Movable Type 6.3.8 - Security Patch and Other Improvements

Six Apart nicely surprised me on January the 15th with a new release of Movable Type v6.3.x which includes a few import improvements as well as a security fix.

SECURITY PATCHES

If a compressed file (tar.gz or zip) contains a symbolic link or absolute path, an error will now occur at decompression.

NEW AND IMPROVED FUNCTIONS

CONTENT SYNC

Immediate delivery changed to background processing

In previous versions, when immediate delivery was executed, processing was done in real time on the browser. However, when the number of target files is enormous, there was a problem that processing timed out. In order to solve this problem, we changed the processing method from real-time distribution on the browser to background distribution using run-periodic-tasks.

When immediate delivery is registered, distribution processing is executed when the next run-periodic-tasks is executed. A notification e-mail is sent when distribution is started.

In environments where run-periodic-tasks is not executed periodically, immediate delivery is not performed.

Following this change, there are some restrictions.

  • When immediate delivery is executed for multiple server delivery settings, processing is executed in the order in which they were registered.
  • For the same server delivery setting, if scheduled delivery is executed before immediate delivery, immediate delivery will not be executed.

Clarification of authentication error

Changed the error message to be appropriate when user authentication error occurs when connecting to FTP server.

Support TLS 1.1 / 1.2

When connecting to ftp server with FTP over SSL, connection using TLS 1.1 / 1.2 has been enabled.

UPDATED FUNCTIONS

MISCELLANEOUS

Bundled Net::FTPSSL is up-to-date.

RESOLVED ISSUES

BLOGS

Resolved issue where replication of blog was not done correctly.

CONTENT SYNC

Fixed an issue where server certificate verification was done even when 1 was specified for SSLVerifyNone or FTPSSSLVerifyNone.

CUSTOM FIELDS

The value of asset type custom fields now displays correct link.

MISCELLANEOUS

Fixed an issue where SMTP authentication fails when ? (question mark) Is included in the value of SMTPPassword configuration directive.

PLUGIN

Fixed an issue where the FacebookCommenter plugin caused a timeout when acquiring user images.

TEMPLATE TAGS

Resolved issue where the value of 0 is not processed correctly by MTIf tag.

You are welcome to explore this release from:
https://www.movabletypedemo.org/v6x/cgi-bin/mt/mt.cgi

Using:
- username: demo
- password: testthis

Enjoy!

No TrackBacks

TrackBack URL: https://www.movabletypedemo.org/admin/mt/mt-tb.cgi/168

Leave a comment

Support

If this initiative is useful for you, please consider making a paypal donation or getting your movable type project done with PRO IT Service.

We're the right people for movable type consultancy services including: installations, upgrades, themes, templates, consulting, troubleshooting as well as hosting.

The complete range of movable type services you might be looking for!

Services

We would love to work on any movable type jobs you might have! To find out more about the movable type services we're offering click here.

You may like to know that we're offering a broad range of web development services as well as professional website hosting service in partnership with Pair Networks, Inc. from Pittsburgh, PA, USA.

Check out everything we're proudly doing by visiting https://www.pro-it-service.com/

Newsletter

Would you like to be updated every time there is a movable type release? If you do, then subscribe for email updates filling out the form below.

Subscribe

Delivered by FeedBurner

Disclaimer

This is a personal website and doesn't have anything to do with Six Apart nevertheless Chris Alden, the former Six Apart CEO, appreciated my idea when he saw it available online.