Announcements - MODX Community Forums https://forums.modx.com/board/?board=7 <![CDATA[You are Invited to MODX Amsterdam, March 29, 2019]]> https://forums.modx.com/thread/104797/you-are-invited-to-modx-amsterdam-march-29-2019#dis-post-563554 MODX Meetup on Friday 29th of March 2019 in Amsterdam.

A historic city with a futuristic outlook, Amsterdam provides the ideal location to bring MODX users together, exchange ideas & extend the professional network. There are plenty of places to visit during the free time.

The organizers have planned a jam-packed one-day event. Expect innovative topics covering the 3 Cs: Core, Content & Commerce. They're working to secure a unique venue, as well.

The event has also received significant assistance and support from Gauke Pieter Sietzema and Henk Everts of Sterc Online Agency and Mark Hamstra from modmore.

For more information and to book your attendance, visit https://modx.amsterdam/.]]>
https://forums.modx.com/thread/104797/you-are-invited-to-modx-amsterdam-march-29-2019#dis-post-563554 Mon, 14 Jan 2019 06:00:37 +0000 https://forums.modx.com/thread/104797/you-are-invited-to-modx-amsterdam-march-29-2019#dis-post-563554
<![CDATA[Urgent! Active Attacks on MODX Revolution Sites Below Revolution 2.6.5]]> https://forums.modx.com/thread/104079/urgent-active-attacks-on-modx-revolution-sites-below-revolution-2-6-5#dis-post-559785 released MODX Revolution 2.6.5 to close two critical vulnerabilities.

On July 16, the members of the MODX team were notified that an example attack script was shared publicly that would enable hackers to modify and use for malicious purposes. Starting on July 18th, 2018, the MODX team began receiving reports that these attacks were compromising MODX Revolution websites.

Upgrade Now
If your site has not been hacked, you MUST upgrade* to MODX Revolution 2.6.5 and all Extras immediately.

Already Hacked
If your site has been compromised, do not panic. It may be possible to recover the site if you have a backup from prior to July 18th, 2018.

Once you have restored from a backup, you should immediately upgrade to MODX Revolution 2.6.5 and then upgrade all Extras from within the MODX Manager, including Gallery if it is installed. Once you login to your site Manager (e.g., at https://www.example.com/manager/), navigate to the top "Extras" menu and press the orange "upgrade" button for each Extra that needs to be upgraded.

No Backup; Still Hacked
The MODX Services team has experience in hacked site remediation. Also some MODX Professionals may have similar experience. Sucuri.net also provides hack remediation to identify and remove compromised files.

Need Help with Upgrades
If you do not know how to upgrade your site there are several support options available. You can contact the developer or builder of your site, ask for help in the MODX Forums, find a MODX Professional or get help from the MODX Services team.

Staying Abreast of Releases is Critical
We cannot stress how important it is to update sites to the latest versions of MODX as they are released. While this active exploit is unusual in the MODX Community, it does underscore the need to be vigilant with new releases and security patches.

* Experienced MODX developers can do an interim manual patch on 2.6.x and above by replacing the following files here, here and if it exists, this file.]]>
https://forums.modx.com/thread/104079/urgent-active-attacks-on-modx-revolution-sites-below-revolution-2-6-5#dis-post-559785 Sun, 22 Jul 2018 12:28:44 +0000 https://forums.modx.com/thread/104079/urgent-active-attacks-on-modx-revolution-sites-below-revolution-2-6-5#dis-post-559785
<![CDATA[PHP 5.6 is Approaching its End of Life]]> https://forums.modx.com/thread/103812/php-5-6-is-approaching-its-end-of-life#dis-post-558318 PHP 5.6 is Approaching its End of Life this Year

December 31, 2018 marks the official end of security support for PHP 5.6, this means there will be no further updates to the software. PHP 7.0 was released in December 2015 and PHP 7.1 was released December of 2016.

What This Change Means For You
Most MODX users and site owners will have no issues with PHP 7 if they run at least MODX 2.5.2 or Evo CMS 1.4.0 (formerly MODX Evolution) or later versions. For MODX Cloud customers, we're ending PHP 5.6 support on July 1, 2018.

Reasons people might have issues with PHP 7 include:
  • Outdated MODX Revolution or other software
  • MODX Extras or software add-ons/Plugins not updated or unsupported
  • Custom code that requires updating
  • If you’re using other software alongside MODX, most applications today should be compatible with PHP 7.1 which was first released in December of 2016.

How to Prepare for PHP 7
Most MODX users will hav no issues with PHP 7. You may just need to upgrade to the lates version of MODX Revolution. For MODX Cloud customers we’ve created a Support Article to guide customers through the move to PHP 7.1.

Need Help Getting Ready?
For site owners who are unsure about how to get their site ready for the upcoming changes, we advise you to contact your developer or designer. If you’ve lost contact with your developer or designer, you can find a local MODX Professional to assist.]]>
https://forums.modx.com/thread/103812/php-5-6-is-approaching-its-end-of-life#dis-post-558318 Tue, 01 May 2018 06:43:40 +0000 https://forums.modx.com/thread/103812/php-5-6-is-approaching-its-end-of-life#dis-post-558318
<![CDATA[MODX3 Project Launch]]> https://forums.modx.com/thread/103640/modx3-project-launch#dis-post-557500 MODX3 Project
MODX3.org was recently deployed to celebrate the official launch of the MODX3 Project. A dedicated team is currently working on making MODX3 a reality. Some familiar names from the MODX Community are pushing the project forward on a daily basis including Vasily Naumkin, Mark Hamstra, Gauke Pieter Sietzema, and myself. The very talented UX designer Rinze van der Brug is providing additional support. We are also getting help from members of the community and the MODX integration team.

