From 1d4e2b3b114513506cf6e02782aab2a954db96d8 Mon Sep 17 00:00:00 2001 From: muxator Date: Tue, 10 Apr 2018 00:17:34 +0200 Subject: [PATCH 01/20] Release version 1.6.5 --- src/package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/package.json b/src/package.json index bf2f8858c..9813d6ab9 100644 --- a/src/package.json +++ b/src/package.json @@ -55,6 +55,6 @@ "repository" : { "type" : "git", "url" : "http://github.com/ether/etherpad-lite.git" }, - "version" : "1.6.4", + "version" : "1.6.5", "license" : "Apache-2.0" } From 3eb3e301a2d729561751faab3aaa6151668203a9 Mon Sep 17 00:00:00 2001 From: muxator Date: Tue, 10 Apr 2018 00:44:14 +0200 Subject: [PATCH 02/20] manually updated CHANGELOG.md due to createRelease.sh not catching an error from sed and continuing: sed: -e expression #1, char 66: unterminated `s' command --- CHANGELOG.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 02accf8cb..df249c258 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,10 @@ +# 1.6.5 + * SECURITY: Escape data when listing available plugins + * FIX: Fix typo in apicalls.js which prevented importing isValidJSONPName + * FIX: fixed plugin dependency issue + * FIX: Update iframe_editor.css + * FIX: unbreak Safari iOS line wrapping + # 1.6.4 * SECURITY: exploitable /admin access - CVE-2018-9845 * SECURITY: DoS with pad exports - CVE-2018-9327 From 686ce054fae48cd0b63adc6370495c858f6a8514 Mon Sep 17 00:00:00 2001 From: "translatewiki.net" Date: Thu, 12 Apr 2018 09:12:18 +0200 Subject: [PATCH 03/20] Localisation updates from https://translatewiki.net. --- src/locales/pms.json | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/src/locales/pms.json b/src/locales/pms.json index 80a857e39..a389d3496 100644 --- a/src/locales/pms.json +++ b/src/locales/pms.json @@ -44,5 +44,17 @@ "pad.importExport.import": "Carié n'archivi o document ëd test", "pad.importExport.importSuccessful": "Bele fàit!", "pad.importExport.export": "Esporté ël feuj atual coma:", - "pad.importExport.exportetherpad": "Etherpad" + "pad.importExport.exportetherpad": "Etherpad", + "pad.importExport.exporthtml": "HTML", + "pad.importExport.exportplain": "Mach test", + "pad.importExport.exportword": "Microsoft Word", + "pad.importExport.exportpdf": "PDF", + "pad.importExport.exportopen": "ODF (Open Document Format)", + "pad.importExport.abiword.innerHTML": "A peul mach amporté dij formà ëd test sempi o HTML. Për dle fonsionalità d'amportassion pi avansà, ch'a anstala AbiWord.", + "pad.modals.connected": "Colegà.", + "pad.modals.reconnecting": "Neuva conession a sò feuj...", + "pad.modals.forcereconnect": "Forsé la neuva conession", + "pad.modals.reconnecttimer": "Tentativ ëd neuva conession", + "pad.modals.cancel": "Anulé", + "pad.modals.userdup": "Duvertà an n'àutra fnestra" } From 6dc8ead8c9e3f17cce2bbb7f75ff1774dad66da4 Mon Sep 17 00:00:00 2001 From: "translatewiki.net" Date: Thu, 12 Apr 2018 15:16:27 +0200 Subject: [PATCH 04/20] Localisation updates from https://translatewiki.net. --- src/locales/pms.json | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/src/locales/pms.json b/src/locales/pms.json index a389d3496..6ac0677b8 100644 --- a/src/locales/pms.json +++ b/src/locales/pms.json @@ -56,5 +56,9 @@ "pad.modals.forcereconnect": "Forsé la neuva conession", "pad.modals.reconnecttimer": "Tentativ ëd neuva conession", "pad.modals.cancel": "Anulé", - "pad.modals.userdup": "Duvertà an n'àutra fnestra" + "pad.modals.userdup": "Duvertà an n'àutra fnestra", + "pad.modals.userdup.explanation": "Ës feuj a smija esse duvert an vàire fnestre ansima a st'ordinator.", + "pad.modals.userdup.advice": "Coleghesse torna për dovré costa fnestra.", + "pad.modals.unauth": "Nen autorisà", + "pad.modals.unauth.explanation": "Ij sò përmess a son cangià antramentre ch'a vëdìa costa pàgina. Ch'a sërca ëd coleghesse torna." } From 9daade0b95bbc5443637977652d3cd0dbc44e112 Mon Sep 17 00:00:00 2001 