0008435: [feature] Implement Global and Inheriting Categories Structure (jreese) - closed.
 - 0008771: [bugtracker] Port 0008738: Allow bugs to have no category (jreese) - closed.
- 0008245: [bugtracker] Target Version value lost in update issue page (giallu) - closed.
- 0008923: [bugtracker] Ability for users and administrators to customize columns for View Issues, Print Issues, CSV, and Excel (vboctor) - closed.
- 0008922: [bugtracker] Support including 'description', 'steps_to_reproduce', 'additional_information' as columns (vboctor) - closed.
- 0008891: [administration] change version's released property's default value to unreleased (jreese) - closed.
- 0008937: [bugtracker] Users with privileges below Administrator cannot see subprojects. (jreese) - closed.
- 0008938: [authentication] Allow site administrators to customize or disable reauthentication timeout. (jreese) - closed.
- 0008969: [bugtracker] Can't switch off Inherit Global Categories (jreese) - closed.
- 0008887: [graphs] Graph legend displays default status names (thraxisp) - closed.
- 0008875: [integration] Refactor Wiki integration engines to achieve better consistency (jreese) - closed.
- 0008514: [other] Support a dynamic and lightweight plugin system (jreese) - closed.
- 0008346: [documentation] Use DocBook for Mantis manual (giallu) - closed.
- 0008965: [api soap] Adding/Updating/Deleting versions using SOAP API requires ADMINISTRATOR rights (vboctor) - closed.
- 0004491: [relationships] Deleting duplicate relationshilp left value in 'duplicate_id' field (vboctor) - closed.
- 0008577: [email] Long utf-8 encoded subject fails (phpmailer bug) (giallu) - closed.
- 0008970: [bugtracker] project delete failed due to category changes (jreese) - closed.
- 0008920: [bugtracker] Visual mark to differentiate "none" and "normal" priorities (vboctor) - closed.
- 0003816: [sponsorships] Include total sponsorships for an issue in csv export (vboctor) - closed.
- 0008981: [bugtracker] Multiple bug submissions (vboctor) - closed.
- 0007214: [printing] Export issues from mantis to a freemind mindmap (vboctor) - closed.
- 0001910: [bugtracker] Provide ability to make version obsolete (vboctor) - closed.
- 0007634: [custom fields] Support relative default for Date Custom Fields (e.g. {tomorrow}, {+2 days}, {next week}) (vboctor) - closed.
- 0009004: [custom fields] Support enumeration custom fields exposed as radio buttons (vboctor) - closed.
- 0009025: [javascript] Enhance Collapse API for Extensiblity and Plugin Usage (jreese) - closed.
- 0008651: [change log] Display release date in changelog for released version (jreese) - closed.
- 0009050: [other] Add support for "Copy Columns From/To" when customizing columns to view in View Issues, Print Issues, CSV, Excel (vboctor) - closed.
[69 issues]

mantisbt - 1.1.1 (released 2008-01-19)
======================================

Mantis 1.1.1

- 0008064: [graphs] Problem with JpGraph (thraxisp) - resolved.
- 0008756: [security] "Most active bugs" summary XSS vulnerability (giallu) - closed.
- 0008681: [upgrade] Mantis 1.1.0 has a dependency on stripos which was added in PHP 5 (vboctor) - closed.
- 0008684: [installation] UPGRADING file missing in doc (thraxisp) - closed.
- 0008707: [filters] "My View" shows warnings about "sort" / "dir" not defined (vboctor) - closed.
- 0008708: [graphs] graph fails with error claiming bad colour name (thraxisp) - closed.
- 0008758: [localization] Application error 18 with russian language (vboctor) - closed.
- 0008742: [localization] "actiongroup_error_issue_is_readonly" isn't defined (vboctor) - closed.
- 0008732: [graphs] Many options on bug_graph_page.php broken, inconsistent, incomplete (thraxisp) - closed.
- 0008721: [upgrade] css and icon paths incorrect (vboctor) - closed.
- 0008695: [api soap] Error with attachments - Method DISK (planser) - closed.
- 0008692: [localization] Russian translation update. (vboctor) - closed.
- 0008662: [bugtracker] Unneeded executable bits on mantis modules (giallu) - closed.
- 0008738: [bugtracker] Could not create bug if project have not categorys and g_default_bug_category is empty (vboctor) - closed.
- 0008683: [api soap] mc_projects_get_user_accessible raises SYSTEM NOTICE, but it should not (vboctor) - closed.
- 0008759: [api soap] Improve error handler to report location of errors (vboctor) - closed.
- 0008767: [api soap] incorrect date and time handling in mc_project_version_add and mc_project_version_update (planser) - closed.
- 0008770: [email] Sending queued emails is still attempted even if email notifications are turned OFF, causing errors (vboctor) - closed.
[18 issues]