The Plan
For a complete plan of MODX3, please check the website. It contains a list of prospective features which we will continue to update with any additional ones we come up with as the project progresses. We are reserving budget for extra features, and we will publish examples of these as part of the weekly updates on MODX3.org.

You Can Contribute to MODX3
STERC, MODX LLC, modmore, and a subsidy from the European Union (European Fund for Regional Development) are subsidizing the MODX3 project. The full budget is available here.

However, three companies cannot entirely fund a project of this size on their own. Therefore, we are seeking additional funding from sponsors and donations. These funds will be utilized to finish the project and enable us to implement extra features in MODX3, to make it even better!

Sponsors can submit the sponsor form and will get an invoice from STERC who is acting as a financial intermediary of the project. We are not defining standard packages, but any amount above € 100,- will help. We will provide optional recognition for all sponsors in a future sponsor listing. Sponsors paying over € 2.500,- can also display their logo on the project website.

Recognition on the site is also available now for those wishing to donate to the project immediately. After submitting the donation form, you can select from the following payment methods: PayPal, iDEAL, Bancontact, SOFORT Banking, bank transfer, KBC/CBC Payment Button, ING HomePay, and credit card.

A Meetup and Official MODX3 Launch
The "Kick-off MODX Northern-Netherlands" Meetup on March 7th, 2018 in Leeuwarden, The Netherlands, was a huge success. Forty people were in attendance.

During the event, Gauke Pieter Sietzema unveiled the ongoing work on the new MODX.org community website and officially kicked off the MODX3 Project. Vasily Naumkin presented a live demo of the current state of MODX3. You can view Gauke Pieter's slides covering the MODX3 project here. Slides from Mark Hamstra's introductory talk at the meetup are also available here.

A report covering this event is already available on modx.pro (in Russian). An English report will be available on MODX.today shortly.]]>
https://forums.modx.com/thread/103640/modx3-project-launch#dis-post-557500 Tue, 20 Mar 2018 04:03:11 +0000 https://forums.modx.com/thread/103640/modx3-project-launch#dis-post-557500
<![CDATA[MODX.com Server Maintenance]]> https://forums.modx.com/thread/103110/modx-com-server-maintenance#dis-post-554984 Scheduled Maintenance Downtime Notice

On November 9, 2017 at 0:600 UTC 0 (12AM US Central) (check your timezone), our upstream provider, IBM Cloud, will be performing server maintenance that will affect nearly all services from modx.com including: 
  • MODX.com Website (modx.com)
  • MODX Community Forums (forums.modx.com)
  • Extras (modx.com/extras)
  • Package Management (you will not be able to search or download Extras)

We anticipate this maintenance will require these sites and services to be down for 20 minutes, however, there is always a possibility of it taking as long as an hour. 


If you have any questions or concerns, please send an email to help@modx.com.]]>
https://forums.modx.com/thread/103110/modx-com-server-maintenance#dis-post-554984 Mon, 06 Nov 2017 05:58:06 +0000 https://forums.modx.com/thread/103110/modx-com-server-maintenance#dis-post-554984
<![CDATA[MODXpo 2017 Tickets Now On Sale!]]> https://forums.modx.com/thread/102963/modxpo-2017-tickets-now-on-sale#dis-post-554422 The MODXpo will be held at 210 METROV, where the hugely successful 2015 MODX Meetup was held. This year, the main room will be 200 square metres with separate rooms for workshops!

Day 1: Talks
The first day of MODXpo 2017 will be a full day of talks, presented by MODX community members including Greame Leighfield, Vasily Naumkin, Ivan Klimchuk and Gauke Pieter Sietzema. See the the full schedule. There are still some spots to fill, so please contact the organizers if you’ve got something up your sleeve!

Day 2: Workshops
The second day will be packed with workshops. Munich’s MODXpo workshops were well received. We’re sure these will be a hit in Minsk.

Tickets
The ticket price has been set at 99BYN (see in EUR, USD and GPB). You’ll get two days full of MODX goodness, including food throughout the day, a tour through Minsk and of course a goodie-bag. Also, expect most of the community heading to a bar together after each day to relax and enjoy some local drinks.
Purchase your tickets at https://modxpo.modx.by/!

Getting to Minsk
A lot of Western European and US citizens haven’t visited Belarus yet and might be hesitant to do so. Our MODX-friends from Sterc have traveled the whole continent for MODX Meetups—including Kazakhstan and Belarus.

Sterc’s Gauke Pieter has this to say about their trip to Belarus:

“Traveling to Minsk was as easy as traveling to Munich: flying from Amsterdam with a decent airplane, landing on a really neat airport and traveling to our Minsk city center Hotel was a breeze.
The taxis we used all had WiFi, which was really useful. If you don’t like taxis: there’s a very good subway. The hotel had high standards and beautiful big rooms. The best part: the people from Belarus are very kind and helpful.”

The MODXpo Minsk website will be updated with options for your hotel of choice. If you’re in doubt, just contact us.

