Discussion about: Upgrade to Joomla! 1.0.10 Security Release

A place to discuss recent announcements made by the Joomla! Core Team. Let's hear what you have to say.
User avatar
vbonzai
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Thu Oct 27, 2005 12:13 am

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by vbonzai » Mon Jun 26, 2006 12:10 pm

"You are not authorized to view this resource" after upgrading to the latest version ?  ???

:'( I just drag and drop to my ftp and now can't log back....

User avatar
Tonie
Joomla! Ace
Joomla! Ace
Posts: 1585
Joined: Thu Aug 18, 2005 7:13 am
Contact:

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by Tonie » Mon Jun 26, 2006 12:19 pm

@yannisc

There are no changes in the language file, so you don't have to change anything here. As a non core coder, I can't tell you why it was included.
Antonie de Wilde - Forum admin

Tony Reid
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Sun Aug 21, 2005 10:55 pm

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by Tony Reid » Mon Jun 26, 2006 12:28 pm

vbonzai wrote:"You are not authorized to view this resource" after upgrading to the latest version ?  ???



Im getting this too
Last edited by Tony Reid on Mon Jun 26, 2006 12:30 pm, edited 1 time in total.

User avatar
stingrey
Joomla! Engineer
Joomla! Engineer
Posts: 360
Joined: Mon Aug 15, 2005 4:36 pm
Location: Marikina, Metro Manila, Philippines
Contact:

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by stingrey » Mon Jun 26, 2006 12:37 pm

vbonzai wrote:"You are not authorized to view this resource" after upgrading to the latest version ?  ???

Please provide more information as to when and how you see this error.

This isnt very much information to attempt to diagnose and debug an issue.
Joomla! Core Team Member
Software Coding and Design - Stability Team Leader

God grant me the Serenity to Accept the things I cannot change, the Courage to change the things I can and the Wisdom to know the Difference.

User avatar
stingrey
Joomla! Engineer
Joomla! Engineer
Posts: 360
Joined: Mon Aug 15, 2005 4:36 pm
Location: Marikina, Metro Manila, Philippines
Contact:

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by stingrey » Mon Jun 26, 2006 12:40 pm

yannisc wrote:Could we have the language file changes so we can upgrade existing translation files?

There are no changes to the language file that will impact on language packs.

One or two changes were made only to the english.php file to correct typographical errors, so this will not impact on non-english users.
Joomla! Core Team Member
Software Coding and Design - Stability Team Leader

God grant me the Serenity to Accept the things I cannot change, the Courage to change the things I can and the Wisdom to know the Difference.

User avatar
vbonzai
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Thu Oct 27, 2005 12:13 am

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by vbonzai » Mon Jun 26, 2006 12:44 pm

I can log to backend, it's just the front end that cause the issue.

I did a updgrade from 1.0.9 to 1.0.10  > upload to my ftp (as usual)

I am using Community builder "version  1.0 RC 1" for the login to my site.
Last edited by vbonzai on Mon Jun 26, 2006 1:14 pm, edited 1 time in total.

Tony Reid
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Sun Aug 21, 2005 10:55 pm

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by Tony Reid » Mon Jun 26, 2006 12:46 pm

Well if you go here : [red]domain address removed by poster[/red]

And click on any content items in the 'Latest get togethers' block - you will see what I mean.

Or if you click on any of the news links at the bottom of the page :(

Any thoughts appreciated.

Tony
Last edited by Tony Reid on Mon Jun 26, 2006 2:21 pm, edited 1 time in total.

User avatar
Mohammed
Joomla! Apprentice
Joomla! Apprentice
Posts: 16
Joined: Thu Oct 27, 2005 11:20 pm
Location: Cairo , Egypt
Contact:

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by Mohammed » Mon Jun 26, 2006 12:55 pm

yannisc wrote:Could we have the language file changes so we can upgrade existing translation files?


Nothing changed in language files since 1.0.9

Rey was faster , didn't see 2nd page !!  :'(
"Joomla! is science made clear."
Mohammed Sh. Abbas  -- Joomla! Fan !!

