Kunena
  • Home
  • Bugs
      • Back
      • Changelog
      • Bugs
  • Download
      • Back
      • Templates
      • Plugins
      • Subscription page
  • Forum
  • Documentation
  • Blog
  • User
      • Back
      • Login
Github BlueSky

Kunena 3.0.6 Released

Details
Published: 28 July 2014

Introduction

ATTENTION! This release contains an XSS and SQL Injection Vulnerability fix. All previous versions of kunena are affected. Please update immediately.

Kunena 3.0.6 [K 3.0.6] is available for download as a native Joomla extension for J! 2.5 and J! 3.x. This version is a security release for Kunena that addresses several maintenance issues that have been reported since the last version release. and this new version replaces (and makes obsolete) all previous versions of Kunena.

This version of Kunena coincides with the simultaneous release of an updated language pack, downloaded separately, for deployment on non-English websites. The release of this version does not not coincide with the release of other Kunena Add-ons that have not been updated at this time and that may or may not be updated for this version.

In general, Kunena Add-ons designed for previous versions of K 3.x should interoperate with this version of Kunena; in general, Kunena Add-ons designed for older major versions of Kunena will not interoperate with this version of Kunena.

The summary of important changes in K 3.0.6 are:

  • XSS vulnerability (credit goes to Raymond Rizk from Dionach Ltd., thank you for the report, much appreciated.
  • SQL Injection vulnerability (credit goes to Raymond Rizk from Dionach Ltd., thank you for the report, much appreciated.

Read more: Kunena 3.0.6 Released

Discuss this article

Log in to comment

Posts in discussion: Kunena 3.0.6 Released
suamaytinhits replied the topic:
#
11 years 2 months ago
suamaytinhits's Avatar
Thanks Coder4life and Kunena Team.

Upgraded from 3.0.5 to 3.0.6 / Joomla 3.3.3 without a hiccup.
sozzled replied the topic:
#
11 years 4 months ago
sozzled's Avatar

lifeguard wrote: It was a plugin ... JCH optimize

Yes, we have written many times in this forum , JCH Optimize is not recommended if you want to use Kunena.
lifeguard replied the topic:
#
11 years 4 months ago
lifeguard's Avatar

lifeguard wrote: this update sucks.

i have a site joomla 3.3 with kunena 3.0.5 and its ok.

i see the update, make a copy of the site, and update to kunena 3.0.6
so far so good.

but the speed of kunena 3.0.6 its horrible.

i cannot understand why it works so slow.
my kunena 3.0.5 need 0,200seconds to load a page, but 3.0.6 needs almost 6 seconds to load everypagee.

the sites ar the same, because its only test copy.
i am not gonna update this to my live-site because my members will kill me.

for the record, all other components working fine. News, search, admin works fast. Only kunena is slow.


Ok, after a time, i will give a reaction.
You were right. It was me, who failed with this.

Foprgive me for this post. It was not to blame anybody, and i have mucht for the team behind Kunena, and his supporters.

It was a plugin, who makes my site slower. JCH optimize. Maybe i mis a setting, or something.
But on a new site, with same config, it works like a charm.
Thanks people, and aigain, forgive me for my stupid comment here.
Oddy94 replied the topic:
#
11 years 4 months ago
Oddy94's Avatar
I can't upgrade to Kunena 3.0.6.
www.kunena.org/forum/k-3-0-installation-...date-to-kunena-3-0-6
IceCube replied the topic:
#
11 years 5 months ago
IceCube's Avatar
Yeah, I already tried this and it won't add new entries (like Kunena) to the table. Purge only resets the enabled column to 1 and Find Updates will check the availability of the URLs and sets enabled to 0 if a URL can't be opened.
Then I'll go for a manual update and let you know if an entry to this table is added with it.

edit: Update successful and entry with URL update.kunena.org/3.0/list.xml was added to the table :)
coder4life replied the topic:
#
11 years 5 months ago
coder4life's Avatar

In this table I can't see an entry referring to a Kunena site. Should there be one?


Yes there should be.

