You can subscribe to this list here.
2001 |
Jan
|
Feb
(1) |
Mar
(265) |
Apr
(166) |
May
(25) |
Jun
(17) |
Jul
(20) |
Aug
(47) |
Sep
(6) |
Oct
(14) |
Nov
(66) |
Dec
(64) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2002 |
Jan
(109) |
Feb
(64) |
Mar
(34) |
Apr
(23) |
May
(64) |
Jun
(9) |
Jul
(13) |
Aug
(6) |
Sep
(33) |
Oct
(272) |
Nov
(67) |
Dec
(75) |
2003 |
Jan
(264) |
Feb
(244) |
Mar
(171) |
Apr
(119) |
May
(54) |
Jun
(93) |
Jul
(51) |
Aug
(48) |
Sep
(14) |
Oct
(49) |
Nov
(47) |
Dec
(15) |
2004 |
Jan
(13) |
Feb
(27) |
Mar
(18) |
Apr
(44) |
May
(35) |
Jun
(24) |
Jul
(39) |
Aug
(142) |
Sep
(35) |
Oct
(34) |
Nov
(49) |
Dec
(24) |
2005 |
Jan
(60) |
Feb
(71) |
Mar
(19) |
Apr
(27) |
May
(68) |
Jun
(4) |
Jul
(30) |
Aug
(10) |
Sep
(23) |
Oct
(24) |
Nov
(13) |
Dec
(6) |
2006 |
Jan
(4) |
Feb
(46) |
Mar
(64) |
Apr
(18) |
May
(16) |
Jun
(37) |
Jul
(7) |
Aug
(19) |
Sep
(9) |
Oct
(8) |
Nov
(3) |
Dec
(23) |
2007 |
Jan
(25) |
Feb
(21) |
Mar
(32) |
Apr
(36) |
May
(12) |
Jun
(1) |
Jul
(7) |
Aug
(15) |
Sep
(13) |
Oct
(1) |
Nov
|
Dec
|
2008 |
Jan
(3) |
Feb
(5) |
Mar
(1) |
Apr
(2) |
May
|
Jun
(1) |
Jul
(2) |
Aug
(7) |
Sep
|
Oct
(5) |
Nov
(1) |
Dec
|
2009 |
Jan
(7) |
Feb
(1) |
Mar
|
Apr
|
May
(1) |
Jun
(2) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
(3) |
2011 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
|
From: <php...@li...> - 2002-11-20 19:31:15
|
Project Manager, Please have someone process (assign, close, etc.) the 60 open Feature Requests. Thanks. Feature Requests ( 60 open / 149 total ) https://sourceforge.net/tracker/?atid=365539&group_id=15539&func=browse -- Mike Noyes <mhnoyes at users.sourceforge.net> http://sourceforge.net/users/mhnoyes/ http://leaf-project.org/ http://sitedocs.sf.net/ http://ffl.sf.net/ |
From: <php...@li...> - 2002-11-20 15:51:16
|
After installing 0.9.0-rc-1, I received three messages. All three of these errors are: "Missing language directory." errors (If you scroll down, you can see the context of these errors. I have highlighted them with <==================) Here's my question: Do I need to correct something in the installation before I proceed with testing 0.9.0 rc-1? Geoff ------------------------------------- Installation Results: Installing phpWebSite 0.9.0-rc1 Core tables successfully installed! Help tables successfully installed! Building required modules All layout tables successfully written. Write to modules table successful! Layout box created. Make sure to edit to match your theme. English language file installed Layout Manager was successfully installed! -------------------------------------------------------------------------------- Write to modules table successful! Layout box created. Make sure to edit to match your theme. Missing language directory. <============================== Help System was successfully installed! -------------------------------------------------------------------------------- Installed Translate portion of language module. Write to modules table successful! Layout box created. Make sure to edit to match your theme. English language file installed Language Administrator was successfully installed! -------------------------------------------------------------------------------- All Approval tables successfully written. Write to modules table successful! Layout box created. Make sure to edit to match your theme. English language file installed Approval was successfully installed! -------------------------------------------------------------------------------- All user tables successfully written. Registered to Approval Module. Write to modules table successful! Layout box created. Make sure to edit to match your theme. English language file installed User Manager was successfully installed! -------------------------------------------------------------------------------- ModMaker doesn't require any database interaction Write to modules table successful! Layout box created. Make sure to edit to match your theme. Missing language directory. <=========================== Module Maker was successfully installed! -------------------------------------------------------------------------------- No install file for Boost Module Upgrader.Assuming files are only requirement for installation. Write to modules table successful! Layout box created. Make sure to edit to match your theme. English language file installed Boost Module Upgrader was successfully installed! -------------------------------------------------------------------------------- All Security tables successfully written. Write to modules table successful! Layout box created. Make sure to edit to match your theme. Missing language directory. <============================ Security was successfully installed! |