Tony Reid
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Sun Aug 21, 2005 10:55 pm

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by Tony Reid » Mon Jun 26, 2006 1:11 pm

Not sure if this is to do with the problem I am having above - but in the permissions tab of system info - my Session Directory is set to :

Session Directory /      unwriteable

Where I can I configure this? and should I change it to /tmp?

thanks in advance,
Tony

User avatar
stingrey
Joomla! Engineer
Joomla! Engineer
Posts: 360
Joined: Mon Aug 15, 2005 4:36 pm
Location: Marikina, Metro Manila, Philippines
Contact:

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by stingrey » Mon Jun 26, 2006 1:14 pm

Tony Reid wrote:Where I can I configure this? and should I change it to /tmp?

By default it is set to /tmp by php.ini - depending on your server host it could something different.

If you are on shared server, you probably dont have access to /tmp as it is a root folder - so you may need to contact your webhost for assistance.
Joomla! Core Team Member
Software Coding and Design - Stability Team Leader

God grant me the Serenity to Accept the things I cannot change, the Courage to change the things I can and the Wisdom to know the Difference.

User avatar
kachete
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Wed Sep 21, 2005 2:29 pm
Location: Venezuela
Contact:

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by kachete » Mon Jun 26, 2006 1:16 pm

I was running a site using 1.0.9 and upgrade to 1.0.10

After upgrading i can install any module or component

Code: Select all

Fatal error: Cannot instantiate non-existent class: ftphostaccnt in /home/eldiario/public_html/administrator/components/com_installer/admin.installer.php on line 46

this is the error

i also see that if we have mor than 50 items in the trash folder we can not see any items in the second number in the breadcumb navigation in the bottom not in the menu items or the conten items

so we have to wait for a solution or hope we can fix this issues

Best regards to the team you are working real hard to make it world for everyone

God bless you all

Alexis Valera
Venezuela
No hay preguntas tontas solo tontos que no preguntan
There is no foolish questions there are only foolish that do not ask questions
VOTE FOR JOOMLA!, UK LINUX AWARDS: http://snipurl.com/xhga
Vote for Joomla! NOW http://www.packtpub.com/article/final_five_joomla

Tony Reid
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Sun Aug 21, 2005 10:55 pm

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by Tony Reid » Mon Jun 26, 2006 1:17 pm

stingrey wrote:
Tony Reid wrote:Where I can I configure this? and should I change it to /tmp?

By default it is set to /tmp by php.ini - depending on your server host it could something different.

If you are on shared server, you probably dont have access to /tmp as it is a root folder - so you may need to contact your webhost for assistance.




It my own colocated box - I'll change it and see if that fixes the problem. not sure that it will though.

Wizzie
Joomla! Intern
Joomla! Intern
Posts: 53
Joined: Tue Sep 06, 2005 4:37 am
Location: Australia

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by Wizzie » Mon Jun 26, 2006 1:20 pm

vbonzai wrote:"You are not authorized to view this resource" after upgrading to the latest version ?  ???


I had that problem when trying to log into the frontend.

I had the extended user login module active and the standard one disabled. As soon as I switched to the standard login module the problem disappeared and I could login. But now I have a problem with not being able to use the extended user component/module.

User avatar
Heart
Joomla! Apprentice
Joomla! Apprentice
Posts: 6
Joined: Fri Aug 19, 2005 11:42 am
Location: near Munich
Contact:

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by Heart » Mon Jun 26, 2006 1:29 pm

Yes... same here... core/standard joomla-login module works finde....

@stingrey
I tried to add the

$validate = josSpoofValue(1); + hidden input field

in the CBE-login module but it seems that this is not the whole changes... Can you explain what else (files...) are involved in the login process?
Regards,
Heart

Tony Reid
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Sun Aug 21, 2005 10:55 pm

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by Tony Reid » Mon Jun 26, 2006 1:30 pm

Ive noticed that all links thowing out the error dont have a second parameter

http://www.mydomain.com/content/view/381/

as opposed to a working version......

http://www.mydomain.com/content/view/381/1

Tony Reid wrote:Well if you go here : [red]domain address removed by poster[/red]

And click on any content items in the 'Latest get togethers' block - you will see what I mean.

Or if you click on any of the news links at the bottom of the page :(

Any thoughts appreciated.