You might of tried this, but lets try this. Click Button "Purge" in the Joomla Extensions Manager and then Click "Find Updates". Let me know if Kunena shows up. If it does not you will need to install manually, however reinstalling should fix the update issue for next time.
IceCube replied the topic:
#
11 years 5 months ago
IceCube's Avatar
Thanks for your fast reply. It's Joomla 2.5

This message contains confidential information

Database collation check: The collation of your table fields are correct

Joomla! SEF: Enabled | Joomla! SEF rewrite: Enabled | FTP layer: Disabled |

This message contains confidential information
htaccess: Exists | PHP environment: Max execution time: 60 seconds | Max execution memory: 64M | Max file upload: 128M

Kunena menu details:

Warning: Spoiler!
ID Name Menutype Link Path
168Forumkunenamenuview=home&defaultmenu=168forum
169Indexkunenamenuview=category&layout=listforum/index
171Neues Themakunenamenuview=topic&layout=createforum/neuesthema
170Aktuelle Themenkunenamenuview=topics&mode=repliesforum/aktuell
172Ohne Antwortkunenamenuview=topics&mode=norepliesforum/ohneantwort
173Meine Themenkunenamenuview=topics&layout=user&mode=defaultforum/meinethemen
174Profilkunenamenuview=userforum/profil
175Hilfekunenamenuview=miscforum/hilfe
176Suchekunenamenuview=searchforum/suche

Joomla default template details : dark_night_free | author: ThemeKat | version: 1.0.0 | creationdate: Unknown

Kunena default template details : Joomlana_Dark_II_FREE | author: bz_kunena-templates | version: 2.0.3 | creationdate: 2013-01-11

Kunena version detailed: Kunena 3.0.5 | 2014-03-09 [ Invecchiato ]
| Kunena detailed configuration:

Warning: Spoiler!
Kunena config settings:
board_offline0
enablerss1
threads_per_page20
messages_per_page10
messages_per_page_search15
showhistory1
historylimit6
shownew1
disemoticons0
templateJoomlana_Dark_II_FREE
showannouncement0
avataroncat0
catimagepathcategory_images
showchildcaticon1
rtewidth480
rteheight400
enableforumjump1
reportmsg1
username1
askemail0
showemail0
showuserstats1
showkarma0
useredit1
useredittime0
useredittimegrace600
editmarkup1
allowsubscriptions1
subscriptionschecked0
allowfavorites0
maxsubject50
maxsig300
regonly0
pubwrite0
floodprotection30
mailmod0
mailadmin0
captcha0
mailfull1
allowavatarupload1
allowavatargallery0
avatarquality75
avatarsize2048
imageheight1500
imagewidth2000
imagesize512
filetypestxt,rtf,pdf,zip,tar.gz,tgz,tar.bz2
filesize512
showranking0
rankimages0
userlist_rows30
userlist_online1
userlist_avatar1
userlist_name0
userlist_posts1
userlist_karma0
userlist_email0
userlist_joindate1
userlist_lastvisitdate1
userlist_userhits0
latestcategory
showstats1
showwhoisonline1
showgenstats1
showpopuserstats1
popusercount5
showpopsubjectstats1
popsubjectcount5
usernamechange0
showspoilertag1
showvideotag1
showebaytag0
trimlongurls1
trimlongurlsfront40
trimlongurlsback20
autoembedyoutube1
autoembedebay1
ebaylanguagecodeen-us
sessiontimeout1800
highlightcode0
rss_typepost
rss_timelimitmonth
rss_limit100
rss_included_categories
rss_excluded_categories
rss_specificationrss2.0
rss_allow_html1
rss_author_formatname
rss_author_in_title1
rss_word_count0
rss_old_titles1
rss_cache900
defaultpagerecent
default_sortasc
sef1
showimgforguest1
showfileforguest1
pollnboptions10
pollallowvoteone1
pollenabled1
poppollscount5
showpoppollstats1
polltimebtvotes00:15:00
pollnbvotesbyuser100
pollresultsuserslist1
maxpersotext50
ordering_systemreplyid
post_dateformatdatetime_today
post_dateformat_hoverdatetime
hide_ip1
imagetypesjpg,jpeg,gif,png
checkmimetypes1
imagemimetypesimage/jpeg,image/jpg,image/gif,image/png
imagequality100
thumbheight30
thumbwidth30
hideuserprofileinfoput_empty
boxghostmessage0
userdeletetmessage0
latestcategory_in1
topicicons1
debug0
catsautosubscribed0
showbannedreason0
version_check1
showthankyou0
showpopthankyoustats0
popthankscount5
mod_see_deleted0
bbcode_img_securetext
listcat_show_moderators1
lightbox1
show_list_time720
show_session_type0
show_session_starttime0
userlist_allowed0
userlist_count_users1
enable_threaded_layouts0
category_subscriptionsdisabled
topic_subscriptionsdisabled
pubprofile0
thankyou_max10
email_recipient_count0
email_recipient_privacybcc
captcha_post_limit0
keywords0
userkeywords0
image_uploadregistered
file_uploadregistered
topic_layoutflat
time_to_create_page0
show_imgfiles_manage_profile0
hold_newusers_posts0
hold_guest_posts0
attachment_limit8
pickup_category1
article_displayintro
send_emails1
fallback_english1
cache0
cache_time60
iptracking0
rss_feedburner_url
autolink1
access_component0
statslink_allowed1
userlist_usertype0
sefutf80
| Kunena integration settings:
Warning: Spoiler!
Kunena - AlphaUserPoints Disabled
Kunena - Community Builder Disabled
Kunena - Gravatar Disabled
Kunena - JomSocial Disabled
Kunena - Joomla Enabled: access=1 login=1
Kunena - Kunena Enabled: avatar=1 profile=1
Kunena - UddeIM Enabled: private=1
| Joomla! detailed language files installed:
Warning: Spoiler!
Joomla! languages installed:
de-DEGerman (DE-CH-AT)
en-GBEnglish (United Kingdom)

