Журнал изменений

Журнал изменений

Фильтр и поиск

Всего: 1045 Доступных коммитов | Отфильтровано: 1045 Коммиты | Страница: 84 / 105
19.02.2026
Style: Increase admin panel font sizes for readability
Автор: Eduard Laas | Дата: 18:09 19.02.2026

Bump base font sizes in the admin area to improve legibility on higher-DPI displays and modern browsers.

Core changes:

  1. CodeMirror editor (templates/admin/system.css):
  2. .CodeMirror font: 11px → 12px Verdana
  3. .CodeMirror-hints font: 11px → 12px Verdana
  4. Admin base layout (templates/admin/theme.css):
  5. body, form elements font: 12px/16px → 13px/16px Tahoma/Arial/Verdana

Benefits:

  • Better readability on HD/Retina screens
  • Consistent sizing between editor widget and surrounding UI

Technical notes:

  • Line-height left at 16px; no layout reflow expected
  • No change to colours, spacing, or other visual properties
Docs: Update code examples to use PREFIX_DB constant
Автор: Eduard Laas | Дата: 18:08 19.02.2026

Replace the deprecated \$prefix variable in all SQL snippets shown in project documentation with the PREFIX_DB constant, keeping examples consistent with the actual codebase after the refactor.

Core changes:

  1. README.md:
  2. SQL example: '.\$prefix.'_users → '.PREFIX_DB.'_users
  3. CONTRIBUTING.md (2 occurrences):
  4. SQL examples in "Correct - Safe" and function sample updated
  5. SECURITY.md:
  6. Prepared-statement example updated
  7. UPGRADING.md:
  8. Migration guide example for 6.3.x updated

Benefits:

  • Documentation reflects current coding standard
  • New contributors see the correct pattern from the start

Technical notes:

  • No functional code changed; documentation only
Fix: Strengthen .htaccess security rules
Автор: Eduard Laas | Дата: 18:08 19.02.2026

Harden the Apache rewrite rules to close several attack vectors and improve reliability across all hosting configurations.

Core changes:

  1. Block PHP execution in uploads (new rule):
  2. RewriteRule ^uploads/.*\.php$ — [F,L,NC]
  3. Prevents uploaded-file code-execution attacks
  4. Exploit-string filter (existing block):
  5. Add [NC] flag to base64_encode and GLOBALS conditions
  6. Change final RewriteRule target from index.php to — [F,L] (returns 403 instead of silently routing malicious queries)

  7. HTTP_AUTHORIZATION passthrough:
  8. Move the Authorization header rule BEFORE the front-controller rule
  9. Ensures REST/API clients receive the header when using BasicAuth
  10. Remove trailing [L] flag from original position (was unreachable)

Benefits:

  • Uploaded PHP files can no longer be executed via the web
  • Malformed query strings return 403 instead of being forwarded
  • HTTP Basic Auth works correctly in CGI/FastCGI environments

Technical notes:

  • No change to normal request routing
  • Backward-compatible with all existing URL rewrite patterns
Chore: Rename config files and remove obsolete editrewrite editor
Автор: Eduard Laas | Дата: 18:08 19.02.2026

Simplify file names in config/ by dropping the redundant config_ prefix. Remove the editrewrite admin function that was editing the now-deleted config/config_rules.php file.

Core changes:

  1. Config file renames:
  2. config/config_chmod.php → config/chmod.php
  3. config/config_header.php → config/header.php
  4. config/config_rules.php — deleted (no longer used)
  5. Security guard (config/system.php):
  6. Add FUNC_FILE guard to match style of all other config files
  7. Remove duplicate license header (already in repo root)
  8. Reference updates (core/admin.php, admin/modules/editor.php):
  9. end_chmod(): update tdir to 'config/chmod.php'
  10. editheader(): switch to CONFIG_DIR.'/header.php'
  11. htaccess(), robots(): switch to BASE_DIR-prefixed paths
  12. Remove editrewrite() function entirely
  13. Admin navigation (admin/modules/editor.php):
  14. Remove "System Rewrite" tab from editor navigation
  15. Renumber remaining tabs accordingly
  16. Documentation (admin/info/blocks-*.html, 6 languages):
  17. Update all references from config/config_header.php → config/header.php
  18. Tests (tests/ConfigValidationTest.php):
  19. Update required file list: config_global.php → global.php

Benefits:

  • Cleaner, shorter file names consistent with the rest of config/
  • Dead code (editrewrite) removed, reducing surface area
  • All paths now use constants (BASE_DIR, CONFIG_DIR) for portability

Technical notes:

  • config/chmod.php and config/header.php already existed as new files
  • Storage format unchanged; only file names differ
Refactor: Remove _REDAKTOR constant, use _EDITOR
Автор: Eduard Laas | Дата: 18:07 19.02.2026

_REDAKTOR was a legacy alias for _EDITOR. Consolidate all references to a single constant and drop the outdated definition from every language file.

Core changes:

  1. Language files (admin/language/*.php, 6 files):
  2. Remove define("_REDAKTOR", ...) from de, en, fr, pl, ru, uk
  3. Remove define("_EREW", ...) and define("_EREWN", ...) — editor rewrite labels
  4. Remove define("_EINFO3", ...) — rewrite editor info text
  5. Admin config panel (admin/modules/config.php):
  6. Replace _REDAKTOR with _EDITOR in editor-selector label
  7. Editor selector labels (core/system.php):
  8. Remove redundant _EDITOR prefix from option strings in redaktor() (e.g., _EDITOR.' SLAED BB' → 'SLAED BB')

Benefits:

  • Single constant _EDITOR used consistently everywhere
  • Removes dead constants that referenced removed functionality
  • Reduces translation maintenance overhead

Technical notes:

  • _REDAKTOR was functionally identical to _EDITOR
  • admin/modules/admins.php already updated in previous commit
Refactor: Replace \$prefix global with PREFIX_DB constant
Автор: Eduard Laas | Дата: 18:07 19.02.2026

Drop all uses of the legacy \$prefix variable in favour of the PREFIX_DB constant defined in core/security.php. This completes the migration started in earlier commits and removes the last runtime dependency on the dynamic global.