Tony

Last edited by Tony Reid on Mon Jun 26, 2006 2:21 pm, edited 1 time in total.

User avatar
stingrey
Joomla! Engineer
Joomla! Engineer
Posts: 360
Joined: Mon Aug 15, 2005 4:36 pm
Location: Marikina, Metro Manila, Philippines
Contact:

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by stingrey » Mon Jun 26, 2006 1:51 pm

Heart wrote:Yes... same here... core/standard joomla-login module works finde....

@stingrey
I tried to add the

$validate = josSpoofValue(1); + hidden input field

in the CBE-login module but it seems that this is not the whole changes... Can you explain what else (files...) are involved in the login process?

It is likely that additional hardening added to login functionality may have broken the CB login module.

We had passed on 1.0.10 beta to CB testing team, but due to teh time constraints of getting 1.0.10 out, they did not have the full time to examine this issue.

Will await further reports from the CB team to try identify the issue
Joomla! Core Team Member
Software Coding and Design - Stability Team Leader

God grant me the Serenity to Accept the things I cannot change, the Courage to change the things I can and the Wisdom to know the Difference.

User avatar
stingrey
Joomla! Engineer
Joomla! Engineer
Posts: 360
Joined: Mon Aug 15, 2005 4:36 pm
Location: Marikina, Metro Manila, Philippines
Contact:

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by stingrey » Mon Jun 26, 2006 1:55 pm

Tony Reid wrote:Ive noticed that all links thowing out the error dont have a second parameter

http://www.mydomain.com/content/view/381/

as opposed to a working version......

http://www.mydomain.com/content/view/381/1

The second parameter is the $Itemid value and is very important for Joomla! to work correctly.
In 1.0.9 for security purposes stricter checks were made for the existance of Itemid values, which would have been ignored in the past.

You may have to utilize this solution:
http://forum.joomla.org/index.php/topic ... #msg354238

More on this topic here:
http://forum.joomla.org/index.php/topic ... l#msg34432
Joomla! Core Team Member
Software Coding and Design - Stability Team Leader

God grant me the Serenity to Accept the things I cannot change, the Courage to change the things I can and the Wisdom to know the Difference.

per
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Tue Feb 21, 2006 10:35 pm

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by per » Mon Jun 26, 2006 2:09 pm

stingrey wrote:It is likely that additional hardening added to login functionality may have broken the CB login module.

We had passed on 1.0.10 beta to CB testing team, but due to teh time constraints of getting 1.0.10 out, they did not have the full time to examine this issue.

Will await further reports from the CB team to try identify the issue


I'm running a site with CB 1.0 stable and login still works after upgrade Joomla to 1.0.10

User avatar
Heart
Joomla! Apprentice
Joomla! Apprentice
Posts: 6
Joined: Fri Aug 19, 2005 11:42 am
Location: near Munich
Contact:

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by Heart » Mon Jun 26, 2006 2:13 pm

per wrote:I'm running a site with CB 1.0 stable and login still works after upgrade Joomla to 1.0.10

CBE here....
Regards,
Heart

per
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Tue Feb 21, 2006 10:35 pm

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by per » Mon Jun 26, 2006 2:20 pm

Heart wrote:
per wrote:I'm running a site with CB 1.0 stable and login still works after upgrade Joomla to 1.0.10

CBE here....

Is it based on CB 1.0 stable or 1.0 RC ?

Tony Reid
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Sun Aug 21, 2005 10:55 pm

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by Tony Reid » Mon Jun 26, 2006 2:20 pm

Thanks - thats got around the problem.

Hopefully this will be fixed in 1.5? as 1.0.10 is still creating news items without the itemid.

Thanks again,
Tony


stingrey wrote:
Tony Reid wrote:Ive noticed that all links thowing out the error dont have a second parameter

http://www.mydomain.com/content/view/381/

as opposed to a working version......

http://www.mydomain.com/content/view/381/1

The second parameter is the $Itemid value and is very important for Joomla! to work correctly.
In 1.0.9 for security purposes stricter checks were made for the existance of Itemid values, which would have been ignored in the past.