Third-party components: UddeIM 3.3

Third-party SEF components: None

Plugins: Content - Kunena Discuss 3.0.1

Modules: Kunena Login 3.0.1


I already noticed this update_sites table in the DB and that most of the entries were disabled. After clearing the extension cache, they were reenabled and it offered me the latest update for Joomla, but not for Kunena. In this table I can't see an entry referring to a Kunena site. Should there be one?
Is it possible to manage these entries in the Joomla Backend somehow or only in the DB?
coder4life replied the topic:
#
11 years 5 months ago
coder4life's Avatar
Hello IceCube,

What version of Joomla are you running out of curiosity, can you please provide a configuration report which gives these details to use automatically.

Just a note the normal Joomla Cache is different from the Extension Manager Cache. In Joomla 2.5 you may notice that Joomla has a "Purge" button for the cache in the Joomla Extensions Manager. This was to purge the update records that had become disabled by Joomla automatically. Joomla does this for security reasons as the update URL has become invalid and there is no reason to check it anymore. However the disable of update capability for a specific URL was not perfect and problems could occur.

Disabling of update records has a side affect, it is subject to to a false positive scenario due to network issues or server maintenance of the vendor, the vendor in this case being our server at Kunena.org. An update record can become disabled if our server becomes unavailable for a short period of time during the time that you used "Find Updates" button. Joomla now ignores that update record in the database because it is set as disabled, it never checks again to see if the site has been made available. So now updates do not get reported in the Joomla Extension Manager from Kunena.org because Joomla never looks again.

What is crazy in J3.0 to J3.3 there is currently no way to purge the disabled status records without going into the database. There is a patch for J3.4 to reapply the purge button to be able to fix these issues in case they happen. If you have J3.0 - J3.3 you will have to manually log into your database (through a tool like phpMyAdmin) and go into the updates table to re-enable the Kunena specifc entry to be able to update. J3.4 should read a purge button (or similar form of it as it exists in J2.5)
Shimei replied the topic:
#
11 years 5 months ago
Shimei's Avatar
Yes. The update wasn't showing in the backend of my Joomla 3.3.3 either. I did a manual install by downloading the package and then installing it onto my site. The downloads are available here:

www.kunena.org/download
IceCube replied the topic:
#
11 years 5 months ago
IceCube's Avatar
Is this version already available via Joomla autoupdate?
I have 3.0.5 installed and Joomla is not displaying that an update is available for Kunena.
I already tried clearing caches.
Matias replied the topic:
#
11 years 5 months ago
Matias's Avatar

lifeguard wrote: but the speed of kunena 3.0.6 its horrible.

i cannot understand why it works so slow.
my kunena 3.0.5 need 0,200seconds to load a page, but 3.0.6 needs almost 6 seconds to load everypagee.


