ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

ExpressionEngine 2.5.0 Released

May 07, 2012 5:06pm

Subscribe [15]
  • #1 / May 07, 2012 5:06pm

    Robin Sowell's avatar

    Robin Sowell

    13218 posts

    ExpressionEngine 2.5.0 is a feature and security release.  It features a new Rich Text Editor field type, a Rich Text Editor Module to allow use of the editor on the front end, and a Cookie Consent Module designed to help European Union (EU) users comply with privacy laws impacting cookie use.  In addition to a number of new features, this release improves XSS filtering and redirect behavior.  For developers there are a number of new hooks and improvements, and everyone will benefit from the stability improvements provided by over 50 bug fixes.  Download it now or read on to find out more!

  • #2 / May 07, 2012 6:24pm

    leeaston's avatar

    leeaston

    634 posts

  • #3 / May 07, 2012 7:34pm

    stinhambo's avatar

    stinhambo

    1268 posts

    Are Publish Layouts now stable?

  • #4 / May 08, 2012 3:56am

    Riverboy's avatar

    Riverboy

    2993 posts

    Does RTE work in Wiki Edit page?
    EDIT: fan-freaking-tastic - it popped up and seems to work. This is so wonderful that this even beats beer. Thanks thanks thanks thanks thanks…

    Did i remember to say thanks?

  • #5 / May 08, 2012 10:25am

    jtrascap's avatar

    jtrascap

    161 posts

    Any news on Language support?  I’m going to need Dutch, Spanish and Russian languages in the CP soon…

  • #6 / May 09, 2012 12:03am

    bgarrant

    356 posts

    ExpressionEngine 2.5.0 is a feature and security release.  It features a new Rich Text Editor field type, a Rich Text Editor Module to allow use of the editor on the front end, and a Cookie Consent Module designed to help European Union (EU) users comply with privacy laws impacting cookie use.  In addition to a number of new features, this release improves XSS filtering and redirect behavior.  For developers there are a number of new hooks and improvements, and everyone will benefit from the stability improvements provided by over 50 bug fixes.  Download it now or read on to find out more!

    I tested on two Windows 2008 IIS7 machines and RTE seems to have issues. The site I tested was updated from 2.4 to 2.5 without issues. All RTE settings are there and enabled. I just can’t see the toolbar. Any chance we have a simple path issue or a conflict with “/” or “\” ?

    Any help is appreciated.

    Bryan

  • #7 / May 09, 2012 7:08am

    moogaloo's avatar

    moogaloo

    200 posts

    couple questions:
    The Cookies module - will that work dropped into EE2.4 and below, or is it only compatibale with EE2.5?
    Is is able to block and/or clear “all” cookies incl 3rd party cookies (specifically Google Analytics) until consent is given?

  • #8 / May 09, 2012 12:05pm

    Robin Sowell's avatar

    Robin Sowell

    13218 posts

    Let’s see if I can hit all the replies in one:

    @leeaston - though we did a forum release, it was only one bug fix and two new hooks.  There’s a feature branch that’s waiting on some live testing before it will be ready for release, which is why it’s not ready now.  Which I realize is vague.  But basically- while an forum update was released, it didn’t include feature additions beyond the hooks.

    @stinhambo - There were fixes related to publish layouts.  From my recollection, existing issues were actually related to third party add-ons and how they handle updating?  In other words- the direct problem was coming from third party code we can’t fix.  But I know Kevin put in a fix so that if ‘leftover’ references are left by an update (or otherwise) it shouldn’t cause a PHP error and failure of the layout.  This is the one I’m specifically thinking of https://support.ellislab.com/bugs/detail/17609.  But Kevin did hit all outstanding bugs related to layouts and they’re all showing as fixed.  I know Marcus ran some tests as well, and he couldn’t duplicate a problem under 2.5, while he COULD using 2.4.  So all outstanding issues are resolved.  Let me know if there’s evidence otherwise.

    @FinPete - 😉  Though, I wouldn’t say it beats beer!

    @HilversumJim - EL doesn’t actually create the language packs, just the mechanism for creating them and then will make them available when they exist.  That said- how that’s distributed is being improved as I speak.  So I can’t really say when or if 2.x versions of those packs will be available soon.

    @bgarrant- I honestly can’t think why the server would be affecting the RTE- aside from your guess on \/ type issue.  And even that… it shouldn’t be.  You’ve definitely created an RTE field and it shows in publish and just… no toolbar?  Any JS errors?  What I’d do for now- start a thread in technical support.  It’s going to get lost/confused in here.  If it’s not something tech support spots being wrong off the bat, we can go in and take a closer look.  Weird, though.