mantisbt - 1.1.0 (released 2007-12-19)
======================================

This is Mantis 1.1.0 Gold Release. All users with pre-release 1.1.0x releases and with 1.0.x releases are encouraged to upgrade to this release. For users who are using non-latin character sets, a manual upgrade process is necessary.

- 0006948: [filters] Not able to filter by project (vboctor) - resolved.
- 0008679: [security] XSS Vulnerability in view.php , Attached Files (vboctor) - closed.
- 0008645: [roadmap] Issue appears more than once in the Roadmap for a release. (jreese) - closed.
- 0008617: [api soap] mc_version() should return the Mantis version (vboctor) - closed.
- 0008602: [api soap] Provide a SOAP friendly error handler (vboctor) - closed.
- 0008604: [api soap] Wrong URL in E-Mail notifications by changes via webservice (vboctor) - closed.
- 0008661: [bugtracker] Possible crash condition leading to blank or incomplete page (giallu) - closed.
- 0008644: [api soap] Many errors of type SYSTEM NOTICE are thrown (planser) - closed.
- 0008437: [localization] Update to italian translation (giallu) - closed.
- 0008591: [api soap] Error in api/soap/mc_filter_api.php#mc_filter_get() (planser) - closed.
- 0008567: [installation] cannot install on shared webserver, core/*.php inconsistent use of require_once($t_core_dir) (vboctor) - closed.
- 0008674: [email] Php script for sending mail via cronjob raise error when lang set to auto (vboctor) - closed.
- 0008499: [graphs] Many graphs show "not enough data to create graph" after upgrading from 1.1.0a2 (jreese) - closed.
[14 issues]

mantisbt - 1.1.0rc3 (released 2007-11-23)
=========================================

This is the third release candidate for Mantis 1.1.0, we believe we are now very close to the final release. This release has several fixes relating to SOAP API, DB2, and others. All users running 1.1.0x releases are encouraged to update to this release.

- 0008509: [bugtracker] Empty Note is added when updating issue (giallu) - closed.
- 0008238: [filters] urldecode() error on creating PermaLink (MartinFuchs) - closed.
- 0008063: [other] mantis_version shouldn't be in the configuration file (jreese) - closed.
- 0008511: [email] send_emails.php is missing <?php at the start of the file (giallu) - closed.
- 0008525: [api soap] mc_projects_get_user_accessible() shouldn't return ALL_PROJECTS (vboctor) - closed.
- 0008524: [integration] core/checkin.php is missing toplevel <? causing the script to fail. (vboctor) - closed.
- 0008566: [api soap] mc_project_version_add() doesn't set the date_order field correctly (vboctor) - closed.
- 0007646: [bugtracker] Show content link should change to Hide content when clicked (giallu) - closed.
- 0008494: [api soap] Remove backward compatibility code from SOAP API (vboctor) - closed.
- 0008589: [bugtracker] file_download.php doesn't work with attachment names that contain accentuated characters when using Firefox (vboctor) - closed.
- 0008541: [api soap] $g_mc_error_when_version_not_found is not defined (vboctor) - closed.
- 0008564: [db db2] Attempting installation of MANTIS400, table not being created (slashsplat) - closed.
- 0008519: [api soap] Name collision between NuSoap SoapClient and PHP 5 Soap extension (vboctor) - closed.
- 0008263: [scripting] smaller issue in email address recognition (jreese) - closed.
- 0008592: [api soap] Error in api/soap/mc_file_api.php#mc_file_add() (vboctor) - closed.
[15 issues]

mantisbt - 1.1.0rc2 (released 2007-10-04)
=========================================

This is the second release candidate for 1.1.0 release. It is recommended that all users with 1.1.0x releases upgrade to this version. This is mainly a bug fixes release.

