CMS Made Simple Forums
https://forum.cmsmadesimple.org/

CMSMS 1.10 Beta3 is available.
https://forum.cmsmadesimple.org/viewtopic.php?f=74&t=56826
Page 1 of 1

Author:  calguy1000 [ Sat Sep 17, 2011 8:37 pm ]
Post subject:  CMSMS 1.10 Beta3 is available.

Ready for download, and hot off the presses.

This release should address all known issues with the beta version. and a few others. There is a new version of MicroTiny, and fixes to smarty processing, a host of typo fixes... fixes for SSL configurations, and a few other things.

Please test this release as fully and completely as possible. Hopefully it will be the last beta.

Author:  fredp [ Sun Sep 18, 2011 7:14 am ]
Post subject:  Re: CMSMS 1.10 Beta3 is available.

Hi,

I extracted cmsmadesimple-1.10-beta3-english.tar.gz atop my 1.10-beta2 test install and did an upgrade. That seemed to go fine. Next, I rechecked Admin:Content->Pages access using the "shared SSL" certificate on my host.

That worked too... but, Firefox again warned of "unencrypted content". So, I extracted a list of http: requests from "Live http headers" output. The list contains jquery and xajax javascript filenames (see attached).

I researched the jquery files case and I found a problem in the OutputHeaderJavascript() function in lib/classes/class.admintheme.inc.php (and a similar problem in lib/classes/class.cms_cookies.php). You can expose these problems using a simple 'grep' of the source tree:
\$1:
#find . -type f -exec fgrep "_SERVER['https']" {} /dev/null \;

./lib/classes/class.cms_cookies.php:    if( !isset($_SERVER['HTTPS']) || empty($_SERVER['https']) || $_SERVER['https'] == 'off' ) return FALSE;
./lib/classes/class.admintheme.inc.php:         $ssl = isset($_SERVER['https']) && (strtolower($_SERVER['https']) == 'on' || $_SERVER['https'] == 1);
fp2 www/110>
The last time I checked, PHP array keys were case-sensitive. Thus, isset($_SERVER['https']) will, generally, always return false -- even when $_SERVER['HTTPS'] is set.

Hope this helps.

Attachments:
beta3_pages_http.txt [286 Bytes]
Downloaded 286 times

Author:  Rolf [ Sun Sep 18, 2011 5:26 pm ]
Post subject:  Re: CMSMS 1.10 Beta3 is available.

@ Fredp
Fixed in SVN rev. 7417

Author:  fredp [ Mon Sep 19, 2011 10:46 am ]
Post subject:  Re: CMSMS 1.10 Beta3 is available.

Rolf \Rolf:
@ Fredp
Fixed in SVN rev. 7417

Thanks for the quick fix!

Page 1 of 1 All times are UTC
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
http://www.phpbb.com/