|
FAPI checkboxes need strengthening for XSS |
needs work |
critical |
bug reports |
7.x-dev |
forms system |
|
|
Secure by default: default should only show errors to admin users |
needs work |
normal |
tasks |
7.x-dev |
base system |
|
|
Module and theme names are not filtered on output. |
needs review |
normal |
bug reports |
7.x-dev |
base system |
|
|
Harden one-time login links against vulnerability from disclosure of SQL backups, or SQL 'SELECT' injection |
needs work |
critical |
bug reports |
7.x-dev |
user system |
|
|
All theme functions should take a single argument to make preprocess sane and meaningful |
closed |
critical |
tasks |
7.x-dev |
theme system |
|
|
Fix bugs in https support and force using https for authorize.php if available |
needs work |
critical |
tasks |
7.x-dev |
base system |
dww |
|
drupal_prepare_form() should always add default validate and submit handlers |
needs review |
normal |
bug reports |
7.x-dev |
forms system |
Dave Reid |
|
Warn about potentially insecure filter configurations |
needs review |
critical |
tasks |
7.x-dev |
filter.module |
|
|
Label permissions which are warned about in the user interface |
needs review |
critical |
tasks |
7.x-dev |
user system |
|
|
Add a standardized full name field to the users table |
active |
normal |
feature requests |
8.x-dev |
base system |
|
|
Image with /logout URL as source |
postponed |
critical |
bug reports |
7.x-dev |
user system |
|
|
Add a UI for if the site supports https |
active |
critical |
tasks |
7.x-dev |
base system |
Dave Reid |
|
Add "current password" field to "change password form" |
needs work |
critical |
bug reports |
7.x-dev |
user.module |
|
|
Edit/delete terms permission per vocabulary |
closed |
normal |
tasks |
7.x-dev |
taxonomy.module |
|
|
Add a core jQuery checkMarkup() function like check_markup() |
needs work |
normal |
feature requests |
7.x-dev |
javascript |
Dave Reid |
|
Create an SSH key-pair FileTransfer class |
won't fix |
normal |
tasks |
7.x-dev |
base system |
|
|
Documentation problem with filter_xss_admin |
needs work |
normal |
bug reports |
7.x-dev |
documentation |
|
|
prevent homographic logins |
active |
normal |
feature requests |
8.x-dev |
user system |
|
|
Improved security: rate limit login attempts. |
closed |
critical |
feature requests |
7.x-dev |
user system |
|
|
Security usability enhancement: update.module email notification to site email by default? |
closed |
normal |
tasks |
7.x-dev |
update.module |
|
|
New role name not filtered into admin/user/permissions |
needs work |
normal |
tasks |
7.x-dev |
user.module |
|
|
Harden FAPI aginst $form array keys containing XSS |
active |
critical |
tasks |
7.x-dev |
forms system |
|
|
Protection against brute force login |
duplicate |
critical |
feature requests |
7.x-dev |
user system |
|
|
Use principle of least privilege: don't suggest DB root account |
by design |
critical |
bug reports |
7.x-dev |
install system |
|
|
Vocabulary help needs filter_xss |
needs work |
minor |
bug reports |
7.x-dev |
taxonomy.module |
|