From: muxator Date: Fri, 13 Apr 2018 18:32:39 +0200 Subject: [PATCH 05/20] fix: line numbers was not aligned with text This change partially reverts 0a9d02562d7e, which got released in 1.6.4 due to #3280. Text size and line alignment are now reverted back to their 1.6.3 appearance (thus stay non customizable, for now). Fixes #3378 --- src/static/css/iframe_editor.css | 8 ++------ 1 file changed, 2 insertions(+), 6 deletions(-) diff --git a/src/static/css/iframe_editor.css b/src/static/css/iframe_editor.css index 0286a5df8..9aa003aaf 100644 --- a/src/static/css/iframe_editor.css +++ b/src/static/css/iframe_editor.css @@ -31,17 +31,13 @@ body { body.grayedout { background-color: #eee !important } #innerdocbody { - font-size: 16px; /* overridden by body.style */ + font-size: 12px; /* overridden by body.style */ font-family:Arial, sans-serif; /* overridden by body.style */ - line-height: 22px; /* overridden by body.style */ + line-height: 16px; /* overridden by body.style */ background-color: white; color: black; } -.innerdocbody>div{ - padding: 1px; -} - body.doesWrap { /* white-space: pre-wrap; */ From 4f2ff31a61f520beea42ddf40806c8e636834720 Mon Sep 17 00:00:00 2001 From: "translatewiki.net" Date: Thu, 19 Apr 2018 09:20:05 +0200 Subject: [PATCH 06/20] Localisation updates from https://translatewiki.net. --- src/locales/pms.json | 62 +++++++++++++++++++++++++++++++++++++++++++- 1 file changed, 61 insertions(+), 1 deletion(-) diff --git a/src/locales/pms.json b/src/locales/pms.json index 6ac0677b8..c73567f5a 100644 --- a/src/locales/pms.json +++ b/src/locales/pms.json @@ -60,5 +60,65 @@ "pad.modals.userdup.explanation": "Ës feuj a smija esse duvert an vàire fnestre ansima a st'ordinator.", "pad.modals.userdup.advice": "Coleghesse torna për dovré costa fnestra.", "pad.modals.unauth": "Nen autorisà", - "pad.modals.unauth.explanation": "Ij sò përmess a son cangià antramentre ch'a vëdìa costa pàgina. Ch'a sërca ëd coleghesse torna." + "pad.modals.unauth.explanation": "Ij sò përmess a son cangià antramentre ch'a vëdìa costa pàgina. Ch'a sërca ëd coleghesse torna.", + "pad.modals.looping.explanation": "A-i é dij problema ëd comunicassion con ël servent ëd sincronisassion.", + "pad.modals.looping.cause": "Peul desse che chiel a l'é colegasse con un para-feu o un mandatari incompatìbil.", + "pad.modals.initsocketfail": "Ël servent a l'é introvàbil.", + "pad.modals.initsocketfail.explanation": "Impossìbil coleghesse al servent ëd sincronisassion.", + "pad.modals.initsocketfail.cause": "A l'é probàbil che sòn a sia dovù a sò navigador o a soa conession an sl'aragnà.", + "pad.modals.slowcommit.explanation": "Ël servent a rëspond nen.", + "pad.modals.slowcommit.cause": "Sòn a podrìa esse dovù a dij problema ëd conession a l'aragnà.", + "pad.modals.badChangeset.explanation": "Na modìfica ch'a l'ha fàit a l'é stàita cassificà tanme ilegal dal servent ëd sincronisassion.", + "pad.modals.badChangeset.cause": "Sòn a podrìa esse dovù a na bruta configurassion dël servent o a chèich àutr comportament nen ëspetà. Për piasì, ch'a contata l'aministrator dël servissi, s'a pensa ch'a sia n'eror. Ch'a preuva a rintré torna ant ël sistema për andé anans a modifiché.", + "pad.modals.corruptPad.explanation": "Ël feuj al qual a sërca d'acede a l'é corompù.", + "pad.modals.corruptPad.cause": "Sòn a podrìa esse dovù a na configurassion ësbalià dël servent o a chèich àutr comportament nen ëspetà. Për piasì, ch'a contata l'aministrator dël servissi.", + "pad.modals.deleted": "Dëscancelà.", + "pad.modals.deleted.explanation": "Ës feuj a l'é stàit eliminà.", + "pad.modals.disconnected": "A l'é stàit dëscolegà", + "pad.modals.disconnected.explanation": "La conession al servent a l'é perdusse", + "pad.modals.disconnected.cause": "Ël servent a podrìa esse indisponìbil. Për piasì, ch'a anforma l'aministrator dël servissi si ël problema a persist.", + "pad.share": "Partagé 