- 0008453: [bugtracker] Sub-project My View highlights all issues as recent (jreese) - resolved.
- 0008480: [security] XSS Vulnerability in Tag details, Attach Tags (jreese) - closed.
- 0008463: [localization] re-authentication button does not appear in user's language (jreese) - closed.
- 0008467: [security] Users can login using the MD5 hash of the password (vboctor) - closed.
- 0008446: [localization] Update Estonian Language (vboctor) - closed.
- 0007497: [other] Summary page is little of Garble (vboctor) - closed.
- 0008454: [time tracking] time tracking sum on request wrong (vboctor) - closed.
- 0008443: [tagging] creating new tags for multi-selection (jreese) - closed.
- 0007999: [other] Project list view corrupted (vboctor) - closed.
- 0008459: [localization] Update catalan translation (vboctor) - closed.
- 0008461: [signup] signup_page and lost_pwd_page don't work if anonymous access not enabled (vboctor) - closed.
- 0008254: [integration] Gravatar integration should handle empty email addresses (giallu) - closed.
- 0008378: [other] Select custom avatar for default Gravatar image. (giallu) - closed.
- 0005612: [other] Redirect time ignored in preferences (giallu) - closed.
- 0008475: [printing] Function used two times in the same file (only one is necessary) (vboctor) - closed.
- 0008476: [other] Add a service to disposable email address checker (zakman) - closed.
- 0008468: [localization] $s_select_option is missing in german language (vboctor) - closed.
- 0008457: [administration] Removing a userdefined field from project results in APPLICATION ERROR #203 (vboctor) - closed.
- 0008493: [api soap] Attachments created via SOAP API don't honor attachments_file_permissions config option (vboctor) - closed.
- 0008492: [api soap] Add attachment succeeds but creates broken attachment if upload path not found (vboctor) - closed.
- 0008490: [administration] Undefined variable: t_version in manage_proj_ver_copy.php (vboctor) - closed.
- 0008489: [localization] Update Japanese Localization for 1.1.0rc2 (vboctor) - closed.
- 0007787: [feature] Robust threading of e-mails using MIME headers (giallu) - closed.
- 0008465: [filters] collapse filter section as default (giallu) - closed.
- 0008241: [customization] Disable Roadmap (vboctor) - closed.
- 0008500: [other] Empty entry in "Category" drop down (vboctor) - closed.
[26 issues]

mantisbt - 1.1.0rc1 (released 2007-08-02)
=========================================

Mantis 1.1.0rc1 is the first release candidate for Mantis 1.1.0 release. This release follows for alpha releases. It includes features like db2 support, XWiki integration and tagging. It also has security improvements and some localization updates. All users of Mantis 1.1.0aX are encouraged to upgrade.

Installations that use non-latin character sets should check the website for the upgrade path.

The code is branched along with this release, hence, the 1.1.0 branch will take fixes that are needed to release 1.1.0 gold. New features will go into CVS HEAD which will go into 1.2.0 release.

