Description
|
Tracking Number
|
Enhancements
|
|
Performance
|
|
Notifiers are now fired in their own threads so that directory group lookups used in permission checks do not delay display of articles.
|
cvs21606
|
Made email completion asynchronous to eliminate interface freezes due to directory server latency.
|
cvs21795
|
Security
|
|
Added a new Access permission that controls to whom the existence of projects is disclosed. Without access, even cross-labeled content will not appear.
|
cvs21183, cvs21245, cvs21262
|
For backward compatibility, by default Everyone is granted access to each project
|
cvs21193
|
Updated visibility interface to show users to whom content would be visible were they not denied access to the project.
|
cvs21447
|
Added a new content transformation framework to allow administrators to configure the transformations that are applied to incoming content, url parameters, etc. Using this framework, configured default transformations designed to prevent cross-site scripting attacks.
|
cvs21189
|
Removed CSS style overrides in document content. Style overrides are now written to external stylesheets.
|
cvs21126
|
Added option to include IP address in authentication token, to help prevent replay attacks
|
|
Display different message if user IP address changes
|
cvs21445
|
Feed manager now requires server admin permissions to view subscribed feeds
|
|
Don't allow visitor access to the collector
|
cvs21152
|
Don't allow visitor access to metrics views
|
cvs21156
|
Require server admin permissions before showing certain links
|
cvs21154
|
Directory Support
|
|
Added asynchronously updated group and principal caches that can be updated at a scheduled interval.
|
cvs21683
|
If a referral times out or an authorization error occurs while following a referral, ignore the error and continue.
|
cvs21202
|
Usernames can now be entirely numeric; numeric usernames are allowed by the page validators.
|
cvs21760
|
Active Directory
|
|
Filter out computer object class from lists
|
cvs21175
|
Hide the Sign In and Sign Out links when using NTLM
|
cvs21260, cvs21261
|
Added login caching for NTLM to preserve AD GUID in a session cookie to reduce load on AD server and delay in servicing requests
|
cvs21681
|
Added support for indirect lookups for improved AD group caching
|
cvs21764
|
Upgraded version of the JCIFS library to fix login issues
|
cvs21719
|
Allow the ldap_lookup_user and ldap_lookup_group properties to be configured and improved defaults.
|
cvs21793
|
LDAP
|
|
Reversed the order of filter terms from most to least specific to optimize query performance.
|
cvs21792
|
Usability
|
|
Removed erase from page options in context menu for Ocean, Earth, 2col, 3col, and Basic
|
cvs21310
|
Improved contrast in default Ocean stylesheet
|
cvs21552
|
Other
|
|
Outgoing http connections, e.
|
cvs21483
|
Feed reader now preserves publish date from the feed.
|
cvs21718
|
Instead of showing user details to all userrs but visitor, user details are now controlled based on the Access Address Book permission
|
|
Added selective cache clearing, so that certain operations do not cause complete cache refreshes
|
cvs21873
|
Allow auto image capture to be disabled for SOAP calls
|
cvs21787
|
SDL
|
|
Added support for refreshOpener=true/
|
cvs21150, cvs21155, cvs21157
|
Added support for accessing scaled width and scaled height in journalrequest blocks, so that changes to image display can take advantage of scaling behavior.
|
cvs21702
|
Admin
|
|
Fixed owner access
|
cvs21363, cvs21401
|
Links to logfiles now reference the file as well as the viewer, so that save target as works.
|
cvs21337
|
Bug Fixes
|
|
Traction no longer eats whitespace after tags, which could result in strange truncation after certain tags.
|
cvs21610
|
Fixed problem where words separated only by HTML content could be concatenated before being entered into fulltext index, resulting in missed search hits. An index rebuild corrects the problem.
|
cvs21648
|
Several compatibility improvements to Rich Text Editing
|
cvs21583, cvs21597, cvs21598,
|
Edit attachments dialog now works on IE 5.
|
cvs21595
|
Use the welcome message instead of the bad password message for new logins
|
cvs21139
|
Report friendly error if an attempt to post a personal note can not be handled because the user doesn't have a personal project
|
|
Fixed mechanism for defaulting to memory based fulltext index. If the default was chosen, the disk-based index may have been used, even though the interface indicated the memory based index was in use. Explicitly selecting memory-based always worked correctly.
|
cvs21756
|
Now PDF export prints entry-level comments in addition to item-level comments.
|
cvs21758
|
Removed references to unsupported viws
|
cvs21159, cvs21281
|
Fixed issue in search engine skin where permalinks were not used.
|
cvs21188
|
Fixed a problem where labels that had two spaces and a colon could cause problems for reclassification
|
cvs21838
|
Print version is only shown if the view file explicitly asks for it
|
cvs21625
|
Traction now itemizes DIV elements
|
cvs21770
|
Email completer now completes only on semicolon or space. Comma and space no longer accept a setting. This fixes completion on friendly names like "lastname, firstname".
|
cvs21839
|
To improve HTML cleanup, Traction ignores whitespace between consecutive BR tags.
|
cvs21771
|
In Principal Details, don't print that a Traction group is a member of itself
|
cvs21201
|
XML Encode email headers so that friendly names work correctly
|
cvs21870
|
Quickadmin does better input checking
|
cvs21858
|
In the related articles section, Traction ID's in the title are no longer omitted.
|
cvs21473
|
Fixed the default comment title when there is a single moderation project
|
cvs21626
|
Documentation
|
|
Updated online doc to include new features
|
|
Unbundled doc from installer
|
|
Bundled doc as a single PDF and, optionally, as separate PDFs
|
|
Improved context-sensitive help links
|
cvs21792
|