's feuj", + "pad.share.readonly": "Mach letura", + "pad.share.link": "Liura", + "pad.share.emebdcode": "Ancorporé na liura", + "pad.chat": "Ciaciarada", + "pad.chat.title": "Duverté la ciaciarada për cost feuj.", + "pad.chat.loadmessages": "Carié pi 'd mëssagi", + "timeslider.pageTitle": "Stòria dinàmica ëd {{appTitle}}", + "timeslider.toolbar.returnbutton": "Torné al feuj", + "timeslider.toolbar.authors": "Autor:", + "timeslider.toolbar.authorsList": "Gnun autor", + "timeslider.toolbar.exportlink.title": "Esporté", + "timeslider.exportCurrent": "Esporté la version corenta tanme:", + "timeslider.version": "Version {{version}}", + "timeslider.saved": "Argistrà ai {{day}} {{month}} {{year}}", + "timeslider.playPause": "Letura / Pàusa dij contnù dël feuj", + "timeslider.backRevision": "Andé andaré ëd na revision ant ës feuj", + "timeslider.forwardRevision": "Andé anans ëd na revision ant ëd feuj", + "timeslider.dateformat": "{{day}}/{{month}}/{{year}} {{hours}}:{{minutes}}:{{seconds}}", + "timeslider.month.january": "Gené", + "timeslider.month.february": "Fërvé", + "timeslider.month.march": "Mars", + "timeslider.month.april": "Avril", + "timeslider.month.may": "Maj", + "timeslider.month.june": "Giugn", + "timeslider.month.july": "Luj", + "timeslider.month.august": "Ost", + "timeslider.month.september": "Stèmber", + "timeslider.month.october": "Otóber", + "timeslider.month.november": "Novèmber", + "timeslider.month.december": "Dzèmber", + "timeslider.unnamedauthors": "{{num}} {[plural(num) one: autor anònim, other: autor anònim ]}", + "pad.savedrevs.marked": "Sa revision a l'é adess marcà tanme revision argistrà", + "pad.savedrevs.timeslider": "A peul vëdde le revision argistrà an visitand la stòria", + "pad.userlist.entername": "Ch'a buta sò nòm", + "pad.userlist.unnamed": "anònim", + "pad.userlist.guest": "Anvità", + "pad.userlist.deny": "Arfudé", + "pad.userlist.approve": "Aprové", + "pad.editbar.clearcolors": "Dëscancelé ij color ëd paternità dj'autor an tut ël document?", + "pad.impexp.importbutton": "Amporté adess", + "pad.impexp.importing": "An camin ch'as ampòrta...", + "pad.impexp.confirmimport": "Amportand n'archivi as dëscancelërà ël test corent dël feuj. É-lo sigur ëd vorèj felo?", + "pad.impexp.convertFailed": "I l'oma nen podù amporté s'archivi. Për piasì, ch'a deuvra n'àutr formà ëd document o ch'a còpia e ancòla a man" } From d26df864902510ca7f325b786183dc9031e04e42 Mon Sep 17 00:00:00 2001 From: Benjamin Schweizer Date: Fri, 19 Feb 2016 10:07:01 +0100 Subject: [PATCH 07/20] made url relative --- src/static/js/pad.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/static/js/pad.js b/src/static/js/pad.js index 8fcec23f1..bab59f422 100644 --- a/src/static/js/pad.js +++ b/src/static/js/pad.js @@ -831,7 +831,7 @@ var pad = { $.ajax( { type: 'post', - url: '/ep/pad/connection-diagnostic-info', + url: 'ep/pad/connection-diagnostic-info', data: { diagnosticInfo: JSON.stringify(pad.diagnosticInfo) }, From fb20c26c5f36be272060a45286188f4eafbd451e Mon Sep 17 00:00:00 2001 From: anugu-chegg Date: Sat, 3 Feb 2018 13:29:52 +0530 Subject: [PATCH 08/20] Don't send COMMIT-MESSAGE when socketio connection is not active --- src/static/js/collab_client.js | 34 ++++++++++++++++++++-------------- src/static/js/pad.js | 4 ++++ 2 files changed, 24 insertions(+), 14 deletions(-) diff --git a/src/static/js/collab_client.js b/src/static/js/collab_client.js index fd0d9d446..9fc03991b 100644 --- a/src/static/js/collab_client.js +++ b/src/static/js/collab_client.js @@ -181,20 +181,26 @@ function getCollabClient(ace2editor, serverVars, initialUserInfo, options, _pad) } var sentMessage = false; - var userChangesData = editor.prepareUserChangeset(); - if (userChangesData.changeset) - { - lastCommitTime = t; - state = "COMMITTING"; - stateMessage = { - type: "USER_CHANGES", - baseRev: rev, - changeset: userChangesData.changeset, - apool: userChangesData.apool - }; - sendMessage(stateMessage); - sentMessage = true; - callbacks.onInternalAction("commitPerformed"); + if (getSocket().realConnected) { + var userChangesData = editor.prepareUserChangeset(); + if (userChangesData.changeset) + { + lastCommitTime = t; + state = "COMMITTING"; + stateMessage = { + type: "USER_CHANGES", + baseRev: rev, + changeset: userChangesData.changeset, + apool: userChangesData.apool + }; + sendMessage(stateMessage); + sentMessage = true; + callbacks.onInternalAction("commitPerformed"); + } + } + else { + // run again in a few seconds, to check if there was a reconnection attempt + setTimeout(wrapRecordingErrors("setTimeout(handleUserChanges)", handleUserChanges), 1000); } if (sentMessage) diff --git a/src/static/js/pad.js b/src/static/js/pad.js index bab59f422..152a48d99 100644 --- a/src/static/js/pad.js +++ b/src/static/js/pad.js @@ -201,15 +201,19 @@ function handshake() }); socket.once('connect', function () { + // Setup our own connected flag since socketio one doesn't work accurately + socket.realConnected = true; sendClientReady(false); }); socket.on('reconnect', function () { + socket.realConnected = true; pad.collabClient.setChannelState("CONNECTED"); pad.sendClientReady(true); }); socket.on('reconnecting', function() { + socket.realConnected = false; pad.collabClient.setChannelState("RECONNECTING"); }); From 4265f4175ee1e11664d6f637dfc6b7b0b601c23c Mon Sep 17 00:00:00 2001 From: anugu-chegg Date: Mon, 5 Feb 2018 22:37:49 +0530 Subject: [PATCH 09/20] Handle socketio errors properly --- src/static/js/collab_client.js | 3 ++- src/static/js/pad.js | 5 +++++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/src/static/js/collab_client.js b/src/static/js/collab_client.js index 9fc03991b..7cf98ae6d 100644 --- a/src/static/js/collab_client.js +++ b/src/static/js/collab_client.js @@ -662,7 +662,8 @@ function getCollabClient(ace2editor, serverVars, initialUserInfo, options, _pad) getMissedChanges: getMissedChanges, callWhenNotCommitting: callWhenNotCommitting, addHistoricalAuthors: tellAceAboutHistoricalAuthors, - setChannelState: setChannelState + setChannelState: setChannelState, + setStateIdle: setStateIdle }; $(document).ready(setUpSocket); diff --git a/src/static/js/pad.js b/src/static/js/pad.js index 152a48d99..9abedd271 100644 --- a/src/static/js/pad.js +++ b/src/static/js/pad.js @@ -221,6 +221,11 @@ function handshake() pad.collabClient.setChannelState("DISCONNECTED", "reconnect_timeout"); }); + socket.on('error', function(error) { + socket.realConnected = false; + pad.collabClient.setStateIdle(); + }); + var initalized = false; socket.on('message', function(obj) From bf05e9ae89a73a1ceead364c42a2f66744c75723 Mon Sep 17 00:00:00 2001 From: anugu-chegg Date: Sat, 10 Feb 2018 22:30:22 +0530 Subject: [PATCH 10/20] Handle client reconnect properly --- src/node/handler/PadMessageHandler.js | 76 +++++++++++++++++++++++++++ src/static/js/collab_client.js | 57 ++++++++++++++++++-- src/static/js/pad.js | 4 +- 3 files changed, 131 insertions(+), 6 deletions(-) diff --git a/src/node/handler/PadMessageHandler.js b/src/node/handler/PadMessageHandler.js index 060bca7b9..1d9b5cf14 100644 --- a/src/node/handler/PadMessageHandler.js +++ b/src/node/handler/PadMessageHandler.js @@ -1153,6 +1153,82 @@ function handleClientReady(client, message) client.join(padIds.padId); //Save the revision in sessioninfos, we take the revision from the info the client send to us sessioninfos[client.id].rev = message.client_rev; + + var changesetsNeeded = []; + var changesets = {}; + var changesetsAuthor = {}; + var changesetsTimestamp = {}; + + var startNum = message.client_rev + 1; + var endNum = pad.getHeadRevisionNumber() + 1; + + async.series([ + //fetch all changesets we need + function(callback) + { + var headNum = pad.getHeadRevisionNumber(); + if (endNum > headNum+1) + endNum = headNum+1; + if (startNum < 0) + startNum = 0; + //create a array for all changesets, we will + //replace the values with the changeset later + for(var r=startNum;r Date: Wed, 14 Feb 2018 13:18:44 +0530 Subject: [PATCH 11/20] Send commits missed during the reconnect --- src/node/handler/PadMessageHandler.js | 31 +++++++++++++++++++++------ src/static/js/collab_client.js | 14 +++++++++--- 2 files changed, 36 insertions(+), 9 deletions(-) diff --git a/src/node/handler/PadMessageHandler.js b/src/node/handler/PadMessageHandler.js index 1d9b5cf14..5e39bdb57 100644 --- a/src/node/handler/PadMessageHandler.js +++ b/src/node/handler/PadMessageHandler.js @@ -1177,33 +1177,51 @@ function handleClientReady(client, message) { changesetsNeeded.push(r); } - //get all changesets - async.forEach(changesetsNeeded, function(revNum) + callback(); + }, + //get all changesets + function(callback) + { + async.eachSeries(changesetsNeeded, function(revNum, callback) { pad.getRevisionChangeset(revNum, function(err, value) { if(ERR(err)) return; changesets[revNum] = value; + callback(); }); + }, callback); + }, + function(callback) + { + async.eachSeries(changesetsNeeded, function(revNum, callback) + { pad.getRevisionAuthor(revNum, function(err, value) { if(ERR(err)) return; changesetsAuthor[revNum] = value; + callback(); }); + }, callback); + }, + function(callback) + { + async.eachSeries(changesetsNeeded, function(revNum, callback) + { pad.getRevisionDate(revNum, function(err, value) { if(ERR(err)) return; changesetsTimestamp[revNum] = value; + callback(); }); - }); - callback(null); + }, callback); } ], //return err and changeset function(err) { if(ERR(err, callback)) return; - async.eachSeries(changesetsNeeded, function(r) + async.eachSeries(changesetsNeeded, function(r, callback) { var forWire = Changeset.prepareForWire(changesets[r], pad.pool); var wireMsg = {"type":"COLLABROOM", @@ -1216,7 +1234,8 @@ function handleClientReady(client, message) currentTime: changesetsTimestamp[r] }}; client.json.send(wireMsg); - }); + callback(); + }); if (startNum == endNum) { var Msg = {"type":"COLLABROOM", diff --git a/src/static/js/collab_client.js b/src/static/js/collab_client.js index 5259efd6c..825803f17 100644 --- a/src/static/js/collab_client.js +++ b/src/static/js/collab_client.js @@ -342,6 +342,7 @@ function getCollabClient(ace2editor, serverVars, initialUserInfo, options, _pad) } else if (msg.type == 'CLIENT_RECONNECT') { + // When client has reconnected but there are no pending changes from other clients if (msg.noChanges) { socketIOError = false; @@ -354,19 +355,26 @@ function getCollabClient(ace2editor, serverVars, initialUserInfo, options, _pad) var author = (msg.author || ''); var apool = msg.apool; - if (rev + 1 == currRev) { if (author == pad.getUserId()) { editor.applyPreparedChangesetToBase(); setStateIdle(); + callCatchingErrors("onInternalAction", function() + { + callbacks.onInternalAction("commitAcceptedByServer"); + }); + callCatchingErrors("onConnectionTrouble", function() + { + callbacks.onConnectionTrouble("OK"); + }); + handleUserChanges(); } else { editor.applyChangesToBase(changeset, author, apool); } - } if (rev + 1 < currRev) { @@ -374,8 +382,8 @@ function getCollabClient(ace2editor, serverVars, initialUserInfo, options, _pad) } if (currRev == newRev) { - socketIOError = false; rev = newRev; + socketIOError = false; } } else if (msg.type == "NO_COMMIT_PENDING") From 461ed413b735a641d0bbb248841411d25045caa7 Mon Sep 17 00:00:00 2001 From: anugu-chegg Date: Fri, 16 Feb 2018 01:31:47 +0530 Subject: [PATCH 12/20] Fix few mistakes --- src/node/handler/PadMessageHandler.js | 6 +-- src/static/js/collab_client.js | 55 +++++++++++++++++---------- 2 files changed, 37 insertions(+), 24 deletions(-) diff --git a/src/node/handler/PadMessageHandler.js b/src/node/handler/PadMessageHandler.js index 5e39bdb57..63349f14a 100644 --- a/src/node/handler/PadMessageHandler.js +++ b/src/node/handler/PadMessageHandler.js @@ -1226,8 +1226,8 @@ function handleClientReady(client, message) var forWire = Changeset.prepareForWire(changesets[r], pad.pool); var wireMsg = {"type":"COLLABROOM", "data":{type:"CLIENT_RECONNECT", - currRev: r, - newRev:pad.getHeadRevisionNumber(), + headRev:pad.getHeadRevisionNumber(), + newRev:r, changeset:forWire.translated, apool: forWire.pool, author: changesetsAuthor[r], @@ -1243,8 +1243,6 @@ function handleClientReady(client, message) noChanges: true, newRev:pad.getHeadRevisionNumber() }}; - - console.log("About to send client reconnect event"); client.json.send(Msg); } }); diff --git a/src/static/js/collab_client.js b/src/static/js/collab_client.js index 825803f17..e2f1240af 100644 --- a/src/static/js/collab_client.js +++ b/src/static/js/collab_client.js @@ -349,38 +349,53 @@ function getCollabClient(ace2editor, serverVars, initialUserInfo, options, _pad) return; } - var currRev = msg.currRev; + var headRev = msg.headRev; var newRev = msg.newRev; var changeset = msg.changeset; var author = (msg.author || ''); var apool = msg.apool; - if (rev + 1 == currRev) + if (msgQueue.length > 0) { - if (author == pad.getUserId()) + if (newRev != (msgQueue[msgQueue.length - 1].newRev + 1)) { - editor.applyPreparedChangesetToBase(); - setStateIdle(); - callCatchingErrors("onInternalAction", function() - { - callbacks.onInternalAction("commitAcceptedByServer"); - }); - callCatchingErrors("onConnectionTrouble", function() - { - callbacks.onConnectionTrouble("OK"); - }); - handleUserChanges(); - } - else - { - editor.applyChangesToBase(changeset, author, apool); + window.console.warn("bad message revision on ACCEPT_COMMIT: " + newRev + " not " + (msgQueue[msgQueue.length - 1][0] + 1)); + // setChannelState("DISCONNECTED", "badmessage_acceptcommit"); + return; } + msg.type = "NEW_CHANGES"; + msgQueue.push(msg); + return; } - if (rev + 1 < currRev) + + if (newRev != (rev + 1)) + { + window.console.warn("bad message revision on ACCEPT_COMMIT: " + newRev + " not " + (rev + 1)); + // setChannelState("DISCONNECTED", "badmessage_acceptcommit"); + return; + } + + rev = newRev; + if (author == pad.getUserId()) + { + editor.applyPreparedChangesetToBase(); + setStateIdle(); + callCatchingErrors("onInternalAction", function() + { + callbacks.onInternalAction("commitAcceptedByServer"); + }); + callCatchingErrors("onConnectionTrouble", function() + { + callbacks.onConnectionTrouble("OK"); + }); + handleUserChanges(); + } + else { editor.applyChangesToBase(changeset, author, apool); } - if (currRev == newRev) + + if (newRev == headRev) { rev = newRev; socketIOError = false; From b4068144c399848e12a1e3cfaf415917fb840499 Mon Sep 17 00:00:00 2001 From: anugu-chegg Date: Tue, 3 Apr 2018 18:51:14 +0530 Subject: [PATCH 13/20] Refactor code --- src/node/handler/PadMessageHandler.js | 40 ++++++++++++++------------- src/static/js/collab_client.js | 32 +++++++++++++-------- src/static/js/pad.js | 6 ++-- 3 files changed, 43 insertions(+), 35 deletions(-) diff --git a/src/node/handler/PadMessageHandler.js b/src/node/handler/PadMessageHandler.js index 63349f14a..c9e0c73ea 100644 --- a/src/node/handler/PadMessageHandler.js +++ b/src/node/handler/PadMessageHandler.js @@ -1154,16 +1154,16 @@ function handleClientReady(client, message) //Save the revision in sessioninfos, we take the revision from the info the client send to us sessioninfos[client.id].rev = message.client_rev; - var changesetsNeeded = []; + //During the client reconnect, client might miss some revisions from other clients. By using client revision, + //this below code sends all the revisions missed during the client reconnect + var revisionsNeeded = []; var changesets = {}; - var changesetsAuthor = {}; - var changesetsTimestamp = {}; var startNum = message.client_rev + 1; var endNum = pad.getHeadRevisionNumber() + 1; async.series([ - //fetch all