- 0008396: [tagging] Don't allow creating tags if user can't attach them (jreese) - closed.
- 0008188: [other] Consistent use of collapse_api.php (DGtlRift) - closed.
- 0006850: [localization] obsolete MANTIS_ERROR (giallu) - closed.
- 0008231: [bugtracker] Summary "By Date" shows suspicious totals (giallu) - closed.
- 0008233: [bugtracker] Long standing issues report on summary page (giallu) - closed.
- 0008246: [upgrade] Add support for running arbitrary functions (thraxisp) - closed.
- 0008206: [integration] Add (gr)avatars for users (giallu) - closed.
- 0008252: [feature] Gravatars and case sensitivity of email addresses (giallu) - closed.
- 0008283: [other] $g_show_notices and $g_show_warnings should be marked as obsolete (vboctor) - closed.
- 0008285: [other] File Download generates an E_NOTICE (vboctor) - closed.
- 0008286: [security] Add .htaccess to block access to core/, doc/, lang/, packages/ (vboctor) - closed.
- 0008291: [administration] check.php: Use of undefined constant db_is_connected - assumed 'db_is_connected' (vboctor) - closed.
- 0008292: [other] my_view_inc: syntax error (vboctor) - closed.
- 0008237: [graphs] Error in dependency graphs (vboctor) - closed.
- 0008269: [roadmap] Reporting a new issue, ADMIN/MANAGER/DEVELOPER should see field "Target Version" (jreese) - closed.
- 0008311: [tagging] System Notice: Undefined index 'tag_select' in view_all_bug_page.php (jreese) - closed.
- 0008274: [tagging] Implement Keyword Tagging Features (jreese) - closed.
- 0008312: [security] Install script shouldn't include password in the form (jreese) - closed.
- 0008324: [administration] Rendering of "Manage Users" menu link ignores $g_manage_user_threshold (giallu) - closed.
- 0007846: [relationships] APPLICATION ERROR #1802: Relationship not found (vboctor) - closed.
- 0007996: [custom fields] Confusion in string values of enumerated custom field due to non strict comparison of strings (zakman) - closed.
- 0007995: [other] Confusion in product_version values due to string comparisons with == operator (zakman) - closed.
- 0008337: [tagging] Blank page (no data) when invalid tag filter chosen (jreese) - closed.
- 0008341: [other] Xwiki integration (vboctor) - closed.
- 0008340: [security] Changing password should create a new cookie_string (vboctor) - closed.
- 0008327: [documentation] show_extended_project_browser can only be set to OFF or ON (vboctor) - closed.
- 0008343: [administration] Admin created users bypass realname validity check (vboctor) - closed.
- 0007690: [db mssql] number_format(); bad for SQL statments (vboctor) - closed.
- 0008344: [other] Tokens API Clean-up and Changes (jreese) - closed.
- 0007809: [custom fields] Filter "none" on custom fields doesn't work (giallu) - closed.
- 0008371: [db db2] Use "days" instead of "to_days" when comparing dates for db2 (vboctor) - closed.
- 0004614: [relationships] Relationship graph: sometimes arrows direction is not correct (vboctor) - closed.
- 0005093: [webpage] Rights in custom menu does not work (vboctor) - closed.
- 0008387: [db db2] adodb2-db2.DBTimeStamp uses TO_DATE() which doesn't work on DB2 (vboctor) - closed.
- 0008384: [db db2] db_table_exists() doesn't work in case of DB2 (vboctor) - closed.
- 0008385: [db db2] ADODB_db2._insert_id doesn't work (vboctor) - closed.
- 0008386: [db db2] ADODB_db2 uses an invalid time format which is not accepted by db2 (vboctor) - closed.
- 0008389: [db db2] Remove references to odbc_db2 driver from code (we only support db2) (vboctor) - closed.
- 0007855: [localization] Priority colum header String not taken from strings file (vboctor) - closed.
- 0008388: [other] Undefined variable $p_this_var in helper_api.php (vboctor) - closed.
- 0008395: [bugtracker] Recently Visited is not displayed. (jreese) - closed.
- 0008336: [security] Require re-login for high impact tasks (jreese) - closed.
- 0008295: [printing] Include the bug history in the printout (zakman) - closed.
- 0008368: [tagging] "Access Denied." when trying to attach a tag to an issue I reported (vboctor) - closed.
- 0008380: [administration] Deleting old user Account results in Database inconsistency (vboctor) - closed.
- 0008423: [localization] Update German Localization (vboctor) - closed.
- 0008413: [performance] Provide a way to show queries for an access level threshold (vboctor) - closed.
- 0008412: [performance] When showing queries show the time spent in SQL vs. PHP (vboctor) - closed.
- 0008407: [performance] Add caller function info to queries list (giallu) - closed.
- 0007647: [localization] [de] Translation change from "Problem" (problem) to "Eintrag" (issue) (vboctor) - closed.
- 0008425: [localization] Update portuguese_brazil localization (vboctor) - closed.
- 0008428: [localization] Update French Localization (vboctor) - closed.
- 0007720: [localization] Japanese language translation patch (vboctor) - closed.
- 0008421: [other] Recently visted is showing some serialized filter instead of bug ids (vboctor) - closed.
- 0008429: [localization] fix miscellanious errors in the german translation files (vboctor) - closed.
[55 issues]

mantisbt - 1.1.0a4 (released 2007-08-01)
========================================

This is the fourth alpha release for Mantis 1.1.0. It is likely to be the last alpha. The next release is planned to be an rc1 release with which we will branch the code and implement a feature freeze. This release has more than 100 features and bug fixes including addition of MantisConnect SOAP API, Twitter integration, permalink filters, MediaWiki integration, custom relationships, more reporting in summary page, project info page, 6 security fixes and a lot of other fixes and improvements. It is a recommended upgrade for all 1.1.0aX installations.

