What's New in Version 1.0
The following outlines the highlights of this debut version of Joomla! All comments are made in reference to Mambo 4.5.2.3 with regard to changes and improvements made.
Bug Fixes
Several crucial fixes have been applied to this version:
- You can now properly login to different sites even if they share the same domain and are nested in sub-directories.
- Slow queries in the User Manager have been corrected. This bug affected sites with thousands of registered users. Registered users (that don't have edit rights) are also excluded from the Author select list shown when editing content pages.
- Variable references that caused notices in PHP 4.4 have been fixed.
Check the CHANGELOG.php file for more information.
Security Fixes
Several important vulnerabilities have been patched in this version:
- Known vulnerabilities in the phpMailer class
- SQL injection vulnerability via the user activation feature
- SQL injection vulnerability via the polls component
- Files such as the CHANGELOG have been converted to PHP files to prevent them being visible.
- The "Email from Friend" form has been hardened to reduce the risk of it being used as a gateway for spam
- The mosGetParam has been hardened by using phpInputFilter for NO_HTML mode
- An alternative version of globals.php has been provided. If you rename globals.php-off to globals.php Joomla! will emulate the php setting register_globals=off. This affords some protection against certainly types of malicious attacks but may prevent some third party applications from working correctly.
Joomla! Site (Front End)
- The site is now visibile to Administrators even when the site is in Offline mode.
- Frontend Users can select the WYSIWYG editor they want to use rather than having to use the default.
Joomla! Administrator (Back End)
- The System Information link has been added back to the System Menu.
- "Force Logout" in the User Manager toolbar has been renamed to simply "Logout".
- "Submit - Content" is a new menu type available
- HTML output is now buffered to improve performance of non-display actions (like saving content)
- Users can select the WYSIWYG editor they want to use rather than having to use the default.
- Contact component: added parameter to define a certain category for a contact menu.
Templates
The Solar Flare 2 template has been freshened with the new name