From: <php...@li...> - 2002-11-20 13:46:17
|
I am working on the upgrade script today. Once finished, you won't have to completely reinstall fallout after each download. Won't that be nice? The basics are in Boost but I have started rewriting portions. I will post the standards and leave an example up once finished. Also, only a few have commented on the templating change. I am REMOVING the former version and the apply_template function from the Template class today unless someone has concerns. Matt P.S. Also to chalk up a big head slap. I logged into email from Brian's computer yesterday and had my preferences looted even though I was warned by Steven earlier that same day. So, beware SquirrelMail on a shared box and I need my prefs back please Jeremy :) |
From: <php...@li...> - 2002-11-19 21:46:41
|
http://www.devarticles.com/art/1/253 Matthew McNaney Internet Systems Architect Electronic Student Services Email: ma...@tu... URL: http://phpwebsite.appstate.edu Phone: 828-262-6493 ICQ: 141057403 |
From: <php...@li...> - 2002-11-19 21:28:23
|
As we get closer to another release candidate, I would like people to start hammering on the code. Developers, if you get a chance, please checkout a CVS copy tonight and report problems to sourceforge. Lets try to flush the bugs out and get a copy up by Thursday or Friday. Matthew McNaney Internet Systems Architect Electronic Student Services Email: ma...@tu... URL: http://phpwebsite.appstate.edu Phone: 828-262-6493 ICQ: 141057403 |
From: <php...@li...> - 2002-11-19 16:02:55
|
sweet :P > I have added module installation to the setup process. Hopefully this > will help those confused by the welcoming screen (if they install > PageMaster anyway). > > > Matthew McNaney > Internet Systems Architect > Electronic Student Services > Email: ma...@tu... > URL: http://phpwebsite.appstate.edu > Phone: 828-262-6493 > ICQ: 141057403 > > > > > ------------------------------------------------------- > This sf.net email is sponsored by: To learn the basics of securing your > web site with SSL, click here to get a FREE TRIAL of a Thawte Server > Certificate: http://www.gothawte.com/rd524.html > _______________________________________________ > Phpwebsite-developers mailing list > Php...@li... > https://lists.sourceforge.net/lists/listinfo/phpwebsite-developers -- Steven Levin Electronic Student Services Appalachian State University Phone: 828.262.2431 PhpWebsite Development Team URL: http://phpwebsite.appstate.edu Email: st...@NO... |
From: <php...@li...> - 2002-11-19 15:36:23
|
I have added module installation to the setup process. Hopefully this will help those confused by the welcoming screen (if they install PageMaster anyway). Matthew McNaney Internet Systems Architect Electronic Student Services Email: ma...@tu... URL: http://phpwebsite.appstate.edu Phone: 828-262-6493 ICQ: 141057403 |
From: <php...@li...> - 2002-11-19 13:03:39
|
I have committed the new processTemplate function. The old one is named backupTemplate. There is one change. The isString parameter is removed as it is not really needed if the session is caching the data. In its place is a variable named defaultDir. It is set to TRUE, which is normal behavior. If set to FALSE, the function will use the directory and file pointed to by the $template parameter no questions asked. It will not try to compare it to the current theme. Please update, test and let me know what you think. A few changes had to be made to layout to accommodate it so grab those files as well. Matthew McNaney Internet Systems Architect Electronic Student Services Email: ma...@tu... URL: http://phpwebsite.appstate.edu Phone: 828-262-6493 ICQ: 141057403 |
