* Wed Feb 08 2023 ecsos <ecsos@opensuse.org>
- Update to 5.2.1
This is a security and bufix release.
* Security
- Fix (PMASA-2023-01, CWE-661, boo#1208186, CVE-2023-25727)
Fix an XSS attack through the drag-and-drop upload feature.
* Bugfix
- issue #17522 Fix case where the routes cache file is invalid
- issue #17506 Fix error when configuring 2FA without XMLWriter or Imagick
- issue Fix blank page when some error occurs
- issue #17519 Fix Export pages not working in certain conditions
- issue #17496 Fix error in table operation page when partitions are broken
- issue #17386 Fix system memory and system swap values on Windows
- issue #17517 Fix Database Server panel not getting hidden by ShowServerInfo configuration directive
- issue #17271 Fix database names not showing on Processes tab
- issue #17424 Fix export limit size calculation
- issue #17366 Fix refresh rate popup on Monitor page
- issue #17577 Fix monitor charts size on RTL languages
- issue #17121 Fix password_hash function incorrectly adding single quotes to password before hashing
- issue #17586 Fix statistics not showing for empty databases
- issue #17592 Clicking on the New index link on the sidebar does not throw an error anymore
- issue #17584 It's now possible to browse a database that includes two % in its name
- issue Fix PHP 8.2 deprecated string interpolation syntax
- issue Some languages are now correctly detected from the HTTP header
- issue #17617 Sorting is correctly remembered when $cfg['RememberSorting'] is true
- issue #17593 Table filtering now works when action buttons are on the right side of the row
- issue #17388 Find and Replace using regex now makes a valid query if no matching result set found
- issue #17551 Enum/Set editor will not fail to open when creating a new column
- issue #17659 Fix error when a database group is named tables, views, functions, procedures or events
- issue #17673 Allow empty values to be inserted into columns
- issue #17620 Fix error handling at phpMyAdmin startup for the JS SQL console
- issue Fixed debug queries console broken UI for query time and group count
- issue Fixed escaping of SQL query and errors for the debug console
- issue Fix console toolbar UI when the bookmark feature is disabled and sql debug is enabled
- issue #17543 Fix JS error on saving a new designer page
- issue #17546 Fix JS error after using save as and open page operation on the designer
- issue Fix PHP warning on GIS visualization when there is only one GIS column
- issue #17728 Some select HTML tags will now have the correct UI style
- issue #17734 PHP deprecations will only be shown when in a development environment
- issue #17369 Fix server error when blowfish_secret is not exactly 32 bytes long
- issue #17736 Add utf8mb3 as an alias of utf8 on the charset description page
- issue #16418 Fix FAQ 1.44 about manually removing vendor folders
- issue #12359 Setup page now sends the Content-Security-Policy headers
- issue #17747 The Column Visibility Toggle will not be hidden by other elements
- issue #17756 Edit/Copy/Delete row now works when using GROUP BY
- issue #17248 Support the UUID data type for MariaDB >= 10.7
- issue #17656 Fix replace/change/set table prefix is not working
- issue Fix monitor page filter queries only filtering the first row
- issue Fix "Link not found!" on foreign columns for tables having no char column to show
- issue #17390 Fix "Create view" modal doesn't show on results and empty results
- issue #17772 Fix wrong styles for add button from central columns
- issue #17389 Fix HTML disappears when exporting settings to browser's storage
- issue #17166 Fix "Warning: #1287 'X' is deprecated [...] Please use ST_X instead." on search page
- issue Use jquery-migrate.min.js (14KB) instead of jquery-migrate.min.js (31KB)
- issue #17842 Use jquery.validate.min.js (24 KB) instead of jquery.validate.js (50 KB)
- issue #17281 Fix links to databases for information_schema.SCHEMATA
- issue #17553 Fix Metro theme unreadable links above navigation tree
- issue #17553 Metro theme UI fixes and improvements
- issue #17553 Fix Metro theme login form with
- issue #16042 Exported gzip file of database has first ~73 kB uncompressed and rest is gzip compressed in Firefox
- issue #17705 Fix inline SQL query edit FK checkbox preventing submit buttons from working
- issue #17777 Fix Uncaught TypeError: Cannot read properties of null (reading 'inline') on datepickers when re-opened
- issue Fix Original theme buttons style and login form width
- issue #17892 Fix closing index edit modal and reopening causes it to fire twice
- issue #17606 Fix preview SQL modal not working inside "Add Index" modal
- issue Fix PHP error on adding new column on create table form