See you in Minsk!]]>
https://forums.modx.com/thread/102963/modxpo-2017-tickets-now-on-sale#dis-post-554422 Tue, 10 Oct 2017 02:52:26 +0000 https://forums.modx.com/thread/102963/modxpo-2017-tickets-now-on-sale#dis-post-554422
<![CDATA[MODX Revolution 2.5.8—Bugfixes from the Bughunt]]> https://forums.modx.com/thread/102831/modx-revolution-2-5-8-bugfixes-from-the-bughunt#dis-post-553884 2.5.8 was released today. It contains over 30 fixes—many of which were the fruits of the recent MODX Bug Hunt, held on July, 7th in Munich, Germany with participants from around the world.

Highlights of Revolution 2.5.8
You can find all the changes in the changelog, but we’ve created a list with highlights for you:

  • Fixed multiple annoyances within the media browser
  • Fixed user session token if it is set but value is empty, which will prevent unexpectedly logging out
  • Fixed issue with incorrect signature during installation of two packages with setup options, which prevented some extras from updating
  • Update xPDO to fix issue with validation rules
  • Refresh Element in tree after changing name in element’s panel
  • Refresh the parent (Resource) node when creating the first child

If you haven’t upgraded to MODX Revolution 2.5.x yet, learn more from its original release announcement.

Upgrading Is Critical

Revolution 2.5.2 contained critical security enhancements, and if you are not yet running 2.5.2 or higher, you should upgrade to 2.5.8 now. See below for more info.

We cannot stress the importance of diligently upgrading to the latest version of MODX enough. While no software is 100% secure, powering your site with the most current version usually helps protect you from hackers that rely on exploiting outdated software. If you’re not sure what version of MODX Revolution you’re running, log into your website Manager. If the version number doesn’t appear in the top left-hand corner of the Manager, go to Manage>Reports>System Info.

If you need help upgrading your site, please contact your website builder, find a MODX Professional or get in touch with MODX Support.

Release contributors
A lot of thanks go out to the following contributors: Jesse Visser, Romain Tripault, Johan van der Molen, David Pede, Jermain Buist, Kristian Pars, Ivan Klimchuk, Julian Weaver, Gernot Ebenlechner, Vasily Naumkin, Jens Külzer, Gauke Pieter Sietzema, Thomas Jakobi, Christian Seel, Jason Coward, John Peca, Mike Reid, Sander Drenth, Thomas Gautvedt, Oene Tjeerd de Bruin, Mark Hamstra, Rico P, Ben Davis, lawrenz1337, islandsins, Susan Ottwell, Henk Everts, Lars Bratke, Mathias Dannevang, Marcus Nickel and Rinze van den Brug. You made this release happen!

Get Started with Revo 2.5
Here’s what you need to get started or upgrade to MODX Revolution 2.5:
Ask Not What MODX Can Do For You
MODX is possible because of the many individual community members and users that take the time to report issues, request new features, and submit code to the project. Make sure you read the documentation, post feedback and share your experiences in the MODX community forums.

On behalf of the entire MODX Team, we thank you!]]>
https://forums.modx.com/thread/102831/modx-revolution-2-5-8-bugfixes-from-the-bughunt#dis-post-553884 Wed, 13 Sep 2017 09:17:20 +0000 https://forums.modx.com/thread/102831/modx-revolution-2-5-8-bugfixes-from-the-bughunt#dis-post-553884
<![CDATA[Guiding the Future of MODX and an Overdue Refresh]]> https://forums.modx.com/thread/101169/guiding-the-future-of-modx-and-an-overdue-refresh#dis-post-550827
First, we kicked off the most important thing to come to the MODX Community since its inception with the MODX Advisory Board—a trusted body of MODXers from various backgrounds to help map the future of MODX. We also launched a new MODX.com, too.

We can’t wait to share more, but in the meantime, take a peek behind the curtain and read what we've been working on in the (new) MODX blog.
]]>
https://forums.modx.com/thread/101169/guiding-the-future-of-modx-and-an-overdue-refresh#dis-post-550827 Tue, 16 May 2017 06:27:04 +0000 https://forums.modx.com/thread/101169/guiding-the-future-of-modx-and-an-overdue-refresh#dis-post-550827
<![CDATA[ [Rescheduled] MODX.com Server Upgrades [Downtime]]]> https://forums.modx.com/thread/102130/rescheduled-modx-com-server-upgrades-downtime#dis-post-550404
During this operation, you will not be able to view or download software or Extras for MODX Revolution or Evolution CMS (formerly MODX Evolution). You will not be able to search the website. It is possible that portions of the MODX Forums will be impacted as well.

This maintenance will help provide more seamless operation in the future.

We apologize for any inconvenience this may cause.
]]>
https://forums.modx.com/thread/102130/rescheduled-modx-com-server-upgrades-downtime#dis-post-550404 Mon, 01 May 2017 07:36:23 +0000 https://forums.modx.com/thread/102130/rescheduled-modx-com-server-upgrades-downtime#dis-post-550404
<![CDATA[MODX Revolution 2.5.7—A little more secure]]> https://forums.modx.com/thread/102084/modx-revolution-2-5-7-a-little-more-secure#dis-post-550182
Highlights of 2.5.7
Here are some of the most important changes in 2.5.7:

  • Fix search bar results not clickable in Chrome & Firefox [#13405]
  • Improve transport package downloads to be more reliable and use additional methods to download. [#13419]
  • Make Forgot Password feature more secure [#13408]
  • Proper use of json_encode and error handling for outputArray() in processors [#13389]
  • Closing various low-risk security vectors for file inclusion, cross-site scripting (XSS) and more
For a complete list of changes in Revolution 2.5.7 read the changelog. If you haven’t upgraded to MODX Revolution 2.5.x yet, learn more from its original release announcement.