There should be no changes in Kunena 3.0.6 which may affect the speed. The only thing that comes into my mind is that something is different in your copy, most likely either you have wrong file permissions (file caching doesn't work) or database doesn't have all the keys (or indexes aren't optimized).

Easiest way to get some idea of what's happening is to enable Joomla debug mode and look what's taking all that time.
coder4life replied the topic:
#
11 years 5 months ago
coder4life's Avatar
Hello lifeguard,

Up to 2 seconds is a long time for a site, are you having the same problems on the Kunena.org website? Also worth noting that we have not received any reports about Kunena being any slower.

From a developer perspective nothing has architecturally change that should create a slow down.

Can you please configuration report as it tell us more about your set up.
lifeguard replied the topic:
#
11 years 5 months ago
lifeguard's Avatar

Shimei wrote: Thanks Coder4life and Kunena Team.

Upgraded from 3.0.5 to 3.0.6 / Joomla 3.3.3 without a hiccup.

where is your copyright to kunena?
lifeguard replied the topic:
#
11 years 5 months ago
lifeguard's Avatar
this update sucks.

i have a site joomla 3.3 with kunena 3.0.5 and its ok.

i see the update, make a copy of the site, and update to kunena 3.0.6
so far so good.

but the speed of kunena 3.0.6 its horrible.

i cannot understand why it works so slow.
my kunena 3.0.5 need 0,200seconds to load a page, but 3.0.6 needs almost 6 seconds to load everypagee.

the sites ar the same, because its only test copy.
i am not gonna update this to my live-site because my members will kill me.

for the record, all other components working fine. News, search, admin works fast. Only kunena is slow.
Shimei replied the topic:
#
11 years 5 months ago
Shimei's Avatar
Thanks Coder4life and Kunena Team.

Upgraded from 3.0.5 to 3.0.6 / Joomla 3.3.3 without a hiccup.
Read More...

Kunena To Drop Support For Joomla 2.5 End of Q4 2014

Details
Published: 12 June 2014
Hello World! The end of Joomla 2.5's life-cycle is approaching. At the end of 2014 Joomla will offically be dropping support for Joomla 2.5 as conveyed here: http://developer.joomla.org/development-status.html. Here are some details web administrators should take into consideration concerning Kunena future versions and Joomla 2.5 support and security.

Who is affected?

Anyone running trying to run a future released version of Kunena after the last support date specified below.

What does this concern?

Kunena and Joomla support and security.

Where will this take place?

Any Kunena Extensions will immediately deny upgrade and install and will eventually remove API support for specific code that pertains to Joomla 2.5.

When does this happen?

Kunena will offically drop Joomla 2.5 support at the end of Q4 of 2014 offically on the date December 31, 2014. (NOTE: This date might be adjusted in accordance to the "End of Support" date Joomla specifies). At Kunena we will most likely be in a minor version release [versioning structure (major).(minor).(revision) example given: 3.1.2] during this release time. The next (major) OR (minor) OR (revision) release will refuse to install on the latest Joomla 2.5.x series.

Why should I update?

Although Kunena and Joomla support and security being the more important reason. Some secondary reasonings are improved performance, improved code quality which means less errors, newer web standards in development and design practices, and thus better experience for your users.

How do I prepare?

There are some good Joomla user guides available on the Internet regaruding moving from Joomla 2.5.x to the latest Joomla 3.x.x. Here is a good starter topic to take note of about the process and procedures involved: http://forum.joomla.org/viewtopic.php?t=793171

I have more questions.

Feel free to ask us questions below or on the forum. Have a good week.

Discuss this article

Log in to comment

Posts in discussion: Kunena To Drop Support For Joomla 2.5 End of Q4 2014
sozzled replied the topic:
#
11 years 1 week ago
sozzled's Avatar
In relatively "simple" English, this is the situation (as best as I understand it):

Joomla does not support J! 2.5 (as from 1 January 2015).

Unless there is something of a major security alert, there are no intentions by the Joomla development team to support or fix any problems with J! 2.5 or release any versions after J! 2.5.28.

