From 037af6890fe6fdb84a08d3c86083e847c90ec0ad Mon Sep 17 00:00:00 2001
From: Aleksander Machniak <alec@alec.pl>
Date: Tue, 22 Oct 2013 08:17:26 -0400
Subject: [PATCH] Fix vulnerability in handling _session argument of utils/save-prefs (#1489382)

---
 plugins/acl/localization/en_GB.inc |   72 ++++++++++++++++++++---------------
 1 files changed, 41 insertions(+), 31 deletions(-)

diff --git a/plugins/acl/localization/en_GB.inc b/plugins/acl/localization/en_GB.inc
index 201cb3c..e1b33fb 100644
--- a/plugins/acl/localization/en_GB.inc
+++ b/plugins/acl/localization/en_GB.inc
@@ -2,18 +2,20 @@
 
 /*
  +-----------------------------------------------------------------------+
- | localization/en_GB/labels.inc                                         |
+ | plugins/acl/localization/<lang>.inc                                   |
  |                                                                       |
- | Language file of the Roundcube Webmail client                         |
- | Copyright (C) 2012, The Roundcube Dev Team                            |
- | Licensed under the GNU General Public License                         |
+ | Localization file of the Roundcube Webmail ACL plugin                 |
+ | Copyright (C) 2012-2013, The Roundcube Dev Team                       |
+ |                                                                       |
+ | Licensed under the GNU General Public License version 3 or            |
+ | any later version with exceptions for skins & plugins.                |
+ | See the README file for a full license statement.                     |
  |                                                                       |
  +-----------------------------------------------------------------------+
- | Author: Lazlo                                                         |
- +-----------------------------------------------------------------------+
+
+ For translation see https://www.transifex.com/projects/p/roundcube-webmail/resource/plugin-acl/
 */
 
-$labels = array();
 $labels['sharing'] = 'Sharing';
 $labels['myrights'] = 'Access Rights';
 $labels['username'] = 'User:';
@@ -23,44 +25,48 @@
 $labels['anyone'] = 'All users (anyone)';
 $labels['anonymous'] = 'Guests (anonymous)';
 $labels['identifier'] = 'Identifier';
+
 $labels['acll'] = 'Look-up';
-$labels['shortacll'] = 'Look-up';
 $labels['aclr'] = 'Read messages';
 $labels['acls'] = 'Keep Seen state';
 $labels['aclw'] = 'Write flags';
 $labels['acli'] = 'Insert (copy into)';
 $labels['aclp'] = 'Post';
-$labels['shortaclp'] = 'Post';
 $labels['aclc'] = 'Create sub-folders';
 $labels['aclk'] = 'Create sub-folders';
 $labels['acld'] = 'Delete messages';
 $labels['aclt'] = 'Delete messages';
 $labels['acle'] = 'Expunge';
-$labels['shortacle'] = 'Expunge';
 $labels['aclx'] = 'Delete folder';
 $labels['acla'] = 'Administer';
-$labels['shortacla'] = 'Administer';
+
 $labels['aclfull'] = 'Full control';
 $labels['aclother'] = 'Other';
-$labels['shortaclother'] = 'Other';
 $labels['aclread'] = 'Read';
-$labels['shortaclr'] = 'Read';
-$labels['shortaclread'] = 'Read';
 $labels['aclwrite'] = 'Write';
-$labels['shortaclw'] = 'Write';
-$labels['shortaclwrite'] = 'Write';
 $labels['acldelete'] = 'Delete';
-$labels['shortacld'] = 'Delete';
-$labels['shortaclt'] = 'Delete';
-$labels['shortacldelete'] = 'Delete';
+
+$labels['shortacll'] = 'Look-up';
+$labels['shortaclr'] = 'Read';
 $labels['shortacls'] = 'Keep';
+$labels['shortaclw'] = 'Write';
 $labels['shortacli'] = 'Insert';
+$labels['shortaclp'] = 'Post';
 $labels['shortaclc'] = 'Create';
 $labels['shortaclk'] = 'Create';
+$labels['shortacld'] = 'Delete';
+$labels['shortaclt'] = 'Delete';
+$labels['shortacle'] = 'Expunge';
 $labels['shortaclx'] = 'Folder delete';
+$labels['shortacla'] = 'Administer';
+
+$labels['shortaclother'] = 'Other';
+$labels['shortaclread'] = 'Read';
+$labels['shortaclwrite'] = 'Write';
+$labels['shortacldelete'] = 'Delete';
+
 $labels['longacll'] = 'The folder is visible on lists and can be subscribed to.';
 $labels['longaclr'] = 'The folder can be opened for reading';
-$labels['longaclread'] = 'The folder can be opened for reading';
 $labels['longacls'] = 'Messages Seen flag can be changed';
 $labels['longaclw'] = 'Messages flags and keywords can be changed, except Seen and Deleted.';
 $labels['longacli'] = 'Messages can be written or copied to the folder';
@@ -72,18 +78,22 @@
 $labels['longacle'] = 'Messages can be expunged';
 $labels['longaclx'] = 'The folder can be deleted or renamed';
 $labels['longacla'] = 'The folder access rights can be changed';
+
 $labels['longaclfull'] = 'Full control including folder administration';
+$labels['longaclread'] = 'The folder can be opened for reading';
 $labels['longaclwrite'] = 'Messages can be marked, written or copied to the folder';
 $labels['longacldelete'] = 'Messages can be deleted';
-$labels['deleting'] = 'Deleting access rights...';
-$labels['saving'] = 'Saving access rights...';
-$labels['updatesuccess'] = 'Successfully changed access rights';
-$labels['deletesuccess'] = 'Successfully deleted access rights';
-$labels['createsuccess'] = 'Successfully added access rights';
-$labels['updateerror'] = 'Ubable to update access rights';
-$labels['deleteerror'] = 'Unable to delete access rights';
-$labels['createerror'] = 'Unable to add access rights';
-$labels['deleteconfirm'] = 'Are you sure, you want to remove access rights of selected user(s)?';
-$labels['norights'] = 'No rights has been specified!';
-$labels['nouser'] = 'No username has been specified!';
 
+$messages['deleting'] = 'Deleting access rights...';
+$messages['saving'] = 'Saving access rights...';
+$messages['updatesuccess'] = 'Successfully changed access rights';
+$messages['deletesuccess'] = 'Successfully deleted access rights';
+$messages['createsuccess'] = 'Successfully added access rights';
+$messages['updateerror'] = 'Ubable to update access rights';
+$messages['deleteerror'] = 'Unable to delete access rights';
+$messages['createerror'] = 'Unable to add access rights';
+$messages['deleteconfirm'] = 'Are you sure, you want to remove access rights of selected user(s)?';
+$messages['norights'] = 'No rights has been specified!';
+$messages['nouser'] = 'No username has been specified!';
+
+?>

--
Gitblit v1.9.1