Dougal Campbell
Forum Replies Created
-
Forum: Plugins
In reply to: [Plugin: OpenID] Itermittent redirect failureOkay, I’ve just manually patched my copy of CFII to use ‘admin_menu’. I think a lot of people get bitten by that (I know I have, before).
I don’t think I got around to saying thanks for that feature. It’s working great now. So, thanks! π
Forum: Plugins
In reply to: No Scroll for Me With WriteScrollDo you have other plugins installed, especially ones that interact with the editor pages?
What version of WordPress?
I just posted a description of a fix for 2.5RC2 in the Google Code issue tracker.
Forum: Plugins
In reply to: Better Shopping Cart?I’m interested in available alternatives, as well.
There’s Zen Cart, and a third-party WordPress integration.
And there’s an old WordPress Paypal Plugin, but that one is pretty simple, and apparently isn’t maintained anymore.
Then there’s osCommerce, which is a full-featured stand-alone system that supports several payment gateways. I haven’t had a chance to research it much yet, but a search turns up some possible WordPress integration implementations.
Forum: Fixing WordPress
In reply to: wp-comments-post.php corrupted??I think this might be a problem at a lower level than WordPress. Is there any way that your .htaccess file could have changed? Or did your web host maybe change something in their Apache configuration?
If your .htaccess file has rules outside of the WordPress area, post it here for us to check. If not, maybe ask your web host if they upgraded/changed any Apache modules recently. I’ve seen mod_security go haywire if you don’t pay close attention to the rules, for example.
I tried POSTing a search request to your server, and got back a 500 Internal Server Error. That’s not normal.
I suppose you could try upgrading to the Release Candidate for WP 2.3.1, but I don’t expect it to fix this problem, really.
Forum: Fixing WordPress
In reply to: high traffic crashing usmagazine.comWell, I guess it’s too late now, but you *did* verify that WP-Cache was creating cache files and serving them up, right?
Forum: Requests and Feedback
In reply to: WP 2.0.2 Update Coming?There is already a 2.0.2 in the works. You can track it in SVN under ‘/branches/2.0’. I know that the comment form XSS bug is already taken care of, and I’m sure that the other issues mentioned will be taken into consideration.
That said… The XSS bug is hard to exploit, because you pretty much have to target a particular individual.
Directory listings are the result of server settings that go beyond WordPress. Yes, we can get rid of it by adding an empty index.php file, but it’s misleading to call this a bug in WP.
Disallowing direct access to some of the files may be a good idea, as noted.
Forum: Fixing WordPress
In reply to: Hacked by SQL injection?!Hmmm… You know, after further investigation, this might not have been the entry point after all.
I didn’t bother to trace down exactly where it happens, but after including wp-blog-header.php, the $_SERVER[‘QUERY_STRING’] variable is escaped. So the value of the $url variable should be safe before it’s used in the db query.
So alvanweb’s security problem is probably still there. :-/
Forum: Fixing WordPress
In reply to: Hacked by SQL injection?!Hrm. It appears that somebody could make a malformed link in a comment that could allow SQL injection via the Click Counter plugin…
It appears that the go.php script passes the $url variable to the wp_ozh_click_increment() function, which in turn uses it in a SQL query without doing any validation.
Forum: Fixing WordPress
In reply to: Hacked by SQL injection?!What plugins do you have running on your site?
Forum: Fixing WordPress
In reply to: Change domain AND permalinks in one redirect?Google will recognize a 301 Permanent Redirect, and should (eventually) adjust pagerank of the destination site accordingly.
As far as what approach to use, it probably depends on how flexible you need to be. If you can easily map the old URLs to the new ones with a regex, then putting the rules in .htaccess should be just fine. If there are funky exceptions to some of the rules that require a little more logic, then handle it in your index.php or maybe in a custom 404 handler.
Personally, I’d probably do it in a 404 handler (make sure that you set the HTTP 301 redirect headers in your code!), unless you have overlapping URIs that need to exist on both sites. You can see how I handled this on my site. (ignore my brutish methods of parsing the request URI — I don’t know why I didn’t use PHP’s parse_url() and parse_string() functions.)
Forum: Fixing WordPress
In reply to: Custom Page/Post TypesThe majority of users don’t need this type of functionality to be ever-present. So, it’s best done as a plugin.
As skeltoac said, there are already hooks available for such a framework to be added as a plugin. This wouldn’t be the first case of a plugin which added capabilities meant to be used by other plugins π
I don’t think that there would be too many cases where adding a whole new table would be necessary, unless the “key/value” capabilities added by the standard custom fields couldn’t be extended easily for a particular case.
Forum: Fixing WordPress
In reply to: NEW: Upgrade to 1.5.2ionic: the faulty archive was only up for a very short time window.
The problem was corrected and a new archive put in place before the announcement of the new version went public.
Forum: Requests and Feedback
In reply to: Bug in wp-rss*.php, handling GMT offsetCan you be more specific about what the real problem is?
We’re sending out a timestamp in GMT rather than in local time, but as far as I can tell, we’re sending out the *correct* timetamp… Is that not the case?