From: <php...@li...> - 2002-11-19 12:21:43
|
This is more a message stating that your main pear sys libs are the problem. Ex. /usr/local/lib/php The copy that comes with phpwebsite is basically newer than pear 4.2.3. When pear makes there big new release this will go away. Some classes have been renamed and this is causing problems. Ill look into trying to make the error messages more clear in the install. Thanks for the questions. For our servers i just replace the system libs with our new pear ones. It hasn't caused any problems so far. > OK. > > I copied the files, including the PEAR files onto the site and then > attempted to run: www.customerwebsitename.com/setup > > I get this error: > > The PEAR Libs on your system are NOT installed correctly or are OUT OF > DATE Using PEAR shiped with phpWebSite located at > /hosting/webpages/s/a/customerwebsitename.com/public/pear/ > > This error implies that there is an install of PEAR that must be done > BEFORE running setup. > > I went to the phpwebsite.appstate.edu, got what is labled as the latest > pear, downloaded it, and copied to the site on the chance that the files > were out of date. > > Geoff > > > At 12:25 PM 11/18/2002 -0600, you wrote: >>RC 1 comes with the PEAR libs and will use those if your system libs >> are out of date. >> >>Don. >> >>On Mon, 18 Nov 2002 php...@li... >> wrote: >> >> > I need to install 0.9 RC 1 on a virtual host without shell access. >> > >> > I've looked for a week for documentation on how to install PEAR in >> this circumstance and have found nothing. >> > >> > Can anybody help out with some info? >> > >> > Thanks, >> > >> > Geoff >> > >> > >> > >> > ------------------------------------------------------- >> > This sf.net email is sponsored by: To learn the basics of securing >> your web site with SSL, click here to get a FREE TRIAL of a Thawte >> Server Certificate: http://www.gothawte.com/rd524.html >> > _______________________________________________ >> > Phpwebsite-developers mailing list >> > Php...@li... >> > https://lists.sourceforge.net/lists/listinfo/phpwebsite-developers >> > >> > >> > >> > >> >> >> >>------------------------------------------------------- >>This sf.net email is sponsored by: To learn the basics of securing your >> web site with SSL, click here to get a FREE TRIAL of a Thawte Server >> Certificate: http://www.gothawte.com/rd524.html >>_______________________________________________ >>Phpwebsite-developers mailing list >>Php...@li... >>https://lists.sourceforge.net/lists/listinfo/phpwebsite-developers -- Jeremy Agee phpWebSite Development Team (http://phpwebsite.appstate.edu) Appalachian State University |
From: <php...@li...> - 2002-11-19 00:21:39
|
> + 1 Woot, I likes a lot. > > I think I will implement that in my modules to. > > Steven Well we can either transfer it to Layout or add the code to the core class. Either way. Matthew McNaney Internet Systems Architect Electronic Student Services Email: ma...@tu... URL: http://phpwebsite.appstate.edu Phone: 828-262-6493 ICQ: 141057403 |
From: <php...@li...> - 2002-11-18 23:00:18
|
+ 1 Woot, I likes a lot. I think I will implement that in my modules to. Steven > Greetings, > > While working on calendar, I needed to create a year view. This > particular view is extremely process heavy as it has to create each > month using templates. I was hitting one template for each day, week, > and month. 7 * 5 * 12 = 420 average file hits for the year view. > > Phew. > > Well what I decided to do was store this data in a session array keyed > into the year. So whenever that year is hit, it delivers the data > without having to hit all those files again. > > Then I thought of another way to speed up time. The processTemplate > function allows you to send a string instead of a filename. So if I > stored that template file information, I could just send it instead. > > After this, I thought why not combine the two? So I copied the > processTemplate function into layout. > > This processTemplate looks in a session named Template. It is indexed by > the module name and filename. If the session component exists, it used > it INSTEAD of loading the file. If it does not exist, it goes on before > loading the file and