    @moogaloo - yep, the cookie module requires 2.5 because some hooks were added that it needs to work.  The big one being a hook in EE’s cookie setting function.  But there’s at least one other- and then for anyone needing it in a forum, there were a couple of hooks added there as well.

  • #9 / May 09, 2012 12:10pm

    bgarrant

    356 posts

    Let’s see if I can hit all the replies in one:

    @leeaston - though we did a forum release, it was only one bug fix and two new hooks.  There’s a feature branch that’s waiting on some live testing before it will be ready for release, which is why it’s not ready now.  Which I realize is vague.  But basically- while an forum update was released, it didn’t include feature additions beyond the hooks.

    @stinhambo - There were fixes related to publish layouts.  From my recollection, existing issues were actually related to third party add-ons and how they handle updating?  In other words- the direct problem was coming from third party code we can’t fix.  But I know Kevin put in a fix so that if ‘leftover’ references are left by an update (or otherwise) it shouldn’t cause a PHP error and failure of the layout.  This is the one I’m specifically thinking of https://support.ellislab.com/bugs/detail/17609.  But Kevin did hit all outstanding bugs related to layouts and they’re all showing as fixed.  I know Marcus ran some tests as well, and he couldn’t duplicate a problem under 2.5, while he COULD using 2.4.  So all outstanding issues are resolved.  Let me know if there’s evidence otherwise.

    @FinPete - 😉  Though, I wouldn’t say it beats beer!

    @HilversumJim - EL doesn’t actually create the language packs, just the mechanism for creating them and then will make them available when they exist.  That said- how that’s distributed is being improved as I speak.  So I can’t really say when or if 2.x versions of those packs will be available soon.

    @bgarrant- I honestly can’t think why the server would be affecting the RTE- aside from your guess on \/ type issue.  And even that… it shouldn’t be.  You’ve definitely created an RTE field and it shows in publish and just… no toolbar?  Any JS errors?  What I’d do for now- start a thread in technical support.  It’s going to get lost/confused in here.  If it’s not something tech support spots being wrong off the bat, we can go in and take a closer look.  Weird, though.

    @moogaloo - yep, the cookie module requires 2.5 because some hooks were added that it needs to work.  The big one being a hook in EE’s cookie setting function.  But there’s at least one other- and then for anyone needing it in a forum, there were a couple of hooks added there as well.

    Thanks Robin.  I did add on to another post someone had created http://ellislab.com/forums/viewthread/216886/.  I also created a bug report.  It works perfect when I run on Apache, but fails when installed on a Windows IIS server.  I am almost positive we have a path issue somewhere in that RTE code.  The plain textarea fieldtype shows in place of the RTE on the IIS website.  I have tested it pretty extensively and that is only potential issue I can imagine.  If anyone can help find that \/ issues it would be greatly appreciated.  I also found a weird paste issue that is happening on all server types http://ellislab.com/forums/viewthread/216920/.  Also have a thread on that one open.

    These issues are happening in the Control Panel.  Have not tested RTE on front end yet.

  • #10 / May 09, 2012 12:32pm

    bgarrant

    356 posts

    Let’s see if I can hit all the replies in one:

    @leeaston - though we did a forum release, it was only one bug fix and two new hooks.  There’s a feature branch that’s waiting on some live testing before it will be ready for release, which is why it’s not ready now.  Which I realize is vague.  But basically- while an forum update was released, it didn’t include feature additions beyond the hooks.

    @stinhambo - There were fixes related to publish layouts.  From my recollection, existing issues were actually related to third party add-ons and how they handle updating?  In other words- the direct problem was coming from third party code we can’t fix.  But I know Kevin put in a fix so that if ‘leftover’ references are left by an update (or otherwise) it shouldn’t cause a PHP error and failure of the layout.  This is the one I’m specifically thinking of https://support.ellislab.com/bugs/detail/17609.  But Kevin did hit all outstanding bugs related to layouts and they’re all showing as fixed.  I know Marcus ran some tests as well, and he couldn’t duplicate a problem under 2.5, while he COULD using 2.4.  So all outstanding issues are resolved.  Let me know if there’s evidence otherwise.

    @FinPete - 😉  Though, I wouldn’t say it beats beer!

    @HilversumJim - EL doesn’t actually create the language packs, just the mechanism for creating them and then will make them available when they exist.  That said- how that’s distributed is being improved as I speak.  So I can’t really say when or if 2.x versions of those packs will be available soon.

    @bgarrant- I honestly can’t think why the server would be affecting the RTE- aside from your guess on \/ type issue.  And even that… it shouldn’t be.  You’ve definitely created an RTE field and it shows in publish and just… no toolbar?  Any JS errors?  What I’d do for now- start a thread in technical support.  It’s going to get lost/confused in here.  If it’s not something tech support spots being wrong off the bat, we can go in and take a closer look.  Weird, though.

