Quote:
|
Originally Posted by SvenErik The problems with the upgrade to the 1.0.7 release are usually because of human error; they don't upload all the files, they mess with file/folder permissions, they have done some core hacks that mess with the code, they need the SafeModePatch for 1.0.7 which hasn't been released yet but upgrade anyway, they have badly configured servers, etc, etc....! |
Well, I think I'll agree with most of what you have to say, but not everything.
A clean install of 1.0.7 on a well configured FreeBSD server still results in consistently reproducable errors. No show stoppers so far, but annoying things like not being able to log out, or losing the contents of the news article a user is trying to post when using the popup in HTMLarea. These are mostly cosmetic, but annoying.
The risk of being hacked can be mitigated, if I'm reading the info correctly, by implementing some very simple controls on IP address ranges that can access the admin tools (assuming mod_access is compiled into your apache).
If I am missing something, and the security holes are larger and more glaring than I have seen, please let me (and everyone else) know, and I'll roll back up to 1.0.7 and live with (or try to diagnose) the cosmetic problems.