Basically means—just like it means if people were using J! 1.0 or J! 1.5—if you are using J! 2.5 then, if it works, good luck and, if it doesn't work, it's a case of "you're on your own". The best advice that anyone can give to people who are using old, outdated and unsupported software is to upgrade to software that is supported.

As far as Kunena is concerned, it is reasonable to say that K 3.0 (and K 3.1—if this ever sees the light of day) will continue to operate on J! 2.5 systems but, as 810 and coder4life have stated, if you have problems then the Kunena developers have no real intention to address them—for the general connunity—as far as J! 2.5 websites are concerned.

Quoting from the article,

The next (major) OR (minor) OR (revision) release will refuse to install on the latest Joomla 2.5.x series.

this is a little misleading. There have been no changes to K 3.0 (or K 3.1 for that matter) that impose this restriction. It is unlikely that this restriction will be enforced in future versions of the K 3.0 series.

In summary, if you are using J! 2.5 then you may use Kunena (for as long as the J! 2.5 codebase is included in the installation) but if you have problems then whatever assistance or help will be minimal or, in all probability, non-existent.
coder4life replied the topic:
#
11 years 1 week ago
coder4life's Avatar
@810 is correct. We plan to support J2.5 minimally in regards to updating to the latest Joomla version in the 3.x series. However any specific bugs that are a result of being J2.5 specific (other then migration bugs) will not be fixed.

You are correct we plan to drop J2.5 specific code, but even 3.1 will be built and work on J2.5 for some time after with the same intention of support.

The goal is to allow a transition period.
Josh replied the topic:
#
11 years 1 week ago
Josh's Avatar
Sounds good. I know that typically unsupported versions break compatibility eventually. B) Eventually will compatibility with J 2.5 be dropped to make Kunena a little lighter as well?
810 replied the topic:
#
11 years 1 week ago
810's Avatar
K3.0.7 And K3.1.0 version still works on J2.5 but we advice the users to upgrade as soon as possible.

If there is a bug for j25 only, we won't fix it. But the code should work there is no b/c issue's.
Josh replied the topic:
#
11 years 1 week ago
Josh's Avatar
The new year is here. I assume Joomla 2.5 support is officially dropped?
Read More...

Automatic subscriptions

Details
Published: 16 May 2014

alt

Introduction

Automatic subscriptions—the ability to enforce a website owner's policy that all members of the site "automatically" receive email notifications whenever there is some new forum activity (a new topic created or replies made to existing topics)—is a subject that has often been discussed on this forum going back as far as I can remember. People have asked for the Kunena project team to deliver features that allow them to "autosubscribe" members of their forums to categories and topics without their members having to do anything except to join their websites. This is a subject that has as many different views about how to implement a solution as well as different opinions about whether such methods are "legitimate", workable, worthy or legal in terms of the protection of an individual's right to privacy or an individual's right to choose.

The different views and opinions expressed by the wider Kunena community exist within the Kunena project team, too. In short, there is no simple answer to this very complex issue.

Every website on the internet is a business in some form or another. Some websites operate in order to generate a cash profit while others operate on a not-for-profit basis—to facilitate sharing of knowledge, community or social activities. Your website provides a service as part of that business and the people who join your site are consumers of that service (or services) that you offer. A forum is part of that business and your members' participation in the forum acts both to give them the means to discuss the range of "services" that your site provides—that is, something that your members consume—as well as where your members contribute to enhance the business of the site.

It really does not matter for what purpose your site exists. As soon as we start talking about sending out emails to people we're talking about how your website operates as a business and, as part of operating that business, questions about how you manage the relationship between you and your "customers" are entirely relevant.

This article identifies the technical and non-technical complexities that people need to understand before you try to "autosubscribe" your members when they did not specifically and explicitly choose to subscribe themselves to your forum. The issues fall into the following broad categories:

  • Feasibility: can it be done?
  • Design: how can it be done?
  • Viability: will it work?
  • Risk management: costs, overheads, ethical and legal consequences.

The views and opinions expressed in this article are my own and do not represent the opinion of the project team as a whole or, necessarily, the opinions of individual members of the team.

