ExpressionEngine 2.10.01 has been released as a security and stability release, along with Discussion Forum 3.1.19. These upgrades are recommended for all installations. Some of the security enhancements include:
- File uploads are now validated against a whitelist of acceptable MIME types.
- Added a config override to blacklist certain filenames from being uploaded.
- Added hidden file upload prevention.
.htaccessto images directory to prevent execution of PHP files.
If you’re within a drive or short flight to Minneapolis, and don’t have plans for April 13–14, you should really check this conference out. With three tracks and topics on design, front-end development, content strategy, and work, there is something for everyone. Register today!
ExpressionEngine 2.9.3 has been released and is a stability release with 11 minor improvements, 44 bug fixes, 3 developer enchancements, and is recommended for all installations. This release mostly cleans up some small annoyances, but has a few relevant changes that will improve your site and how you work. For example:
- Fixed a bug (#20621) where fieldtype modifiers were not working in conditionals unless they were braced and quoted.
This change means that you should be able to stop using
When I heard of Microsoft’s supposed plans to rebrand their browser as Spartan in Windows 10, killing the tainted Explorer brand, I couldn’t help but dredge up this eulogy that Leslie Camacho and I made almost eight years ago. Also, wow, what a difference eight years makes in the quality of internet video. If you focus on the poor quality of the video, you hardly even notice how corny we are.
Originally posted by Leslie Camacho in 2007:
Please don’t take this video post for anything
We are giving away a ticket to this year’s MinneWebCon in Minneapolis, Minnesota on April 13–14. MinneWebCon focuses on grassroots knowledge-sharing. If that doesn’t sound like the ExpressionEngine community, I don’t know what does! MinneWebCon attracts many people who work in public and non-profit sectors, but has something for everybody. It was a no brainer for us to sponsor.
To enter, tweet why you love ExpressionEngine, following the official rules:
- Tweet a brief reason why you love
Calling all ExpressionEngine users in the UK (and within a short trip by boat/plane/car), there are two opportunities in March to meet and chat with our very own software engineer Kevin Cupp. He’s coming to London and Rye, England, and will be available at the following events:
The LondonEErs meeting has no topic set other than Kevin lending his ear, and he’s eager to speak to you. The ExpressionEngine Dev Day is focusing on Varnish
We’re going to show how you and your clients can save thousands of dollars a year by paying more for hosting. No typo.
While helping our customers, we log in to many sites. Sometimes, the control panel is slow. To see why it’s taking so long, my first stop used to be Extensions. Now it’s a quick trip to whoishostingthis.com.
Normally, the ExpressionEngine control panel is fast. Zippy even. There aren’t many pages in the control panel that should have an execution time of more than a second.
Are you a WordPress, Joomla, Textpattern, or Drupal user in the Albuequerque area who has been curious about ExpressionEngine? Or just new to ExpressionEngine and want to see what it’s capable of? Mark March 4, 2015 on your calendar and head to the ABQ Web Geeks presentation, “ExpressionEngine—A Practical Introduction.”
Seven year ExpressionEngine expert Caroline C. Blaker of Petroglyph Creative will give a live tour of ExpressionEngine and its ecosystem. She will not only explain what you
You can now download the previous version of your purchased software on your Manage Purchases page. In the case of ExpressionEngine, this means you can download the most mature version of one minor release back. This can be handy if you have bespoke add-ons that have not yet been tested on the latest version. For Multiple Site Manager and the Discussion Forums, it will also list which version of ExpressionEngine it is compatible with, which may include older versions of ExpressionEngine as
- Only Active licenses are shown by default. Inactive licenses (transfers and licenses that have since been upgraded) can be added in with the “Show Inactive” link, or shown exclusively with the “Only Inactive” link. This should help developers who purchase licenses and then transfer to their clients upon project delivery.
- Registration pings have been consolidated for secondary domains, and the alert message when a license is seen to be in use in multiple locations has been modified to be more informative.
- If you saw last week’s article when it was first posted, you may also have missed a feature we added later in the day: when you click on a license number, the whole license number is selected for you to make copy and paste a snap.
We have more updates in store for the future, but hope you find these changes handy.