- issue #17482 Default to "Full texts" when running explain statements
- issue Fixed Chrome scrolling performance issue on a textarea of an "export as text" page
- issue #17703 Fix datepicker appears on all fields, not just date
- issue Fix space in the tree line when a DB is expanded
- issue #17340 Fix "New Table" page -> "VIRTUAL" attribute is lost when adding a new column
- issue #17446 Fix missing option for STORED virtual column on MySQL and PERSISTENT is not supported on MySQL
- issue #17446 Lower the check for virtual columns to MySQL>=5.7.6 nothing is supported on 5.7.5
- issue Fix column names option for CSV Export
- issue #17177 Fix preview SQL when reordering columns doesn't work on move columns
- issue #15887 Fixed DROP TABLE errors ignored on multi table select for DROP
- issue #17944 Fix unable to create a view from tree view button
- issue #17927 Fix key navigation between select inputs (drop an old Firefox workaround)
- issue #17967 Fix missing icon for collapse all button
- issue #18006 Fixed UUID columns can't be moved
- issue Add `spellcheck="false"` to all password fields and some text fields to avoid spell-jacking data leaks
- issue Remove non working "Analyze Explain at MariaDB.org" button (MariaDB stopped this service)
- issue #17229 Add support for Web Authentication API because Chrome removed support for the U2F API
- issue #18019 Fix "Call to a member function fetchAssoc() on bool" with SQL mode ONLY_FULL_GROUP_BY on monitor search logs
- issue Add back UUID and UUID_SHORT to functions on MySQL and all MariaDB versions
- issue #17398 Fix clicking on JSON columns triggers update query
- issue Fix silent JSON parse error on upload progress
- issue #17833 Fix "Add Parameter" button not working for Add Routine Screen
- issue #17365 Fixed "Uncaught Error: regexp too big" on server status variables page
- Rebase phpMyAdmin-config.patch.
* Thu May 12 2022 ecsos <ecsos@opensuse.org>
- Update to 5.2.0
* Bugfix
- issue #16521 Upgrade Bootstrap to version 5
- issue #16521 Drop support for Internet Explorer and others
- issue Upgrade to shapefile 3
- issue #16555 Bump minimum PHP version to 7.2
- issue Remove the phpseclib dependency
- issue Upgrade Symfony components to version 5.2
- issue Upgrade to Motranslator 4
- issue #16005 Improve the performance of the Export logic
- issue #16829 Add NOT LIKE %...% operator to Table search
- issue #16845 Fixed some links not passing through url.php
- issue #16382 Remove apc upload progress method (all upload progress code was removed from the PHP extension)
- issue #16974 Replace zxcvbn by zxcvbn-ts
- issue #15691 Disable the last column checkbox in the column list dropdown instead of not allowing un-check
- issue #16138 Ignore the length of integer types and show a warning on MySQL >= 8.0.18
- issue Add support for the Mroonga engine
- issue Double click column name to directly copy to clipboard
- issue #16425 Add DELETE FROM table on table operations page
- issue #16482 Add a select all link for table-specific privileges
- issue #14276 Add support for account locking
- issue #17143 Use composer/ca-bundle to manage the CA cert file
- issue #17143 Require the openssl PHP extension
- issue #17171 Remove the printview.css file from themes
- issue #17203 Redesign the export and the import pages
- issue #16197 Replace the master/slave terminology
- issue #17257 Replace libraries/vendor_config.php constants with an array
- issue Add the Bootstrap theme
- issue #17499 Remove stickyfilljs JavaScript dependency
- Rebase phpMyAdmin-config.patch.
* Fri Feb 11 2022 ecsos <ecsos@opensuse.org>
- Update to 5.1.3
This is a security and bufix release.
* Security
- Fix for boo#1197036 (CVE-2022-0813)
- Fix for path disclosure under certain server configurations
(if display_errors is on, for instance)
* Bugfix
- issue #17308 Fix broken pagination links in the navigation sidebar
- issue #17331 Fix MariaDB has no support for system variable "disabled_storage_engines"
- issue #17315 Fix unsupported operand types in Results.php when running "SHOW PROCESSLIST" SQL query
- issue #17288 Fixed importing browser settings question box after login when having no pmadb
- issue #17288 Fix "First day of calendar" user override has no effect
- issue #17239 Fixed repeating headers are not working
- issue #17298 Fixed import of email-adresses or links from ODS results in empty contents
- issue #17344 Fixed a type error on ODS import with non string values
- issue #17239 Fixed header row show/hide columns buttons on each line after hover are shown on each row
Version: 4.9.11-bp153.2.6.1
* Tue May 23 2023 chris@computersalat.de
- Update to 4.9.11
This is a security and bugfix release.