Upgrading Is Critical
Revolution 2.5.2 contained critical security enhancements, and if you are not yet running 2.5.2 or higher, you should upgrade to 2.5.7 now. See below for more info.
We cannot stress the importance of diligently upgrading to the latest version of MODX enough. While no software is 100% secure, powering your site with the most current version usually helps protect you from hackers that rely on exploiting outdated software. If you’re not sure what version of MODX Revolution you’re running, log into your website Manager. If the version number doesn’t appear in the top left-hand corner of the Manager, go to <em>Manage>Reports>System Info</em>.
If you need help upgrading your site, please contact your website builder, find a MODX Professional or get in touch with MODX Support.

Release Contributors
Let’s take the time to thank the individual contributors to this release: Mark Hamstra, Jason Coward, Thomas Jakobi, Romain Tripault, and Christian Seel.

Security Reporters
We also would like to thank the two security consultants, Anti Räis of Clarified Security and Tomáš Melicher of Citadelo, who reported these issues so that we could make MODX more secure for everyone who uses it.
If you find a security issue with MODX Revolution, please send a detailed report to security@modx.com for review of our security team.

Get Started with Revo 2.5
Here’s what you need to get started or upgrade to MODX Revolution 2.5:
Ask Not What MODX Can Do For You
MODX is possible because of the many individual community members and users that take the time to report issues, request new features, and submit code to the project. Make sure you read the documentation, post feedback and share your experiences in the MODX community forums.
On behalf of the entire MODX Team, we thank you!
]]>
https://forums.modx.com/thread/102084/modx-revolution-2-5-7-a-little-more-secure#dis-post-550182 Fri, 21 Apr 2017 03:45:22 +0000 https://forums.modx.com/thread/102084/modx-revolution-2-5-7-a-little-more-secure#dis-post-550182
<![CDATA[Extras/Downloads Scheduled Server Upgrade [Completed]]]> https://forums.modx.com/thread/102080/extras-downloads-scheduled-server-upgrade-completed#dis-post-550162
During this operation, you will not be able to view or download software or Extras for MODX Revolution or Evolution CMS (formerly MODX Evolution). You will not be able to search the website. It is possible that portions of the MODX Forums will be impacted as well.

This maintenance will help provide more seamless operation in the future.

We apologize for any inconvenience this may cause.]]>
https://forums.modx.com/thread/102080/extras-downloads-scheduled-server-upgrade-completed#dis-post-550162 Thu, 20 Apr 2017 03:46:43 +0000 https://forums.modx.com/thread/102080/extras-downloads-scheduled-server-upgrade-completed#dis-post-550162
<![CDATA[MODX Revolution 2.5.6—Fixes from the MODX Bug Hunt]]> https://forums.modx.com/thread/101963/modx-revolution-2-5-6-fixes-from-the-modx-bug-hunt#dis-post-549742
Highlights of 2.5.6
Here are some of the highlights of 2.5.6:
  • Fix broken images in File tree when media source above doc root [#13292]
  • Added validation for min and max length of text Template Variable (TV) configuration
  • Fix error in Firefox preventing using enter in the uberbar [#12714]
  • Show proper error page when viewing an inaccessible symlink [#12380]
  • Show proper error message when trying to rename a file/folder that already exists [#13256]
  • Hide database username, password, and database name from advanced setup [#13090]

For a complete list of changes in Revolution 2.5.6 read the changelog. If you haven’t upgraded to MODX Revolution 2.5.x yet, learn more from its original release announcement.

MODX Bug Hunt
On March 3, 2017, Dutch digital agency, Sterc, hosted the first MODX Bug Hunt. Dozens of MODX community members reviewed, fixed or closed over 140 issues in the MODX bug tracker at GitHub. You can see more details about the MODX Bug Hunt at the website including the reviewer/fixer leaderboard, with top prize taken by Peter Bowyer. Thanks so much to the team who put together the bug hunt.

The second MODX Bug Hunt has been scheduled for July 7, 2017. Join in on the action or support with your presence for the live show.

Upgrading Is Critical
Revolution 2.5.2 contained critical security enhancements and if you are not yet running 2.5.2 or higher you should upgrade to 2.5.6 now. See below for more info.
We cannot stress the importance of diligently upgrading to the latest version of MODX enough. While no software is 100% secure, powering your site with the most current version usually helps protect you from hackers that rely on exploiting outdated software. If you’re not sure what version of MODX Revolution you’re running, log into your website Manager. If it is not shown at the top left-hand corner of the Manager, go to Manage>Reports>System Info.

If you need help upgrading your site, please contact your website builder, find a MODX Professional or get in touch with MODX Support.

Release Contributors
Let’s take the time to thank the individual contributors to this release: Mark Hamstra, Jan Peca, Jason Coward, Thomas Jakobi, Romain Tripault, Lukas Zahnd, Mat Dave Jones, Peter Bowyer, OptimusCrime, Christian Seel, Mike Schell, Lars Bratke, Mike Reid, Mikhail Dyachuk, Oetzie, Fabian Christen, Володя, Hugo Peek, Ivan Klimchuk, Jesse Visser, Joeke Kloosterman, Sebastian G. Marinescu, Sergey Shlokov, Sytske Haagsma, Vasily Krakovetsky, sander, Romain, goldsky, Pien van Dalen, Simon Champion, Johan van der Molen, and Bob Ray.