Core changes:

  1. Remove \$prefix assignment (core/security.php):
  2. Delete the \$prefix = \$conf['db']['prefix'] line
  3. PREFIX_DB constant was already defined; variable was redundant
  4. All blocks (blocks/block-*.php, 15 files):
  5. Remove \$prefix from global declarations
  6. Replace ".$prefix."_table with ".PREFIX_DB."_table in all queries
  7. All front-end modules (modules/*/index.php, 24 files):
  8. Remove \$prefix from function global declarations
  9. Replace \$prefix in every SQL query string
  10. All admin modules (admin/index.php, admin/modules/.php, modules//admin/index.php):
  11. Same substitution as front-end modules
  12. Templates (templates/admin/index.php, templates/lite/index.php, templates/lite/0index.php):
  13. Remove \$prefix from global declarations
  14. Replace \$prefix in SQL queries

Benefits:

  • Single source of truth: PREFIX_DB constant eliminates accidental overrides
  • Consistent style across the entire codebase
  • Prepares for full removal of legacy globals

Technical notes:

  • No behaviour change; queries produce identical SQL
  • Backward-compatible: PREFIX_DB was already defined before any query runs
Fix: Security and code quality improvements
Автор: Eduard Laas | Дата: 14:19 19.02.2026

Harden .htaccess and fix string quoting in setConfigFile().

Core changes:

  1. .htaccess:
  2. Added Options -Indexes (prevent directory listing)
  3. Added RewriteRule ^config/ [F,L] (block config access)
  4. Added RewriteRule ^setup/ [F,L] (block installer access)
  5. Split commented deflate/expires into separate IfModule blocks
  6. setConfigFile() (core/system.php, setup/index.php):
  7. Replaced double-quoted "\n" with PHP_EOL and single quotes
  8. '['.PHP_EOL and ','.PHP_EOL consistent with rest of function

Benefits:

  • config/ directory with DB credentials no longer web-accessible
  • setup/ installer blocked after initial setup
  • Directory listing disabled sitewide
  • String quoting consistent with Rule 17 (single quotes)
Style: Fix variable names in setConfigFile() per Rule 6
Автор: Eduard Laas | Дата: 11:02 19.02.2026

Rename single-letter and over-length variables to comply with SLAED coding rules (Rule 6: prefer 4-8 chars, no camelCase).

Core changes:

  1. setConfigFile() (core/system.php, setup/index.php):
  2. \$normalize (9 chars) → \$norm
  3. \$exp closure: \$a→\$arr, \$d→\$dep, \$p→\$pad, \$i→\$ind, \$s→\$out
  4. Loop vars: \$k→\$key, \$v→\$val throughout the function

Benefits:

  • Compliant with Rule 6 (4-8 char variable names)
  • No functional changes
Feature: Add dev_mode toggle to admin config panel
Автор: Eduard Laas | Дата: 10:30 19.02.2026

Expose the existing dev_mode flag in the admin interface so it can be toggled without manually editing config files or local.php.

Core changes:

  1. admin/modules/config.php:
  2. Added radio_form row for dev_mode (after site close toggle)
  3. Added 'dev_mode' => getVar('post', 'dev_mode', 'num') to save \$cont
  4. admin/language/*.php (6 files):
  5. Added _DEVMODE constant after _DEAKTIVE (alphabetical order) ru: «Режим разработки» en: «Developer Mode» de: «Entwicklermodus» fr: «Mode développeur» pl: «Tryb deweloperski» uk: «Режим розробника»

  6. config/global.php:
  7. Added 'dev_mode' => false as explicit default

Benefits:

  • dev_mode can be enabled/disabled without file editing
  • Config fingerprint tracking active when dev_mode is on
  • Consistent with all other boolean toggles in general preferences

Technical notes:

  • getConfig() already provides $conf['dev_mode'] ??= false fallback
  • normalize() converts false → '0', true → '1' on save
  • String '0' is falsy in PHP, behavior unchanged
Fix: setConfigFile() — use []-bracket format instead of array()
Автор: Eduard Laas | Дата: 10:11 19.02.2026

Replace var_export() with a recursive closure that produces modern PHP short-array syntax ([]) consistent with all config/*.php files.

Core changes:

  1. setConfigFile() (core/system.php, setup/index.php):
  2. Added $exp closure: renders arrays as [...] with 4-space indent
  3. Replaced var_export($data, true) with $exp($data)
  4. Output format now matches manually-converted config files

Benefits:

  • Config files saved by admin panel are readable and consistent
  • No more array() vs [] style mismatch after save
  • Multi-level arrays (ratings, modules) properly indented

Technical notes:

  • $exp recurses for nested arrays using depth counter
  • Scalar values still use var_export() for correct quoting
  • Both system.php and setup/index.php versions kept in sync

Всего: 1045 на 105 страницах по 10 на каждой странице

1 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 105
Хотите опробовать SLAED CMS в действии?
Идеи и предложения
Обратная связь
Подтверждение

Поделиться
QR-код