* Fix for boo#1208186 (CVE-2023-25727, PMASA-2023-1, CWE-661)
XSS vulnerability in drag-and-drop upload
- An XSS vulnerability has been discovered where an authenticated
user can trigger an XSS attack by uploading a specially-crafted
.sql file through the drag-and-drop interface.
* Wed Jul 13 2022 chris@computersalat.de
- update changes file
* fix missing bugzilla information
* Thu Dec 10 2020 Arjen de Korte <suse+build@de-korte.org>
- Use system apache rpm macros
* Fri Oct 16 2020 Andreas Stieger <andreas.stieger@gmx.de>
- phpMyAdmin 4.9.7:
* Fix two factor authentication that was broken in 4.9.6
* Fix incompatibilities with older PHP versions
* Sun May 03 2020 chris@computersalat.de
- fix for boo#1170743
phpMyAdmin installation wipes it's sysconfig apache_server_flag entry
* Sat May 02 2020 Arjen de Korte <suse+build@de-korte.org>
- Don't expand @FQDN@ from /etc/HOSTNAME (this used to set
$cfg['PmaAbsoluteUri'] parameter, but this variable is no longer
in the config.sample.ini file)
* Thu Apr 23 2020 Dominique Leuenberger <dimstar@opensuse.org>
- Drop python-devel BuildRequires: python2 is EOL and this seems
unused.
- Drop xz BuildRequires: OBS takes care of unpacking the tarball.
* Tue Jan 21 2020 chris@computersalat.de
- fix for boo#1092345
* change ap_docroot from /srv/www/htdocs to /usr/share
work is based on changes provided by ecsos@opensuse.org
if phpMyAdmin.conf for apache was changed by local admin, we will
create a backup and replace the original file with the new version
sorry admins, but you need to apply your changes again
* needed Alias /phpMyAdmin is an enabled APACHE_SERVER_FLAGS default
for more info have a look into /etc/apache2/conf.d/phpMyAdmin.conf
- cleanup tmp/twig on
* uninstall
* ap_docroot change
Version: 5.1.1-bp154.1.31
* Sat Jun 05 2021 ecsos <ecsos@opensuse.org>
- Update to 5.1.1
- Fixes for several PHP errors
- Fixes for "$cfg['DefaultTabDatabase']" and other related configuration directives not working properly
- Fix Yaml export to quote strings even when they are numeric
- Fix TCPDF open_basedir issue due to internal guessing code from TCPDF
- Fix for quick search not working when using more than one configured server
Fix datetime decimals displayed (.00000) after edit
- Fix new lines in text fields are doubled
- Fixed URL generation by removing un-needed & escaping for & char
- Improvements for working with PHP 8.1
- Improved handling of adding a new user with the Percona database server
For a detail changelog see:
https://demo.phpmyadmin.net/master-config/index.php?route=/changelog
* Fri Feb 26 2021 ecsos <ecsos@opensuse.org>
- Update to 5.1.0
- issue #15350 Change Media (MIME) type references to Media type
- issue #15377 Add a request router
- issue Automatically focus input in the two-factor authentication window
- issue #15509 Replace gender-specific pronouns with gender-neutral pronouns
- issue #15491 Improve complexity of generated passwords
- issue #14909 Add a configuration option to define the 1st day of week
- issue #12726 Made user names clickable in user accounts overview
- issue #15729 Improve virtuality dropdown for MariaDB > 10.1
- issue #15312 Added an option to perform ALTER ONLINE (ALGORITHM=INPLACE)
when editing a table structure
- issue Added missing 'IF EXISTS' to 'DROP EVENT' when exporting databases
- issue #15232 Improve the padding in query result tool links
- issue #15064 Support exporting raw SQL queries
- issue #15555 Added ip2long transformation
- issue #15194 Fixed horizontal scroll on structure edit page
- issue #14820 Move table hide buttons in navigation to avoid hiding a table by mistake
- issue #14947 Use correct MySQL version if the version is 8.0 or above for documentation links
- issue #15790 Use "MariaDB Documentation" instead of "MySQL Documentation" on a MariaDB server
- issue #15880 Change "Show Query" link to a button
- issue #13371 Automatically toggle the radio button to "Create a page and save it" on Designer
- issue #12969 Tap and hold will not dismiss the error box anymore, you can now copy the error
- issue #15582 Don't disable "Empty" table button after clicking it
- issue #15662 Stay on the structure page after editing/adding/dropping indexes
- issue #15663 show structure after adding a column
- issue #16005 Remove symfony/yaml dependency
- issue #16005 Improve performance of dependency injection system by removing yaml parsing
