Conversation
… both: Remove exec/shell_exec from update checker and domain lookups Update checker (fetchUpdates) no longer shells out to git: - Current commit read directly from .git/HEAD, following the branch ref through loose refs with a packed-refs fallback (survives git gc); detached HEAD handled - Latest commit fetched from the GitHub API via curl using the Accept: application/vnd.github.sha header (returns bare SHA, no JSON parsing) - Repo owner/name derived from the origin remote in .git/config so forks check against their own remote, falling back to itflow-org/itflow - Failures now distinguish unreadable .git (permissions) from API errors (network/rate limit) instead of silently returning empty Domain lookups no longer shell out to dig and whois: - DNS records (A/NS/MX/TXT) via dns_get_record() - Registration data via RDAP (JSON over HTTPS, curl), the ICANN successor to port-43 whois; RDAP server per TLD resolved from IANA's bootstrap registry, cached locally for a week, rdap.org as secondary lookup - Expiration date from RDAP's structured expiration event, replacing regex/date-format guessing for RDAP-covered TLDs - Port-43 whois retained as socket-based fallback (fsockopen) for ccTLDs without RDAP, with IANA server discovery and one registrar referral follow - RDAP responses cached per-run: getDomainRecords() and getDomainExpirationDate() on the same domain = one HTTP request Fixes whois rate limiting, removes the exec dependency for hardened hosts (Snuffleupagus etc.), and eliminates the shell injection surface - no shell, nothing to escape.
… provider as smtp host is not filled in when OAUTH2 is selected
…rovider as smtp host is not filled in when OAUTH2 is selected
…e namespace is INBOX. or can be created in root directory. Fixes issue with CPanel Dovecot Maildir++ configuration where their namespace is just INBOX
…OST also add client selection in edit trip and enforce client permissions on trips
…ice, recurring invoice, quote and rework the UI for Ticket/Recurring ticket create Put Billable beside subject so it doesnt take up a whole row
…n file and use function.php to call them
…ew enforce fumctions.
Replace srand()/rand() with random_int() for cryptographically secure, unbiased key generation. The previous implementation seeded rand() from microtime(), making TOTP secrets predictable if the generation time could be approximated. Also removes modulo bias and dead while(1) wrapper. Output format is unchanged: 32 chars from the base32 alphabet (A-Z, 2-7), so existing TOTP enrollments are unaffected.
…pdate all instances throughout
… instances throughout
…notificaiton and into cron
…d wasnt updating and a dash was being put in front
|
wrongecho
approved these changes
Aug 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.




Develop to Master for26.08 Release