Maintenance

For the many who attempted to visit this morning, I apologize. It turns out there was a cross-site scripting vulnerability in the weblogging software in use here at barnson.org. I upgraded to the latest version.

For the many who attempted to visit this morning, I apologize. It turns out there was a cross-site scripting vulnerability in the weblogging software in use here at barnson.org. I upgraded to the latest version.

Known-broken stuff:

  • Private messages aren’t working. Note: Fixed this, working now.
  • The “theme”, or look-and-feel, of the site isn’t what it used to be. It turns out that the theme I slaved over to get just the way I wanted it isn’t working (yet) with the new codebase. I’ll be doing some programming over the coming days to get this back the way I want it. After some effort, and remembering little hacks I’d done two years ago, I got it looking mostly like it’s the same website again, with the exception of the missing avatars (which were totally changed for this version, it will take time to fix). Still some spacing tweaks to be done, but overall I’m pleased that the look and feel is similar. Now it’s time to plan my next site redesign around the same color scheme, but an improved layout…
  • The photo album is gone. I think I’m going to actually leave it permanently gone from its old location, and instead begin using the new photo functionality within Drupal. So long, Gallery. This also means I’ll have to go back and fix some links for pictures, though…
  • But on the plus side, the MP3’s are all working!

Let me know if you run into any weird issues not mentioned above; I’ll update this page when maintenance is fully complete. In the meantime, post all you like!

19 thoughts on “Maintenance”

    1. 4.5.2

      Upgraded Drupal to 4.5.2, the latest version.

      And your timezone is customizable in your user preferences. Mine is set to GMT right now, so it’s telling me it’s much later than it is 🙂


      Matthew P. Barnson

        1. Important notes

          Important notes:

          • Remember that, in update.php, you have to follow all the instructions since your released version. Since I had been running 4.2.0, I had to do the changes for 4.2, 4.3, and 4.4 before the upgrade.php script would work.
          • I had to drop my “cache” table, and re-create it using the database.mysql file (just copy-and-paste the cache table definition) before the update.php script would work. I was getting an error about “header” not being a recognized column. update.php really should not have those kinds of dependencies, IMHO. But once I did that, the upgrade ran just fine with many dozens of changes, and when I checked, the only ones that failed were related to the cache table (which I had blown away and created new).

          All seems to be well now, but it certainly was a pain. Glad I did it, though, now I’m working off a release that’s not full of CVS-tagged files with a date in 2003…


          Matthew P. Barnson

          1. updates

            I had to actually rebuild php as I didn’t have xml.so installed. I agree that the update script shouldn’t have any dependencies at all but it seemed to work out. I too had to kill a table, watchdog, as it had become corrupted on the server somehow. So far, all is well but now I’m faced with the overwhelming task of recreating my look and feel and all the little custom features I hacked into the old versions.

          2. Yes, but goodness looms!

            It’s a pain to rebuild all the fun custom crap, but man, did you see how much the stock module list has expanded at drupal.org?

            I’m thinking the Instant Messenger feature would be awesome. Lets you send IMs to currently logged-in users (like the private messages feature, which I get a lot of mileage out of) which appear on their next page refresh. Nifty stuff. Must get out and play 🙂


            Matthew P. Barnson

          3. Hey dere..

            Wheres the “view most recent posts” and “all time top”..

            WHERE, $%&#^#, WHERE!!!

          4. “Recent Posts”

            It’s called “recent posts” now. The format is slightly different, but it still does the same thing. You can even see how many hours ago the last post was, now 🙂


            Matthew P. Barnson

          5. Toplist

            The Top Nodes list got disabled by the upgrade. Just turned it back on again. Today’s stats won’t be accurate.


            Matthew P. Barnson

  1. Is this something i should look at fixing

    Is this something i should look at fixing at Brusco.org. I haven’t the time to post there right now, but still want it to remain in line with security…

    Please advise…

    JB

    1. Yep!

      Yes. I have a half-dozen sites I run on this same software; brusco.org is on the list to be fixed this weekend 🙂


      Matthew P. Barnson

  2. problems

    I attempted to post a comment on your previous blog and it didn’t show up. Don’t know why. Teresa

    1. Delayed comments

      Unfortunately, due to spammers attempting to exploit this web site, if you’re not a registered user, you cannot post comments without my approval. If you’ve gone to the trouble of registering and still abuse me, at least I have an email account so I can track down the person who is causing problems.

      So if you’re not logged in, there’s a delay of up to a few hours as I find time to approve the posting…


      Matthew P. Barnson

  3. I hate this look. I makes me

    I hate this look. I makes me realize my eyes aren’t what they used to be. Everything is so tiny. Can’t see anything. Please make it better Matt. I also had to relog in and get a new password, to let me in where as before it remembered me. Oh well. Teresa

    1. Theme issues

      See my “theme problems” item, above. Avatars, as those little pictures are called, are part of the theme. Unfortunately, Drupal totally changed their uploaded-file handling between 4.2.0 and 4.5.2, so my existing code hacks to put avatars into my theme no longer work. The theme I use as my base (called “Interlaced”) to which I have made significant modifications to create the barnson.org look has never supported avatars; I’ve always had to code that support in.

      I might get to it this weekend; then again, I might not 🙂 Regardless, your avatars are not lost. They are stored safely on my hard drive, and I’ll be putting them back once I figure it all out. You can also choose to upload your own avatars right away again, if you like, but people will only see them when viewing your profile page.


      Matthew P. Barnson

  4. Posting

    I can’t seem to find the link to post new stuff up. Is this not there during the maintenance period?

    1. Create Content

      It’s under the “Create Content” link in your menu on the right-hand side.


      Matthew P. Barnson

Comments are closed.