1. 论坛系统升级为Xenforo,欢迎大家测试!
    Dismiss Notice

textpattern 4.0.6 released

Discussion in '源码讨论' started by seasun, Feb 3, 2008.

  1. seasun

    seasun New Member

    Joined:
    Feb 22, 2007
    Messages:
    8
    Likes Received:
    0
    http://textpattern.com/weblog/310/textpattern-406-released

    After quite a while and lots of work from many, many people it’s finally here. Textpattern 4.0.6 is available as always on the download page.

    We have fixed no less than six security issues. Because half of those can be used from the public side, updating is strongly recommended.

    Updates should be seamless for the vast majority of people, otherwise make sure that all plugins are also updated to their most recent version, especially admin-side plugins. We’ll add entries to the FAQ specifically for 4.0.6 where questions may arise.

    Changes in 4.0.6:

    * Security (public side):
    o safer use of txp_login cookie + nonce (note: users are logged out after upgrading!)
    o fixed XSS vulnerability (thanks DSecRG) and input validation in setup script.
    o fixed XSS vulnerability and parameter value overflow in comments preview (thanks DSecRG)
    * Security (admin side):
    o add missing escape in SQL query (admin side)
    o fixed local file include vulnerability (publisher only) in textpattern/index.php (thanks DSecRG and Victor)
    o escape request method as shown on logs tab (thanks Victor)
    * New languages: Croatian, Korean, Português (Brasil), Serbian (Latin + Cyrillic), Turkish and Vietnamese
    * New tags:
    o <txp:if_search_results> </txp:if_search_results>
    o <txp:search_term />
    * Changed tags:
    o <txp:thumbnail /> allows non-JS links to the full-size image
    o <txp:article_custom /> allows comma-separated lists for category, section and author attributes (thanks Manfr
    e)
    o <txp:linklist /> allows comma-separated list for category attribute
    o <txp:file_download_list /> allows comma-separated list for category attribute
    o <txp:recent_articles /> allows comma-separated lists for category and section attribute
    o <txp:related_articles /> allows comma-separated list for section attribute
    o <txp:search_result_excerpt /> allows a custom “break” attribute defaulting to an ellipsis
    * Several tags have been deprecated and will be replaced automatically during the upgrade: <txp:sitename />, <txp:request_uri />, <txp:s />, <txp:c />, <txp:q />, <txp:id />, <txp: pg /> (more info)
    * Added ‘password reset’ functionality (with confirmation email) on the login screen
    * Update to jQuery 1.2.2 as a default JavaScript library
    * Fix textile list incompatibility with PHP 5.2.4 (and higher)
    * Fix http-auth when using lighttpd or (mostly) apache+fcgi
    * Fix HTTPS protocol check for ISAPI with IIS
    * Fix use of article tags on a sticky article page
    * Speed improvements (less SQL queries needed)
    * Pages, categories and styles can no longer be accidentally deleted if they are used on other tabs.
    * Corrections in the tag builder
    * Refrain from showing sticky articles from non-frontpage sections in search results
    * Enable separate search section for messy URL mode
    * Plugin developers should note that using add_privs() for admin-side plugins is now required (used to be optional for publisher-only plugins) and the included HISTORY.txt contains other useful information.
    * Many, many minor improvements, see SVN logs

    Further reading:
    FAQ-Entries specific to 4.0.6 (will be added when they arise)
    Textpattern Contributors (will soon be updated to 4.0.6)
    Forum-Thread for the announcement
     
  2. laogui

    laogui Administrator
    Staff Member

    Joined:
    Aug 30, 2005
    Messages:
    15,216
    Likes Received:
    35
    不错,比4.0.5改进了很多,现在搜索结果页面可以用标签独立定制了
     
  3. deadfire

    deadfire New Member

    Joined:
    Nov 13, 2007
    Messages:
    621
    Likes Received:
    0
    在抗一阵看看是不是要换这个。
     
  4. sluke

    sluke New Member

    Joined:
    Sep 4, 2005
    Messages:
    4,550
    Likes Received:
    13
    升级好了
     
  5. laogui

    laogui Administrator
    Staff Member

    Joined:
    Aug 30, 2005
    Messages:
    15,216
    Likes Received:
    35
    楼上的啥时候换模板了
     
  6. sluke

    sluke New Member

    Joined:
    Sep 4, 2005
    Messages:
    4,550
    Likes Received:
    13
    换好久了,正准备再换。
     
  7. hjb1

    hjb1 Active Member

    Joined:
    Sep 4, 2005
    Messages:
    1,623
    Likes Received:
    5
    难用~

    要自我升级一下~
     
  8. oicq我爱玩

    oicq我爱玩 New Member

    Joined:
    Jan 27, 2006
    Messages:
    5,205
    Likes Received:
    28
    textpattern 后台界面不是很友好`