processing it. It then copies the template file > into the session. > > My file hits should go from around 420 to 3. > > Now I could have just pulled those files separately but, with the > session, it carries over from function to function. The month creation > script would lose that template file each one of the eleven other times > it was hit for the year view. > > IMHO I think this could be a substantional speed increase were it > implemented in the core. However, there might be issues I am unaware of. > > So I would like discussion on whether this should be implemented into > the processTemplate function. > > Please vote and post! > > Thanks, > Matt > > > Matthew McNaney > Internet Systems Architect > Electronic Student Services > Email: ma...@tu... > URL: http://phpwebsite.appstate.edu > Phone: 828-262-6493 > ICQ: 141057403 > > > > > ------------------------------------------------------- > This sf.net email is sponsored by: To learn the basics of securing your > web site with SSL, click here to get a FREE TRIAL of a Thawte Server > Certificate: http://www.gothawte.com/rd524.html > _______________________________________________ > Phpwebsite-developers mailing list > Php...@li... > https://lists.sourceforge.net/lists/listinfo/phpwebsite-developers -- Steven Levin Electronic Student Services Appalachian State University Phone: 828.262.2431 PhpWebsite Development Team URL: http://phpwebsite.appstate.edu Email: st...@NO... |
From: <php...@li...> - 2002-11-18 20:16:03
|
If I may vote ;-)? +1 on 4.2.2 or higher. >>> Personally, I am going to vote +1 for 4.2.2 or higher. Yves Malouin --------------------------------------------- Malouin Design Graphique --------------------------------------------- http://www.malouin.qc.ca Cap-Rouge, (Qu=E9bec) CANADA |
From: <php...@li...> - 2002-11-18 20:15:27
|
+1 to 4.2.2 or higher. On Mon, 18 Nov 2002 php...@li... wrote: > +1 on 4.2.2 or higher. > > > +1 on requiring php v4.2.2 > > >> Personally, I am going to vote +1 for 4.2.2 or higher. > > |
From: <php...@li...> - 2002-11-18 20:00:54
|
+1 on 4.2.2 or higher. > +1 on requiring php v4.2.2 >> Personally, I am going to vote +1 for 4.2.2 or higher. -- Brian W. Brown Director, Electronic Student Services Room 269, John Thomas Hall Appalachian State University Boone, NC 28608 vox: 828-262-7124 fax: 828-262-2585 http://ess.appstate.edu/ http://phpwebsite.appstate.edu/ http://lug.appstate.edu/ |
From: <php...@li...> - 2002-11-18 19:54:37
|
Greetings, While working on calendar, I needed to create a year view. This particular view is extremely process heavy as it has to create each month using templates. I was hitting one template for each day, week, and month. 7 * 5 * 12 = 420 average file hits for the year view. Phew. Well what I decided to do was store this data in a session array keyed into the year. So whenever that year is hit, it delivers the data without having to hit all those files again. Then I thought of another way to speed up time. The processTemplate function allows you to send a string instead of a filename. So if I stored that template file information, I could just send it instead. After this, I thought why not combine the two? So I copied the processTemplate function into layout. This processTemplate looks in a session named Template. It is indexed by the module name and filename. If the session component exists, it used it INSTEAD of loading the file. If it does not exist, it goes on before loading the file and processing it. It then copies the template file into the session. My file hits should go from around 420 to 3. Now I could have just pulled those files separately but, with the session, it carries over from function to function. The month creation script would lose that template file each one of the eleven other times it was hit for the year view. IMHO I think this could be a substantional speed increase were it implemented in the core. However, there might be issues I am unaware of. So I would like discussion on whether this should be implemented into the processTemplate function. Please vote and post! Thanks, Matt Matthew McNaney Internet Systems Architect Electronic Student Services Email: ma...@tu... URL: http://phpwebsite.appstate.edu Phone: 828-262-6493 ICQ: 141057403 |