- issue #15447 Disable phpMyAdmin storage database checkbox on databases list
- issue #16001 Add autocomplete attributes on login form
- issue #13519 Add "Preview SQL" option on Index dialog box when creating a new table
- issue #15954 Fixed export maximal length of created query input is too small
- issue Redesign the server status advisor page
- issue #13124 Use same height for SQL query textarea and Columns select in SQL page
- issue #16005 Add a new vendor constant "CACHE_DIR" that defaults
to "libraries/cache/" and store routing cache into this folder
- issue #16005 Warm-up the routing cache before building the release
- issue #16005 Use --optimize-autoloader when installing composer vendors before building the release
- issue #15992 Add back the table name to the printable version on "Structure" page
- issue #14815 Allow simplifying exported view syntax to only "CREATE VIEW"
- issue #15496 Add $cfg['CaptchaSiteVerifyURL'] for Google ReCaptcha siteVerifyUrl
- issue #14772 Add the password_hash PHP function as an option when inserting data
- issue #15136 Add a notice for Hex converter giving invalid results
- issue #16139 Use a textarea for JSON columns
- issue #16223 Make JSON input transformation editor less narrow
- issue #14340 Add a button on Export Page to show the SQL Query
- issue #16304 Add support for INET6 column type
- issue #16337 Fix example insert/update query default values
- issue #12961 Remove indexes from table relation
- issue #13557 Use a full list of functions instead of a separated one on insert/edit page "Function" selector
- issue #14795 Include routines in the export in a predictable order
- issue #16227 Fixed autocomplete is not working in case the table name is quoted by "`" symbols
- issue #15463 Force BINARY comparison when looking at privileges to avoid an SQL error on privileges tab
- issue #16430 Fixed Windows error message uses trailing / instead of \
- issue #16316 Added support for "SameSite=Strict" on cookies using configuration "$cfg['CookieSameSite']"
- issue #16451 Fixed AWS RDS IAM authentication doesn't work because pma_password is truncated
- issue #16451 Show an error message when the security limit is
reached instead of silently trimming the password to avoid confusion
- issue #15001 Add back Login Cookie Validity setting to the features form
- issue #16457 Add config parameters to support third-party ReCaptcha v2 compatible APIs like hCaptcha
- issue #13077 Moved tools section to left on large devices (Bootstrap xl)
- issue #15711 Moved some buttons to left on large devices (Bootstrap xl)
- issue #15584 Add $cfg['MysqlSslWarningSafeHosts'] to set the red text black when ssl is not used on a private network
- issue #15652 Replace deprecated FOUND_ROWS() function call on "distinct values" feature
- issue Export blobs as hex on JSON export
- issue #16095 Fix leading space not shown in a CHAR column when browsing a table
- issue Make procedures/functions SQL editor both side scrollable
- issue #16407 Bump pragmarx/google2fa conflict to >8.0
- issue #14953 Added a rename Button to use RENAME INDEX syntax of MySQL 5.7 (and MariaDB >= 10.5.2)
- issue #16477 Fixed no Option to enter TABLE specific permissions when the database name contains an "_" (underscore)
- issue #16498 Fixed empty text not appearing after deleting all Routines
- issue #16467 Fixed a PHP notice "Trying to access array offset on value of type null" on Designer PDF export
- issue #15658 Fixed saving UI displayed columns on a non database request fails
- issue #16495 Fix drop tables checkbox is above the checkbox for foreign keys
- issue #16485 Fix visual query builder missing "Build Query" button
- issue #16565 Added 'IF EXISTS' to 'DROP EVENT' when updating events to avoid replication issues
- issue Removed metro fonts that where Apache-2.0 files that are incompatible with GPL-2.0
- issue #16464 Made the relation view default to the current database when creating relations
- issue #16463 Fixed 'REFERENCES' privilege checkbox's title on new MySQL versions and on MariaDB
- issue #16405 Added jest as a Unit Testing tool for our javascript code
- issue #16252 Fixed the too small font size when editing rows (textareas)
- issue #16585 Fixed BLOB to JPG transformation PHP errors
- issue Made the console setup async to avoid blocking the page render
- issue #16429 Use PHP 8.0 fixed version (commit) for TCPDF
- issue #16005 Major performance improvements on browsing a lot of rows
