User tests: Successful: Unsuccessful:
The JSST has been contacted about an missing path filter whithin the joomla download process. Given that an successfull attack requires a Super User access to change the tmp path setting and also to trigger the update itself the JSST decided to move this patch to the public tracker.
The upgrade works as expected
The upgrade works as expected
none
Status | New | ⇒ | Pending |
Category | ⇒ | Administration com_joomlaupdate |
Right even better
Labels |
Added:
?
|
This has to wait for the archive package to be merged and the path filter patched as noted above. The package i mean is the one generated by drone.
Category | Administration com_joomlaupdate | ⇒ | Administration com_joomlaupdate Libraries |
Test on Linux was ok, but on Windows it was failing. See joomla-framework/filter#40 for the fix in the framework package.
I have just merged the filter package and updated the branch here so this is ready to be tested again.
I've updated in the description the link to the update package for this PR so it points to the latest build.
I've updated in the description the link to the update package for this PR so it points to the latest build.
Thanks was about to do that too as we have to wait for it to be generated
I had to do it again because I had to restart drone.
I have tested this item
Tested with 2 server environments, one Linux with PHP 7.3, and one Windows with PHP 7.4.
I have tested this item
Tested on win10, with php8, following the testing instructions
Status | Pending | ⇒ | Ready to Commit |
RTC
@zero-24 Could you check @Quy 's suggestion above and fix it? #32076 (comment) . It will not change RTC status.
Labels |
Added:
?
|
@zero-24 Could you check @Quy 's suggestion above and fix it? #32076 (comment) . It will not change RTC status.
Moved with: ce05326
Previous tests are still valid since last change after tests was code style only. I've restored the test results in the tracker.
Status | Ready to Commit | ⇒ | Fixed in Code Base |
Closed_Date | 0000-00-00 00:00:00 | ⇒ | 2021-02-03 11:18:50 |
Closed_By | ⇒ | HLeithner |
Thanks
You can then replace the whole switch statement with
$result = parent::clean($source, $type);