Blame view

framework/docs/en/04_Changelogs/rc/3.1.3-rc1.md 1.64 KB
385d70ca   Administrator   Importers CRUD
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
  # 3.1.3-rc1
  
  ## Overview
  
   * Security: Require ADMIN for ?flush=1&isDev=1 ([SS-2014-001](http://www.silverstripe.org/ss-2014-001-require-admin-for-flush1-and-isdev1))
   * Security: XSS in third party library (SWFUpload) ([SS-2014-002](http://www.silverstripe.org/ss-2014-002-xss-in-third-party-library-swfupload/))
   * Security: SiteTree.ExtraMeta allows JavaScript for malicious CMS authors ([SS-2014-003](http://www.silverstripe.org/ss-2014-003-extrameta-allows-javascript-for-malicious-cms-authors-/))
   * Better loading performance when using multiple `UploadField` instances
   * Option for `force_js_to_bottom` on `Requirements` class (ignoring inline `<script>` tags)
   * Added `ListDecorator->filterByCallback()` for more sophisticated filtering
   * New `DataList` filters: `LessThanOrEqualFilter` and `GreaterThanOrEqualFilter`
   * "Cancel" button on "Add Page" form
   * Better code hinting on magic properties (for IDE autocompletion)
   * Increased Behat test coverage (editing HTML content, managing page permissions)
   * Support for PHPUnit 3.8
  
  ## Upgrading
  
  ### SiteTree.ExtraMeta allows JavaScript for malicious CMS authors
  
  If you have previously used the `SiteTree.ExtraMeta` field for `<head>` markup
  other than its intended use case (`<meta>` and `<link>`), please consult
  [SS-2014-003](http://www.silverstripe.org/ss-2014-003-extrameta-allows-javascript-for-malicious-cms-authors-/).
  
  ## Changelog
  
   * [framework](https://github.com/silverstripe/silverstripe-framework/releases/tag/3.1.3-rc1)
   * [cms](https://github.com/silverstripe/silverstripe-framework/releases/tag/3.1.3-rc1)
   * [installer](https://github.com/silverstripe/silverstripe-framework/releases/tag/3.1.3-rc1)