- issue #16595 Fixed editing columns having a `_` in their name in specific conditions
- issue #16608 Fix "Sort by key" restore auto saved value
- issue #16611 Fixed unable to add tables to rename aliases twice on Export
- issue #16621 Fixed link HTML messed up in Advisor
- issue #16622 Fixed Advisor formatting incorrect for long_query_time notice
- issue #15389 Fixed reset current page indicator after deleting all rows to current page and not page 1
- issue #15997 Fixed auto save query
- issue #15997 Made auto saved query database or database+table independent
- issue #16641 Fixed query generation that was allowing JSON to have a length
- issue #15994 Fixed the selected value detection for "on update current_timestamp"
- issue #16614 Fixed PHP 8.0 dataseek offset call to the MySQLI extension
- issue #16662 Fixed Uncaught TypeError on "delete" button click of a database search results page
- issue Fixed Undefined index: selected_usr when the user tried to delete no selected user
- issue #16657 Fixed the QBE interface when the configuration storage is not enabled
- issue #16479 Fix our Selenium test-suite
- issue #16669 Fixed table search modal for BETWEEN
- issue #16667 Fixed LIKE and TINYINT in search not working properly
- issue #16424 Fixed numerical search in table and zoom
- issue Improve the version handling (new Version class) and add a VERSION_SUFFIX for vendors
- issue #14494 Fix uncaught TypeError when editing partitioning
- issue #16525 Fix PHP 8.0 failing tests when comparing 0 to ''
- issue #16429 Fixed PHP 8.0 errors on preg_replace and operand types
- issue #16490 Fixed PHP 8.0 function libxml_disable_entity_loader() is deprecated
- issue #16429 Fixed failing unit tests on PHP 8.0
- issue #16609 Fixed Sql.rearrangeStickyColumns is not a function
- Rebase phpMyAdmin-config.patch.
* Tue Dec 22 2020 Arjen de Korte <suse+build@de-korte.org>
- Use coreutils to generate blowfish secret to reduce dependencies
* Tue Dec 15 2020 Arjen de Korte <suse+build@de-korte.org>
- Attempt to migrate modified configuration file rather than just
replacing it by default configuration
* Tue Dec 15 2020 Arjen de Korte <suse+build@de-korte.org>
- The apache subpackage must require the main package, otherwise it
will not be uninstalled when the main package is uninstalled
* Sun Dec 13 2020 Arjen de Korte <suse+build@de-korte.org>
- Generate blowfish secret and enable Apache modules/flags only on
install
- Only empty temporary directory on upgrade/uninstall (not remove)
to prevent RPM warnings/errors
- Don't empty directories not owned by this package (these should
have been cleaned up by previous versions that owned them)
* Sun Dec 13 2020 Arjen de Korte <suse+build@de-korte.org>
- Use %apache_request_restart/%apache_restart_if_needed macros to restart
apache in order to prevent unneccessary restarts
* Fri Dec 11 2020 Arjen de Korte <suse+build@de-korte.org>
- Package language files in separately
* Fri Dec 11 2020 Arjen de Korte <suse+build@de-korte.org>
- Put Apache configuration files in separate subpackage
- Generate blowfish secret with openssl on non-openSUSE systems as
pwgen is not available
* Mon Nov 09 2020 ecsos <ecsos@opensuse.org>
- Update to 5.0.4
- issue #16245 Fix failed Zoom search clears existing values
- issue Fixed a PHP error when reporting a particular JS error
- issue #16326 Fixed latitude and longitude swap for geometries in edit mode
- issue #16032 Fix CREATE TABLE not being tracked when auto tracking is enabled
- issue #16397 Fix compatibility problems with older PHP versions (also issue #16399)
- issue #16396 Fix broken two-factor authentication
- Changes from 5.0.3
- https://github.com/phpmyadmin/phpmyadmin/blob/RELEASE_5_0_3/ChangeLog
- Changes from 5.0.2
- https://github.com/phpmyadmin/phpmyadmin/blob/RELEASE_5_0_2/ChangeLog
- Changes from 5.0.1
- https://github.com/phpmyadmin/phpmyadmin/blob/RELEASE_5_0_1/ChangeLog
- Changes from 5.0.0
- https://github.com/phpmyadmin/phpmyadmin/blob/RELEASE_5_0_0/ChangeLog
- Set php >= 7.4 as recommends because:
Due to changes in the MySQL authentication method, PHP versions
prior to 7.4 are unable to authenticate to a MySQL 8.0 or newer
server (our tests show the problem actually began with MySQL 8.0.11).
This relates to a PHP bug https://bugs.php.net/bug.php?id=76243.
- Remove Suggests: php-mcrypt as described in boo#1050980
- Change tmpdir from ap_docroot/tmp to localstatedir/cache/phpMyAdmin.
