Version 3.4.7.2 Stable Security Release Now Available E-mail
Written by Administrator   
Wednesday, 02 November 2011 00:00

W

We recently released JCK Editor 3.4.7.2 with many improvements and some cool new features such as: new relationship attribute, color picker, improved speed & reliability and a important security fix!. Please see changelogs for more infomation.

 

 

 

 

Relationship attribute

Added a new extension value for the rel="" attribute in HTML. The ‘rel’ attribute specifies the relationship between the current document and the linked document in HTML. Please see: http://www.w3schools.com/html5/att_a_rel.asp for more information on how this works.

Color picker

We added a new color picker to the editor parameters. Like a chameleon, the colour of skin and background can be defined in the editor’s parameters, so you can precisely match its colour to your needs.

Improved speed & performance

We have rewritten the editors authentication system to use only specific libraries instead of loading up the entire application. This works to streamline authentication and improves the speed and performance of the editor on load. We have also gone even further and performance enhanced the loading of subsequent instances of the editor.

 

Improved reliability

  • Remove the reliance on Joomla's caching system in the authentication process. This now works to circumvent some file permission issues, which may result in authentication failures.
  • Remove its reliance on the window onload-event. This was problematic and caused a race condition which could have prevented the subsequent instances of the editor loading up;
  • Remove the reliance of mootool to load up the subsequent instance of the editor.

security fix

There is a security vulnerability which affected all versions between 3.4.6 to 3.4.7 beta2. This allowed users to journey into the file browser without the correct checks being in place. In 3.4.7 we reinstated these check's and rewritten the editor’s authentication system to use only specific libraries instead of loading up the entire application. It is highly recommended that users upgrade immediately!

3.4.7.2 Fixes

  1.  JTreeLlink wasn’t  working in multiple instances
  2. Button wasn’t loading up correctly on the 2nd and 3rd instance of itself. This affected the editor in 3rd party components requiring it to be loading up multiple times on a page.

3.4.7.1 Fixes

  1. Fix: address an issue with the editor’s new authentication system which caused the “file browser is disabled for security reasons” alert to be thrown when the Joomla system was managing international languages.
  2. Fix: address an issue with decoding encrypted session data.

3.4.7 stable Fixes & Security

  1.  jTree Link fix - certain html entries were causing jTree the plugin to fall over. The fix was to improve upon the comprehensive HTML filters list.
  2. Category id was not being passed correctly into article belonging to a blog category. This affected Joomla 1.6 & 1.7 users when the SEF was enabled
  3. Improved the jTree links ability to update existing links
  4. Fixed the collapsing of the editing area when using the Code Mirror plug-in with IE
  5. Fixed a bug with resizing the editor editing area with Code Mirror plug-in
  6. Google Chrome – fixed a editor resize bug
  7. The authentication plug-in was not authenticating users correctly allowing unauthenticated uses to browse the file manager. It is highly recommended that users immediately upgrade!
  8. The default Spell checker and SCAYT plug-in was referring to a legacy service on spellchecker.net. This service has become compromised which caused Google Chrome the throw a browser error, whenever the spell check service was requested.  The fix was to update the service to use webspellchecker.net
  9. Fixed an issue which logged out some users after loading the editor up a numerous amount of times.

Upgrading from an existing version

 The upgrade package will allow you to preserve your custom toolbars and plug-ins. This can be applied quickly via Joomla’s extensions manager.  Please see: Installing and Upgrading...

 

 

Share this post