changesets we need + //push all the revision numbers needed into revisionsNeeded array function(callback) { var headNum = pad.getHeadRevisionNumber(); @@ -1171,67 +1171,69 @@ function handleClientReady(client, message) endNum = headNum+1; if (startNum < 0) startNum = 0; - //create a array for all changesets, we will - //replace the values with the changeset later + for(var r=startNum;r Date: Fri, 20 Apr 2018 01:36:30 +0530 Subject: [PATCH 14/20] Remove leftover code from earlier commits --- src/node/handler/PadMessageHandler.js | 2 +- src/static/js/pad.js | 2 -- 2 files changed, 1 insertion(+), 3 deletions(-) diff --git a/src/node/handler/PadMessageHandler.js b/src/node/handler/PadMessageHandler.js index c9e0c73ea..b575125a2 100644 --- a/src/node/handler/PadMessageHandler.js +++ b/src/node/handler/PadMessageHandler.js @@ -1243,7 +1243,7 @@ function handleClientReady(client, message) var Msg = {"type":"COLLABROOM", "data":{type:"CLIENT_RECONNECT", noChanges: true, - newRev:pad.getHeadRevisionNumber() + newRev: pad.getHeadRevisionNumber() }}; client.json.send(Msg); } diff --git a/src/static/js/pad.js b/src/static/js/pad.js index ac6d63723..de613910d 100644 --- a/src/static/js/pad.js +++ b/src/static/js/pad.js @@ -201,8 +201,6 @@ function handshake() }); socket.once('connect', function () { - // Setup our own connected flag since socketio one doesn't work accurately - socket.realConnected = true; sendClientReady(false); }); From ba322012d7151310496a716f2e968101493d860a Mon Sep 17 00:00:00 2001 From: "translatewiki.net" Date: Mon, 23 Apr 2018 08:52:57 +0200 Subject: [PATCH 15/20] Localisation updates from https://translatewiki.net. --- src/locales/pms.json | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/src/locales/pms.json b/src/locales/pms.json index c73567f5a..cdc80bea3 100644 --- a/src/locales/pms.json +++ b/src/locales/pms.json @@ -120,5 +120,10 @@ "pad.impexp.importbutton": "Amporté adess", "pad.impexp.importing": "An camin ch'as ampòrta...", "pad.impexp.confirmimport": "Amportand n'archivi as dëscancelërà ël test corent dël feuj. É-lo sigur ëd vorèj felo?", - "pad.impexp.convertFailed": "I l'oma nen podù amporté s'archivi. Për piasì, ch'a deuvra n'àutr formà ëd document o ch'a còpia e ancòla a man" + "pad.impexp.convertFailed": "I l'oma nen podù amporté s'archivi. Për piasì, ch'a deuvra n'àutr formà ëd document o ch'a còpia e ancòla a man", + "pad.impexp.padHasData": "I l'oma nen podù amporté s'archivi përché 's feuj a l'ha già avù dle modìfiche; për piasì, ch'a ampòrta un feuj neuv", + "pad.impexp.uploadFailed": "Ël cariament a l'ha falì, për piasì ch'a preuva torna", + "pad.impexp.importfailed": "Amportassion falìa", + "pad.impexp.copypaste": "Për piasì, ch'a còpia e ancòla", + "pad.impexp.exportdisabled": "L'esportassion an formà {{type}} a l'é disativà. Për piasì, ch'a contata sò aministrator ëd sistema për ij detaj." } From 903a2c8e43641574ac46f8be56cefd9278bbeb11 Mon Sep 17 00:00:00 2001 From: muxator Date: Thu, 3 May 2018 23:54:08 +0200 Subject: [PATCH 16/20] createRelease.sh: added error checking in modify_files() Otherwise, when inserting a multiline changelog sed would with this message: sed: -e expression #1, char 27: unterminated `s' command And the script would continue with an unmodified CHANGELOG.md For simmetry, added the same check to package.json, too --- bin/createRelease.sh | 3 +++ 1 file changed, 3 insertions(+) diff --git a/bin/createRelease.sh b/bin/createRelease.sh index 5afced8f2..bffa96ad9 100755 --- a/bin/createRelease.sh +++ b/bin/createRelease.sh @@ -66,8 +66,11 @@ function check_api_token { function modify_files { # Add changelog text to first line of CHANGELOG.md sed -i "1s/^/${changelogText}\n/" CHANGELOG.md + [[ $? != 0 ]] && echo "Aborting: Error modifying CHANGELOG.md" && exit 1 + # Replace version number of etherpad in package.json sed -i -r "s/(\"version\"[ ]*: \").