Get Started with Revo 2.5
Here’s what you need to get started or upgrade to MODX Revolution 2.5:
Ask Not What MODX Can Do For You
MODX is possible because of the many individual community members and users that take the time to report issues, request new features, and submit code to the project. Make sure you read the documentation, post feedback and share your experiences in the MODX community forums.

On behalf of the entire MODX Team, we thank you!]]>
https://forums.modx.com/thread/101963/modx-revolution-2-5-6-fixes-from-the-modx-bug-hunt#dis-post-549742 Tue, 28 Mar 2017 08:54:24 +0000 https://forums.modx.com/thread/101963/modx-revolution-2-5-6-fixes-from-the-modx-bug-hunt#dis-post-549742
<![CDATA[MODX Revolution 2.5.5—Improved logging for URL errors and more]]> https://forums.modx.com/thread/101782/modx-revolution-2-5-5-improved-logging-for-url-errors-and-more#dis-post-548937
Highlights of 2.5.5
Here are some of the highlights of 2.5.5:

  • Fix the way bad links are logged in the error log to provide useful information to resolve
  • Address a few potential security issues in the setup (installer)
  • Add checks to validate file extension when renaming/creating files using file browser
  • Extras repository (Download Extras) now uses HTTPS (SSL) URL
  • Site name now appears on the title of the Manager Login page
  • Fix File Unzip feature

For a complete list of changes in Revolution 2.5.5 read the changelog. If you haven’t upgraded to MODX Revolution 2.5.x yet, learn more from its original release announcement.


Upgrading Is Critical
Revolution 2.5.2 contained critical security enhancements and if you are not yet running 2.5.2 or higher you should upgrade to 2.5.5 now. See below for more info.

We cannot stress the importance of diligently upgrading to the latest version of MODX enough. While no software is 100% secure, powering your site with the most current version usually helps protect you from hackers that rely on exploiting outdated software. If you're not sure what version of MODX Revolution you're running, login to your website Manager. If it is not shown at the top left hand corner of the Manager, go to Manage>Reports>System Info.


If you need help upgrading your site, please contact your website builder, find a MODX Professional or get in touch with MODX Support.


Release Contributors
Let’s take the time to thank the individual contributors to this release: Jan Peca, Thomas Jakobi, Romain Tripault, Jason Coward, Sergey Shlokov, Lukas Zahnd, Mat Dave Jones, Mark Hamstra, OptimusCrime, Володя, Fabian Christen, Sebastian G. Marinescu, Vasily Krakovetsky, twet2f999, xf0, Romain, Bruno17, goldsky, JP de Vries, lexsmil, Mike Reid, and Simon Champion.


Get Started with Revo 2.5
Here’s what you need to get started or upgrade to MODX Revolution 2.5:


Ask Not What MODX Can Do For You
MODX is possible because of the many individual community members and users that take the time to report issues, request new features, and submit code to the project. Make sure you read the documentation, post feedback and share your experiences in the MODX community forums.

On behalf of the entire MODX Team, we thank you!
]]>
https://forums.modx.com/thread/101782/modx-revolution-2-5-5-improved-logging-for-url-errors-and-more#dis-post-548937 Fri, 24 Feb 2017 08:14:03 +0000 https://forums.modx.com/thread/101782/modx-revolution-2-5-5-improved-logging-for-url-errors-and-more#dis-post-548937
<![CDATA[MODX Evolution 1.2.1 - Security and Bugfix Release]]> https://forums.modx.com/thread/101609/modx-evolution-1-2-1---security-and-bugfix-release#dis-post-548072
Thanks go out to the community developers for getting this out so soon

You can currently download this latest release only from GitHub, the LLC may update the MODx website shortly with the new version, but until then, GitHub is your friend.

Please read the release notes that are shown on the release page - they can have an effect your installation]]>
https://forums.modx.com/thread/101609/modx-evolution-1-2-1---security-and-bugfix-release#dis-post-548072 Fri, 13 Jan 2017 10:58:41 +0000 https://forums.modx.com/thread/101609/modx-evolution-1-2-1---security-and-bugfix-release#dis-post-548072
<![CDATA[MODX Revolution 2.5.4 —PHP Mailer Security Update and More]]> https://forums.modx.com/thread/101547/modx-revolution-2-5-4-php-mailer-security-update-and-more#dis-post-547756
Highlights of 2.5.4
Here are some of the highlights of 2.5.4:
  • Update PHP Mailer library for security fixes
  • Fixed Resources not loading on sqlsrv environments
  • Fixes to Extras package listings in the Installer
  • Update Font Awesome to 4.7.0
  • Improved Accessibily/UX of Manager login screen by removing placeholders

For a complete list of changes in Revolution 2.5.4 read the changelog. If you haven’t upgraded to MODX Revolution 2.5.x yet, learn more from its original release announcement.

Upgrading Is Critical
[strong]Revolution 2.5.2 contained critical security enhancements and if you are not yet running 2.5.2 or higher you should upgrade to 2.5.4 now. See below for more info.[/strong]

We cannot stress the importance of diligently upgrading to the latest version of MODX enough. While no software is 100% secure, powering your site with the most current version usually helps protect you from hackers that rely on exploiting outdated software. If you’re not sure what version of MODX Revolution you’re running, log in to your website Manager. If it is not shown at the top left hand corner of the Manager, go to Manage>Reports>System Info.

If you need help upgrading your site, please contact your website builder, find a MODX Professional or get in touch with MODX Support.

