aboutsummaryrefslogtreecommitdiff
path: root/src
AgeCommit message (Collapse)Author
2015-06-29prefs.http_strict_transport_securitycorvid
2015-06-29HTTP Strict Transport Securitycorvid
I'm not including the preload file yet.
2015-06-24add a tls test sitecorvid
2015-06-18use [IMG] placeholder even if prefs.load_images is truecorvid
2015-06-03web must be valid in order to continue in a_Http_connect_donecorvid
A site triggers this with a background image where the style is deleted upon </div>, and Capi_stop_client() finds that a_Cache_client_get_if_unique() is false, so nothing aborts the connection. And there's time for this to happen because we're doing TLS handshake. I don't know whether all of what triggered this is doing the right thing, but at least when it comes to capi, we can see that there's the idea of permitting it (with whether we ever actually want that in practice being yet another question). In any case, Http_make_query_str() definitely thinks the web is there. If we really decided that we wanted connections to continue without webs, we could stuff 1) what sort of thing are we requesting? 2) is this a third-party request? into the socket data. Making the query earlier is probably not advisable because we'd want the cookies available at the time that we send the query and not the cookies that were available somewhat earlier.
2015-06-03show certificate hash algorithm (and complain feebly if it's weak)corvid
2015-06-01constcorvid
2015-06-01url: rm unused flagscorvid
2015-06-01rm the old-style url alt stuffcorvid
2015-06-01TLS servers sortedcorvid
2015-06-01url: rm dead codecorvid
2015-05-31mergecorvid
2015-05-31rm MSGcorvid
2015-05-31rm MSGcorvid
2015-05-31fix up socket queuecorvid
2015-05-30fix warningcorvid
2015-05-30print certificate chaincorvid
2015-05-30let's not print tls alerts for 'close notify'corvid
2015-05-29print out TLS version and cipher agreed upon after first connection with servercorvid
2015-05-29documentation and not-currently-possible error casecorvid
2015-05-29some more information for TLS warning popupscorvid
2015-05-28'ssl' -> 'tls' where reasonable, given that ssl3 is dead and allcorvid
I used 'hg rename' and expected (at least hoped) that 'hg diff' would do what I would naturally want, but no.
2015-05-28make http_max_conns truly per server/proxy rather than hostcorvid
And separate http from https for safety while we're at it. We were checking this where we needed to, but it would be easy to forget about in the future. Not that very much happens when you try http://example.com:443 or https://example.com:80, but I'm being careful nevertheless.
2015-05-19http use-after-freecorvid
openbsd tripped over this for me
2015-05-18make it clearer that ssl popups are about security (well, if one's WM shows ↵corvid
titles) I've noticed how users on forums can be like "Oh, it must be something about bugs in dillo. But it manages to load the page". This is a degree of misunderstanding which I wouldn't expect from anyone interested in using dillo, but there it is, so I should deal with it.
2015-05-18let's add LibreSSL to the OpenSSL licensing linking exceptioncorvid
I tried dillo on openbsd and, unsurprisingly, it seems fine with libressl. I still would like it if some other TLS library would become the clear choice for dillo at some point...
2015-05-18let fltk wrap this dialog's textcorvid
2015-05-18clean up the SSL error dialog strings a littlecorvid
2015-05-18gain some space in a_Dialog_choicecorvid
2015-05-18not use strcpy herecorvid
I see that openbsd likes to complain when it's used, and we certainly don't have a deep need for it in this case.
2015-05-09splash: urge users to read help. mention domainrc.corvid
Just recently I added some mention of domainrc to the website. I hadn't made enough of an effort to communicate the fact that it exists, and now it's time to remedy that.
2015-05-09keys: add Menu keycorvid
Now have a computer with windows keys :( and, at least for me, the one that looks like a menu is apparently "Menu" in xev. (Although some FLTK documentation and other stuff on the web suggests that this used to [or maybe still does for some people] cause Super_R (xev), which would then turn into FL_Meta_R in FLTK.)
2015-05-09fix font-size:(larger|smaller)corvid
2015-05-08https: the rest :)corvid
Normally I really like to make commits in small pieces that all compile and make sense in isolation, but with this https work, the effort vs the reward just wasn't going to make sense.
2015-05-08ssl.[ch]corvid
2015-05-08https: url updatescorvid
2015-05-05html5 coords don't permit percentagescorvid
2015-04-28BUG_MSGcorvid
2015-04-27html5 permits relative BASE urlcorvid
2015-04-26in html5, ADDRESS may contain certain elements that we classify as block.corvid
Not heading/sectioning ones, but P is legal, for example.
2015-04-12more html5 doctype stringscorvid
Followed a link to instructables.com and found that they use one of these. I'm a little surprised to see one of these strings around. A minute of research shows: Apparently it generally has something to do with xslt restrictions.
2015-04-11provide a redirection-blocked pagecorvid
2015-04-05http socket reuse must test for HTTP_SOCKET_TO_BE_FREEDcorvid
2015-04-03html5 (and css3) permit gr[ae]y in color namescorvid
2015-04-01limit size when copying strings to find character referencescorvid
https://github.com/torvalds/linux/pull/17 has a five-megabyte title attribute, which is just a bit excessive. Since it has tons of &lt; and &gt;, dillo couldn't cope with it. Over five minutes to parse as much of it as it got before the connection broke. With this change, it's about fifty seconds (on this old computer) to get/show the full 24 megs, which is an improvement, at least.
2015-03-22socket freecorvid
2015-03-08fix leak introduced in bbd25bf5Johannes Hofmann
noticed-by: eocene
2015-03-05http, don't presume that socket data is found in ValidSockscorvid
jeremy's valgrind logs have an instance of ==15610== Invalid read of size 4 ==15610== at 0x8090B53: Http_socket_reuse (http.c:668)
2015-03-04better error msg when we can't save a file from cachecorvid
2015-02-21update some urls in commentscorvid