<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>brian.teeman.net - Latest Comments in Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>http://brianteeman.disqus.com/</link><description>agree or disagree... i don't care</description><atom:link href="https://brianteeman.disqus.com/automatic_joomla_updates_joomla_gps_brianteemannet/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Fri, 26 Sep 2014 09:32:45 -0000</lastBuildDate><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-1606862898</link><description>&lt;p&gt;P.S. WordPress is better than Joomla! :-p&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Cinnamon Challenge</dc:creator><pubDate>Fri, 26 Sep 2014 09:32:45 -0000</pubDate></item><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-1606861228</link><description>&lt;p&gt;I disagree... and I don't care that you don't care. :-p&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Cinnamon Challenge</dc:creator><pubDate>Fri, 26 Sep 2014 09:31:20 -0000</pubDate></item><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-65177667</link><description>&lt;p&gt;I don't think I said you should wait at all.&lt;/p&gt;&lt;p&gt;What I was saying is that because of the way template overrides are done and that there can be issues with these overrides it is important to look and see what is being updated so that you can ensure that your site is correctly updated.&lt;/p&gt;&lt;p&gt;Otherwise you might be updating your site correctly but leaving it exposed to a vulnerability because you didnt upgrade the template overrides in your own template.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Brian Teeman</dc:creator><pubDate>Thu, 29 Jul 2010 18:32:26 -0000</pubDate></item><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-65176000</link><description>&lt;p&gt;I know this is an old post, but as the topic just came up again, I wanted to comment a little.&lt;/p&gt;&lt;p&gt;Brian - I totally agree that you need to check your overrides. But I can not see any reason to wait with any upgrade! Especially if you have made overrides.&lt;/p&gt;&lt;p&gt;I wish upgrades in Joomla where as easy as they are in WordPress. I was one of the people pushing hard for it and absolutely love it. Push the button and get the latests upgrades.&lt;/p&gt;&lt;p&gt;THEN - after the base has been upgraded, it is time to look at overrides to get them up to date as well.&lt;/p&gt;&lt;p&gt;I also agree with the comment that was made about not having things in templates that could lead to security problems. There should be a way to avoid this. Unfortunately, I am not a developer that can figure out that problem and I think it might be a difficult one to solve.&lt;/p&gt;&lt;p&gt;I have heard talk about automatic or easier updates in 1.6, but until now, nobody has said anything about it and I have not seen any blogposts about it. Should this not be on the list of functionality to test in a betacycle?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Svein Wisnaes</dc:creator><pubDate>Thu, 29 Jul 2010 18:20:06 -0000</pubDate></item><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-12167235</link><description>&lt;p&gt;Hit this issue so often it's not funny whilst consulting/contracting for other businesses.&lt;/p&gt;&lt;p&gt;And no, it's not pretty to fix, especially when dealing with fragmented custom templates.&lt;/p&gt;&lt;p&gt;The overrides change PHP behaviours which, in reality, should not be part of a template. Templates should stick to artwork, CSS and HTML (maybe a little JS), not behavioural changes inside PHP.&lt;/p&gt;&lt;p&gt;Studios and template farms use the overrides system to churn out templates quickly, without testing the quality and security of their own code in comparison to the security updates. And then get their clients breached because of it. I've had to clean up such messes.&lt;/p&gt;&lt;p&gt;Whilst overrides seem to be a good shortcut feature to better functionality, we are left with designers (who generally have little to no security knowledge about Joomla) hacking override templates to pieces, exposing new security holes.&lt;/p&gt;&lt;p&gt;The multiplication of work and effort in order to patch and secure everything due to the overrides also presents a quandary.&lt;/p&gt;&lt;p&gt;If it's creating more work at the expense of security, is the override system an overall positive or negative at the end of the day?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lawrence Meckan</dc:creator><pubDate>Sun, 05 Jul 2009 01:38:46 -0000</pubDate></item><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-12075245</link><description>&lt;p&gt;Yeh I know about the changes.  But that's my point is, if at all possible, there shouldn't be things in the view that would allow for these types of vulnerabilities. You're absolutely right about updating Joomla.  I use overrides extensively and have used the Beez overrides for many a site so it's annoying to have to go through that stuff.&lt;/p&gt;&lt;p&gt;Ideally, the view won't have anything BUT html markup and stay away from opening up the system from within the view.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Rick Blalock</dc:creator><pubDate>Fri, 03 Jul 2009 12:35:25 -0000</pubDate></item><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-12073959</link><description>&lt;p&gt;I Agree with thomas. Maybe if they put in some page some aspects that was changed on each release can help final users to pay atention in some special aspect, and provably give feedback more faster or even avoid problems.&lt;/p&gt;&lt;p&gt;its ok that we have one Bug squad on Joomla that make one good work, but maybe for a Joomla they need MORE help, and give information about problems and how they solve, can help a bit better.&lt;/p&gt;&lt;p&gt;For now, at least on last releases, people do not have at least one page with more detalied changelog, that can avoid users start to think that maintain joomla up-to-date fast can simple make they a problem&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Emerson Rocha Luiz</dc:creator><pubDate>Fri, 03 Jul 2009 11:23:01 -0000</pubDate></item><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-12073124</link><description>&lt;p&gt;Rick if you look at the template override changes in the last 2 releases of joomla you will see that both of them have modification to protect your site from xss and sql injection vulnerabilities&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Brian Teeman</dc:creator><pubDate>Fri, 03 Jul 2009 10:34:17 -0000</pubDate></item><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-12069181</link><description>&lt;p&gt;Meaning....it's a view....there shouldn't be any DB calls or the like in it.  Right?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Rick</dc:creator><pubDate>Fri, 03 Jul 2009 09:09:52 -0000</pubDate></item><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-12069170</link><description>&lt;p&gt;Perhaps the issue is template overrides should be made in a way that won't affect the security of the site.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Rick</dc:creator><pubDate>Fri, 03 Jul 2009 09:09:15 -0000</pubDate></item><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-12069083</link><description>&lt;p&gt;The issue I was trying to explain is that end users are using template overrides but most of them probably do not even realise that. They just download a template and use it.&lt;br&gt;joomla tells them to update for security purposes but they dont realise they have to update the template as well&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Brian Teeman</dc:creator><pubDate>Fri, 03 Jul 2009 09:03:17 -0000</pubDate></item><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-12068809</link><description>&lt;p&gt;I don't know the percentage of Joomla-Users that know what an SVN is. Do you think it is more than 10% ;-)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Kahl</dc:creator><pubDate>Fri, 03 Jul 2009 08:46:29 -0000</pubDate></item><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-12068676</link><description>&lt;p&gt;I agree especial for the more technical user. Personaly I always download a full copy of the new release and then do a diff against the previous version/&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Brian Teeman</dc:creator><pubDate>Fri, 03 Jul 2009 08:36:46 -0000</pubDate></item><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-12068483</link><description>&lt;p&gt;... that's why a more detailed changelog would be useful. You multiply the work that has to be done when every site-owner has to check for the changes on his own. It would be much better if the changelog would show exactly what was changed. A simple "Fixed issue 1234 in file abc.php" doesn't help much.&lt;br&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Kahl</dc:creator><pubDate>Fri, 03 Jul 2009 08:20:35 -0000</pubDate></item><item><title>Re: Automatic Joomla updates | Joomla GPS - brian.teeman.net</title><link>https://brian.teeman.net/joomla/192-automatic-joomla-updates#comment-12067202</link><description>&lt;p&gt;Thanks for the important advice with joomla updates and the template overides.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alexander Schmidt</dc:creator><pubDate>Fri, 03 Jul 2009 06:30:16 -0000</pubDate></item></channel></rss>