Version: 4.8.2-bp150.2.1
* Tue Jul 31 2018 chris@computersalat.de
- fix for boo#1103305
* add missing dependency for php-ctype
* Fri Jun 22 2018 chris@computersalat.de
- update to 4.8.2 (2018-06-21)
* issue #14370 WHERE 0 causes Fatal error
* issue #14225 Fix missing index icon
- fix for boo#1098752
* PMASA-2018-3 (CVE-2018-12581, CWE-661)
https://www.phpmyadmin.net/security/PMASA-2018-3/
- XSS in Designer feature
- fix for boo#1098751
* PMASA-2018-4 (CVE-2018-12613, CWE-661)
https://www.phpmyadmin.net/security/PMASA-2018-4/
- File inclusion and remote code execution attack
- some minor changelog fixes about security fix entries
* Sat May 26 2018 ecsos@opensuse.org
- update to 4.8.1 (2018-05-25)
* gh#12772 Fix case where the central columns attributes don't
get filled in
* gh#14049 Fix case where the query builder doesn't work when
selected column is *
* gh#14029 Revert "Browse" table CSS overflow
* gh#14241 Dropping indexes and foreign keys fail
* gh#14227 Relational linking broken
* gh#14246 Fixed error in configuration storage zero config
* gh#14128 Show 2FA Secret next to QR code
* gh#14212 XML Export from single table throws fatal error
* gh#14239 Line and some other charts ignore result set order of
values chosen for the x-axis
* gh#14260 Fixed configuration for DefaultLang and Lang
* gh#14264 Linking for 'Distinct values' broken
* gh#13968 Fix MariaDB 10.2 current_timestamp()
* gh#14249 Fix for missing go button in view edit
* gh#14125 Fix for issues with spatial fields
* gh#14189 Remember table's sorting broken
* gh#14289 Fix multi-column sorting
* gh#14278 Fix central columns in-line edit bug
* gh#14066 Fix AUTO_INCREMENT error when only exporting table
structure in database-level exports
* gh#13893 Simulating queries produces unexpected results
* gh#14309 Setup script icons missing
* Fri Apr 20 2018 ecsos@opensuse.org
- update to 4.8.0.1 (2018-04-19)
- fix for boo#1090309
* PMASA-2018-2 (CVE-2018-10188, CWE-661)
https://www.phpmyadmin.net/security/PMASA-2018-2/
- Multiple CSRF vulnerabilities
* Wed Apr 11 2018 ecsos@opensuse.org
- fix wrong require /usr/bin/bash to /bin/bash so phpMyAdmin could
install
- insert missing templates dir in htaccess
See https://docs.phpmyadmin.net/de/latest/setup.html#securing-your-phpmyadmin-installation
- create tmp dir and insert this in htaccess to fix the errormessage
after login
* Wed Apr 11 2018 javier@opensuse.org
- spec clean up
* Let rpm find the library dependencies by itself. Remove
unneeded explicit Requires: tags (php-zlib)
* Remove logic for obsolete openSUSE releases
* Ignore pem-certificate rpmlint warning (see
libraries/certs/README.rst)
* Remove hidden .github, .php_cs.dist, .scrutinizer.yml and
.editorconfig
* Remove php_twig.h and twig.c (devel)
* Set proper shebang for bash and php scripts
* Make phpmyadmin/sql-parser/bin/*-query and
paragonie/random_compat/*.sh executable
* Wed Apr 11 2018 javier@opensuse.org
- update to 4.8.0 (2018-04-07)
* gh#12946 Allow to export JSON with unescaped unicode chars
* gh#12983 Disable login button without solved reCaptcha
* gh#12315 Allow to remove individual segments from pie charts
* gh Change label from "Improve table structure" to
"Normalize" to match standard terminology
* gh#13087 Offer login as different user on access denied from
MySQL
* gh#13110 Indicate when HTTPS is not properly reported on the
server
* gh#13119 No database selected error when adding foreign key
* gh#12388 Improved database search to allow search for exact
phrase match
* gh#13099 Report error when trying to copy database to same
name
* gh#13167 Themes now have to contain metadata in theme.json
* gh#6363 phpMyAdmin no longer requires eval() in PHP
* gh#12386 The mbstring dependency is now optional
* gh#13269 Small refactoring in preparation to CSP
* gh#13384 Database link broken in Databases Page
* gh#13391 Configurable authentication logging using
$cfg['AuthLog']
* gh#13086 Add support for Google Invisible Captcha
* gh#13058 Improved error reporting for reCAPTCHA
* gh#12899 Improved rendering of server variables table
* gh#12948 Fixed javascript editor for TIME values
* gh#13095 Fixed alignment of foreign keys editing
* gh#12944 Improved inline editor for JSON
* gh#13145 Improved layout of operations pages