Release Contributors
Let’s take the time to thank the individual contributors to this release: Jason Coward, Thomas Jakobi, Mark Hamstra, Romain Tripault, Jan Peca, Sergey Shlokov, Mike Reid, fn3k4, Mat Dave Jones, Serge, Vasily Naumkin, and JP DeVries.

Get Started with Revo 2.5
Here’s what you need to get started or upgrade to MODX Revolution 2.5:
Ask Not What MODX Can Do For You
MODX is possible because of the many individual community members and users that take the time to report issues, request new features, and submit code to the project. Make sure you read the documentation, post feedback and share your experiences in the MODX community forums.

On behalf of the entire MODX Team, we thank you!]]>
https://forums.modx.com/thread/101547/modx-revolution-2-5-4-php-mailer-security-update-and-more#dis-post-547756 Tue, 03 Jan 2017 09:56:46 +0000 https://forums.modx.com/thread/101547/modx-revolution-2-5-4-php-mailer-security-update-and-more#dis-post-547756
<![CDATA[MODX Evolution 1.2—Security Fixes and Hundreds of Improvements and Updates]]> https://forums.modx.com/thread/101384/modx-evolution-1-2-security-fixes-and-hundreds-of-improvements-and-updates#dis-post-546998
This is release includes critical security enhancements and should be considered a mandatory upgrade.

Highlights Evo 1.2
Here are some highlights of MODX Evolution 1.2:

  • Corrected issue allowing Evolution sites to be compromised using several Extras
  • Updated TinyMCE in the Manager to 4.0 which includes new themes and more
  • New default Manager theme called MODxRE2
  • Changes to the Resource Tree, providing quick access to Elements, Files and etc.
  • New start page on new installs based on Bootstrap 3
  • New Output Modifiers in the core, including conditionals
  • New Manager User roles for better, more granular access for site administrators
  • Language overrides in the Manager
  • Upgrade jQuery in Manager
  • For a list of all of the changes in Evolution 1.2 read the changelog


Upgrading Is Critical
We cannot stress the importance of diligently upgrading to the latest version of MODX enough. While no software is 100% secure, powering your site with the most current version usually helps protect you from hackers that rely on exploiting outdated software. If you’re not sure what version of MODX Evolution you’re running, login to your website Manager and it should be in the upper right hand corner—possibly left, if extremely old.

If you need help upgrading your site, please contact your website builder, find a MODX Professional or get in touch with MODX Support.

MODX Evolution 1.2 was developed, managed and released by the dedicated team of community members, shown in order by number of contributions.

  • Mananori Yamamoto (yama)
  • Dennis Helfensteller (Deesen)
  • Nicola Lambathakis (Nicola1971)
  • Dmytro Lukianenko (Dmi3yy)
  • Piotr Matysiak (pmfx)
  • Sergey Davydov (MrSwed)
  • (bossloper)
  • fourroses666, Fr3ddy7, mcparana, amaksymiuk, vhollo, poh-am, ricardo-lewis, typhoon2099,
  • esszett, Jako


The MODX Evolution team would like to send a special thanks to all translators and testers!

Download Evo 1.2:
You can download the latest version of MODX Evo from the following sources:

Install, Upgrade and More Links
For those users who are interested in using Evo, but are unsure where to begin:

For more details about the MODX Evolution 1.2 release, please read the complete announcement.]]>
https://forums.modx.com/thread/101384/modx-evolution-1-2-security-fixes-and-hundreds-of-improvements-and-updates#dis-post-546998 Tue, 06 Dec 2016 10:02:36 +0000 https://forums.modx.com/thread/101384/modx-evolution-1-2-security-fixes-and-hundreds-of-improvements-and-updates#dis-post-546998
<![CDATA[MODX Revolution 2.5.2—Important Security Fixes and More]]> https://forums.modx.com/thread/101242/modx-revolution-2-5-2-important-security-fixes-and-more#dis-post-546371
This is release includes critical security enhancements and should be considered a mandatory upgrade.

Highlights of 2.5.2
Here are some of the highlights of 2.5.2:
  • Security—MODX has high standards for security and this release predominantly focuses on the areas that were found and fixed by the contributors listed below
  • Bugfixes—several small bugs were fixed in this release, creating a better experience for MODX users
  • Updates—phpThumb was updated to the latest version, and support for newer versions of MySQL improved to ensure MODX Revolution is compatible with current releases of other software used alongside MODX

For a complete list of changes in Revolution 2.5.2 read the changelog. If you haven’t upgraded to MODX Revolution 2.5.x yet, learn more from its original release announcement.

Upgrading Is Critical
We cannot stress the importance of diligently upgrading to the latest version of MODX enough. While no software is 100% secure, powering your site with the most current version usually helps protect you from hackers that rely on exploiting outdated software. If you’re not sure what version of MODX Revolution you’re running, login to your website Manager. If it is not shown at the top left hand corner of the Manager, go to Manage>Reports>System Info.

If you need help upgrading your site, please contact your website builder, find a MODX Professional or get in touch with MODX Support.

Special Thanks
We would like to especially thank the following community members who helped identify and resolve these important security issues. They have helped make MODX Revolution more secure:
Please let them know you appreciate their efforts.