- 0008091: [csv] csv_export doesn't work when project name contains accentuated characters (vboctor) - resolved.
- 0008154: [security] Port: CVE-2007-3215: PHPMailer vulnerability (thraxisp) - closed.
- 0008164: [security] Potential URL redirection flaw in set_project.php (grangeway) - closed.
- 0008165: [security] Potential URL redirection flaw in account_prefs_reset.php (grangeway) - closed.
- 0008166: [security] Potential URL redirection flaw in permalink_page.php (grangeway) - closed.
- 0008180: [security] Potential URL redirection flaw in login.php (grangeway) - closed.
- 0008181: [security] Display of database error message could be used to generate Cross site scripting issue (grangeway) - closed.
- 0007938: [rss] Replace non free RSS creation class (vboctor) - closed.
- 0007907: [installation] Allow using system adodb (vboctor) - closed.
- 0007895: [bugtracker] Recently Visited when logged in as Anonymous shows issues i have not visited (giallu) - closed.
- 0007885: [other] System logging constants (vboctor) - closed.
- 0008044: [bugtracker] Edit/Delete bugnote buttons missing (giallu) - closed.
- 0007871: [bugtracker] Move "Add Note" pane below previous notes (giallu) - closed.
- 0006725: [filters] Filtering on "duplicate of" fails while "has duplicate" works (giallu) - closed.
- 0007849: [custom fields] filters on custom date field causes SQL error (giallu) - closed.
- 0007842: [bugtracker] File attachment permissions (giallu) - closed.
- 0007125: [bugtracker] Application Error #200 (grangeway) - closed.
- 0007944: [time tracking] 'Update Perfs' error in 1.1.0a3 (vboctor) - closed.
- 0006782: [sql] MantisBT should do "SET NAMES $charset" on connect to database (vboctor) - closed.
- 0007965: [time tracking] Time tracking information not shown on email notifications (vboctor) - closed.
- 0008174: [bugtracker] & is displayed as & stopping us from using Unicode Characters (grangeway) - closed.
- 0006772: [other] Bugnote ids are numeric, which is not valid HTML (giallu) - closed.
- 0008150: [bugtracker] Summary By Date could show also resolved bugs count (giallu) - closed.
- 0008120: [installation] all the files and directories has permission 777 in mantis-1.0.8.tar.gz (vboctor) - closed.
- 0007531: [bugtracker] Get a wrong (?) error message by upload a big file (grangeway) - closed.
- 0007984: [bugtracker] Wrong default value for additional info during report (vboctor) - closed.
- 0007985: [administration] Database Schema that is more up-to-date than code is reported as out-of-date (vboctor) - closed.
- 0007986: [custom fields] Removing a custom field to project link from manage_custom_field_edit_page.php returns to wrong page (vboctor) - closed.
- 0007931: [time tracking] $g_time_tracking_hours config option is never used (davidnewcomb) - closed.
- 0007987: [custom fields] Projects that a custom field can be linked to in manage_custom_field_edit_page.php shouldn't include ALL PROJECTS (vboctor) - closed.
- 0007993: [filters] "Create Permalink" should show URL in a Mantis page (vboctor) - closed.
- 0007992: [filters] "Create Permalink" should support custom fields (vboctor) - closed.
- 0008018: [bugtracker] Add configuration option to allow/disallow free text in platform, os, and os_build (vboctor) - closed.
- 0005333: [other] Invalid zip file core/adodb/adodb-time.zip in CVS (giallu) - closed.
- 0008047: [db db2] DB2 Support (experimental) (vboctor) - closed.
- 0008016: [email] Check Email broken in 1.1.0a3 (vboctor) - closed.
- 0008023: [localization] [all lang] Wrong URL on summary (vboctor) - closed.
- 0008031: [localization] Update simplified chinese localization to 1.1.0a3 (giallu) - closed.
- 0007981: [custom fields] Manage projects custom field: Link custom field to project Errors (vboctor) - closed.
- 0008005: [bugtracker] items cannot be added to projects without categories (vboctor) - closed.
- 0007982: [filters] "Create Permlink" not reliable (vboctor) - closed.
- 0008077: [email] Block use of disposable email addresses (vboctor) - closed.
- 0008054: [other] Mediawiki integration (vboctor) - closed.
- 0006217: [localization] [all lang] Wrong fIlename on download (vboctor) - closed.
- 0007947: [roadmap] when bulk assigning target version I get permission messages (vboctor) - closed.
- 0006773: [relationships] When cloning an issue, cannot make it "not related" to parent issue (vboctor) - closed.
- 0008105: [time tracking] Total time on billing page (vboctor) - closed.
- 0008094: [administration] Managing versions / release schedule accross multiple projects. (vboctor) - closed.
- 0008084: [localization] Spelling mistake in value of string $s_this_bug file lang/strings_spanish.txt (zakman) - closed.
- 0008051: [localization] [all lang] Wrong fIlename on print report (zakman) - closed.
- 0008113: [localization] Error typo $s_signup_link in Spanish traslation ..... (zakman) - closed.
- 0008115: [integration] Implement Twitter Integration (vboctor) - closed.