* gh#13448 Add "format" query button in edit view form
* gh#6241 Implement Responsive Design/mobile interface
* gh Use a single location for classes under PhpMyAdmin
namespace
* gh#12354 Indicate SSL status on main page
* gh#5666 Configuration directives for defaults of Transformation
options
* gh#12261 Remove inline JavaScript
* gh#13408 Show MySQL warnings when executing SQL queries
* gh#5827 Allow Designer to show tables from other databases
* gh#13268 Replace Query-By-Example with multi-table query
generator interface
* gh#13576 Add privileges export to per-database listing
* gh Consolidate functions into class files
* gh#13560 Add support for changing collation for all tables and
columns in database
* gh#13303 Add support for creating fulltext index from table
structure
* gh#13711 Lower default value for $cfg['MaxExactCount']
* gh#13722 DisableIS is not fully honored
* gh#6197 Added support for authentication using U2F and 2FA
* gh#13480 Avoid removing cookies on upgrade
* gh#13397 Remember state of navigation panel
* gh#11688 Reduced cookie usage
* gh#13466 Better utilization of user preferences
* gh#14042 Rename PMD to Designer
* gh#13940 Honor arg_separator in AJAX requests
* gh#14060 Can't edit rows in Internet Explorer
* gh#14096 Internet Explorer compatibility; fixes JavaScript error
Object doesn't support property or method 'startsWith'
* Tue Mar 06 2018 ecsos@opensuse.org
- update to 4.7.9 (2018-03-05)
* gh#13931 Fixed browsing tables with more results
* gh#13927 "Not an integer" when browsing a table
* gh#13887 "Input variables exceeded 1000" error relating
to PHP's max_input_vars directive
* Thu Feb 22 2018 astieger@suse.com
- phpMyAdmin 4.7.8:
* Fixed error handling with PHP 7.2
* Fixed resetting default setting values
* Fixed fallback value for collation connection
- fix for boo#1082188
* PMASA-2018-1 (CVE-2018-7260, CWE-661)
https://www.phpmyadmin.net/security/PMASA-2018-1/
- Fix XSS in Central Columns Feature
* Mon Dec 25 2017 astieger@suse.com
- phpMyAdmin 4.7.7:
* Fixed displaying of formatted numeric values for some locales
* Ensure datetimepicker is always loaded for datetime fields
* Fixed PHP error when browsing certain results
* Fix XSRF/CSRF vulnerability (bsc#1074066, PMASA-2017-09)
CVE-2017-1000499
* Sat Dec 02 2017 ecsos@opensuse.org
- update to 4.7.6 (2017-11-29)
* gh#13517 Fixed check all interaction with filtering
* gh#13803 Add SJIS-win to default list of allowed charsets
* gh#13436 Improve detection that MySQL server needs SSL connection
* gh#13038 Support JSON datatype on MariaDB 10.2.7 and newer
* gh#13824 Fixed constructing ALTER query with AFTER
* gh#13821 Lock page when changes are done in the SQL editor
* gh#13842 Prefer iconv for encoding conversions
* gh#13737 Fixed changing password on MariaDB cluster
* Sun Nov 26 2017 suse+build@de-korte.org
- fix for boo#1057661
* no longer require php_mod_any (recommend it instead)
* only enable php5 / php7 if running Apache prefork MPM
- fix %post
* use sed instead of grep/awk to determine PHP version
* Tue Oct 24 2017 ecsos@opensuse.org
- update to 4.7.5 (2017-10-23)
* gh#13615 Avoid problems with browsing unknown query types
* gh#13612 Integrate tooltip into datetime pickers
* gh#13628 Fixed javascript error in server monitor
* gh#13444 Fixed server monitor on non Linux and Windows systems
* gh#13633 Reload javscript messages when changing language
* gh#13604 Fixed crash on invalid ordering data
* gh#13639 Fixed error when browsing non SELECT results
* gh#13533 Fixed saving column to display
* gh#13647 Fixed export of tables with VIRTUAL columns
* gh#13669 Fixed selecting multiple rows accidentally selects
the next row too
* gh#13513 Fixed edit index Column alignment issue
* gh#13515 Fixed rendering of add index dialog
* gh#13710 Fixed possible error in server advisor
* gh#13477 Fixed setting input transformations
* gh#13552 Fixed IPv4/IPv6 To Binary input transformation
* gh#13686 Clicking on column name to trigger sort with an active
search leads to logout
* gh#13725 Fixed copying tables with specific PARTITION
definition
* gh#13761 Fixed listing of bookmarks for a database
* Fri Sep 08 2017 chris@computersalat.de
- fix recommends
* php5-curl -> php-curl
* php5-zip -> php-zip
- fix post step
