From 037af6890fe6fdb84a08d3c86083e847c90ec0ad Mon Sep 17 00:00:00 2001
From: Aleksander Machniak <alec@alec.pl>
Date: Tue, 22 Oct 2013 08:17:26 -0400
Subject: [PATCH] Fix vulnerability in handling _session argument of utils/save-prefs (#1489382)

---
 skins/larry/ie7hacks.css |   68 ++++++++++++++++++++++++++++-----
 1 files changed, 57 insertions(+), 11 deletions(-)

diff --git a/skins/larry/ie7hacks.css b/skins/larry/ie7hacks.css
index e56e1e3..fc47133 100644
--- a/skins/larry/ie7hacks.css
+++ b/skins/larry/ie7hacks.css
@@ -7,9 +7,27 @@
  * License. It is allowed to copy, distribute, transmit and to adapt the work
  * by keeping credits to the original autors in the README file.
  * See http://creativecommons.org/licenses/by-sa/3.0/ for details.
- *
- * $Id$
  */
+
+/* #1488618 */
+#mainscreen {
+  height: expression((parseInt(document.documentElement.clientHeight)-108)+'px');
+}
+#mainscreen.offset {
+  height: expression((parseInt(document.documentElement.clientHeight)-150)+'px');
+}
+
+.minimal #mainscreen {
+  height: expression((parseInt(document.documentElement.clientHeight)-82)+'px');
+}
+
+.minimal #mainscreen.offset {
+  height: expression((parseInt(document.documentElement.clientHeight)-120)+'px');
+}
+
+#messagepartframe {
+	height: expression((parseInt(this.parentNode.offsetHeight)-1)+'px');
+}
 
 input.button {
 	display: inline;
@@ -23,7 +41,9 @@
 .boxfooter .listbutton .inner,
 .attachmentslist li a.delete,
 .attachmentslist li a.cancelupload,
-#messagepreviewheader .iconlink {
+#contacts-table td.action a,
+.previewheader .iconlink,
+.minimal #taskbar .button-inner {
 	/* workaround for text-indent which also offsets the background image */
 	text-indent: 0;
 	font-size: 0;
@@ -39,16 +59,33 @@
 
 .pagenav a.button,
 .pagenav a.button span.inner,
-#messagepreviewheader .iconlink,
+.previewheader .iconlink,
 #uploadform a.iconlink {
 	display: inline;
+}
+
+.pagenavbuttons {
+	top: 4px;
 }
 
 .dropbutton .dropbuttontip {
 	right: -2px;
 }
 
-#messagepreviewheader .iconlink {
+#login-form .box-inner form {
+	margin: 0;
+}
+
+#login-form #message div {
+	float: left;
+	display: block;
+	width: 200px;
+	margin-left: 130px;
+	white-space: nowrap;
+	text-align: left;
+}
+
+#messageheader.previewheader .iconlink {
 	color: #fff;
 	height: 14px;
 }
@@ -102,9 +139,9 @@
 	padding: 3px 8px;
 }
 
-#quicksearchbar input {
+.searchbox input {
 	padding-top: 4px;
-	padding-bottom: 4px;
+	padding-bottom: 2px;
 }
 
 #messagelistfooter #listcontrols,
@@ -126,10 +163,6 @@
 	right: 0;
 	top: 0;
 	bottom: 0;
-}
-
-#composeoptionsbox {
-	padding-top: 2px;
 }
 
 #composeoptionstoggle {
@@ -164,3 +197,16 @@
 	padding: 0 1px 0 0;
 }
 
+.minimal #topline {
+	width: 100%;
+	height: 18px;
+	box-sizing: border-box;
+}
+
+
+.minimal #taskbar a:hover .tooltip {
+	right: 34px;
+	top: 1px;
+}
+
+

--
Gitblit v1.9.1