[pmwiki-users] A few more ZAP fixes...

The Editor editor at fast.st
Mon May 7 13:59:27 CDT 2007


After getting the last major security release out the door, I've been
able to go back and take the time to do a second round of code
examination, line by line, this time for various polishing kind of
stuff.  I discovered a few minor problems and released a few more
fixes with todays release.

Specifically:

Bugs (both fixed):
* The Site group security blocking code had a typo...
* The anchors were not working exactly as hoped...

Other changes
* Can now use target or datapage equally.
* Separated a pagefmt and a namefmt conditional
* Added target checking to create and delete
* The code command is now encode

I also annotated the code sporadically with comments on areas that
could still use some updating, could potentially be enhanced for
greater functionality, questions that need to be re-thought, possible
security vulnerabilities to be analyzed, etc.  Any experienced coders
that would like to glance through my notes and offer suggestions would
be appreciated.

// is my annotations
## is documentation

ZAP is about 400 lines and ZAPtoolbox nearly 1000. It's quite a bit of
functionality--but keeping everything humming along flawlessly is a
lot of work. As I learn more and more how to do this, it makes going
back and sweeping cobwebs out of all the corners more and more time
consuming. So help is welcome.

Cheers,
Dan

PS. I'm presuming all is well on the security front though I haven't
heard a trace from Pm since the last ZAP release.  No news is good
news???



More information about the pmwiki-users mailing list