From: <php...@li...> - 2002-11-18 19:39:01
|
I've been screwing around trying to get version 0.9 RC 1 installed on a virtual server without shell access. I think I may have it working now, after wasting many hours and many days. Here are the instructions that would have made it go smoothly: 1. Copy the distribution to your server. 2. Run setup. 3. If you get errors about PEAR, ignore them and proceed. 4. If you cannot write the pear_path and config files to your server, save them locally and copy them to your server. 5. You will need to do something about setting permissions - (I haven't quite figured out what I need to do here!) When I got the PEAR error message on install, I stopped and researched the problem. I wasted many hours and many days because I had no clue that I should continue with the install to resolve the problem. Geoff |
From: <php...@li...> - 2002-11-18 19:10:26
|
+1 on requiring php v4.2.2, I think this is definately a much better approach then putting in code to patch a vulnerable version of php. Steven >> I noticed some stangeness while coding today. > > Update: I reinstalled phpWS at work without a problem. > > After a little research, I found out this is an old issue. Multiport > forms had security issues in < 4.1.2. This version was a bug fix for a > security issue. > > I believe I might have file_uploads disabled at my home station but it > is odd that the form is destroyed instead of just not allowing the file > transfer. > > In any case, I need a recommendation. > > Should setup check for a deactivated file_uploads setting? > > Should we code forms to check this variable before adding the multipart > parameter? > > Should we force the a version check > 4.2.2 (the secure version)? > > Personally, I am going to vote +1 for 4.2.2 or higher. I don't want to > support a version that can be hacked just as we are releasing are newest > code. The downside is, of course, the groaning of people we force to > upgrade. I would also perform a check on the file_upload setting during > install. > > Let me hear what you think. > Matt > > > Matthew McNaney > Internet Systems Architect > Electronic Student Services > Email: ma...@tu... > URL: http://phpwebsite.appstate.edu > Phone: 828-262-6493 > ICQ: 141057403 > > > > > ------------------------------------------------------- > This sf.net email is sponsored by: To learn the basics of securing your > web site with SSL, click here to get a FREE TRIAL of a Thawte Server > Certificate: http://www.gothawte.com/rd524.html > _______________________________________________ > Phpwebsite-developers mailing list > Php...@li... > https://lists.sourceforge.net/lists/listinfo/phpwebsite-developers -- Steven Levin Electronic Student Services Appalachian State University Phone: 828.262.2431 PhpWebsite Development Team URL: http://phpwebsite.appstate.edu Email: st...@NO... |
From: <php...@li...> - 2002-11-18 18:55:58
|
Our servers does not have PEAR active. What is this about creating the pear_path.php files? Again: I can find no documentation of any kind anywhere that talks about installing the PEAR libraries on a virtual host with no shell access. Geoff At 01:36 PM 11/18/2002 -0500, you wrote: >One other thing. It appeared that having your system and local phpws >pears installed will cause problems. It gets confused sometimes. I fixed >this in cvs but all you need to do is after the pear_path.php files is >created edit it. Set the function call to just have >"/your/path/phpws/pear/:." and note all that other stuff like the system >paths. This should work. > > > I need to install 0.9 RC 1 on a virtual host without shell access. > > > > I've looked for a week for documentation on how to install PEAR in this > > circumstance and have found nothing. > > > > Can anybody help out with some info? > > > > Thanks, > > > > Geoff > > > > > > > > ------------------------------------------------------- > > This sf.net email is sponsored by: To learn the basics of securing your > > web site with SSL, click here to get a FREE TRIAL of a Thawte Server > > Certificate: http://www.gothawte.com/rd524.html > > _______________________________________________ > > Phpwebsite-developers mailing list > > Php...