    @moogaloo - yep, the cookie module requires 2.5 because some hooks were added that it needs to work.  The big one being a hook in EE’s cookie setting function.  But there’s at least one other- and then for anyone needing it in a forum, there were a couple of hooks added there as well.

    I think this is issue Robin.  Not sure what we need to change:

    Webpage error details

    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; WOW64; Trident/4.0; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 1.1.4322; .NET CLR 3.0.30729)
    Timestamp: Wed, 9 May 2012 16:30:48 UTC


    Message: Syntax error
    Line: 1
    Char: 1
    Code: 0
    URI: http://www.domain.com/?ACT=23&cp=y&toolset_id=0&selector;=.rte

     

  • #11 / May 09, 2012 4:58pm

    Andru Edwards's avatar

    Andru Edwards

    330 posts

    Is it ridiculous of me to ask how Gallery module 1.x->2.x is going?

  • #12 / May 09, 2012 6:58pm

    bgarrant

    356 posts

    Let’s see if I can hit all the replies in one:

    @leeaston - though we did a forum release, it was only one bug fix and two new hooks.  There’s a feature branch that’s waiting on some live testing before it will be ready for release, which is why it’s not ready now.  Which I realize is vague.  But basically- while an forum update was released, it didn’t include feature additions beyond the hooks.

    @stinhambo - There were fixes related to publish layouts.  From my recollection, existing issues were actually related to third party add-ons and how they handle updating?  In other words- the direct problem was coming from third party code we can’t fix.  But I know Kevin put in a fix so that if ‘leftover’ references are left by an update (or otherwise) it shouldn’t cause a PHP error and failure of the layout.  This is the one I’m specifically thinking of https://support.ellislab.com/bugs/detail/17609.  But Kevin did hit all outstanding bugs related to layouts and they’re all showing as fixed.  I know Marcus ran some tests as well, and he couldn’t duplicate a problem under 2.5, while he COULD using 2.4.  So all outstanding issues are resolved.  Let me know if there’s evidence otherwise.

    @FinPete - 😉  Though, I wouldn’t say it beats beer!

    @HilversumJim - EL doesn’t actually create the language packs, just the mechanism for creating them and then will make them available when they exist.  That said- how that’s distributed is being improved as I speak.  So I can’t really say when or if 2.x versions of those packs will be available soon.

    @bgarrant- I honestly can’t think why the server would be affecting the RTE- aside from your guess on \/ type issue.  And even that… it shouldn’t be.  You’ve definitely created an RTE field and it shows in publish and just… no toolbar?  Any JS errors?  What I’d do for now- start a thread in technical support.  It’s going to get lost/confused in here.  If it’s not something tech support spots being wrong off the bat, we can go in and take a closer look.  Weird, though.

    @moogaloo - yep, the cookie module requires 2.5 because some hooks were added that it needs to work.  The big one being a hook in EE’s cookie setting function.  But there’s at least one other- and then for anyone needing it in a forum, there were a couple of hooks added there as well.

    I think this is issue Robin.  Not sure what we need to change:

    Webpage error details

    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; WOW64; Trident/4.0; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 1.1.4322; .NET CLR 3.0.30729)
    Timestamp: Wed, 9 May 2012 16:30:48 UTC


    Message: Syntax error
    Line: 1
    Char: 1
    Code: 0
    URI: http://www.domain.com/?ACT=23&cp=y&toolset_id=0&selector;=.rte

     

    My issue is resolved.  Please see http://ellislab.com/forums/viewthread/216886/P18.

  • #13 / May 10, 2012 6:40am

    moogaloo's avatar

    moogaloo

    200 posts

    Some excellent suggestions / solutions to the cookie control issue here - http://www.facebook.com/ellislab/posts/307091169368505?comment_id=2119816&offset=0&total_comments=3

  • #14 / May 14, 2012 8:46am

    geekamongus

    4 posts

    In addition to a number of new features, this release improves XSS filtering and redirect behavior.

    What is the impact of this? How vulnerable is a site that is not updated to 2.5.0? What are the potential attack vectors, and have any attacks been reported in the wild?

  • #15 / May 14, 2012 1:07pm

    Robin Sowell's avatar

    Robin Sowell

    13218 posts

    @Andru- not ridiculous at all, though I don’t have a good answer for you.  It’s still in progress, with comments preventing the last big roadblock to a resolution.

    @willc- in ExpressionEngine it’s very unlikely and we haven’t had any reports in the wild.  However, we always recommend running the latest security fixes.  And from a support perspective, the latest version is also highly encouraged.

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases