Line: 1 to 1 | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Changed: | |||||||||||||||||||
< < | TWiki Release 4.3.1 (Georgetown), 2009-04-29 | ||||||||||||||||||
> > | TWiki Release 4.3.2 (Georgetown), 2009-09-02 | ||||||||||||||||||
On this page:
Introduction | |||||||||||||||||||
Changed: | |||||||||||||||||||
< < | TWiki 4.3.0 released on 2009-03-30 introduces security enhancements, usability enhancements, feature enhancements, and adds extensions to strengthen TWiki as an enterprise collaboration platform. | ||||||||||||||||||
> > | TWiki-4.3.0 released on 2009-03-30 introduces security enhancements, usability enhancements, feature enhancements, and adds extensions to strengthen TWiki as an enterprise collaboration platform. | ||||||||||||||||||
Changed: | |||||||||||||||||||
< < | TWiki 4.3.1 released on 2009-04-29 introduces security enhancements. This release also introduces use of ISO date format by default. | ||||||||||||||||||
> > | TWiki-4.3.1 released on 2009-04-29 introduces security enhancements. This release also introduces use of ISO date format by default. | ||||||||||||||||||
Changed: | |||||||||||||||||||
< < | It is highly recommended to upgrade to TWiki 4.3.1. Users will find this release much more stable and secure in daily use. | ||||||||||||||||||
> > | TWiki-4.3.2 released on 2009-09-02 introduces security enhancements (CSRF fix). WYSIWYG editing is enhanced as well, the TinyMCEPlugin is upgraded with latest tinyMCE Javascript library.
It is highly recommended to upgrade to TWiki-4.3.2. Users will find this release much more stable and secure in daily use. | ||||||||||||||||||
Pre-installed Extensions | |||||||||||||||||||
Changed: | |||||||||||||||||||
< < | TWiki 4.3.1 is ships with: | ||||||||||||||||||
> > | TWiki-4.3.2 ships with: | ||||||||||||||||||
| |||||||||||||||||||
Added: | |||||||||||||||||||
> > | Note: HeadlinesPlugin, TWikiNetSkin and TWikiNetSkinPlugin are new in TWiki-4.3.0. | ||||||||||||||||||
New Features Highlights
| |||||||||||||||||||
Changed: | |||||||||||||||||||
< < |
| ||||||||||||||||||
> > |
| ||||||||||||||||||
| |||||||||||||||||||
Changed: | |||||||||||||||||||
< < |
| ||||||||||||||||||
> > |
| ||||||||||||||||||
| |||||||||||||||||||
Line: 43 to 48 | |||||||||||||||||||
See the full list of bug fixes at the bottom of this topic. | |||||||||||||||||||
Added: | |||||||||||||||||||
> > | Important Changes
1. Added protection against CSRF (cross-site request forgery) in TWiki 4.3.2 patch releaseTWiki protects content updates with a one-time-use crypt token to guard against CSRF exploits. This means that it is no longer possible to hit the browser back button to fix a typo; you get an "invalid crypt token" error message if you try to save again. Workaround: Instead of browser back button, hit the "Edit" button to fix a typo.
There is a balance between security and user convenience. A TWiki administrator can enable and disable the crypt token based CSRF protection with the | ||||||||||||||||||
Deprecation NoticesThe %MAINWEB% and %TWIKIWEB% variables have been deprecated. For compatibility reasons they are unlikely to ever be removed completely, but you should use the %USERSWEB% and %SYSTEMWEB% variables instead. | |||||||||||||||||||
Line: 82 to 95 | |||||||||||||||||||
Enhancements
| |||||||||||||||||||
Added: | |||||||||||||||||||
> > |
| ||||||||||||||||||
| |||||||||||||||||||
Line: 100 to 115 | |||||||||||||||||||
Fixes
| |||||||||||||||||||
Added: | |||||||||||||||||||
> > |
| ||||||||||||||||||
| |||||||||||||||||||
Line: 165 to 184 | |||||||||||||||||||
| |||||||||||||||||||
Added: | |||||||||||||||||||
> > | TWiki 4.3.2 Patch Release - Details
TWiki-4.3.2 was built from SVN http://svn.twiki.org/svn/twiki/branches/TWikiRelease04x03
Highlights
Enhancements
Fixes
| ||||||||||||||||||
<-- Note: Do not use TWikibug: interwiki links because interwiki rule might not be defined--> |