- 0008067: [bugtracker] show status legend on top AND bottom (zakman) - closed.
- 0003477: [bugtracker] print_mantis_error() function does not display msg. (grangeway) - closed.
- 0004831: [installation] accessing mantis webserver through a proxy websserver (vboctor) - closed.
- 0007417: [documentation] operating mysql user needs DELETE privilege (grangeway) - closed.
- 0007928: [bugtracker] print_column_eta function missing (vboctor) - closed.
- 0008131: [upgrade] install/upgrade tries to use "set schema" on a non db2 installation. (vboctor) - closed.
- 0008144: [administration] Remove obsolete CSS edit tool (vboctor) - closed.
- 0005138: [email] Bugnote Id doesn't appear in emails (vboctor) - closed.
- 0003902: [bugtracker] all logins fail with "Cannot modify header information" (grangeway) - closed.
- 0002950: [bugtracker] Hide Edit or Delete Profile when not needed (grangeway) - closed.
- 0002996: page link from email (in browser) - display more than "access denied" (grangeway) - closed.
- 0008147: [bugtracker] 'continue' while outside loop in function print_news_string_by_news_id() (grangeway) - closed.
- 0007255: [rss] APPLICATION WARNING #user_get_field() for NO_USER (grangeway) - closed.
- 0007487: [graphs] wrong title of dependency-graph (grangeway) - closed.
- 0006116: [rss] "Issues" RSS feed doesn't work when $g_anonymous_account = '' (grangeway) - closed.
- 0008168: [localization] german localisation in the current installation at www.mantisbt.org/bug (giallu) - closed.
- 0008159: [scripting] Provide MantisConnect webservice out of the box as the Mantis SOAP API (vboctor) - closed.
- 0008111: [bugtracker] No space between date and username in email notifications (grangeway) - closed.
- 0008002: [custom fields] Unable to report issue. Error "data too long" on custom field name (grangeway) - closed.
- 0007548: [relationships] Status is underlined using a deprecated HTML element (giallu) - closed.
- 0007912: [db mssql] Time tracking doesn't work- SQL syntax error (grangeway) - closed.
- 0008103: [bugtracker] Cannot modify the bugnote order. (giallu) - closed.
- 0007733: [ldap] when using LDAP auth blank page upon login if LDAP extension not loaded (grangeway) - closed.
- 0008176: [email] Email Server offline causes a delay in mantis interface (grangeway) - closed.
- 0005544: [db mssql] MSSQL APPLICATION ERROR 0000401 When Uploading Files (grangeway) - closed.
- 0007140: [db mssql] Upload File Less than 8 K (grangeway) - closed.
- 0006063: [scripting] APPLICATION ERROR 0000401 on MSSQL while uploading files (grangeway) - closed.
- 0007138: [other] pages are not valid xhtml 1.0 transitional (giallu) - closed.
- 0008101: [feature] List of involved developers (vboctor) - closed.
- 0008195: [bugtracker] Create Project Info Page (vboctor) - closed.
- 0007681: [localization] [es] Full review of spanish translation (Bithunter) - closed.
- 0007346: [custom fields] Copy custom fields from one project to another (zakman) - closed.
- 0008201: [localization] Sync italian messages (giallu) - closed.
- 0008177: [localization] Extra characters in lang/strings_spanish.txt (giallu) - closed.
- 0007961: [localization] Spanish translation (Bithunter) - closed.
- 0008190: [bugtracker] Showing Access Level in Note details (giallu) - closed.
- 0008130: [relationships] Custom relationships (grangeway) - closed.
- 0008194: [roadmap] Roadmap and Changelog list nesting for parent/child issues (grangeway) - closed.
- 0006836: [filters] Switching to "Advanced Filters" (or "Simple Filters") forgets the ?filter=N setting (grangeway) - closed.
- 0007340: [webpage] my view: status percentage legend shown on top and not as stated (giallu) - closed.
- 0007597: [email] Notification e-mail contain no messages. (grangeway) - closed.
- 0007812: [bugtracker] Remove white box around jump button in main menu (zakman) - closed.
- 0007735: [filters] Filters are lost when clicking on page navigation (vboctor) - closed.
- 0007730: [localization] [de] Translation change from "Aktualisieren" to "Bearbeiten" (zakman) - closed.
- 0006468: [filters] My View page incorrectly sets filters (grangeway) - closed.
- 0006633: [change log] Editing a bug in advanced bug update page (grangeway) - closed.
- 0008121: [custom fields] Error message doesn't show field name after entering invalid value in custom field (zakman) - closed.
- 0008208: [bugtracker] Most popular bug table on summary page (giallu) - closed.
- 0008214: [change log] Change Log displays the version description as many times as the number of issues show (grangeway) - closed.
- 0008215: [sql] APPLICATION ERROR 401 on MySQL with file_upload_method = DISK (1.1.0a4-CVS) (giallu) - closed.
- 0008221: [localization] Sync italian messages (vboctor) - closed.
- 0008220: [db mssql] New summary item contains invalid sql (giallu) - closed.
- 0008138: [other] Add more services to disposable email address checker (zakman) - closed.
- 0008224: [authentication] anonymous login is not automatic (vboctor) - closed.
[106 issues]