You may have to utilize this solution:
http://forum.joomla.org/index.php/topic ... #msg354238

More on this topic here:
http://forum.joomla.org/index.php/topic ... l#msg34432

User avatar
horus_68
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 100
Joined: Sun Sep 25, 2005 5:29 am
Location: Algarve - Portugal
Contact:

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by horus_68 » Mon Jun 26, 2006 2:44 pm

3 sites updated. Still running!!

A long life to this version!  8)
- Portuguese Translation Team (pt-PT) and Portuguese Joomla Community: http://www.joomlapt.com

Wizzie
Joomla! Intern
Joomla! Intern
Posts: 53
Joined: Tue Sep 06, 2005 4:37 am
Location: Australia

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by Wizzie » Mon Jun 26, 2006 3:56 pm

stingrey wrote:It is likely that additional hardening added to login functionality may have broken the CB login module.

We had passed on 1.0.10 beta to CB testing team, but due to teh time constraints of getting 1.0.10 out, they did not have the full time to examine this issue.

Will await further reports from the CB team to try identify the issue


CB login works fine, it is the login module associated with the User Extended Component that is causing grief.

User avatar
Heart
Joomla! Apprentice
Joomla! Apprentice
Posts: 6
Joined: Fri Aug 19, 2005 11:42 am
Location: near Munich
Contact:

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by Heart » Mon Jun 26, 2006 4:18 pm

...for CBE have a look at this  8)
Regards,
Heart

bob23
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Mon Jun 26, 2006 6:11 pm

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by bob23 » Mon Jun 26, 2006 6:48 pm

After updating, my section description have disapeared from the front end. They are still in the backend but I can't get them to show up in the front.  ???

AmyStephen

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by AmyStephen » Mon Jun 26, 2006 6:51 pm

Bob - Can you do a screen print of the menu item that presents that section? Or, look on the right side of the menu item and make certain that the section description is actually enabled? Plus - your address? Thanks!

bishal

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by bishal » Mon Jun 26, 2006 6:54 pm

Hi,

I did a fresh install of Joomla 1.10 and when i log in to admin cpanel i noticed the user icon, message icons and etc are displayed twice. I have attached a snap shot.

thansk,
Bishal
Attachments
Joomla110.JPG

bob23
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Mon Jun 26, 2006 6:11 pm

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by bob23 » Mon Jun 26, 2006 6:57 pm

AmyStephen wrote:Bob - Can you do a screen print of the menu item that presents that section? Or, look on the right side of the menu item and make certain that the section description is actually enabled? Plus - your address? Thanks!


http://hylianhd.rpgplanet.gamespy.com/area_51/joomla_problem.PNG Is that what your looking for?

My sites at hylianhelpdesk.com/zelda  I'm working on converting my normal HTML site to Joomla.

User avatar
Manoxtra
Joomla! Apprentice
Joomla! Apprentice
Posts: 16
Joined: Thu Aug 18, 2005 5:35 pm
Location: Holland
Contact:

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by Manoxtra » Mon Jun 26, 2006 6:58 pm

Error after upgrading >>> After I login in the backend this message appeares in the top of my screen:

Code: Select all

Warning: Missing argument 2 for initsessionadmin() in /home/manonet/public_html/aob/includes/joomla.php on line 742



Code: Select all

Database Version:       4.1.19-standard
PHP Version:    4.4.2
Web Server:    Apache/1.3.33 (Unix) mod_gzip/1.3.26.1a mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_ssl/2.8.22 OpenSSL/0.9.7g
Attachments
joomla_110_backend_error.png
Power to the devs!!!

bob23
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Mon Jun 26, 2006 6:11 pm

Re: Discussion about: Upgrade to Joomla! 1.0.10 Security Release

Post by bob23 » Mon Jun 26, 2006 6:59 pm

bob23 wrote:
AmyStephen wrote:Bob - Can you do a screen print of the menu item that presents that section? Or, look on the right side of the menu item and make certain that the section description is actually enabled? Plus - your address? Thanks!


http://hylianhd.rpgplanet.gamespy.com/area_51/joomla_problem.PNG Is that what your looking for?

My sites at hylianhelpdesk.com/zelda  I'm working on converting my normal HTML site to Joomla.



I just fixed the problem. It seems you need to turn off showing the description then save it and turn it back on. :)


Locked