@li... > > https://lists.sourceforge.net/lists/listinfo/phpwebsite-developers > > >-- >Jeremy Agee >phpWebSite Development Team (http://phpwebsite.appstate.edu) >Appalachian State University > > > > >------------------------------------------------------- >This sf.net email is sponsored by: To learn the basics of securing >your web site with SSL, click here to get a FREE TRIAL of a Thawte >Server Certificate: http://www.gothawte.com/rd524.html >_______________________________________________ >Phpwebsite-developers mailing list >Php...@li... >https://lists.sourceforge.net/lists/listinfo/phpwebsite-developers |
From: <php...@li...> - 2002-11-18 18:47:50
|
OK. I copied the files, including the PEAR files onto the site and then attempted to run: www.customerwebsitename.com/setup I get this error: The PEAR Libs on your system are NOT installed correctly or are OUT OF DATE Using PEAR shiped with phpWebSite located at /hosting/webpages/s/a/customerwebsitename.com/public/pear/ This error implies that there is an install of PEAR that must be done BEFORE running setup. I went to the phpwebsite.appstate.edu, got what is labled as the latest pear, downloaded it, and copied to the site on the chance that the files were out of date. Geoff At 12:25 PM 11/18/2002 -0600, you wrote: >RC 1 comes with the PEAR libs and will use those if your system libs are >out of date. > >Don. > >On Mon, 18 Nov 2002 php...@li... wrote: > > > I need to install 0.9 RC 1 on a virtual host without shell access. > > > > I've looked for a week for documentation on how to install PEAR in this > > circumstance and have found nothing. > > > > Can anybody help out with some info? > > > > Thanks, > > > > Geoff > > > > > > > > ------------------------------------------------------- > > This sf.net email is sponsored by: To learn the basics of securing > > your web site with SSL, click here to get a FREE TRIAL of a Thawte > > Server Certificate: http://www.gothawte.com/rd524.html > > _______________________________________________ > > Phpwebsite-developers mailing list > > Php...@li... > > https://lists.sourceforge.net/lists/listinfo/phpwebsite-developers > > > > > > > > > > > >------------------------------------------------------- >This sf.net email is sponsored by: To learn the basics of securing >your web site with SSL, click here to get a FREE TRIAL of a Thawte >Server Certificate: http://www.gothawte.com/rd524.html >_______________________________________________ >Phpwebsite-developers mailing list >Php...@li... >https://lists.sourceforge.net/lists/listinfo/phpwebsite-developers |
From: <php...@li...> - 2002-11-18 18:36:14
|
One other thing. It appeared that having your system and local phpws pears installed will cause problems. It gets confused sometimes. I fixed this in cvs but all you need to do is after the pear_path.php files is created edit it. Set the function call to just have "/your/path/phpws/pear/:." and note all that other stuff like the system paths. This should work. > I need to install 0.9 RC 1 on a virtual host without shell access. > > I've looked for a week for documentation on how to install PEAR in this > circumstance and have found nothing. > > Can anybody help out with some info? > > Thanks, > > Geoff > > > > ------------------------------------------------------- > This sf.net email is sponsored by: To learn the basics of securing your > web site with SSL, click here to get a FREE TRIAL of a Thawte Server > Certificate: http://www.gothawte.com/rd524.html > _______________________________________________ > Phpwebsite-developers mailing list > Php...@li... > https://lists.sourceforge.net/lists/listinfo/phpwebsite-developers -- Jeremy Agee phpWebSite Development Team (http://phpwebsite.appstate.edu) Appalachian State University |
From: <php...@li...> - 2002-11-18 18:25:37
|