* enable correct phpX module
* Fri Aug 25 2017 ecsos@opensuse.org
- update to 4.7.4
* gh#13415 Remove shadow from the logo
* gh#13507 Fixed per server theme feature
* gh#13523 Missing newline in ALTER exports
* gh#13414 Fixed several compatibility issues with PHP 7.2
* gh#13550 Fixed copy results to clipboard
* gh#13562 Add limitation for user group length
* gh#13561 Fixed edit variable link in advisor
* gh#13579 Optimize table link should not be visible in print
page
* gh#13553 Improved error handling on corrupted tables
* gh#13512 Fixed rendering of add index dialog
* gh#13606 Fixed refreshing server variables
* Fri Jul 28 2017 chris@computersalat.de
- fix for boo#1050980
* replace mcrypt with openssl, see
https://github.com/phpseclib/phpseclib/issues/1028
- update changes (update to 4.6.6 (2017-01-23))
* add missing (CVE-Not yet available) CVE's
* Sat Jul 22 2017 ecsos@opensuse.org
- update to 4.7.3
* gh#13447 Large multi-line query removes Export operation and
blanks query box options
* gh#13445 Fixed rendering of query results
* gh#13437 Fixed version check when not connected to a database
* gh#13465 Fixed creating relation
* gh#13475 Fixed export without backquotes
* gh#13482 Improved handling of uploaded files with open_basedir
* gh#13387 Fixed inline editing of hex values
* gh#13382 Fixed size of index edit dialog
* gh#13489 Fixed rendering SQL lint errors
* gh#13468 Avoid breakage if set_time_limit is disabled
* gh#13471 Fail if ini_set/ini_get are disabled
* gh#13436 Automatically connect using SSL when server is
configured so
* gh#13478 Fixed usage of some browser transformations
* Sun Jul 02 2017 ecsos@opensuse.org
- update to 4.7.2 (2017-06-29)
* gh#13314 Make theme selection keep current server
* gh#13311 Fixed direct login for accounts without password
* gh#13316 Fixed check for mbstring.func_overload
* gh#13323 Fixed wrong encoding of table at triggers
* gh#12976 Fixed natural sorting in several places
* gh#12718 Show warning for users removed from mysql.user table
* gh#13362 Fixed loading additional javascripts
* gh#13343 Fixed editing QBE
* gh#13193 Improved documentation on user settings
* gh#13092 Gracefully handle early fatal errors in AJAX requests
* gh#13327 Fixed Incorrect NavigationTreeEnableExpansion default
value in the documentation
* gh#13008 Fixed export of database with a lot of tables
* gh#13318 Improved performance when importing with enabled
tracking
* gh#13386 Avoid PHP errors with non existing configuration on
OS X
* gh#13388 Show only supported charsets for conversion
* gh#13392 Fixed operation with session.auto_start enabled
* gh#13383 "Create PHP code" is broken
* gh#13189 Fixed links to resume timeouted import
* Fri Jun 02 2017 ecsos@opensuse.org
- update to 4.7.1 (2017-05-25)
* gh#13132 Always execute tracking queries as controluser
* gh#13125 Focus on SQL editor after inserting field name
* gh#13133 Fixed broken links in setup
* gh#13135 Database list Tooltips: Show wrong value
* gh#13150 Fixed pagination while browsing resuls
* gh#13149 Fixed outbound links in changelog.php
* gh#13146 Do not include devel dependencies in the release
* gh#13144 Do not show New as a database in database dropdown
* gh#13130 Fixed handling of errors in AJAX requests
* gh#13152 Fixed PHP error in case of invalid table preferences
* gh#13154 Fixed PHP error on password change
* gh#13219 Fix Refresh of Process List
* gh#13182 Fix refresh of long queries
* gh#12301 Improved handling of logout with disabled
LoginCookieDeleteAll
* gh#13216 Add support for MySQL 8.0 collations
* gh#13218 Fixed rendering of phpMyAdmin logos
* gh#13234 Properly report not working sessions
* gh#13256 Fixed password check on server replication
* gh#13252 Fixed grid editing time column
* gh#13258 Fixed detection of Amazon RDS
* gh#13241 Redirect user to last page that has any tables to
display
* gh#13266 Fix link to User accounts overview page
* gh#13274 Fix error in query builder
* gh#13177 Grid editing repeats action after error
* Sat Apr 22 2017 chris@computersalat.de
- restore phpMyAdmin-pma.patch
* because it is NOT upstream and needed for configuration storage
- restore previous phpMyAdmin-config.patch
* merge with upstream config VAR changes
- removed $cfg['Servers'][$i]['designer_coords']