Read more: Automatic subscriptions

Discuss this article

Log in to comment

Posts in discussion: Automatic subscriptions
Boby71 replied the topic:
#
7 years 11 months ago
Boby71's Avatar
Well, I'm running a small online community (=no problems with workload & staff) and lately we started to switch over to using Facebook groups, because people WANT to get a notification of EVERYTHING. That's what they are trained to by various social media channels. Unfortunately, our online community isn't being used anymore because of this missing feature.

Wake up, Kunena - it's time to adapt or forums will be completely gone soon; this is 2018!
thepiston replied the topic:
#
11 years 2 months ago
thepiston's Avatar
What's best way to mass subscribe a bunch of users to a forum? I can easily get an ID list too and do it in phpmyadmin if anyone knows the syntax to do that in one query.

thanks
sozzled replied the topic:
#
11 years 5 months ago
sozzled's Avatar
Thank you to everyone who has read this topic and replied. :)

I would like to remind people who are contemplating "autosubscriptions" - remembering that there is no built-in mechanism in Kunena to automatically subscribe all of your users to a topics/categories on your forum - of the point I made in the article:

Additionally, generating email increases the workload on your server and may, over time, impact on the performance of your site particularly if your forum is busy and emails are sent to many subscribed members every time a new topic is created or a topic is replied to.


If your forum generates a lot of email every time your users post messages on the forum we are aware that forum performance will be affected because of the background tasks involved in sending the emails.

There may also be some confusion about what "autosubscriptions" means. The term does not mean, for example, that if you set the configuration setting

Users » Subscriptions » Topic Subscriptions = Email every update

that all of your users will receive email every time a new message is posted on your forum. This setting only applies to those users who are subscribed to topics where new messages are posted. In other words, if a new message is posted on your forum, only subscribed members will receive email and, by the way, the author of the message will not receive an email notifying them of the message that they just posted.

I hope this added explanation helps.
PopleMediaSolutions replied the topic:
#
11 years 7 months ago
PopleMediaSolutions's Avatar
Great post!
Thanks for this - I totally understand. I have managed, with this, to persuade them against the automatic subscription.

Thanks!

Rowan
Pople Media Solutions
PopleMediaSolutions replied the topic:
#
11 years 7 months ago
PopleMediaSolutions's Avatar
Hi All,

Just wondering if you can help me with this the following:

We have a customer who is using the Kunena forum and community builder (with CBsubs) to allow access to the forum. Upon registering they would like all users to be automatically subscribed not only to all categories but all topics as well.

Can you help me with this?

Thanks.

Rowan
Pople Media Solutions
MarioMari replied the topic:
#
11 years 7 months ago
MarioMari's Avatar
Kunena must develop. :) If you think someone will think Kunena forum.

Maybe the idea is to create a ranking of new features Kuenne that after reaching some number of votes will be considered a priority in the work of the Forum?

Perhaps this type of tool?
helpocean.com/
Or a plugin for Kunena who will vote and count the votes on a specific topic in the "New Features"?
MarioMari replied the topic:
#
11 years 7 months ago
MarioMari's Avatar
Hi!

[...] This is a subject that has as many different views about how to implement a solution as well as different opinions about whether such methods are "legitimate", workable, worthy or legal in terms of the protection of an individual's right to privacy or an individual's right to choose. [...]


— Thank you for the article and a serious approach to the subject. Give someone a hammer, one builds a house, the second kills a man. You can not affect the use of tools.

Kunena, should offer superlative and effective solutions. Without this, there will be the leader. If you do not strive to be a leader to date the work will be thrown into the trash.
Read More...

Kunena 3.0.5 released

Details
Published: 08 March 2014

Introduction

Kunena 3.0.5 [K 3.0.5] is available for download as a native Joomla extension for J! 2.5 and J! 3.x. This version is a security release for Kunena that addresses several maintenance issues that have been reported since the last version release. and this new version replaces (and makes obsolete) all previous versions of Kunena.

This version of Kunena coincides with the simultaneous release of an updated language pack, downloaded separately, for deployment on non-English websites. The release of this version does not not coincide with the release of other Kunena Add-ons that have not been updated at this time and that may or may not be updated for this version.

In general, Kunena Add-ons designed for previous versions of K 3.x should interoperate with this version of Kunena; in general, Kunena Add-ons designed for older major versions of Kunena will not interoperate with this version of Kunena.