Release Contributors
Let’s take the time to thank the individual contributors to this release (in alphabetical order by GitHub username): Alexander Herling, Andrey, Anton Pastukhoff, appchecker, argnist, Bruno17, Christian Seel, Elizabeth, Fabian Christen, Gildas NOEL, goldsky, ilyautkin, inreti, Ivan Klimchuk, Jan Peca, Jan Tezner, Jan-Christoph Ihrens, Jason Coward, Jay Gilmore, Jens Külzer, Johan van der Molen, JP DeVries, Kirill, Lars Bratke, lefthandmedia, Liam Kerr, Lukas Zahnd, Maarten Wolzak, Mark Hamstra, Mat Dave Jones, Mike Reid, Nikolay Lanets, Oleg, oori, OptimusCrime, Realetive, Romain, Ronald Exterkate, sepiariver, Sergey Shlokov, Susan Ottwell, Thomas Jakobi, Treigh, Vague Rabbit, Vasily Naumkin, ViieeS, Whitebyte, Zaigham Rana, володя, and Илья Уткин.

Get Started with Revo 2.5
Here’s what you need to get started or upgrade to MODX Revolution 2.5:
Ask Not What MODX Can Do For You
MODX is possible because of the many individual community members and users that take the time to report issues, request new features, and submit code to the project. Make sure you read the documentation, post feedback and share your experiences in the MODX community forums.

On behalf of the entire MODX Team, We thank you!]]>
https://forums.modx.com/thread/101242/modx-revolution-2-5-2-important-security-fixes-and-more#dis-post-546371 Mon, 14 Nov 2016 10:48:31 +0000 https://forums.modx.com/thread/101242/modx-revolution-2-5-2-important-security-fixes-and-more#dis-post-546371
<![CDATA[MODX Revolution 2.5.1—S3 Media Source Fixes and much More]]> https://forums.modx.com/thread/100576/modx-revolution-2-5-1-s3-media-source-fixes-and-much-more#dis-post-543466 Revo 2.5 announcement.

Highlights from the changelog:
  • Fix problem with S3 bucket names containing dot characters
  • Correctly display image preview in file tree for S3 media sources.
  • Use sans-serif font for TV textareas
  • Ensure Uberbar search results respect ACLs (user permissions/access)
  • Add missing viewport meta tag needed to correctly enable responsive MODX Manager and Manager login screen
  • E-Mail validation now supports domain extentions (gTLDs) with more than 6 characters
  • Two security fixes to prevent reflected XSS and closing SQL injection.


Important Note for TinyMCE Users

We have found an issue with the widely used TinyMCE Extra (the word processor-like toolbar for MODX Resources) where you cannot load Resources after Upgrading. TinyMCE by splittingred is no longer actively maintained and we recommend choosing one of the other TinyMCE Extras for 2.5.1+. There is a one-line patch available if you want to continue using TinyMCE.

Important
Nearly all releases contain vital security patches. If you are using a version lower than 2.3.6 you should consider an upgrade to 2.5.1 mandatory.

Security is an Ongoing Process
We cannot stress how important it is to run the most current version of MODX. We are always improving security. Upgrade regularly to reduce the chance of your site getting hacked. If you need help upgrading your MODX site, let us know.

Release Contributors
Let’s take the time to thank the individual contributors to this release (in alphabetical order by GitHub username): achterbahn, AppChecker, Bruno17, christianseel, enigmatic, ilyautkin, Jako, labr1005, lefthandmedia, MaartenW, Mark, matdave, opengeek, OptimusCrime, pixelchutes, Realetive, Ronald, sergant210, sottwell, theboxer, thewhiterabbit, and vgrish, along with many other contributors who log & triage issues, review PRs, and commit code. The MODX Community is amazing.

Get Started with Revo 2.5
Here’s what you need to get started or upgrade to MODX Revolution 2.5:

Ask Not What MODX Can Do For You
MODX is only as good as it is because of the many individual community members and users that take the time to report issues, request new features, and submit code to the project. Make sure you read the documentation,post feedback and share your experiences in the MODX community forums.

On behalf of the entire MODX Team,
We thank you!
]]>
https://forums.modx.com/thread/100576/modx-revolution-2-5-1-s3-media-source-fixes-and-much-more#dis-post-543466 Thu, 21 Jul 2016 11:03:18 +0000 https://forums.modx.com/thread/100576/modx-revolution-2-5-1-s3-media-source-fixes-and-much-more#dis-post-543466
<![CDATA[MODX Revolution 2.5—PHP 7, Performance and More]]> https://forums.modx.com/thread/100001/modx-revolution-2-5-php-7-performance-and-more#dis-post-540768
Highlights of Revolution 2.5
MODX Revolution 2.5 continues the tradition of enhancing functionality and performance for MODX Revolution, augmenting security, and fixing a variety of bugs. The excellent new features include the following areas:

Preparing for the Future
MODX CMS has alway been forward thinking. We adopted PDO for database access years before others even considered it, and you could power HTML5/CSS3 mobile responsive sites with our first release in 2005, even though those technologies didn’t exist at the time. We continue this tradition with a few things that are here today, and that will be huge soon:

  • PHP 7 compatibility (it’s coming soon to a server near you). PHP 7 performs significantly faster than any previous release before it so your sites should be able to handle more visitors and serve them more quickly, keeping them engaged and returning for more.
  • Accessibility improvements worked into the core Manager experience including screen reader and keyboard navigation on the Login screen. The work that is going on for the Accessible Manager theme that takes this much further, works in MODX Revolution 2.5, too.