*(\")/\1$VERSION\2/" src/package.json + [[ $? != 0 ]] && echo "Aborting: Error modifying package.json" && exit 1 } function create_release_branch { From 6dbeca217ed7209e63fa510d59a468136c3c0052 Mon Sep 17 00:00:00 2001 From: muxator Date: Fri, 4 May 2018 00:36:09 +0200 Subject: [PATCH 17/20] createRelease.sh: changelog editing failed for multiline messages sed does not accept multiline strings in its replacement text. Let's replace newlines with literal "\n" in modify_files() --- bin/createRelease.sh | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/bin/createRelease.sh b/bin/createRelease.sh index bffa96ad9..0439026bd 100755 --- a/bin/createRelease.sh +++ b/bin/createRelease.sh @@ -65,7 +65,16 @@ function check_api_token { function modify_files { # Add changelog text to first line of CHANGELOG.md - sed -i "1s/^/${changelogText}\n/" CHANGELOG.md + + msg="" + # source: https://unix.stackexchange.com/questions/9784/how-can-i-read-line-by-line-from-a-variable-in-bash#9789 + while IFS= read -r line + do + # replace newlines with literal "\n" for using with sed + msg+="$line\n" + done < <(printf '%s\n' "${changelogText}") + + sed -i "1s/^/${msg}\n/" CHANGELOG.md [[ $? != 0 ]] && echo "Aborting: Error modifying CHANGELOG.md" && exit 1 # Replace version number of etherpad in package.json From 10d555bc91a04e1d4316d56ae1d7d092dfcfaaf1 Mon Sep 17 00:00:00 2001 From: muxator Date: Fri, 4 May 2018 23:15:22 +0200 Subject: [PATCH 18/20] changelog: better specified CVE description fixes #3372 --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index df249c258..9dd333fe6 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,7 +7,7 @@ # 1.6.4 * SECURITY: exploitable /admin access - CVE-2018-9845 - * SECURITY: DoS with pad exports - CVE-2018-9327 + * SECURITY: DoS with pad exports and arbitrary code execution - CVE-2018-9327 * SECURITY: Remote Code Execution - CVE-2018-9326 * SECURITY: Pad data leak - CVE-2018-9325 * Fix: Admin redirect URL From e13ae0aec58413293bb7368436c8eb3c2f760f88 Mon Sep 17 00:00:00 2001 From: muxator Date: Fri, 4 May 2018 23:24:58 +0200 Subject: [PATCH 19/20] changelog: better specified CVE description Previous commit was wrong. Fixes #3372, really. --- CHANGELOG.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9dd333fe6..7de4b605b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,9 +6,9 @@ * FIX: unbreak Safari iOS line wrapping # 1.6.4 - * SECURITY: exploitable /admin access - CVE-2018-9845 - * SECURITY: DoS with pad exports and arbitrary code execution - CVE-2018-9327 - * SECURITY: Remote Code Execution - CVE-2018-9326 + * SECURITY: Access Control bypass on /admin - CVE-2018-9845 + * SECURITY: Remote Code Execution through pad export - CVE-2018-9327 + * SECURITY: Remote Code Execution through JSONP handling - CVE-2018-9326 * SECURITY: Pad data leak - CVE-2018-9325 * Fix: Admin redirect URL * Fix: Various script Fixes From 7e69a82cea35b604cdedfec007529abd55c17cc2 Mon Sep 17 00:00:00 2001 From: muxator Date: Fri, 4 May 2018 23:40:09 +0200 Subject: [PATCH 20/20] Release version 1.6.6 --- CHANGELOG.md | 5 +++++ src/package.json | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 7de4b605b..1293b578d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,8 @@ +# 1.6.6 + * FIX: line numbers are aligned with text again (broken in 1.6.4) + * FIX: text entered between connection loss and reconnection was not saved + * FIX: diagnostic call failed when etherpad was exposed in a subdirectory + # 1.6.5 * SECURITY: Escape data when listing available plugins * FIX: Fix typo in apicalls.js which prevented importing isValidJSONPName diff --git a/src/package.json b/src/package.json index 9813d6ab9..cb243ccb1 100644 --- a/src/package.json +++ b/src/package.json @@ -55,6 +55,6 @@ "repository" : { "type" : "git", "url" : "http://github.com/ether/etherpad-lite.git" }, - "version" : "1.6.5", + "version" : "1.6.6", "license" : "Apache-2.0" }