The summary of important changes in K 3.0.5 are:

  • XSS vulnerability in BBCode output (thanks Qoppa for finding it)
  • Improvements to lightbox
  • Fixes some JomSocial stream issues
  • Improvements to backend

Read more: Kunena 3.0.5 released

Discuss this article

Log in to comment

Posts in discussion: Kunena 3.0.5 released
sozzled replied the topic:
#
11 years 6 months ago
sozzled's Avatar

viper2k wrote: When will you release the new version of Kunena 3.1?

I'm sorry but this topic is about the release of K 3.0.5. I am sure that, when someone takes the time to write some details about when K 3.1 will be released, this will be done in a different place.

viper2k wrote: Hopefully [K 3.1] comes with a more modern design and some new features.

Yes (for those who use J! 3.x). For those who use J! 2.5, K 3.1 will look much the same as K 3.0 does now.

In response to your comments about professional ticketing systems and "more templates" (which do not really have a lot to do with the announcement about the release of K 3.0.5), we are considering a range of options in relation to "paid support" but we are not in a position to provide you with those kinds of details.

There are a range of services available to you today for support, for additional Kunena templates and for a wide range of things involving Kunena. Perhaps a good place to start your search for services and templates is to look at the advertisements that appear on this website. I am sure that you will be rewarded for your efforts.

As you know, there is no company behind Kunena. Everyone who contributes to Kunena is a hobbyist, enthusiast or professional web developer who gives their time freely to this project - volunteers every one of us. The forum is provided mainly as a self-help community-driven resource for users but there is no "formal" obligation of support, necessarily. We do our best. Our job, in moderating the forum is not necessarily to answer every question but, rather, to point people in the right direction where they can find the answers. It is unfortunate (perhaps) that in this case I do not have a specific answer to the question "when will K 3.1 be released".

If you are interested in being part of the project team that is building K 3.1, and you have software coding skills that will assist the project, you might like join the GitHub community.
viper2k replied the topic:
#
11 years 6 months ago
viper2k's Avatar
When will you release the new version of Kunena? 3.1? Hopefully it comes with a more modern design and some new features :). I would also pay for the version if you have:

- professional support with ticket system
- some more templates

Thanks
s23Nation replied the topic:
#
11 years 9 months ago
s23Nation's Avatar
plenty of support up to date features very modern working platform
so take it for a test drive and get a feel of what you can and can not do
sozzled replied the topic:
#
11 years 10 months ago
sozzled's Avatar
Anastasiya: Please start a new topic in our Installation and Upgrade category and read the installation guide in the Wiki.
Anastasiya replied the topic:
#
11 years 10 months ago
Anastasiya's Avatar
The situation with downloading large files remains the same. If the attachment is too large, the message "COM_KUNENA_UPLOAD_ERROR_NOT_UPLOADED", but not "COM_KUNENA_UPLOAD_ERROR_SIZE".
naimless replied the topic:
#
11 years 10 months ago
naimless's Avatar
Thanks sozzled, no problem at all, I know how much you and the rest of your team have on your plate! And apologies, I didn't mean to hijack this thread. Just thought it was the most appropriate place since it was directly related to this release and could have been helpful to others looking to patch security quickly...

Will go for option (a) that you suggest as soon as I have 20 minutes or so to spare :) Thanks! :)
sozzled replied the topic:
#
11 years 10 months ago
sozzled's Avatar
I do not know if Qoppa will read this topic or if he will reply directly to you with the information that you are looking for. I have to admit that for this K 3.0.5 release I did not prepare the release notes because I have been very busy doing other things (and so, if the information is not as complete as you will find in other release notes where I was involved in writing them, please accept my apologies).

So you are right. The "abridged change log" for K 3.0.5 does not specifically state exactly which GitHub bug. Sorry about that. As I said, I haven't had the time lately to review what's in the Wiki. :blush:

This is really not the best topic to ask these kinds of questions. It may be better for you to go to GitHub where you can search for the information that you're looking for. If you can't find the information in GitHub, you have the following choices:

(a) upgrade to K 3.0.5 (in the normal, recommended manner) and reapply any customised changes that you specifically want (or need); or

(b) create a topic in the Custom work - not offering to pay or Miscellaneous, off-topic and general Joomla and wait for another member of this community, who has a common interest in your problem, to reply with the specific information you are looking for.

Please remember, as a courtesy to other users of this forum, to not hijack this topic further by continuing to ask about how to make out-of-the-ordinary changes to your customised installation, questions that do not apply to the majority of other members of the community. Thank you.
naimless replied the topic:
#
11 years 10 months ago
naimless's Avatar
Thanks for your prompt reply Sozzled.

I'd already looked through release notes (no specific mention of where the XSS vulnerability was, other than BBCode), and through GitHub (where the latest commit has over 1400 changed files, mostly with version numbers, etc, so it was almost impossible for a GitHub newbie such as myself to find which bit was responsible for the security flaw).

I'd agree with you generally though, that if I make core hacks, on my own head be it, though in the case of urgent security alerts, which are now public due to the update, it would be really helpful for someone on the team to be able to confirm which two or three files absolutely need to be patched (and I assume it's a tiny independent change in this case, such as all the files in library/kunena/bbcode or somesuch maybe?).

If Qoppa or someone who was responsible for finding / fixing the flaw is reading this, would be great if they could just ping a quick line across letting me know if any other files are at risk or if that would do.

I don't think that in the case of small security updates, which by their nature are more urgent and important than feature releases, those who choose to embrace Kunena's flexibility and open source nature by hacking it a little bit, can not be supported, at least a little bit?

Anyway, didn't mean to start a long thread or debate over this, it was literally just a quick request for help in case a kind soul happened to have an answer to hand.

Keep up the great work Team K!
sozzled replied the topic:
#
11 years 10 months ago
sozzled's Avatar

naimless wrote: Quick question - could you please confirm which files I need to patch for the BBCode XSS vulnerability?

As you probably know, these kinds of announcement topics are not the best places to ask "quick questions" like those. Details about what is fixed (and how) are usually contained in the release notes and the full source codes is availabled (for those who want to get it) on GitHub.

naimless wrote: Have some core modifications done to Kunena (I know, it's not a good idea to hack core files) ...

This is an example of why we do not recommend to people that they should modify the original source code. People modify source code and then they kind of "paint themselves into a corner" and they're unable to upgrade to new versions because their highly-customised software contains so many changes that it takes a significant time to reapply them when new versions are released. However, as we have always said here, Kunena is open-source and people are free to change it as much as they like but, if they change it, they cannot expect that we will be able to help them when they do. My advice is to read the release notes (in the Wiki) to see what changes have been applied to the new version and then to go to GitHub to find the actual source code that relates to those things.
naimless replied the topic:
#
11 years 10 months ago
naimless's Avatar
Hi,

Great work on the new release and security fix.

Quick question - could you please confirm which files I need to patch for the BBCode XSS vulnerability?

Have some core modifications done to Kunena (I know, it's not a good idea to hack core files) and would be great if I could just copy those files across without having to patch the other core files again with my modifiations.

Thanks!
jimrowland replied the topic:
#
11 years 10 months ago
jimrowland's Avatar
Looking forward to this, and 3.1! Noticed a typo in the release note, 2nd line above the "Other Details" header:

"For this reason it is advisable that you first test K 3.0.4 on a test site before you upgrade your live production site(s)."

Should be 3.0.5, I assume.

Good work to all the volunteers who keep the prject moving on the back end and to the mod team who keeps all of us "dumb users" functioning!
roland76 replied the topic:
#
11 years 10 months ago
roland76's Avatar
Hello,

everything works fine. Thanks a lot :-)...

Hopefully 3.1 is not so far away... ;-)

Greetings, Roland
Read More...
  1. Kunena 3.0.4 released
  2. Kunena 3.0.3 released
  3. Kunena 3.0.2 Released
  4. Kunena 3.0.1 Released

Page 43 of 58

  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
© The Kunena Project 2008 - 2026
Joomla is a registered trademark of Open Source Matters, Inc. in the U.S. and/or other countries. The Kunena Project is not affiliated with or endorsed by Open Source Matters, Inc.

Hosting sponsored by:
  • Terms of Use
  • History
  • Team
  • Privacy Policy
  • Sponsorships
Back to top