mantisbt - 1.0.8 (released 2007-07-01)
======================================

Mantis 1.0.8 is a maintenance release for the 1.0.x stable releases branch. This release was mainly focused on fixing an application error that caused users to sometimes get a blank screen and some minor fixes that were requested by packagers for Linux distributions. It is a recommended updated for all 1.0.x users.

- 0007939: [rss] Port 7738: Replace non free RSS creation class (vboctor) - closed.
- 0008019: [other] Port 5333: Invalid zip file core/adodb/adodb-time.zip in CVS (giallu) - closed.
- 0008020: [installation] Port 7907: Allow using system adodb (giallu) - closed.
- 0008029: [localization] Spelling mistake in value of string $s_by_severity file lang/strings_spanish.txt (giallu) - closed.
- 0007902: [bugtracker] constant_inc is missing statement in 1.0.7 (vboctor) - closed.
[5 issues]

mantisbt - 1.1.0a3 (released 2007-05-08)
========================================

This alpha release includes about 50 enhancements and bug fixes. One of the major highlights of this release is the time tracking feature. There is also enhanced management for custom fields, support for URL to express filter criteria, and many others. Similar to 1.1.0a2, the upgrade path to non-English installations is not yet implemented, hence, this alpha release SHOULD ONLY BE USED FOR ENGLISH installations. This release implements database schema changes and hence the install script will need to be run.

- 0007795: [security] Port 7784: XSS vulnerabilities (vboctor) - closed.
- 0007921: [localization] Add Greek UTF-8 translation (vboctor) - closed.
- 0007650: [roadmap] "Issues done" in roadmap should be included for each release, not for each project. (vboctor) - closed.
- 0007651: [roadmap] Support ability to set target release for multiple issues (vboctor) - closed.
- 0007658: [custom fields] Adding the option to manage the projects custum field will be added to. (vboctor) - closed.
- 0007662: [change log] Support ability to set fixed in version for multiple issues (vboctor) - closed.
- 0007663: [upgrade] Add support for unattended upgrades (vboctor) - closed.
- 0007680: [signup] Successful Sign up should set login count to 1 (vboctor) - closed.
- 0007682: [roadmap] Add progress bar to Roadmap (