Improved UX

Our quest to improve end-user and developer experiences will never be over. To that point, the following areas received attention for 2.5:

  • New default content for new installs provides helpful resources and information. Instead of the empty blank page in all previous versions of MODX Revolution, you now get a nice intro page with some important links to assist and orient new users.
  • Much more mobile-friendly Manager. As a stepping stone towards a new Manager in the future, this allows you to make edits and access the Manager much more easily than was possible before thanks to the intense efforts of JP Devries.
  • Add ability to unpack zip files in the file tree / media manager

Developer Sugar
Sometimes you need to create custom functionality that available MODX Extras do not address. Often this involves creating a Custom Manager Pages and interfaces inside a Component.

Previously, this required a dive into the “exciting” world of ExtJS, with which most people have a loathe-hate relationship. Now, views for applications you build into the MODX Manager are much easier to create using plain old HTML/CSS and MODX Tags. A special thanks goes to Romain Tripault and Susan Ottwell for this example of the new Custom Manager Pages in 2.5.

Faster Performance
Google loves fast sites, as do your visitors. MODX has always been performant when serving cached pages, now it’s even more so:

  • Parser optimizations which improve pre-caching performance. This means visitors will be served more quickly, and Google will give your site a little more respect, which it clearly deserves.
  • The new anonymous_sessions setting (enabled by default) can significantly speed up the performance for sites that don’t need to have PHP sessions or logged in users. When this setting is disabled, and a page is fully cached, having sessionless anonymous visitors eliminates the need for a database connection for that visitor on each request. If your site serves even moderate traffic, this can significantly reduce the amount of processor required to operate.

Changes in MODX Revolution 2.5
Previously created sites, currently on Revolution 2.3 or above, should work when upgrading to 2.5, but we do suggest testing on an clone of your site, first. Earlier versions may take a bit of extra effort and code updates if they use non-public APIs or directly access the database.

Release Contributors
Let’s take the time to thank the individual contributors to this release (in no particular order):John Peca, Jason Coward, Thomas Jakobi, Ronald Exterkate, Mike Reid, inreti, Zaigham Rana, Jan Tezner, Elizabeth, Romain, argnist, Anton Pastukhoff, Илья Уткин, Gildas NOEL, Ivan Klimchuk, JP DeVries, Kirill, Mark Hamstra, Mat Dave Jones, Nikolay Lanets, Sergey Shlokov, and Vasily Naumkin, along with many other contributors who log & triage issues, review PRs, and commit code. The MODX Community is Amazing.

Get Started with Revolution 2.5
Here’s what you need to get started or upgrade to MODX Revolution 2.5:

It Takes a Global Village
MODX is only as good as it is because of the many individual community members and users, from around the world, who take the time to report issues, request new features, and submit code to the project. Make sure you read the documentation,post feedback and share your experiences in the MODX community forums.

On behalf of the entire MODX Team,

We thank you!]]>
https://forums.modx.com/thread/100001/modx-revolution-2-5-php-7-performance-and-more#dis-post-540768 Thu, 21 Apr 2016 11:48:37 +0000 https://forums.modx.com/thread/100001/modx-revolution-2-5-php-7-performance-and-more#dis-post-540768
<![CDATA[MODX Revolution 2.5-RC2 Out Now, Help us Ready it for Release]]> https://forums.modx.com/thread/99896/modx-revolution-2-5-rc2-out-now-help-us-ready-it-for-release#dis-post-540237
What's New in Revolution 2.5
This new release of MODX Revolution includes a number of excellent new features including:

  • PHP7 compatibility (it's coming soon to a server near you)
  • Much more mobile-friendly Manager as a stepping stone towards a new manager in the future.
  • Custom Manager Pages (the views for applications built into MODX) are now much easier to build using HTML and MODX Tags. Thanks to Romain Tripault and Susan Ottwell for this example of the new Custom Manager Pages in 2.5.
  • Accessibility improvements worked into the core Manager experience including screen reader and keyboard navigation on the Login screen.
  • Significant improvement to the parser which could potentially improve pre-caching performance by 15%;
  • New installs get a new look. Instead of the empty blank page in previous versions you now get a nice intro page with some important links so new users can more easily get started.


Contributors on this Release
Let’s take the time to thank the individual contributors to this release (in no particular order):Jan Peca, Jason Coward, Thomas Jakobi, Ronald Exterkate, Mike Reid, inreti, Zaigham Rana, Jan Tezner, Elizabeth, Romain, argnist, Anton Pastukhoff, Илья Уткин, Gildas NOEL, Ivan Klimchuk, JP DeVries, Kirill, Mark Hamstra, Mat Dave Jones, Nikolay Lanets, Sergey Shlokov, and Vasily Naumkin, along with many other contributors who log & triage issues, review PRs, and commit code. The MODX Community is Amazing.

Ready, Set, Test Revo 2.5
In order for a successful release of 2.5 we need people to test these release candidates on their projects, of course, do keep in mind there will be bugs—that's what we're looking to find. Here’s what you need to get started or upgrade to MODX Revolution 2.5-RC2:

It Takes a Global Village
MODX is only as good as it is because of the many individual community members and users, from around the world, who take the time to report issues, request new features, and submit code to the project. Make sure you read the documentation,post feedback and share your experiences in the MODX community forums.

On behalf of the entire MODX Team,
We thank you!]]>
https://forums.modx.com/thread/99896/modx-revolution-2-5-rc2-out-now-help-us-ready-it-for-release#dis-post-540237 Thu, 07 Apr 2016 12:23:03 +0000 https://forums.modx.com/thread/99896/modx-revolution-2-5-rc2-out-now-help-us-ready-it-for-release#dis-post-540237