-
Website
http://brian.teeman.net/ -
Original page
http://brian.teeman.net/joomla-gps/automatic-joomla-updates.html -
Subscribe
All Comments -
Community
-
Top Commenters
-
ninjaforge
14 comments · 2 points
-
Phil Taylor
14 comments · 3 points
-
torkil
20 comments · 2 points
-
abtop
17 comments · 1 points
-
Dr_Who
19 comments · 2 points
-
-
Popular Threads
-
Stand up, Speak out! | Joomla GPS - brian.teeman.net
4 weeks ago · 48 comments
-
Joomla Community Xmas Carol | Mister Men - brian.teeman.net
2 weeks ago · 11 comments
-
Joomla Manual for Users | Bookshelf - brian.teeman.net
3 weeks ago · 14 comments
-
Radical Transparency | Tips and Tricks - brian.teeman.net
1 week ago · 3 comments
-
Stand up, Speak out! | Joomla GPS - brian.teeman.net
So we should explain to the average users that they shouldn't use output overrides.. or this is a responsability of the template builders?
joomla tells them to update for security purposes but they dont realise they have to update the template as well
And no, it's not pretty to fix, especially when dealing with fragmented custom templates.
The overrides change PHP behaviours which, in reality, should not be part of a template. Templates should stick to artwork, CSS and HTML (maybe a little JS), not behavioural changes inside PHP.
Studios and template farms use the overrides system to churn out templates quickly, without testing the quality and security of their own code in comparison to the security updates. And then get their clients breached because of it. I've had to clean up such messes.
Whilst overrides seem to be a good shortcut feature to better functionality, we are left with designers (who generally have little to no security knowledge about Joomla) hacking override templates to pieces, exposing new security holes.
The multiplication of work and effort in order to patch and secure everything due to the overrides also presents a quandary.
If it's creating more work at the expense of security, is the override system an overall positive or negative at the end of the day?
its ok that we have one Bug squad on Joomla that make one good work, but maybe for a Joomla they need MORE help, and give information about problems and how they solve, can help a bit better.
For now, at least on last releases, people do not have at least one page with more detalied changelog, that can avoid users start to think that maintain joomla up-to-date fast can simple make they a problem
Ideally, the view won't have anything BUT html markup and stay away from opening up the system from within the view.