Commit Graph

78 Commits

Author SHA1 Message Date
DL6ER a3efdab5df Small fix 2016-12-11 19:55:58 +01:00
DL6ER 99ddf6cabd Change temperature unit via settings page 2016-12-11 19:37:15 +01:00
DL6ER 4ec6a2d673 Modifying excluded entries for top domains/top ads and top clients working 2016-12-11 19:29:23 +01:00
DL6ER 7c1c45dbbd Simplified IP address validation 2016-12-11 18:34:02 +01:00
DL6ER 28ca620f31 Enable/Disable query logging implemented 2016-12-11 18:30:48 +01:00
DL6ER f2974d4b61 Implemented setting of DNS server IPs 2016-12-11 18:14:23 +01:00
Mcat12 3c79f7c692 Merge pull request #222 from pi-hole/queryadsnoauth
Improve Query adlists scripts
2016-12-10 13:51:53 -05:00
Mcat12 8cf7e262a2 Remove CORS skip log message
It can fill up the error log really quickly, since this function is now used on all pages. Most of these pages are not able to be protected by CORS but can still be protected by the Host check.
2016-12-10 11:47:47 -05:00
DL6ER beeea0edfb Implemented new "pihole -q <domain> -exact" argument in web UI 2016-12-06 13:30:53 +01:00
DL6ER acbef91e9c Make sure that js/pihole/queryads.js always finds its target + remove requirement for authorization on php/queryads.php for using it within the new blocking page 2016-12-05 11:04:00 +01:00
Mcat12 0dec4b8aa0 Protect Enable/Disable with a CSRF token check
The token is now added for all pages.
2016-12-04 13:16:45 -05:00
Mcat12 40c6ee9f5a Remove strict flag and change Host check
Since the Host header is easily manipulated, we can only check if
it's wrong and can't use it to validate that the client is authorized,
only unauthorized. There's no need for the strict flag anymore
because of this.
2016-12-02 16:06:43 -05:00
Mcat12 6b8fa7dbe4 Merge remote-tracking branch 'origin/devel' into secure-pause-resume
Conflicts:
	header.php
2016-12-01 20:47:04 -05:00
DL6ER fbe715c338 Small fix in password.php: Verify that there is a password hash before trying to access it 2016-11-24 12:54:26 +01:00
DL6ER 21649a2017 Extended password protection to php/queryads.php 2016-11-23 18:05:07 +01:00
DL6ER d9adcccbc3 Merge branch 'devel' into auth
Conflicts:
	header.php
2016-11-23 18:02:40 +01:00
DL6ER 5b15755014 Added new check for validity of domain name 2016-11-23 12:18:27 +01:00
DL6ER 64d532a95c Pass "Invalid domain!" error message to user 2016-11-22 15:36:16 +01:00
DL6ER 7f779e482f Check if url does exists (try to resolve!) 2016-11-22 15:30:51 +01:00
DL6ER 7f7604a6af Add "Query adlists" feature 2016-11-22 15:23:30 +01:00
DL6ER 9e3a092701 Addressed codacy issues 2016-11-21 10:51:45 +01:00
Mcat12 591bc2c3f5 Change another else for codacy 2016-11-20 18:23:18 -05:00
Mcat12 2989709a23 Re-arrange check_cors if statements for codacy 2016-11-20 18:11:02 -05:00
DL6ER f84d54558b Allow GET hash for API calls 2016-11-20 15:46:05 +01:00
DL6ER cd75d7e7a3 Remove hash from the javascript scripts. 2016-11-20 15:34:03 +01:00
DL6ER 02dc741209 Move from GET to SESSION variables for the sake of convenience 2016-11-20 15:27:35 +01:00
DL6ER 2c93be0174 Extended current password protection to gravity.sh page 2016-11-20 14:52:53 +01:00
DL6ER 6781fa7919 Merge branch 'devel' into auth 2016-11-20 14:47:25 +01:00
DL6ER d899293c67 Test if POST and GET variables are set before trying to actually access them. This increases code complexity noticable, let's see if codacy complains ... 2016-11-19 22:05:26 +01:00
DL6ER ba811544f8 Okay, once more ... 2016-11-18 15:25:32 +01:00
DL6ER f9b6d4d887 Make sure that the green "Success" box is only shown if gravity.sh returned "Pi-hole blocking is Enabled" 2016-11-18 15:04:46 +01:00
DL6ER 66e4da7724 Run gravity.sh from the web UI 2016-11-18 13:43:05 +01:00
Mcat12 b2b93e90b3 Add flag for strict CORS
Prevents enable/disable from requests without CORS info
2016-11-17 16:47:14 -05:00
DL6ER 4372c2e25b Extend hash auth to API calls 2016-11-16 23:35:10 +01:00
Mcat12 d2fcc36341 Require CORS check on all admin pages
This is mainly added so that an ad can't enable/disable the Pi-hole
by simply loading a url like `http://pi.hole/admin/index.php?disable`
2016-11-07 21:10:36 -05:00
Adam Warner b9f186befb Revert "set default time zone for date" 2016-10-18 15:52:58 +01:00
Mcat12 871bef985d Add fallback hash_equals and use old array syntax 2016-10-13 16:25:05 -04:00
Jakob Ackermann fb995872d1 run date command right before log event 2016-10-09 04:04:40 +02:00
Jakob Ackermann 9cd0f4b4fa use output of command date as datestring
this will imply the system time zone. command date and the given format
are supported by the majority of linux distros
2016-10-09 03:06:09 +02:00
Jakob Ackermann b73d6e0329 set default time zone for date
this prevents basic error messages from php(-cgi) for not setting the
timezone and then using UTC as default
2016-10-04 17:57:34 +02:00
brantje 4da38e5472 Check if a domain name is valid 2016-08-17 21:18:17 +02:00
Mcat12 62feb36640 Merge devel 2016-08-16 16:08:28 -04:00
Mcat12 c41d377eb3 Fix always returning invalid parameter 2016-08-16 15:55:41 -04:00
Mcat12 7265405424 Fix possible list param exploit
Sanitize list parameter, so that only the whitelist or blacklist are able to be read.
2016-08-16 15:17:28 -04:00
Mcat12 122f1d4bd0 Merge branch 'devel' into get-list-XSS-fix 2016-08-02 11:58:41 -04:00
Mcat12 9f6fac65cb Fix possible XSS attack through white/black lists 2016-07-20 20:43:18 -04:00
diginc f460607bde semicolon because php 2016-07-18 21:38:48 -05:00
diginc b6e177de6c Set a default error log when empty 2016-07-18 21:04:17 -05:00
diginc 246599a0ba Don't need docker server IP in here anymore 2016-07-08 08:23:12 -05:00
diginc d1ef51a358 cleanup and tested on alpine/debian 2016-07-07 23:30:58 -05:00