RC 1 comes with the PEAR libs and will use those if your system libs are out of date. Don. On Mon, 18 Nov 2002 php...@li... wrote: > I need to install 0.9 RC 1 on a virtual host without shell access. > > I've looked for a week for documentation on how to install PEAR in this > circumstance and have found nothing. > > Can anybody help out with some info? > > Thanks, > > Geoff > > > > ------------------------------------------------------- > This sf.net email is sponsored by: To learn the basics of securing > your web site with SSL, click here to get a FREE TRIAL of a Thawte > Server Certificate: http://www.gothawte.com/rd524.html > _______________________________________________ > Phpwebsite-developers mailing list > Php...@li... > https://lists.sourceforge.net/lists/listinfo/phpwebsite-developers > > > > |
From: <php...@li...> - 2002-11-18 17:26:52
|
I need to install 0.9 RC 1 on a virtual host without shell access. I've looked for a week for documentation on how to install PEAR in this circumstance and have found nothing. Can anybody help out with some info? Thanks, Geoff |
From: <php...@li...> - 2002-11-17 17:46:27
|
On Sun, 2002-11-17 at 09:24, php...@li... wrote: > Should we force the a version check > 4.2.2 (the secure version)? > > Personally, I am going to vote +1 for 4.2.2 or higher. I don't want to > support a version that can be hacked just as we are releasing are newest > code. The downside is, of course, the groaning of people we force to > upgrade. I would also perform a check on the file_upload setting during > install. +1 to 4.2.2 or higher, provided we can get SourceForge to update from 4.1.2. SourceForge phpinfo() PHP Version 4.1.2 PHP Core Directive Local Value Master Value file_uploads 1 1 Unfortunately, the file_uploads value can only be specified in php.ini. However, the default is 1. ref. http://www.php.net/manual/en/function.ini-set.php Name Default Changeable file_uploads "1" PHP_INI_SYSTEM -- Mike Noyes <mhnoyes at users.sourceforge.net> http://sourceforge.net/users/mhnoyes/ http://leaf-project.org/ http://sitedocs.sf.net/ http://ffl.sf.net/ |
From: <php...@li...> - 2002-11-17 17:24:57
|
> I noticed some stangeness while coding today. Update: I reinstalled phpWS at work without a problem. After a little research, I found out this is an old issue. Multiport forms had security issues in < 4.1.2. This version was a bug fix for a security issue. I believe I might have file_uploads disabled at my home station but it is odd that the form is destroyed instead of just not allowing the file transfer. In any case, I need a recommendation. Should setup check for a deactivated file_uploads setting? Should we code forms to check this variable before adding the multipart parameter? Should we force the a version check > 4.2.2 (the secure version)? Personally, I am going to vote +1 for 4.2.2 or higher. I don't want to support a version that can be hacked just as we are releasing are newest code. The downside is, of course, the groaning of people we force to upgrade. I would also perform a check on the file_upload setting during install. Let me hear what you think. Matt Matthew McNaney Internet Systems Architect Electronic Student Services Email: ma...@tu... URL: http://phpwebsite.appstate.edu Phone: 828-262-6493 ICQ: 141057403 |
From: <php...@li...> - 2002-11-16 21:42:32
|
I noticed some stangeness while coding today. While posting a form in FatCat, I was forced back to the index.php page. When I try to list the $_POST array, it is empty. I turned off redirection in Opera to see if I was hitting a header, but it didn't seem to be the problem. I also checked some common header redirections but they came up negative as well. There were two places where it would blank out: pagemaster and fatcat. The shared characteristic of both was they were using a multipart forms. Other forms submissions ran just fine. If someone could test the current CVS so I will know it is not the code, I would appreciate it. I am GUESSING that this is a characteristic of 4.1.2. I know some people have been complaining about getting blank screens when they try to post the main page. This would make sense now as only pagemaster and fatcat use multiforms. If this is the case, we will need to bump the requirements up to 4.2.0 (or 4.2.2) from 4.1.2. I can't test a higher version of php until I can get to work Monday. Thanks, Matt Matthew McNaney Internet Systems Architect Electronic Student Services Email: ma...@tu... URL: http://phpwebsite.appstate.edu Phone: 828-262-6493 ICQ: 141057403 |